Debian 7.x的安装
1)安装相关包
apt-get install lxde-core xinit xdm; apt-get install -f 2) 配置启动方式
echo 'exec startlxde' > ~/.xsession
update-alternatives --config x-session-manager 3) 配置分辨率
echo '@xrandr -s 1024x768' >> /etc/xdg/lxsession/LXDE/autostart Debian 8.x的安装
1)安装相关包
aptitude install xinit slim lightdm
aptitude install --without-recommends lxde-core 2)配置启动方式
echo 'exec startlxde' > ~/.xinitrc
update-alternatives --config x-session-manager 2.5.2 kde桌面
1)完全安装
aptitude install kde-full 2.6 安装谷歌浏览器 Debian 7.x的安装
1)安装软件包
dpkg -i google-chrome-stable_current_amd64.deb;apt-get install -f 2)修改配置
vi /usr/bin/chromium-browser 找到如下行:
exec $LIBDIR/$APPNAME $CHROMIUM_FLAGS "$@" 替换为如下行:
exec $LIBDIR/$APPNAME $CHROMIUM_FLAGS "$@" --user-data-dir Debian 8.x的安装
1)下载安装包
下载页面:
http://www.google.cn/chrome/browser/desktop/index.html
下载的命令:
wget https://dl.google.com/linux/direct/google-chrome-stable_current_amd64.deb 2)启动安装
dpkg -i google-chrome-stable_current_amd64.deb;apt-get install -f
3)加载flash插件
cd ~
wget https://fpdownload.adobe.com/pub/flashplayer/pdc/25.0.0.127/flash_player_ppapi_linux.x86_64.tar.gz
tar -xf flash_player_ppapi_linux.x86_64.tar.gz
mkdir /opt/google/chrome/PepperFlash
cp libpepflashplayer.so manifest.json /opt/google/chrome/PepperFlash/
chmod -R 755 /opt/google/chrome/PepperFlash/ 配置快捷方式加载flash插件
vim /usr/share/applications/google-chrome.desktop 将如下行:
Exec=/usr/bin/google-chrome-stable %U 修改为:
Exec=/usr/bin/google-chrome-stable %U --ppapi-flash-path=/opt/google/chrome/PepperFlash/libpepflashplayer.so 4)pepperflashlugin方式安装(失败几率高,不建议采用)
aptitude install pepperflashplugin-nonfree 2.7 火狐浏览器的安装 Debian 7.x的安装
1)配置安装源
echo "deb http://downloads.sourceforge.net/project/ubuntuzilla/mozilla/apt all main" | tee -a /etc/apt/sources.list.d/mozilla.list
apt-key adv --recv-keys --keyserver keyserver.ubuntu.com 2667CA5C 2)更新安装源
apt-get update 3)安装浏览器
apt-get install firefox-mozilla-build Debian 8.x的安装
aptitude install firefox-esr 2.8 安装Teamviewar 2.8.1 下载安装包
wget https://downloadus2.teamviewer.com/download/version_12x/teamviewer_12.0.76279_amd64.deb 2.8.2 选择本地安装
dpkg -i teamviewer_12.0.76279_amd64.deb
apt-get install -f 下载页面:
https://community.teamviewer.com/t5/Knowledge-Base/How-do-I-install-TeamViewer-on-my-Linux-distribution/ta-p/4351 2.8.3 解决依赖关系
apt-get install teamviewer; apt-get -f install 2.8.4 查看帮助
teamviewer --help 2.9 中文支持 2.9.1 支持显示中文
apt-get install fonts-droid 2.9.2 界面中文化
aptitude install locales
dpkg-reconfigure locales 注:选择“zh_CN.UTF-8”即可 2.10 安装vim
apt-get install vim;apt-get install -f 2.11 防火墙配置 2.11.1 编写临时规则
vim /etc/iptables.test.rules 复制官方提供的模板并根据自己的需求修改
*filter
# Permette tutto il traffico su loopback (lo0) traffic e elimina tutto il traffico che non usa lo0 verso 127/8
-A INPUT -i lo -j ACCEPT
-A INPUT ! -i lo -d 127.0.0.0/8 -j REJECT
# Accetta in entrata su tutte le connessioni stabilite
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# Permette tutto il traffico in uscita
# Potrebbe essere modificato per permettero solo un certo tipo di traffico
-A OUTPUT -j ACCEPT
# Permette connessioni HTTP e HTTPS da qualsiasi parte provengano (le normali porte per i siti web)
-A INPUT -p tcp --dport 80 -j ACCEPT
-A INPUT -p tcp --dport 443 -j ACCEPT
# Permette le connessioni SSH
# Il numero --dport e' lo stesso di quello in /etc/ssh/sshd_config
-A INPUT -p tcp -m state --state NEW --dport 22 -j ACCEPT
# Ora ci si dovrebbe informare sulle regole di iptables e considerare se l'accesso ssh
# per tutti sia realmente quello che si vuole. Molto probabilmente si preferisce
# permettere l'accesso solo per alcuni IP.
# Permettere ping
# notare che bloccare altri tipi di pacchetti icmp è considerata da alcuni una cattiva idea
# rimuovere -m icmp --icmp-type 8 da questa riga per permettere tutti i tipi di icmp:
# https://security.stackexchange.com/questions/22711
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
# registrare le chiamate negate di iptables (accesso via il comando 'dmesg')
-A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level 7
# Respingere tutto il resto del traffico in entrata: politica del negare in modo predefinito quando non esplicitamente permesso
-A INPUT -j REJECT
-A FORWARD -j REJECT
COMMIT 2.11.2 导轨规则使之生效
iptables-restore < /etc/iptables.test.rules 2.11.3 命令行确认规则生效
iptables -L 2.11.4 保存规则到主配置文件
iptables-save > /etc/iptables.up.rules 2.11.5 配置开机自动加载
echo '#!/bin/sh' > /etc/network/if-pre-up.d/iptables
echo '/sbin/iptables-restore < /etc/iptables.up.rules' >> /etc/network/if-pre-up.d/iptables
chmod +x /etc/network/if-pre-up.d/iptables 2.12 路由转发配置 2.12.1 临时开启路由转发
echo 1 > /proc/sys/net/ipv4/ip_forward 2.12.2 永久开启路由转发
vim /etc/sysctl.conf 去掉此行的注解: