UFW Firewall စီမံခြင်း၊ Fail2ban နှင့် Swap Memory Setup
UFW (Uncomplicated Firewall) ဆိုတာ ဘာလဲ?
Section titled “UFW (Uncomplicated Firewall) ဆိုတာ ဘာလဲ?”UFW သည် Linux Kernel ၏ ရှုပ်ထွေးသော iptables စည်းမျဉ်းများကို ရိုးရှင်းသော Commands များဖြင့် လွယ်ကူစွာ စီမံနိုင်စေရန် ပြုလုပ်ထားသော Host-level Firewall ဖြစ်ပါတယ်။
graph TD Internet["🌐 Public Internet Traffic"]
subgraph UFW Firewall Rule22["Port 22 (SSH) - ALLOWED ✅"] Rule80["Port 80 (HTTP) - ALLOWED ✅"] Rule443["Port 443 (HTTPS) - ALLOWED ✅"] RuleOther["Other Random Ports - BLOCKED ❌"] end
Internet --> Rule22 Internet --> Rule80 Internet --> Rule443 Internet -.-> RuleOtherUFW Firewall စနစ်တကျ Setup လုပ်နည်း
Section titled “UFW Firewall စနစ်တကျ Setup လုပ်နည်း”အဆင့် ၁: Default Policy သတ်မှတ်ခြင်း
Section titled “အဆင့် ၁: Default Policy သတ်မှတ်ခြင်း”အဝင် Traffic အားလုံးကို မူလအားဖြင့် ပိတ်ထားပြီး အထွက် Traffic ကို ခွင့်ပြုပါမည်:
sudo ufw default deny incomingsudo ufw default allow outgoingအဆင့် ၂: လိုအပ်သော Ports များကို ဖွင့်ပေးခြင်း
Section titled “အဆင့် ၂: လိုအပ်သော Ports များကို ဖွင့်ပေးခြင်း”# 1. SSH ဆက်သွယ်မှုကို အရင်ဆုံး ဖွင့်ပါsudo ufw allow OpenSSH# (သို့မဟုတ် Custom Port သုံးထားပါက: sudo ufw allow 2222/tcp)
# 2. Web Traffic များအတွက် HTTP (80) နှင့် HTTPS (443) ကို ဖွင့်ပါsudo ufw allow 80/tcpsudo ufw allow 443/tcpအဆင့် ၃: Firewall ကို စတင် အသက်သွင်းခြင်း
Section titled “အဆင့် ၃: Firewall ကို စတင် အသက်သွင်းခြင်း”sudo ufw enableအဆင့် ၄: Firewall အခြေအနေ စစ်ဆေးခြင်း
Section titled “အဆင့် ၄: Firewall အခြေအနေ စစ်ဆေးခြင်း”sudo ufw status verboseOutput တွင် Action ကော်လံ၌ ALLOW IN ဖြစ်နေသော Ports များကို ရှင်းလင်းစွာ တွေ့မြင်ရပါမည်။
Fail2ban ဖြင့် Brute-force တိုက်ခိုက်မှုများကို ကာကွယ်ခြင်း
Section titled “Fail2ban ဖြင့် Brute-force တိုက်ခိုက်မှုများကို ကာကွယ်ခြင်း”Bots များသည် Server သို့ တစ်စက္ကန့်လျှင် အကြိမ်ပေါင်းများစွာ Password မှန်းဆပြီး ဝင်ရောက်ရန် ကြိုးစားတတ်ကြပါတယ်။ Fail2ban သည် Authentication Log ဖိုင်များကို စောင့်ကြည့်ပြီး သတ်မှတ်အကြိမ်ထက် ပိုမှားယွင်းပါက ထို IP ကို Firewall မှတစ်ဆင့် ရက်သတ္တပတ်ပေါင်းများစွာ အလိုအလျောက် Ban ပစ်ပါတယ်:
# 1. Fail2ban Install ပြုလုပ်မည်sudo apt install -y fail2ban
# 2. Custom Configuration File ကူးယူမည်sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
# 3. Service စတင်ပြီး Enable လုပ်မည်sudo systemctl enable --now fail2ban
# 4. လက်ရှိ Ban ထားသော Hacker IP စာရင်းကို ကြည့်မည်sudo fail2ban-client status sshdRAM နည်းသော VPS များအတွက် Swap Memory Setup ပြုလုပ်ခြင်း
Section titled “RAM နည်းသော VPS များအတွက် Swap Memory Setup ပြုလုပ်ခြင်း”အကယ်၍ ခင်ဗျား၏ VPS Server သည် 1GB သို့မဟုတ် 2GB RAM သာရှိပါက Node.js Build လုပ်ချိန် သို့မဟုတ် Database Data များလာချိန်တွင် “Out of Memory (OOM Kill)” ဖြစ်ကာ Server Crash ကျတတ်ပါတယ်။
Swap Memory သည် Hard Disk ပေါ်တွင် Virtual RAM ၂ Gigabytes ခန့် နေရာချန်ထားပေးခြင်းဖြင့် Server Crash မဖြစ်အောင် ကယ်တင်ပေးနိုင်ပါတယ်:
graph LR RAM["⚡ Physical RAM (1GB) ပြည့်သွားပါက"] --> Swap["💾 Virtual Swap File (2GB on SSD) သို့ အလိုအလျောက် ကူးပြောင်း သုံးစွဲသည်"]2GB Swap Memory ဖန်တီးနည်း:
Section titled “2GB Swap Memory ဖန်တီးနည်း:”# 1. 2GB ရှိသော Swap ဖိုင်တစ်ခု အလွတ်ဆောက်မည်sudo fallocate -l 2G /swapfile
# 2. ဖိုင်ကို root သာ ဖတ်နိုင်ရန် Permission ပိတ်မည်sudo chmod 600 /swapfile
# 3. Swap ဖိုင်အဖြစ် Format ချမည်sudo mkswap /swapfile
# 4. Swap ကို ချက်ချင်း စတင် သုံးစွဲမည်sudo swapon /swapfile
# 5. Server Reboot ကျတိုင်း အလိုအလျောက် သုံးစေရန် /etc/fstab ထဲ ထည့်မည်echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstabစစ်ဆေးရန်:
free -h# Swap ကော်လံတွင် 2.0Gi ပေါ်လာသည်ကို တွေ့ရပါမည်!🧠 အသိပညာ စစ်ဆေးမှု (Quiz)
Section titled “🧠 အသိပညာ စစ်ဆေးမှု (Quiz)”Firewall & Server Hardening စစ်ဆေးမှု
မေးခွန်းများကို ဖြေဆိုပြီး မိမိ၏ နားလည်မှုကို စစ်ဆေးပါ
1. 'sudo ufw enable' မနှိပ်မီ အဘယ်ကြောင့် SSH Port ကို ကြိုတင် allow လုပ်ထားရသနည်း?
ဒီသင်ခန်းစာ ဖတ်ပြီးပြီလား?
ပြီးမြောက်ကြောင်း မှတ်သားထားရန် အောက်ပါ ခလုတ်ကို နှိပ်ပါ