17wz0x3265 发表于 2016-6-8 12:16:27

AIX 关闭ftp服务

很多情况下,比如处于安全考虑,我们需要关闭ftp服务。在AIX平台下可以采用如下方法。
一、检查代理服务进程(inetd,很多平台如linux,已经被xinetd所取代)是否存在。
引用
# ps -ef|grep inetd
    root 18892 39822   0   Mar 04      -0:00 /usr/sbin/inetd
    root 43704 56780   0 23:21:22pts/00:00 grep inetd

检查ftp端口是否已经更改,也可以在/etc/services中查看
引用
# netstat -Aan|grep 21
70dec210 tcp      0      0*.21               *.*                LISTEN

查看进程号
引用
# rmsock70bf1210 tcpcb
The socket 0x70bf1008 is being held by proccess 18892 (inetd).


使用rmsock需要注意的是
rmsock is used to remove sockets that do not have file descriptors. However, rmsock doesn’t remove a socket that still has a valid file descriptor but, instead, returns the identity of the process owner.

二、修改/etc/inetd.conf,注释ftp一行。
三、刷新代理服务
引用
# refresh -s inetd
0513-095 The request for subsystem refresh was completed successfully.

或者刷新tcpip
引用
# refresh -g tcpip
0513-095 The request for subsystem refresh was completed successfully.
0513-036 The request could not be passed to the rwhod subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the xntpd subsystem.
Start the subsystem and try your command again.
0513-095 The request for subsystem refresh was completed successfully.
0513-095 The request for subsystem refresh was completed successfully.
0513-095 The request for subsystem refresh was completed successfully.
0513-095 The request for subsystem refresh was completed successfully.
0513-036 The request could not be passed to the dpid2 subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dhcpcd subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dhcpcd6 subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the ndpd-host subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the ndpd-router subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the tftpd subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the gated subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the named subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the routed subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the iptrace subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the timed subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dhcpsd subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dhcpsdv6 subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dhcprd subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the mrouted subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the pxed subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the binld subsystem.
Start the subsystem and try your command again.
0513-036 The request could not be passed to the dfpd subsystem.
Start the subsystem and try your command again.
0513-095 The request for subsystem refresh was completed successfully.


检查客户端是否能连接至主机,可以看到ftp服务已经被关闭
引用
D:\>ftp 172.16.4.2
Connected to 172.16.4.2.
Connection closed by remote host.
页: [1]
查看完整版本: AIX 关闭ftp服务