WEBVTT

00:09.060 --> 00:15.190
Hello friends welcome back in this section we're going to talk about different ways to protest or do

00:15.190 --> 00:15.690
so.

00:15.700 --> 00:18.910
OK we're going to learn different ways to protect our work.

00:18.910 --> 00:23.240
So we're against hacker attacks or against an art that is Rexus.

00:23.360 --> 00:23.860
OK.

00:24.250 --> 00:31.450
So in this lesson I'm going to show you how to set up and you have w firewall by setting up your firewall

00:31.450 --> 00:33.390
you can't protect your server.

00:33.550 --> 00:34.020
OK.

00:34.180 --> 00:36.940
From an advisory or IP addresses.

00:36.970 --> 00:37.360
OK.

00:37.450 --> 00:41.600
Or you can allow all the connections for only particular ports.

00:41.620 --> 00:42.090
OK.

00:42.370 --> 00:46.640
So let's see practically hope to set up a new firewall.

00:47.180 --> 00:51.010
OK you know stands for uncomplicate firewall OK.

00:51.010 --> 00:54.580
It is the most popular firewall in the school.

00:54.940 --> 00:59.440
And that's why it comes by default in Linux distributions.

00:59.450 --> 00:59.930
OK.

01:00.190 --> 01:06.820
So you don't need to install in this Ubuntu server distribution by default it comes in this package

01:07.110 --> 01:13.870
only in some cases if you want to install it just takes sudo is stolen.

01:14.010 --> 01:18.170
You have to install the firewall.

01:18.460 --> 01:21.360
You can only see how to use this firewall.

01:21.850 --> 01:26.280
OK first of all you should check the status of the firewall.

01:26.560 --> 01:33.530
So check the status this type Sudol w status.

01:33.730 --> 01:34.030
OK.

01:34.060 --> 01:40.250
Right now it says actually this will shows you the current status of the blue firewall.

01:40.280 --> 01:41.130
OK.

01:42.340 --> 01:48.400
If you want to disable the firewall in some situations then you can simply disable it by sudo.

01:48.400 --> 01:52.750
You have to disable it it takes some time.

01:53.100 --> 01:53.420
OK.

01:53.440 --> 01:55.780
And not the status.

01:56.290 --> 01:58.310
OK right now it is inactive.

01:58.720 --> 02:07.230
And if you want to enable it then just type in invoke again take the status.

02:07.820 --> 02:12.860
Right now it's easy to get in this way you can disable enable the firewall.

02:12.950 --> 02:13.450
OK.

02:13.550 --> 02:17.820
In some situation you need to reload all the rules of the firewall.

02:17.870 --> 02:18.190
OK.

02:18.200 --> 02:25.500
So in those situations you just need to simply type sudo with W reload key.

02:25.560 --> 02:30.270
It didn't and now it says firewall reloaded.

02:30.350 --> 02:36.180
OK in this way you can perform these basic operations with this new firewall.

02:36.680 --> 02:44.310
The next operation that I would like to show you is how to allow calls or IP addresses from the firewall.

02:44.870 --> 02:45.380
OK.

02:45.710 --> 02:53.510
Let's talk about if you want to allow some particular ports on your server OK if you follow some connections

02:53.810 --> 02:55.170
on a particular call.

02:55.270 --> 02:55.860
OK.

02:56.130 --> 03:01.560
Then in this condition you use to type sudo if you have to do a lot.

03:01.730 --> 03:02.240
OK.

03:02.420 --> 03:06.600
And I want to allow the connections on what we're going get to.

03:06.620 --> 03:08.790
People generally used by.

03:08.930 --> 03:09.590
OK.

03:09.650 --> 03:14.670
All we learned in the last lessons about how to set up the assets is OK.

03:14.860 --> 03:18.620
So I want connections outside connections on this board.

03:18.710 --> 03:23.070
Then I can simply type like this and hit enter.

03:23.500 --> 03:24.030
OK.

03:24.330 --> 03:28.470
And after adding in this rule you can check the status.

03:29.190 --> 03:29.600
OK.

03:29.660 --> 03:32.830
After writing the rule you can see we got a different status.

03:33.020 --> 03:33.570
OK.

03:33.680 --> 03:38.430
In this way you can check the rules by status.

03:38.480 --> 03:38.980
OK.

03:39.980 --> 03:45.480
OK like the port number we can also add in particular IP address to connect on our server.

03:45.740 --> 03:51.050
So for that just helps slow if you allow from.

03:51.100 --> 03:54.690
OK if I want a connection from 1 9.

03:54.780 --> 04:01.610
Got 1 6 8 0 0 0 1 true added.

04:02.240 --> 04:04.090
Then check the status.

04:04.630 --> 04:04.950
OK.

04:04.970 --> 04:08.870
Now here you can see at line number two we have over rule.

04:09.010 --> 04:09.380
OK.

04:09.410 --> 04:17.270
That means this IP addresses are allowed on our server to connect OK like this we can't allow an particular

04:17.360 --> 04:20.840
IP address a no particular order only.

04:21.050 --> 04:21.440
OK.

04:21.530 --> 04:29.980
So what you need to do for that Sudol w love from.

04:30.770 --> 04:41.030
1 9 2 you got 1 6 8 0 1 and I want this IP address to connect only for granted.

04:41.240 --> 04:41.520
OK.

04:41.540 --> 04:53.230
So just like any port 22 this IP is allowed only on port number 22 after this rule did did the status.

04:54.090 --> 04:58.000
This way we cannot allow any IP addresses in this V.

04:58.300 --> 04:58.740
OK.

04:59.030 --> 05:00.750
And after allowing.

05:00.980 --> 05:04.740
We can also deny support or IP addresses.

05:05.030 --> 05:08.440
So you deny in particular for just pipes.

05:08.480 --> 05:10.860
You have to keep the key.

05:10.940 --> 05:16.550
And if I want to deny Port Authority or give partner we're used to private service we're talking all

05:16.550 --> 05:20.000
we have learned in the previous lesson.

05:20.010 --> 05:22.250
He to OK.

05:22.280 --> 05:26.940
He says really did exist sturgeons.

05:27.050 --> 05:27.730
OK.

05:29.900 --> 05:33.540
And you can also deny in particular IP.

05:33.590 --> 05:44.110
So for that just the night from 1 9 4 1 6 0 1 0 0 0 Google kid.

05:45.630 --> 05:47.440
His rule added means.

05:47.450 --> 05:54.640
Suppose there is some hacker who was trying to hack a server and then you can grab that hackers IP address

05:54.640 --> 06:00.700
and you can block that hacker from connecting to a surrogate by this one.

06:01.030 --> 06:01.560
OK.

06:01.690 --> 06:08.260
Alavi and denying the IP and port numbers I want to show you how good the lead the rules that we have

06:08.470 --> 06:09.680
added.

06:10.090 --> 06:14.930
So there are movies by which you can delete the rules in the firewall.

06:15.010 --> 06:17.750
OK number one is with the help off number.

06:18.130 --> 06:19.960
And number two is Vittal off.

06:19.990 --> 06:20.590
Come on.

06:20.710 --> 06:21.010
OK.

06:21.010 --> 06:23.700
So let's see how you do this.

06:23.750 --> 06:30.710
OK first just type sudo status number one.

06:31.080 --> 06:35.020
OK get this view uses the numbers for each room.

06:35.050 --> 06:35.360
OK.

06:35.380 --> 06:39.190
So the numbers from 1 to 7 for each rule.

06:39.280 --> 06:39.780
OK.

06:40.060 --> 06:41.740
And I want to delete.

06:41.740 --> 06:44.770
Rule number two here so read that.

06:44.810 --> 06:55.660
So you have to delete and enter the number here in Atlanta to my Ok it is related.

06:55.660 --> 06:57.680
Again take the status.

06:57.990 --> 07:02.470
Now we have only six rules here with six numbers.

07:02.680 --> 07:03.250
OK.

07:03.430 --> 07:06.700
This is the first mail by which we can delete it rule.

07:06.910 --> 07:07.220
OK.

07:07.250 --> 07:12.950
The second way is from common means so you need to know how you entered the command.

07:12.940 --> 07:13.550
OK.

07:13.990 --> 07:21.630
So to delete I suppose who'll hear sudo if you get delete.

07:21.720 --> 07:22.630
You need to type that.

07:22.630 --> 07:29.670
Come on I mean suppose we have added allowing port number 22 for IP address 1 9 2 and 6.

07:30.070 --> 07:38.970
So here sudo you have w delete allow from one line.

07:39.130 --> 07:41.430
Once you've got 0 1

07:45.400 --> 07:49.800
we're going to hit enter again later.

07:49.930 --> 07:53.480
This is the second way for deleting the rule in the file.

07:53.560 --> 07:56.930
Ok you need to have that come on like this.

07:57.230 --> 07:58.400
OK.

07:58.930 --> 07:59.230
OK.

07:59.230 --> 08:04.140
In this way you can add the rules or delete the rules looking in the firewall.

08:04.160 --> 08:04.700
OK.

08:04.720 --> 08:08.940
All this depends on your requirement for a server.

08:09.160 --> 08:11.930
What you want to do with your server.

08:12.490 --> 08:19.660
Ok after doing all this there are some situations where you need to reset your firewall background you

08:19.680 --> 08:20.490
know status.

08:20.500 --> 08:21.160
OK.

08:21.190 --> 08:31.740
So in such situations what you need to do is just pseudo cop you can type reset and you don't get into

08:31.750 --> 08:37.500
why look at this reset the firewall back group's original status.

08:37.630 --> 08:46.540
In this way you can use this firewall and secure your Ubuntu server from that has real users OK or an

08:46.610 --> 08:48.740
authorized IP addresses.
