๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
DevOps/AWS

AWS EC2 iptables๋ฅผ ํ†ตํ•ด ์„œ๋ฒ„ ํฌํŠธ ํฌ์›Œ๋”ฉ(HTTP 80 -> Tomcat 8080)

by ์ฃผ๋ฐœ2 2021. 4. 30.
๋ฐ˜์‘ํ˜•

 ์•ˆ๋…•ํ•˜์„ธ์š”~ ์ด์ „์— ์šด์˜ํ•˜๋˜ ๋ธ”๋กœ๊ทธ ๋ฐ GitHub, ๊ณต๋ถ€ ๋‚ด์šฉ์„ ์ •๋ฆฌํ•˜๋Š” Study-GitHub ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค!

 ๋„ค์ด๋ฒ„ ๋ธ”๋กœ๊ทธ

 GitHub

Study-GitHub

 ๐Ÿ”


 

โœ” AWS EC2 ์„œ๋ฒ„ ํฌํŠธ ํฌ์›Œ๋”ฉ(HTTP 80 -> Tomcat 8080)

 

์•ˆ๋…•ํ•˜์„ธ์š”, ์ด๋ฒˆ์— ์ •๋ฆฌํ•  ๋‚ด์šฉ์€ AWS EC2์œ„์˜ ์„œ๋ฒ„์—์„œ iptables ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด

ํฌํŠธ ํฌ์›Œ๋”ฉ(80 -> 8080)์„ ์ง„ํ–‰ํ•ด๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

 

 

 

 

๐ŸŽ— ์™œ 80ํฌํŠธ๋ฅผ 8080ํฌํŠธ๋กœ ํฌ์›Œ๋”ฉ์„ ํ•ด์•ผํ• ๊นŒ์š”?

ํ˜„์žฌ ์ €๋Š” AWS EC2์— ์Šคํ”„๋ง ๋ถ€ํŠธ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋ฐฐํฌํ•œ ์ƒํƒœ์ž…๋‹ˆ๋‹ค.

 

ํ•ด๋‹น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— IP๋ฅผ ํ†ตํ•ด ์ ‘๊ทผํ•˜๋ ค๋ฉด IP ๋’ค์— ํ†ฐ์บฃ์˜ ํฌํŠธ(8080) ์„ ๋ถ™์—ฌ์•ผ ์ ‘์†์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  - 15.162.211.192:8080

 

๋งŒ์•ฝ 80 ํฌํŠธ๋ฅผ 8080 ํฌํŠธ๋กœ ํฌ์›Œ๋”ฉ์„ ํ•˜์ง€ ์•Š๊ณ  ๋‹ค์Œ IP๋กœ ์ ‘์†์„ ์‹œ๋„ํ•˜๋ฉด ์ ‘์†์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

  - 15.162.211.192

 

 

์œ„์™€ ๊ฐ™์ด IP ๋’ค์— ํ†ฐ์บฃ์˜ ํฌํŠธ๋ฅผ ๋ถ™์—ฌ์ค˜์•ผํ•ด์„œ ๋ฒˆ๊ฑฐ๋กญ๊ธฐ๋„ ํ•˜๊ณ , ๊ฐ€๋น„์•„๋ฅผ ํ†ตํ•ด ๋„๋ฉ”์ธ์„ ๊ตฌ๋งคํ•œ ๋’ค ์—ฐ๊ฒฐํ•˜๋Š”๋ฐ ํ•ด๋‹น ๋„๋ฉ”์ธ์œผ๋กœ ์ ‘์†์ด ์•ˆ๋˜๊ธธ๋ž˜ ํฌํŠธ ๋ฌธ์ œ๋ผ๊ณ  ์ƒ๊ฐ์„ ํ–ˆ์Šต๋‹ˆ๋‹ค.

  - ํ˜„์žฌ ์ƒํƒœ์—์„œ ๋„๋ฉ”์ธ ๋’ค์— :8080 ํฌํŠธ๋ฅผ ๋ถ™์ด๋ฉด ์ ‘์†์ด ๊ฐ€๋Šฅ์€ ํ•ฉ๋‹ˆ๋‹ค!!

  - example-test.shop:8080

 

 

๋”ฐ๋ผ์„œ URL์„ ๋” ๊น”๋”ํ•˜๊ฒŒ ๋‚˜ํƒ€๋‚ด๊ธฐ ์œ„ํ•ด 80 ํฌํŠธ๋ฅผ 8080 ํฌํŠธ๋กœ ํฌ์›Œ๋”ฉ์„ ์ง„ํ–‰ํ•  ๊ฒƒ์ด๊ณ ,

์ค‘๊ฐ„ ๊ณผ์ •์—์„œ ์‚ฝ์งˆ์„ ํ–ˆ์—ˆ๋Š”๋ฐ.. ์–ด๋– ํ•œ ์‚ฝ์งˆ์„ ํ–ˆ๋Š”์ง€ ์•Œ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค ! ๐Ÿคฃ

 

 

 

 

๐ŸŽ— 80 -> 8080 ํฌํŠธํฌ์›Œ๋”ฉ ํ•˜๊ธฐ

ํฌํŠธ ํฌ์›Œ๋”ฉ ํ•˜๋Š” ๋ช…๋ น์–ด๋Š” ๋‹จ ํ•œ์ค„๋กœ ๋์ž…๋‹ˆ๋‹ค.

# iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 8080
# service iptables save // ๊ทœ์น™ ์ €์žฅ

 

 

์ €๋Š” ์ด๋ฒˆ ์ž‘์—…์„ ํ†ตํ•ด iptables๋ผ๋Š” ๋ช…๋ น์–ด๋ฅผ ์ฒ˜์Œ ์•Œ๊ฒŒ๋˜์—ˆ๋Š”๋ฐ์š”, ์‚ฝ์งˆ์„ ํ•˜๋ฉด์„œ ์ข€ ๋” ์ฐพ์•„๋ณด์•˜์Šต๋‹ˆ๋‹ค.

 

 

* iptables์ด๋ž€, ๋ฆฌ๋ˆ…์Šค์—์„œ ๋ฐฉํ™”๋ฒฝ์„ ์„ค์ •ํ•˜๋Š” ๋„๊ตฌ์ž…๋‹ˆ๋‹ค.

 

์ข€ ๋” ์ž์„ธํ•œ ์„ค๋ช…์€ ์•„๋ž˜ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ•ด์ฃผ์„ธ์š”!

webterror.net/?p=1622

 

iptables ๊ทธ๋ฆผ๋ณด๋ฉด์„œ ์ดํ•ดํ•˜๊ธฐ – WEBTERROR.net

๋ฆฌ๋ˆ…์Šค์—์„œ์˜ iptables ๋‚ด๊ฐ€ ์ฒ˜์Œ iptables์„ ์ดํ•ด ํ•˜๋ ค๊ณ  ํ–ˆ์„๋•Œ๊ฐ€ 10๋…„์ „์ด์˜€๋˜๊ฒƒ ๊ฐ™์€๋ฐ ๊ธฐ์ดˆ์ ์ธ ์ง€์‹์ด ๋ถ€์กฑํ•ด์„œ ๊ทธ ๋‹น์‹œ์—๋Š” ์™ธ๊ณ„์–ด๋ฅผ ์ฝ๋Š” ๋“ฏํ•œ ๊ธฐ๋ถ„์ด์˜€๋‹ค. ๊ทธ๋ฆฌ๊ณ ๋„ ๊ณ„์† ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉํ•ด์•ผ

webterror.net

 

 

 

์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•˜๊ณ  ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด iptables์˜ Chain์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

# sudo iptables -t nat -L --line-numbers

 

ํ™•์ธํ•ด๋ณด๋ฉด ์œ„์™€ ๊ฐ™์ด PREROUTING์— 8080 ํฌํŠธ๊ฐ€ ์„ค์ •๋˜์–ด ์žˆ๋Š”๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  * PREROUTING: ์žฅ์น˜์— ํŒจํ‚ท์ด ๋„๋‹ฌํ–ˆ์„๋•Œ์˜ ์‹œ์ 

 

 

 

๋”ฐ๋ผ์„œ ์œ„์™€ ๊ฐ™์ด ์ ์šฉ์„ ํ•œ ํ›„ 8080 ํฌํŠธ๋ฅผ ์ œ์™ธํ•˜๊ณ  IP์— ์ ‘์†์„ ํ•ด๋ณด๋ฉด.. ์„ฑ๊ณตํ•ด์•ผ ํ•˜๋Š”๋ฐ ....

์ ‘์†์ด ์•ˆ๋ฉ๋‹ˆ๋‹ค.. ๐Ÿ˜ฅ

 

๋‹ค๋ฅธ ์‚ฌ์ดํŠธ๋“ค๋„ ๋ชจ๋‘ ๋น„์Šทํ•˜๊ฒŒ ์œ„์™€ ๊ฐ™์ด ์ž‘์—…์„ ์ง„ํ–‰ํ•˜๊ณ , ์ •์ƒ์ ์œผ๋กœ ์ ‘์†์ด ์ž˜ ๋˜๋Š”๋ฐ

์ €๋Š” ๊ณ„์† ์ ‘์†์ด ์•ˆ๋˜์—ˆ๋Š”๋ฐ์š”.... ๋ฌธ์ œ๋Š” ๊ฐ„๋‹จํ–ˆ์Šต๋‹ˆ๋‹ค.

 

AWS EC2์—์„œ ๋ณด์•ˆ ๊ทธ๋ฃน์„ ์„ค์ •ํ•  ๋•Œ, 80ํฌํŠธ์— ๋Œ€ํ•ด ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์„ ์„ค์ •ํ•˜์ง€ ์•Š์•„์„œ ์ ‘์†์ด ์•ˆ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

 

์ €๋Š” ๋‹น์—ฐํžˆ HTTPS๋กœ ์ ‘์†์„ ํ• ๊ฑฐ๋ผ๊ณ  ์ƒ๊ฐํ•ด์„œ ์ฒ˜์Œ์— 443 ํฌํŠธ์— ๋Œ€ํ•ด์„œ๋งŒ ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์„ ์ ์šฉํ–ˆ์—ˆ๋Š”๋ฐ์š”,

์•„์ง HTTPS ์ ์šฉ์„ ํ•˜์ง€ ์•Š์„ ์ƒํƒœ์ด๋ฏ€๋กœ HTTP(80ํฌํŠธ)๋กœ ์ ‘์†์„ ํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

 

๋”ฐ๋ผ์„œ, AWS EC2 ๋ณด์•ˆ๊ทธ๋ฃน์—์„œ 80 ํฌํŠธ์— ๋Œ€ํ•ด ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์„ ์„ค์ •ํ•ด์ฃผ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

80 ํฌํŠธ๊ฐ€ ์„ค์ •๋˜์–ด ์žˆ์ง€ ์•Š๋Š” ๋ณด์•ˆ ๊ทธ๋ฃน ๐Ÿ˜ฅ

 

 

๋ณด์•ˆ ๊ทธ๋ฃน > ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™ ํŽธ์ง‘ ์—์„œ HTTP(80) ํฌํŠธ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

 

 

๊ทธ ํ›„ ํ†ฐ์บฃ ํฌํŠธ์ธ 8080ํฌํŠธ๋ฅผ ์ œ๊ฑฐํ•œ ํ›„ IP๋ฅผ ์ ‘์†์„ ํ•˜๋ฉด ์ ‘์†์ด ์ž˜ ๋ฉ๋‹ˆ๋‹ค !!!!!!!!!

 

๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€