1 Permanently close SELinux, modify to permissive or disabled (recommended), modify the need to restart
2 Configuring Network
3. Disable ping (optional, generally do not need to prohibit) (default is 0-bit enable ICMP protocol, 1 is forbidden), no restart required after modification
- [[email protected] ipv4]# echo "1" >/proc/sys/net/ipv4/icmp_echo_ignore_all
Or add a sysctl.conf in the
- [Email protected] ~]# echo "net.ipv4.icmp_echo_ignore_all=1" >>/etc/sysctl.conf
- [Email protected] ~]# tail-1/etc/sysctl.conf
- Net.ipv4.icmp_echo_ignore_all=1
- [Email protected] ~]# sysctl-p
(optional) Display the message after logging in, enter the information that needs to be displayed after login
- [Email protected] ~]# echo "It is product Environment,be careful ..." >/ETC/MOTD
5. Modify the default SSH settings to increase system security
Backing Up Sshd_config files
[email protected] ssh]# cp/etc/ssh/sshd_config/etc/ssh/sshd_config.bak.20150915
Modify the following configuration
- //Modify the default port for SSH remote connection;
- #Port 22
- Modify to
- port 2510 port number to specify
-
- //ssh does not allow root user login
- #PermitRootLogin yes
- Modify to
- PERMITROOTLOGIN NO  
-
- //resolves the problem of slow DNS resolution   
- #UseDNS yes
- modified to
- usedns no
-   
- //Resolve ssh slow problem
- #GSSAPIAuthentication no
- gssapiauthentication yes
- Modify to
- gssapiauthentication no
- #GSSAPIAuthentication yes
-
6. Optimized terminal timeout, automatic disconnection of terminal over 600 seconds
- [Email protected] ~]# echo "Export tmout=600" >>/etc/profile
- [Email protected] ~]# tail-1/etc/profile
- Export tmout=600
- [Email protected] ~]# Source/etc/profile
7. Control History Command record number, History command file path: ~/.bash_history
- [Email protected] ~]# echo "Export histsize=20" >>/etc/profile
- [Email protected] ~]# echo "Export histfilesize=20" >>/etc/profile
- [Email protected] ~]# Tail-2/etc/profile
- Export HISTSIZE=20
- Export HISTFILESIZE=20
- [Email protected] ~]# Source/etc/profile
Some necessary processing work after installation of CentOS