Подскажите, пожалуйста, что означает вот это:
# nmap -sU -p 631 mydomain Starting Nmap 7.93 ( https://nmap.org ) at 2024-10-01 20:36 UTC Nmap scan report for mydomain (mydomain) Host is up (0.051s latency). PORT STATE SERVICE 631/udp open|filtered ipp
Закрыт или не закрыт порт 631 в iptables?
Закрывал (в связи с уязвимостью) так:
# reject all iptables -F iptables -X iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -P FORWARD DROP #accept all for 127.0.0.1 iptables -A INPUT -s 127.0.0.1 -j ACCEPT iptables -A OUTPUT -s 127.0.0.1 -j ACCEPT iptables -A INPUT -d 127.0.0.1 -j ACCEPT iptables -A OUTPUT -d 127.0.0.1 -j ACCEPT #deny connect to localhost from non localhost addresses iptables -A INPUT -s 127.0.0.1/255.0.0.0 ! -i lo -j DROP # Allow already established connections iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT #accept all incoming tcp port, exclude 631 iptables -A INPUT -p tcp -m multiport --dports 631 -j DROP iptables -A INPUT -p tcp -m multiport --sports 631 iptables -A INPUT -p tcp -j ACCEPT #accept all outgoing tcp port, exclude 631 iptables -A OUTPUT -p tcp -m multiport --dports 631 -j DROP iptables -A OUTPUT -p tcp -m multiport --sports 631 -j DROP iptables -A OUTPUT -p tcp -j ACCEPT #accept all incoming udp port, exclude 631 iptables -A INPUT -p udp -m multiport --dports 631 -j DROP iptables -A INPUT -p udp -m multiport --sports 631 -j DROP iptables -A INPUT -p udp -j ACCEPT #accept all outgoing udp port, exclude 631 iptables -A OUTPUT -p udp -m multiport --dports 631 -j DROP iptables -A OUTPUT -p udp -m multiport --sports 631 -j DROP iptables -A OUTPUT -p udp -j ACCEPT