歡迎來到Linux教程網
Linux教程網
Linux教程網
Linux教程網
Linux教程網 >> Linux基礎 >> Linux教程 >> Linux iptables 異機備份、恢復實例

Linux iptables 異機備份、恢復實例

日期:2017/2/28 15:46:20   编辑:Linux教程

1、iptables的配置文件位置:/etc/sysconfig/iptables
主控機:即業務運行中的機子;備份機:即主控機故障時,切換到備份的機子

--在主控機上的操作-------------------
2、建立目錄:
mkdir -p /bak/iptables/
mkdir /root/script/

3、在/root/script/目錄下建立腳本:
vi backup.sh

\cp /etc/sysconfig/iptables /bak/iptables/iptables_$(date +%Y%m%d%H)

4、定制自動任務:
crontab -e
*/10 * * * * /usr/sbin/ntpdate 210.72.145.44
10 * * * * sh /root/script/backup.sh

--在備份機上操作---------------------
5、建立目錄:
mkdir -p /bak/iptables/{lt,yd} #lt目錄放聯通跳轉的備份,yd目錄放移動跳轉的備份
mkdir /root/script/

6、在/root/script/目錄下建立腳本:
vi scp_lt.sh

#!/usr/bin/expect -f
set password gst
spawn scp -P 22 [email protected]:/etc/sysconfig/iptables /bak/iptables/lt/iptables
set timeout 300
expect "[email protected]'s password:"
set timeout 300
send "$password\r"
set timeout 300
send "exit\r"
expect eof

7、在/root/script/目錄下建立腳本:
vi scp_yd.sh

#!/usr/bin/expect -f
set password gst
spawn scp -P 22 [email protected]:/etc/sysconfig/iptables /bak/iptables/yd/iptables
set timeout 300
expect "[email protected]'s password:"
set timeout 300
send "$password\r"
set timeout 300
send "exit\r"
expect eof

8、在/root/script/目錄下建立腳本:
vi backup.sh

expect /root/script/scp_lt.sh
expect /root/script/scp_yd.sh
sed -i 's/202.105.135.52/183.62.178.85/g' /bak/iptables/lt/iptables
sed -i 's/58.251.49.18/58.250.56.154/g' /bak/iptables/lt/iptables
\cp /bak/iptables/lt/iptables /etc/sysconfig/iptables
/etc/init.d/iptables restart
/etc/init.d/iptables save
mv /bak/iptables/lt/iptables /bak/iptables/lt/iptables_$(date +%Y%m%d%H)
mv /bak/iptables/yd/iptables /bak/iptables/yd/iptables_$(date +%Y%m%d%H)

9、注意,要在備份機上手動遠程登陸一次,以獲得RSA的公鑰,之後就不用這樣登陸了,否則腳本會執行錯誤

10、定制自動任務:
crontab -e
*/10 * * * * /usr/sbin/ntpdate 210.72.145.44
20 * * * * sh /root/script/backup.sh

Copyright © Linux教程網 All Rights Reserved