- Beka phambili umgaqo-nkqubo wokukhanyela ongagqibekanga kwaye usebenzise uluhlu olumhlophe lwe-SSH.
- Idibanisa i-NAT + ACL: ivula izibuko kunye nemida ngomthombo we-IP.
- Qinisekisa nge-nmap/ping kwaye uhloniphe umthetho ophambili ngokubaluleka (ID).
- Yomeleza ngohlaziyo, izitshixo ze-SSH, kunye neenkonzo ezincinci.
¿Indlela yokunqanda ukufikelela kwi-SSH kwi-router ye-TP-Link kwii-IP ezithembekileyo? Ukulawula ukuba ngubani onokufikelela kuthungelwano lwakho nge-SSH ayisiyonto, ngumaleko obalulekileyo wokhuseleko. Vumela ukufikelela kuphela kwiidilesi ze-IP ezithembekileyo Inciphisa indawo yokuhlaselwa, icothise ukuskena okuzenzekelayo, kwaye inqande iinzame zokungena rhoqo kwi-Intanethi.
Kulo khokelo olusebenzayo kunye nolubanzi uya kubona indlela yokwenza ngayo kwiimeko ezahlukeneyo kunye nezixhobo ze-TP-Link (i-SMB kunye ne-Omada), yintoni ekufuneka uyiqwalasele ngemithetho ye-ACL kunye ne-whitelists, kunye nendlela yokuqinisekisa ukuba yonke into ivaliwe ngokufanelekileyo. Sidibanisa iindlela ezongezelelweyo ezifana ne-TCP Wrappers, iptables, kunye neendlela ezifanelekileyo ukuze ukwazi ukukhusela okusingqongileyo ngaphandle kokushiya naziphi na iziphelo ezikhululekileyo.
Kutheni unciphisa ukufikelela kwe-SSH kwiirutha ze-TP-Link
Ukuveza i-SSH kwi-intanethi kuvula ucango lokutshayela okukhulu nge-bots esele inomdla ngenjongo ekhohlakeleyo. Akuqhelekanga ukubona izibuko ezingama-22 ezifikelelekayo kwi-WAN emva kokuskena, njengoko kubonwe kwi [imizekelo ye-SSH]. ukusilela okubalulekileyo kwiirotha ze-TP-Link. Umyalelo olula we-nmap ungasetyenziswa ukujonga ukuba idilesi yakho ye-IP yoluntu inezibuko 22 elivuliweyo.: yenza into enje kumatshini wangaphandle nmap -vvv -p 22 TU_IP_PUBLICA kwaye khangela ukuba "vula ssh" ivela.
Nokuba usebenzisa izitshixo zikawonke-wonke, ukushiya izibuko ezingama-22 zivulekile kumema ukuphononongwa ngakumbi, ukuvavanya amanye amazibuko, kunye neenkonzo zolawulo ezihlaselayo. Isisombululo sicacile: ukukhanyela ngokungagqibekanga kwaye unike amandla kuphela kwii-IPs ezivunyelweyo okanye uluhlu.Kukhethwa ukuba ilungiswe kwaye ilawulwe nguwe. Ukuba awufuni ulawulo olukude, lukhubaze ngokupheleleyo kwi-WAN.
Ukongeza ekuvezeni amazibuko, kukho iimeko apho unokukrokrela utshintsho lomgaqo okanye ukuziphatha okungaqhelekanga (umzekelo, imodem yentambo eqala "ukuwisa" i-traffic ephumayo emva kwexesha). Ukuba uqaphela ukuba i-ping, traceroute, okanye ukukhangela kubambekile kwimodem, jonga useto, i-firmware, kwaye ucinge ngokubuyisela useto lwasefektri. kwaye uvale yonke into ongayisebenzisiyo.
Imodeli yengqondo: vala ngokungagqibekanga kwaye wenze uluhlu olumhlophe
Ifilosofi ephumelelayo ilula: Ukungagqibeki khanyela umgaqo-nkqubo kunye nezinxaxhi ezicacileyoKwiirotha ezininzi ze-TP-Link ezinojongano oluphambili, ungacwangcisa i-drop-uhlobo lwenkqubo yokungena ekude kwifirewall, kwaye emva koko uvumele iidilesi ezithile kuluhlu olumhlophe lweenkonzo zolawulo.
Kwiinkqubo eziquka "Umgaqo-nkqubo woNgeniso olukude" kunye "nemithetho yoLuhlu olugunyazisiweyo" ukhetho (kwiNethiwekhi - kumaphepha eFirewall), Lahla uphawu kumgaqo-nkqubo wokungena okude Kwaye ungeze kuluhlu olumhlophe lwee-IP zoluntu kwifomathi ye-CIDR XXXX/XX ekufuneka ikwazi ukufikelela kuqwalaselo okanye iinkonzo ezifana ne-SSH/Telnet/HTTP(S). La mangeno angabandakanya inkcazelo emfutshane ukuphepha ukubhideka kamva.
Kubalulekile ukuqonda umahluko phakathi kweendlela. Ukuhanjiswa kwezibuko (i-NAT/DNAT) iphinda iqondise izibuko koomatshini be-LANNgoxa "imithetho yokucoca" ilawula i-WAN-to-LAN okanye i-traffic inter-network, i-firewall "Imithetho ye-Whitelist" ilawula ukufikelela kwinkqubo yokulawula ye-router. Imithetho yokucoca ayithinteli ukufikelela kwisixhobo ngokwaso; kuba, usebenzisa whitelists okanye imithetho ethile malunga traffic engenayo kumzila.
Ukufikelela kwiinkonzo zangaphakathi, imephu yezibuko yenziwa kwi-NAT kwaye emva koko kuthintelwe ngubani onokufikelela kuloo maphu evela ngaphandle. Iresiphi yile: vula izibuko eliyimfuneko kwaye emva koko unqande ngokulawula ukufikelela. evumela kuphela imithombo egunyazisiweyo ukuba idlule kwaye ithintele abanye.

I-SSH evela kwii-IP ezithembekileyo kwi-TP-Link SMB (ER6120/ER8411 kunye nezinye ezifanayo)
Kwii-router ze-SMB ezifana ne-TL-ER6120 okanye i-ER8411, ipateni eqhelekileyo yokuthengisa inkonzo ye-LAN (umzekelo, i-SSH kumncedisi wangaphakathi) kunye nokunciphisa ngomthombo we-IP zigaba ezimbini. Okokuqala, izibuko livulwa nge-Virtual Server (NAT), kwaye emva koko ihluzwe ngoLawulo lokuFikelela. ngokusekelwe kumaqela e-IP kunye neentlobo zenkonzo.
Inqanaba loku-1-Umncedisi weVirtual: yiya ku Ikwinqanaba eliphezulu → NAT → Iseva Ebonakalayo kwaye yenza ingeniso yojongano oluhambelanayo lweWAN. Qwalasela izibuko zangaphandle ezingama-22 kwaye zikhombe kwidilesi ye-IP yangaphakathi yomncedisi (umzekelo, 192.168.0.2:22)Gcina umthetho ukuwudibanisa kuluhlu. Ukuba imeko yakho isebenzisa izibuko eyahlukileyo (umzekelo, utshintshe i-SSH ukuya ku-2222), lungisa ixabiso ngokufanelekileyo.
Inqanaba lesi-2 – Uhlobo lwenkonzo: ngena Ezikhethwayo → Uhlobo lweNkonzo, yenza inkonzo entsha ebizwa, umzekelo, SSH, khetha TCP okanye TCP/UDP kwaye uchaze izibuko lendawo ekuyiwa kuyo 22 (uluhlu lwezibuko lomthombo lunokuba ngu-0–65535). Lo maleko uya kukuvumela ukuba ubhekisele kwizibuko ngokucocekileyo kwi-ACL.
Isigaba 3 - IP Group: yiya ku Ezikhethwayo → Iqela le-IP → Idilesi ye-IP kwaye wongeze amangeno awo omabini umthombo ovunyelweyo (umzekelo, IP yakho yoluntu okanye uluhlu, olunegama "Ufikelelo_Umxhasi") kunye nomthombo wendawo (umzekelo "SSH_Umncedisi" nge-IP yangaphakathi yomncedisi). Emva koko udibanise idilesi nganye kunye neQela le-IP elihambelanayo ngaphakathi kwimenyu enye.
Isigaba sesi-4 – Ulawulo lofikelelo: kwi Udonga lomlilo → Ulawulo lokuFikelela Yenza imithetho emibini. 1) Vumela uMthetho: Vumela umgaqo-nkqubo, inkonzo esanda kuchazwa "SSH", Umthombo = iqela le-IP "Access_Client" kunye nendawo = "SSH_Server". Yinike i-ID 1. 2) Umgaqo wokuthintela: umgaqo-nkqubo weBlock nge umthombo = IPGROUP_ANY kunye nendawo = "SSH_Server" (okanye njengoko kusebenza) nge-ID 2. Ngale ndlela, kuphela i-IP ethembekileyo okanye uluhlu luya kuhamba nge-NAT kwi-SSH yakho; ezinye ziya kuthintelwa.
Ulandelelwano lovavanyo lubalulekile. Izazisi ezisezantsi zithatha indawo yokuqalaNgoko ke, umgaqo ovunyelweyo kufuneka wandulele (i-ID esezantsi) umthetho weBloko. Emva kokufaka utshintsho, uya kukwazi ukuxhuma kwidilesi ye-WAN ye-IP ye-router kwi-port echazwe kwidilesi ye-IP evunyelweyo, kodwa uxhulumaniso oluvela kweminye imithombo luya kuvalwa.
Amanqaku omzekelo/i-firmware: Ujongano lunokwahluka phakathi kwehardware kunye neenguqulelo. I-TL-R600VPN ifuna i-hardware v4 ukugubungela imisebenzi ethileKwaye kwiinkqubo ezahlukeneyo, iimenyu zinokufuduswa. Nangona kunjalo, ukuhamba kuyafana: uhlobo lwenkonzo → amaqela e-IP → ACL ene-Vumela kwaye Block. Sukulibala gcina kwaye ufake isicelo ukuze imithetho isebenze.
Ukuqinisekiswa okuCetyisiweyo: Ukusuka kwidilesi ye-IP egunyazisiweyo, zama ssh usuario@IP_WAN kwaye uqinisekise ukufikelela. Ukusuka kwenye idilesi ye-IP, izibuko kufuneka ingafikeleleki. (unxibelelwano olungafikiyo okanye olukhatywayo, ngokufanelekileyo ngaphandle kwebhena ukuphepha ukunika imikhondo).
I-ACL ene-Omada Controller: Uluhlu, States, kunye neMizekeliso yeMizekeliso
Ukuba ulawula amasango e-TP-Link kunye noMlawuli we-Omada, ingqiqo iyafana kodwa inokhetho olubonakalayo. Yenza amaqela (IP okanye amazibuko), chaza isango le-ACLs, kwaye uququzelele imithetho ukuvumela ubuncinci obuncinci kwaye ukhanyele yonke enye into.
Uluhlu kunye namaqela: kwi Useto → Iiprofayili → Amaqela Unokwenza amaqela e-IP (ii-subnets okanye iinginginya, ezifana ne-192.168.0.32/27 okanye 192.168.30.100/32) kunye namaqela ezibuko (umzekelo, i-HTTP 80 kunye ne-DNS 53). La maqela ayenza lula imithetho entsonkothileyo ngokusebenzisa kwakhona izinto.
Isango ACL: kwi Uqwalaselo → Ukhuseleko lwenethiwekhi → ACL Yongeza imithetho nge-LAN→WAN, LAN→LAN okanye WAN→indlela yeLAN ngokuxhomekeke kwinto ofuna ukuyikhusela. Umgaqo-nkqubo womgaqo ngamnye unokuvunyelwa okanye uYale. kwaye umyalelo umisela isiphumo sokwenene. Khangela "Yenza" ukuze zisebenze. Ezinye iinguqulelo zikuvumela ukuba ushiye imithetho elungiselelwe kwaye ivaliwe.
Iimeko eziluncedo (ezinokulungelelaniswa kwi-SSH): vumela kuphela iinkonzo ezithile kwaye uvimbele ezinye (umzekelo, Vumela i-DNS kunye ne-HTTP kwaye uYale Konke). Kubaphathi abamhlophe, yenza i-Vumela kwii-IP ezithembekileyo ukuya "kwiPhepha loLawulo lweGateway" kwaye ke ukukhanyela ngokubanzi ukusuka kwezinye iinethiwekhi. Ukuba i-firmware yakho inaloo ndlela. Eya kumacala amabiniUnokwenza ngokuzenzekelayo umgaqo oguquliweyo.
Ubume boQhagamshelwano: Ii-ACL zinokuthi zichaze. Iindidi eziqhelekileyo ziNtsha, zisekiwe, eziNxulumeneyo, kunye nezingasebenziyo"Entsha" iphatha ipakethi yokuqala (umzekelo, i-SYN kwi-TCP), "Isekiwe" iphatha i-traffic edityaniswe ne-bidirectional ngaphambili, i-"Related" iphatha imidibaniso exhomekeke (efana namajelo edatha e-FTP), kunye ne-"Invalid" iphatha i-traffic engaqhelekanga. Kungcono kakhulu ukugcina useto olungagqibekanga ngaphandle kokuba ufuna ubumbuku obongezelelweyo.
I-VLAN kunye nokwahlulahlula: Inkxaso ye-Omada kunye ne-SMB routers Unidirectional kunye neemeko ezimbini phakathi kweVLANUnakho ukubhloka iNtengiso→R&D kodwa uvumele iR&D→Intengiso, okanye uthintele imikhombandlela yomibini kwaye ugunyazise umlawuli othile. I-LAN→ isalathiso seLAN kwi-ACL isetyenziselwa ukulawula i-traffic phakathi kwee-subnets zangaphakathi.

Iindlela ezongezelelweyo kunye nokuqinisa: I-TCP Wrappers, iptables, iMikroTik kunye ne-firewall yakudala
Ukongeza kwii-ACL ze-router, kukho ezinye iileya ezifanele ukusetyenziswa, ngakumbi ukuba indawo ye-SSH yiseva ye-Linux emva komzila. I-TCP Wrappers ivumela ukuhluzwa nge-IP nge-hosts.allow kunye ne-hosts.deny kwiinkonzo ezihambelanayo (kuquka i-OpenSSH kuqwalaselo oluninzi lwemveli).
Iifayile zokulawula: ukuba azikho, zidale nge sudo touch /etc/hosts.{allow,deny}. Eyona ndlela ilungileyo: khanyela yonke into ekwi host.deny kwaye ivumela ngokucacileyo kumamkeli.vumela. Umzekelo: kwi /etc/hosts.deny iphe sshd: ALL nangaphakathi /etc/hosts.allow yongeza sshd: 203.0.113.10, 198.51.100.0/24Ke, ezo IPs kuphela eziya kukwazi ukufikelela kwidaemon ye-SSH yomncedisi.
Iiptables eziqhelekileyo: Ukuba i-router yakho okanye iseva iyayivumela, yongeza imithetho eyamkela kuphela i-SSH kwimithombo ethile. Umgaqo oqhelekileyo uya kuba: -I INPUT -s 203.0.113.10 -p tcp --dport 22 -j ACCEPT ilandelwa ngumgaqo-nkqubo we-DROP ongagqibekanga okanye umgaqo ovimba intsalela. Kwiirotha ezinethebhu ye Imithetho yesiko Unako ukutofa le migca kwaye uyisebenzise ngo "Gcina & Faka".
Eyona ndlela ilungileyo kwiMikroTik (esebenzayo njengesikhokelo ngokubanzi): tshintsha amazibuko angagqibekanga ukuba kunokwenzeka, vula iTelnet (sebenzisa kuphela i-SSH), sebenzisa amagama ayimfihlo anamandla okanye, ngcono noko, uqinisekiso olungundoqoNciphisa ukufikelela ngedilesi ye-IP usebenzisa i-firewall, yenza i-2FA ukuba isixhobo siyayixhasa, kwaye ugcine i-firmware/i-RouterOS isexesheni. Khubaza ufikelelo lwe-WAN ukuba awuyifuniIbeka iliso kwiinzame ezisileleyo kwaye, ukuba kukho imfuneko, isebenzisa imida yoqhagamshelo ukunqanda uhlaselo olungenalusini.
I-TP-Link Classic Interface (iFirmware eNdala): Ngena kwiqela lenjongo usebenzisa idilesi ye-IP ye-LAN (ehlala ikho 192.168.1.1) kunye neziqinisekiso zolawulo/zolawulo, emva koko uye ku Ukhuseleko → Udonga lomliloYenza isihluzi se-IP kwaye ukhethe ukuba neepakethi ezingachazwanga zilandele umgaqo-nkqubo ofunekayo. Emva koko, kwi Uhluzo lwedilesi yeIP, cofa "Yongeza entsha" kwaye uchaze apho ii-IPs zinako okanye azinakusebenzisa izibuko lenkonzo kwi-WAN (ye-SSH, 22/tcp). Gcina inyathelo ngalinye. Oku kukuvumela ukuba ufake isicelo sokukhanyela ngokubanzi kwaye wenze okungafaniyo ukuvumela kuphela ii-IP ezithembekileyo.
Vimba ii-IP ezithile kunye neendlela ezimileyo
Kwezinye iimeko luncedo ukuvala ukuphuma kwii-IP ezithile ukuphucula uzinzo kunye neenkonzo ezithile (ezifana nokusasaza). Enye indlela yokwenza oku kwizixhobo ezininzi ze-TP-Link kukuhamba ngendlela engatshintshiyo., ukudala / iindlela ze-32 ezinqanda ukufikelela kwezo ndawo zokuya kuzo okanye ziqondise ngendlela yokuba zingadli ngendlela engagqibekanga (inkxaso iyahluka nge-firmware).
Iimodeli zamva nje: yiya kwithebhu Ikwinqanaba eliPhambili → Uthungelwano → Umzila okwiNdlela eNgqongileyo → uNdlela ongatshintshiyo kwaye cinezela "+ Yongeza". Ngena "INdawo yokuFikela kwiNethiwekhi" kunye nedilesi ye-IP ukubhloka, "I-Subnet Mask" 255.255.255.255, "Isango eliMiselweyo" isango le-LAN (ngokuqhelekileyo 192.168.0.1) kunye ne-"Interface" LAN. Khetha "Vumela olu ngeniso" kwaye ugcinePhinda kwidilesi nganye ye-IP ekujoliswe kuyo ngokuxhomekeke kwinkonzo ofuna ukuyilawula.
Iifirmware ezindala: yiya ku Indlela ekwinqanaba eliphezulu → Uluhlu lwendlela engatshintshiyo, cofa "Yongeza entsha" kwaye ugcwalise iindawo ezifanayo. Vula imo yendlela kwaye ugcineQhagamshelana nenkxaso yenkonzo yakho ukufumanisa ukuba zeziphi ii-IP onokuzinyanga, njengoko zinokutshintsha.
Ukuqinisekisa: Vula i-terminal okanye i-prompt yomyalelo kwaye uvavanye nge ping 8.8.8.8 (okanye iIP yendawo oyivalile). Ukuba ubona u-"Timeout" okanye "Indawo ekufikelelwa kuyo ayifikeleleki"Ukubhloka kuyasebenza. Ukuba akunjalo, hlaziya amanyathelo kwaye uqalise kwakhona i-router ukuze zonke iitafile zisebenze.
Ukuqinisekiswa, uvavanyo, kunye nesisombululo sesiganeko
Ukuqinisekisa ukuba uluhlu lwakho olumhlophe lwe-SSH luyasebenza, zama ukusebenzisa idilesi ye-IP egunyazisiweyo. ssh usuario@IP_WAN -p 22 (okanye izibuko olisebenzisayo) kwaye uqinisekise ufikelelo. Ukusuka kwidilesi ye-IP engagunyaziswanga, ichweba akufanele linikeze ngenkonzo.. i-USA nmap -p 22 IP_WAN ukujonga imeko eshushu.
Ukuba kukho into engaphenduliyo njengoko kufanele, khangela i-ACL ephambili. Imithetho icutshungulwa ngokulandelelana, kwaye abo bane-ID ephantsi baphumelele.Ukwala ngentla kwe-Vumela yakho kwenza uluhlu olumhlophe lungasebenzi. Kwakhona, khangela ukuba "uHlobo lweNkonzo" lukhomba kwizibuko elichanekileyo kwaye "Amaqela e-IP" akho aqulethe uluhlu olufanelekileyo.
Kwimeko yokuziphatha okukrokrisayo (ukulahleka konxibelelwano emva kwexesha, imithetho eguqukayo yodwa, i-LAN traffic eyehlayo), qwalasela hlaziya i-firmwareKhubaza iinkonzo ongazisebenzisiyo (iwebhu ekude/iTelnet/SSH), tshintsha iziqinisekiso, jonga i-cloning ye-MAC ukuba iyasebenza, kwaye ekugqibeleni, Buyisela useto lwefektri kwaye uhlengahlengise ngoseto oluncinci kunye noluhlu olungqongqo olumhlophe.
Ukuhambelana, iimodeli, kunye namanqaku okufumaneka
Ubukho beempawu (ii-ACL ezixeliweyo, iinkangeleko, uluhlu lwabamhlophe, ukuhlelwa kwePVID kumazibuko, njl.njl.) Inokuxhomekeka kwimodeli yehardware kunye noguquleloKwezinye izixhobo, ezifana ne-TL-R600VPN, amandla athile afumaneka kuphela ukusuka kwinguqulo yesi-4 ukuya phambili. Ujongano lomsebenzisi nalo luyatshintsha, kodwa inkqubo esisiseko iyafana: ukubhloka ngokungagqibekanga, chaza iinkonzo kunye namaqela, vumela kwii-IP ezithile kwaye uvimbele ukuphumla.
Ngaphakathi kwe-TP-Link ecosystem, kukho izixhobo ezininzi ezibandakanyekayo kuthungelwano lwamashishini. Iimodeli ezikhankanywe kumaxwebhu zibandakanya T1600G-18TS, T1500G-10PS, TL-SG2216, T2600G-52TS, T2600G-28TS, TL-SG2210P, T2500-28TC, T2700G-28TQ, T2500G-15TS,10TS,1 T2600G-28MPS, T1500G-10MPS, SG2210P, S4500-8G, T1500-28TC, T1700X-16TS, T1600G-28TS, TL-SL3452, TL-SG3216, T57T000G T1700G-28TQ, T1500-28PCT, T2600G-18TS, T1600G-28PS, T2500G-10MPS, Festa FS310GP, T1600G-52MPS, T1600G-52PS, T1600G-28PS, T2500G-10MPS. T3700G-28TQ, T1500G-8T, T1700X-28TQphakathi kwabanye. Gcina engqondweni oko Unikezelo luyahluka ngokwengingqi. kwaye ezinye zisenokungafumaneki kwindawo yakho.
Ukuhlala usexesheni, ndwendwela iphepha lenkxaso yemveliso yakho, khetha uhlobo oluchanekileyo lwehardware, kwaye ujonge amanqaku firmware kunye neenkcukacha zobugcisa ngophuculo lwamva nje. Ngamanye amaxesha uhlaziyo lwandisa okanye lucokise i-firewall, i-ACL, okanye iimpawu zolawulo olukude.
Vala i SSH Kuzo zonke kodwa ii-IPs ezithile, ukulungelelanisa ngokufanelekileyo ii-ACL kunye nokuqonda ukuba yeyiphi indlela elawula into nganye kukusindisa kwizinto ezothusayo ezingathandekiyo. Ngomgaqo-nkqubo wokukhanyela omiselweyo, uluhlu olumhlophe oluchanekileyo, kunye nokuqinisekiswa rhoqoUmzila wakho we-TP-Link kunye neenkonzo ezisemva kwayo ziya kukhuselwa ngcono kakhulu ngaphandle kokuyeka ulawulo xa ulufuna.
Ukuthanda itekhnoloji ukusukela esemncinci. Ndiyakuthanda ukuhlala unolwazi kweli candelo kwaye, ngaphezu kwako konke, ukunxibelelana nalo. Yiyo loo nto ndizinikele kunxibelelwano lwetekhnoloji kunye neewebhusayithi zomdlalo wevidiyo iminyaka emininzi ngoku. Ungandifumana ndibhala malunga ne-Android, iWindows, iMacOS, i-iOS, iNintendo okanye nasiphi na esinye isihloko esihambelanayo esiza engqondweni.

