Java 代码连接服务器 获取防火墙策略(入站 出站 转发) 转换成java对象(iptables )

1.POM

<!-- https://mvnrepository.com/artifact/ch.ethz.ganymed/ganymed-ssh2 -->
		<dependency>
		    <groupId>ch.ethz.ganymed</groupId>
		    <artifactId>ganymed-ssh2</artifactId>
		    <version>262</version>
		</dependency>
		<dependency>
            <groupId>org.apache.commons</groupId>
            <artifactId>commons-lang3</artifactId>
            <version>3.12.0</version>
        </dependency>
         <dependency>
            <groupId>org.slf4j</groupId>
            <artifactId>slf4j-api</artifactId>
            <version>1.7.30</version>
        </dependency>
         <!--lombok-->
        <dependency>
            <groupId>org.projectlombok</groupId>
            <artifactId>lombok</artifactId>
            <version>1.18.20</version>
            <scope>provided</scope>
        </dependency>

2.连接ssh远程服务器 执行shell指令代码

package com.ccit.vpn.utils;

import ch.ethz.ssh2.Session;

import org.apache.commons.lang3.StringUtils;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
import ch.ethz.ssh2.Connection;
import ch.ethz.ssh2.StreamGobbler;

import java.io.*;
import java.util.ArrayList;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

/**
 *工具类
 */
public class DMruntimeUtil {

    private static final String DEFAULT_CHARSET = "utf-8";

    private static final  Logger LOGGER = LoggerFactory.getLogger(DMruntimeUtil.class);

    /**
     * 登录主机
     *
     * @return 登录成功返回true,否则返回false
     */
    public static Connection login(String ip, String userName, String userPwd,Integer prot) {

        boolean flg = false;
        Connection conn = null;
        try {
            conn = new Connection(ip,prot);
            conn.connect();// 连接
            flg = conn.authenticateWithPassword(userName, userPwd);// 认证
            if (flg) {
                LOGGER.info("=========登录成功=========" + conn);
                return conn;
            }
        } catch (IOException e) {
            LOGGER.error("=========登录失败=========" + e.getMessage());
            e.printStackTrace();
        }
        return conn;
    }

    /**
     * 远程执行shll脚本或者命令
     *
     * @param cmd 即将执行的命令
     * @return 命令执行完后返回的结果值
     */
    public static Map<String, Object> execute(Connection conn, String cmd) {
    	Map<String, Object> result =  new HashMap<String, Object>();
        try {
            if (conn != null) {
                Session session = conn.openSession();// 打开一个会话
                session.execCommand(cmd);// 执行命令
                result = processStdout(session.getStdout(), DEFAULT_CHARSET);
                // 如果为得到标准输出为空,说明脚本执行出错了
                if (StringUtils.isBlank(result.get("value")+"")) {
                    LOGGER.info("得到标准输出为空,链接conn:" + conn + ",执行的命令:" + cmd);
                    result = processStdout(session.getStderr(), DEFAULT_CHARSET);
                } else {
                    LOGGER.info("执行命令成功,链接conn:" + conn + ",执行的命令:" + cmd);
                }
                conn.close();
                session.close();
            }
        } catch (IOException e) {
            LOGGER.info("执行命令失败,链接conn:" + conn + ",执行的命令:" + cmd + "  " + e.getMessage());
            e.printStackTrace();
            result= null;
        }
        return result;
    }

 /**
     * 解析脚本执行返回的结果集
     *
     * @param in      输入流对象
     * @param charset 编码
     * @return 以纯文本的格式返回
     */
    private static Map<String, Object> processStdout(InputStream in, String charset) {
    	//创建String 集合
    	List<String> arrString = new ArrayList<String>(); 
        InputStream stdout = new StreamGobbler(in);
        StringBuffer buffer = new StringBuffer();
        ;
        try {
            BufferedReader br = new BufferedReader(new InputStreamReader(stdout, charset));
            String line = null;
            while ((line = br.readLine()) != null) {
                buffer.append(line + "\n");
                arrString.add(line);
            }
        } catch (UnsupportedEncodingException e) {
            LOGGER.error("解析脚本出错:" + e.getMessage());
            e.printStackTrace();
        } catch (IOException e) {
            LOGGER.error("解析脚本出错:" + e.getMessage());
            e.printStackTrace();
        }
        Map<String, Object> result =  new HashMap<String, Object>();
        result.put("arrString", arrString);
        result.put("value", buffer.toString());
        return result;
    }
}
 

3.实体类

package com.ccit.vpn.entity;

import java.io.Serializable;

import lombok.AllArgsConstructor;
import lombok.Data;
import lombok.NoArgsConstructor;
import lombok.experimental.Accessors;

@Data
@AllArgsConstructor
@NoArgsConstructor
@Accessors(chain = true)
public class FireWall implements Serializable {
	
	 /**
	 * 
	 */
	private static final long serialVersionUID = 1L;
	
	/**
	 * 编号
	 */
	private Integer count;
	/**
	 * 网口
	 */
	private String network;
	
	/**
	 * 策略
	 */
	private String tactics;
	
	/**
	 * 协议
	 */
	private String agreement;
	
	/**
	 * 源IP
	 */
	private String sourceAddress;
	
	/**
	 * 目标IP
	 */
	private String targetAddress;
	
	/**
	 * 端口号
	 */
	private String portNumber;
	
	/**
	 * 使用流量
	 */
	private String ptks;
	
	/**
	 * 是否正常
	 */
	private String isok;

}

4.处理shell返回结果 转换对象接收

package com.ccit.vpn.utils;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.HashMap;
import java.util.List;
import java.util.Map;

import com.ccit.vpn.entity.FireWall;

import ch.ethz.ssh2.Connection;
import lombok.extern.slf4j.Slf4j;

@Slf4j
public class FireUtil {
	
    private static	String ip = "";//ip地址
    private static String root="";//用户名
    private static String pwd="";//密码
    private static Integer prot = 22;//远程端口号 默认22
    private static String[] chains = {"INPUT","OUTPUT","FORWARD"};
    
    /**
     * 执行CMD命令,并返回String字符串
     * chain 链规则  INPUT,OUTPUT、 和FORWARD
     * target 策略 ACCEPT
     * 这里默认访问的 -t filter 表  其他表和知识请查阅 iptables 知识了解
     */
    public static List<FireWall> executeCmd(String target,String chain)  {
    	List<FireWall> listFire = new ArrayList<FireWall>();
        Connection conn = DMruntimeUtil.login(ip, root, pwd,prot);
        Map<String, Object> results =  new HashMap<String, Object>();
        	if(target.equals("ACCEPT")) {
        		String cmd = "iptables -P "+chain+" ACCEPT";
    		    results = DMruntimeUtil.execute(conn, cmd);	
        	}else if(target.equals("DROP")){
        		String cmd = "iptables -P "+chain+" DROP";
    		    results = DMruntimeUtil.execute(conn, cmd);	
        	}else {
        		log.info("-==[ 防火墙策略参数错误! ]==-");
        		return null;
        	}
        	if(Arrays.asList(chains).contains(chain)) {
        		conn = DMruntimeUtil.login(ip, root, pwd,prot);
        		String cmd = "iptables -t filter  -vnL "+chain+" --line-number";
    		    results = DMruntimeUtil.execute(conn, cmd);
    		    if (results != null) {
    		    	log.info("-==[ shell指令运行完成! ]==-");
    		    	log.info("shell指令运行结果:"+results);
    		    	//处理获取到的shell结果
    		    	List<String> arrString = (List<String>) results.get("arrString"); 
    		    	for (int i = 2; i < arrString.size(); i++) {
    		    		FireWall fireEntity = new FireWall();
						String val = arrString.get(i);
						String [] arr = val.split("\\s+");
						if(arr.length<11) {
							fireEntity.setCount(Integer.valueOf(arr[0])).setNetwork(arr[4]).setTactics(arr[3])
							.setAgreement(arr[4]).setSourceAddress(arr[8]).setTargetAddress(arr[9])
							.setPortNumber("").setPtks(arr[1]+"-"+arr[2]).setIsok("Y");
							System.out.println(fireEntity.toString());
						}else {
							fireEntity.setCount(Integer.valueOf(arr[0])).setNetwork(arr[4]).setTactics(arr[3])
							.setAgreement(arr[4]).setSourceAddress(arr[8]).setTargetAddress(arr[9])
							.setPortNumber(arr[11]).setPtks(arr[1]+"-"+arr[2]).setIsok("Y");
							System.out.println(fireEntity.toString());
						}
						listFire.add(fireEntity);
					}
    		    	
    		    } else {
    		    	log.info("-==[ shell指令运行失败! ]==-");
    		    }
    		   
    		    return listFire;
        	}else {
        		return null;
        	}
		   
			
    }
    
    public static void main(String[] args) {
    	FireUtil.executeCmd("ACCEPT","INPUT");
	}

}

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

Heart&Fire

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值