Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
P
project_operation
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
chenzy
project_operation
Commits
76faf0f3
Commit
76faf0f3
authored
Feb 26, 2025
by
chenzy
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
[新增]ES访问风险处理,防火墙限制方法
parent
fa4c4ed2
Show whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
19 additions
and
0 deletions
+19
-0
ES访问风险处理.txt
ES访问风险处理.txt
+19
-0
No files found.
ES访问风险处理.txt
0 → 100644
View file @
76faf0f3
1. ES风险处理
1. ES风险处理
有两种解决方式,一种是用防火墙,一种是nginx代理接口访问
nginx的在集群环境下数据同步会有问题,所以这里只写防火墙处理方法
方案一:用防火墙,控制一些服务器能访问es主机,达到其它用户不能通过9200和9300端口随意操作数据库的目的
开启防火墙启用白名单
# 检查防火墙状态,如果没有开启则开启
systemctl status firewalld
# 设置开机启动防火墙
systemctl enable firewalld
# 启动防火墙
systemctl start firewalld
# 设置白名单
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="后端服务IP" port protocol="tcp" port="1-65535" accept"
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="后端服务IP" port protocol="tcp" port="1-65535" accept"
firewall-cmd --permanent --add-rich-rule="rule family="ipv4" source address="后端服务IP" port protocol="tcp" port="1-65535" accept"
# 重启防火墙
systemctl restart firewalld
\ No newline at end of file
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment