Hosts.allow and deny
The / etc/hosts.allow and / etc/hosts.deny files control remote access settings, allowing or denying access to a linux service from a computer in an ip or ip segment. For example, for SSH services, we are usually only open to administrators, so we can disable unnecessary IP and open only IP segments that may be used by administrators.
# vim / etc/hosts.allow
# allowed to use the local INET services, as decided# by the'/ usr/sbin/tcpd' server.#sshd:210.13.218.*,222.77.15.*all:218.24.129.110
The above words mean that two ip segments 210and 222are allowed to connect to the sshd service and accept all requests for the ip of 110s!
Don't forget to edit the deny file and reject all sshd connections to ip
# vim / etc/hosts.deny
Sshd:all
After modification, it will take effect in real time.
When hosts.allow and host.deny conflict, the hosts.allow setting shall prevail.