· KLDP.org · KLDP.net · KLDP Wiki · KLDP BBS ·
Linuxdoc Sgml/IP-Masquerade-HOWTO

Linux IP Masquerade HOWTO

Linux IP Masquerade HOWTO

David Ranch, dranch@trinnet.net; Ambrose Au, ambrose@writeme.com

v1.79, 21 October 1999


ÀÌ ¹®¼­´Â ¸®´ª½º È£½ºÆ®¿¡¼­ IP ¸¶½ºÄ¿·¹À̵å¶ó´Â ±â´ÉÀ» »ç¿ëÇÏ´Â ¹æ¹ýÀ» ±â¼úÇϰí ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵å´Â Network Address Translation(NAT)ÀÇ ÇÑ ÇüÅ·Î, ¸®´ª½º box¿¡ ¿¬°áµÈ ÇѰ³ÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ ÅëÇØ¼­ µî·ÏµÈ IP ÁÖ¼Ò°¡ ¾ø´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» ÀÌ¿ëÇϵµ·Ï ÇÏ´Â ±â´ÉÀÌ´Ù.

1. ¼Ò°³

1.1 IP Masquerading(ÁÙ¿©¼­ IP MASQ) ¿¡ ´ëÇÑ ¼Ò°³

(¿ªÀÚÁÖ: [ masquerade ] n, °¡Àå ¹«µµÈ¸, °¡Àå, ±¸½Ç [ masquerade ] v, °¡Àå ¹«µµ¸¦ ÇÏ´Ù, °¡ÀåÇÏ´Ù, üÇÏ´Ù)

ÀÌ ¹®¼­´Â ¸®´ª½º È£½ºÆ®¿¡¼­ IP ¸¶½ºÄ¿·¹À̵å¶ó´Â ±â´ÉÀ» »ç¿ëÇÏ´Â ¹æ¹ýÀ» ±â¼úÇϰí ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵å´Â Network Address Translation(NAT)ÀÇ ÇÑ ÇüÅ·Î, ¸®´ª½º box¿¡ ¿¬°áµÈ ÇѰ³ÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ ÅëÇØ¼­ µî·ÏµÈ IP ÁÖ¼Ò°¡ ¾ø´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» ÀÌ¿ëÇϵµ·Ï ÇÏ´Â ±â´ÉÀÌ´Ù. ³»ºÎÀÇ ÄÄÇ»Å͵éÀº ÀÌ´õ³Ý(Ethernet), ÅäÅ« ¸µ(TokenRing), FDDI°°Àº LAN ¿¬°áÀ̳ª ´ÙÀ̾ó¾÷ PPP(¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ ÀüÈ­Á¢¼Ó ³×Æ®¿öÅ·), ȤÀº SLIP °°Àº ¹æ¹ýÀ» ÅëÇØ¼­ ¸®´ª½º È£½ºÆ®¿¡ ¿¬°áÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®¼­´Â ÀÌ´õ³Ý(Ethernet)À» ÀÌ¿ëÇÏ´Â ¹æ¹ýÀ» ¿ì¼±ÀûÀ¸·Î ´Ù·é´Ù.

ÀÌ ¹®¼­´Â IBM ȣȯ PC¿¡¼­ 2.0.36ÀÌ»ó, 2.2.9ÀÌ»óÀÇ ¾ÈÁ¤ Ä¿³ÎÀ» »ç¿ëÇÏ´Â »ç¿ëÀÚµéÀ» À§Çؼ­ ¾²¿©Á³´Ù. 1.2.x ³ª 1.3.xÀÇ ¿À·¡µÈ Ä¿³ÎÀº ´Ù·çÁö ¾Ê°í, ¾î¶² ¹öÁ¯ÀÇ Ä¿³Î¿¡¼­´Â À߸øµÈ °á°ú¸¦ ³¾ ¼öµµ ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ ÀÌÀü¿¡ »õ·Î¿î ¾ÈÁ¤ Ä¿³Î·Î ¾÷±×·¹À̵åÇϱ⠹ٶõ´Ù.

IP ¸¶½ºÄ¿·¹À̵带 ¸ÅŲÅä½Ã¿¡¼­ »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, Taro Fukunaga, tarozax@earthlink.net ¿¡°Ô ¸ÞÀÏÀ» º¸³»¼­ ÀÌ HOWTOÀÇ °£·«ÇÑ MkLinux¿ë ¹öÁ¯À» ¾ò±æ ¹Ù¶õ´Ù..

1.2 ¸Ó¸®¸», ÀÇ°ß ¹× °ø·Î

»õ·Î¿î »ç¿ëÀڵ鿡°Ô´Â ¸®´ª½º Ä¿³Î(1.2.x ÀÌÀü ¹öÁ¯ Æ÷ÇÔ)¿¡¼­ IP Masq¸¦ ¼³Á¤ÇÏ´Â °ÍÀÌ ¸Å¿ì È¥µ¿½º·´´Ù. FAQ¿Í ¸ÞÀϸµ ¸®½ºÆ®°¡ ÀÖÁö¸¸, IP Masq¸¦ À§Çؼ­ ¾²¿©Áø ¹®¼­´Â ¾ø¾ú´Ù. ±×¸®°í, ¸ÞÀϸµ ¸®½ºÆ®¿¡µµ IP Masq¸¦ À§ÇÑ HOWTO¸¦ ¿äûÇÏ´Â ±ÛÀÌ ÀÖ¾ú´Ù. ±×·¡¼­, »õ·Î¿î »ç¿ëÀÚµéÀÌ Ãâ¹ßÁ¡À¸·Î »ïÀ» ¼ö ÀÖµµ·Ï ÀÌ HOWTO¸¦ ¾²±â·Î °áÁ¤Çß°í, ¼÷·ÃµÈ »ç¿ëÀÚµéÀÌ ÃßÈÄ¿¡ ´õ Ãß°¡ÇÒ ¼ö ÀÖ±æ ¹Ù¶õ´Ù. ÀÌ ¹®¼­¿¡ ´ëÇØ ¾î¶² Á¾·ùÀÇ ¾ÆÀ̵ð¾î³ª, ¼öÁ¤»çÇ׵鵵 ȯ¿µÇÑ´Ù. ±×·¡¼­ ÀÌ ¹®¼­°¡ ´õ ÁÁÀº ¹®¼­°¡ µÇ±æ ¹Ù¶õ´Ù.

ÀÌ ¹®¼­´Â Ken EvesÀÇ FAQ¿Í IP ¸¶½ºÄ¿·¹ÀÌµå ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ¼ö¸¹Àº ¸Þ½ÃÁöµéÀ» Âü°íÇÏ¿© ¸¸µé¾îÁ³´Ù. ³»°¡ IP Masq¸¦ ¼³Á¤Çϴµ¥ µµ¿òÀ» ÁÖ°í, ¸¶Ä§³»´Â ÀÌ ¹®¼­¸¦ ¾²´Âµ¥ ¿µ°¨À» ÁØ Mr. Matthew Driver ¿¡°Ô Ưº°ÇÑ °¨»ç¸¦ Ç¥ÇÑ´Ù. ÃÖ±Ù¿¡´Â David Ranch°¡ HOWTO¸¦ ÀçÀÛ¼ºÇßÀ¸¸ç ,HOWOT¿¡ ¸¹Àº sectionµéÀ» Ãß°¡ÇÏ¿© ÀÌ ¹®¼­°¡ ´õ¿í ¿Ïº®ÇØ Áöµµ·Ï Çß´Ù.

¼öÁ¤ÇØ¾ß ÇÒ Á¡À̳ª, Á¤º¸, URL, ±âŸÀÇ ¾î¶°ÇÑ ÀǰßÀÌ¶óµµ ±âź¾øÀÌ ambrose@writeme.com °ú dranch@trinnet.net·Î º¸³»Áֱ⠹ٶõ´Ù. ¿©·¯ºÐÀÇ Âü¿©°¡ ÀÌ HOWTO¿¡ ¸¹Àº µµ¿òÀ» ÁÙ °ÍÀÌ´Ù.

ÀÌ HOWTO´Â ¿©·¯ºÐÀÌ °¡´ÉÇÑ ºü¸¥ ½Ã°£¾È¿¡ ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ³×Æ®¿÷À» ÀÛµ¿Çϵµ·Ï Çϴµ¥ µµ¿òÀ» ÁÙ Àǵµ·Î ¾²¿©Á³´Ù. Ambrose³ª David°¡ Á÷¾÷ÀûÀÎ ÀúÀÚ°¡ ¾Æ´Ï±â ¶§¹®¿¡, ¿©·¯ºÐÀº ÀÌ ¹®¼­¿¡¼­ ÀϹÝÀûÀÌÁö ¾Ê°Å³ª ¾ÖÃÊÀÇ ¸ñÀûÀÌ ¸ÂÁö ¾Ê´Â ³»¿ëÀ» ¹ß°ß ÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù. ÀÌ HOWTO¿¡ °üÇÑ ÃֽŠÁ¤º¸³ª ±âŸ IP ¸¶½ºÄ¿·¹À̵忡 °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ¿ì¸®°¡ ÀÇ¿åÀûÀ¸·Î °ü¸®Çϰí ÀÖ´Â web page IP Masquerade Resource ¿¡¼­ ¾òÀ» ¼ö ÀÖ´Ù. ¿©·¯ºÐÀÌ IP ¸¶½ºÄ¿·¹À̵忡 ´ëÇØ¼­ ±â¼úÀûÀÎ Àǹ®»çÇ×ÀÌ ÀÖ´Ù¸é, Amrose³ª David¿¡°Ô ¸ÞÀÏÀ» º¸³»´Â ´ë½Å¿¡ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ÞÀϸµ ¸®½ºÆ®¿¡ Âü°¡Çϱ⠹ٶõ´Ù. IP ¸¶½ºÄ¿·¹À̵忡 °üÇÑ ¸ðµç ¹®Á¦Á¡Àº ´ëºÎºÐÀÇ À¯Àúµé¿¡°Ô °øÅëµÈ °ÍÀ̰í, ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ´©±º°¡¿¡°Ô¼­ °£´ÜÇÑ ´äÀ» ¾òÀ» ¼öµµ ÀÖÀ» °ÍÀÌ´Ù. µ¡ºÙ¿©¼­, Ambrose³ª David·ÎºÎÅÍ ´äÀåÀ» ¹Þ´Â ½Ã°£º¸´Ù ¸ÞÀϸµ ¸®½ºÆ®·ÎºÎÅÍ ´äÀ» ¾ò´Â ½Ã°£ÀÌ ÈξÀ Àû°Ô °É¸± °ÍÀÌ´Ù.

ÀÌ ¹®¼­ÀÇ ÃֽйöÁ¯Àº ´ÙÀ½ »çÀÌÆ®¿¡¼­ ¾òÀ» ¼ö ÀÖ°í, ±×°÷¿¡¼­ HTMLÀ̳ª postscript¹öÁ¯ÀÇ ¹®¼­µµ ¾òÀ» ¼ö ÀÖ´Ù.

1.3 ÆÇ±Ç°ú Æ÷±â

ÀÌ ¹®¼­´Â Ambrose Au¿Í David Ranch¿¡°Ô ÆÇ±ÇÀÌ ÀÖ°í, ÀÚÀ¯·Ó°Ô ÀÌ¿ë °¡´ÉÇÑ ¹®¼­ÀÌ´Ù. ÀÌ ¹®¼­´Â GNU General Public License¿¡ ÀÇÇØ¼­ Àç ¹èÆ÷ÇÒ ¼ö ÀÖ´Ù.

This document is copyright(c) 1999 Ambrose Au and David Ranch and it is a FREE document. You may redistribute it under the terms of the GNU General Public License.

ÀÌ ¹®¼­´Â Ambrose¿Í David°¡ ÃÖ¼±À» ´ÙÇÑ ¹®¼­·Î¼­, ¿Ç¹Ù¸¥ ³»¿ëÀ» ´ã°í ÀÖ´Ù. ±×·¯³ª, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀº »ç¶÷¿¡ ÀÇÇØ¼­ °³¹ßµÈ °ÍÀ̹ǷÎ, ¶§¶§·Î ½Ç¼ö³ª ¹ö±×µîÀÌ ÀÖÀ» ¼ö ÀÖ´Ù.

ÀÌ ¹®¼­¿¡ ¾²¿©Áø Á¤º¸¸¦ »ç¿ëÇØ¼­ »ý±â´Â, ¿©·¯ºÐÀÇ ÄÄÇ»ÅÍÀÇ ¼Õ»óÀ̳ª ¾î¶°ÇÑ ¼Õ½Ç¿¡ ´ëÇØ¼­µµ ¾Æ¹«µµ Ã¥ÀÓÀ» ÁöÁö ¾Ê´Â´Ù.

ÀÌ ¹®¼­ÀÇ Á¤º¸¿¡ ÀÇÇØ ÇàÇØÁø ÇàÀ§ ¶§¹®¿¡ ¹ß»ýµÈ ¾î¶² ¼Õ»óµµ ÀúÀڴ åÀÓÁöÁö ¾Ê´Â´Ù.

No person, group, or other body is responsible for any damage on your computer(s) and any other losses by using the information on this document. i.e.

THE AUTHORS AND ALL MAINTAINERS ARE NOT RESPONSIBLE FOR ANY DAMAGES INCURRED DUE TO ACTIONS TAKEN BASED ON THE INFORMATION IN THIS DOCUMENT.

ÀÚ, ÀÌ »óÀÇ ³»¿ëÀ» ¼÷ÁöÇϰí... ½ÃÀÛÇØ º¸µµ·Ï ÇÏÀÚ..

2. ¹è°æ Áö½Ä

2.1 IP ¸¶½ºÄ¿·¹À̵å¶õ ¹«¾ùÀΰ¡?

IP ¸¶½ºÄ¿·¹À̵å´Â ¸®´ª½ºÀÇ ³×Æ®¿öÅ· ±â´ÉÀ¸·Î, »ó¿ë ¹æÈ­º®(firewall)À̳ª ³×Æ®¿÷ ¶ó¿ìÅÍ(network router)¿¡¼­ ÈçÈ÷ º¼ ¼ö ÀÖ´Â 1 ´ë ´Ù(one-to-many) ¹æ½ÄÀÇ NAT(Network Address Translation: ³×Æ®¿÷ ÁÖ¼Ò ÇØ¼®)¿Í À¯»çÇÏ´Ù. ¿¹À» µé¾î¼­, ¾î¶² ¸®´ª½º È£½ºÆ®°¡ PPP(¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ ÀüÈ­Á¢¼Ó ³×Æ®¿öÅ·¿¡ ÇØ´çÇÔ), ÀÌ´õ³Ý(Ethernet), ±âŸµîµîÀÇ ¹æ¹ýÀ¸·Î ÀÎÅͳݿ¡ ¿¬°áµÇ¾î ÀÖ´Ù¸é, ÀÌ ¸®´ª½º ¹Ú½º¿¡ ¿¬°áµÈ(PPP, Ethernet, ±âŸµîµî) ³»ºÎÀÇ ÄÄÇ»Å͵鵵 IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼­ ÀÎÅͳݿ¡ ¿¬°áÇÒ ¼ö ÀÖ´Ù. ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵带 ÅëÇϸé, ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ °ø½ÄÀûÀ¸·Î ÇÒ´çµÈ IP ÁÖ¼Ò°¡ ¾ø´õ¶óµµ °¡´ÉÇÏ´Ù.

MASQ¸¦ »ç¿ëÇϸé, MASQ °ÔÀÌÆ®¿þÀÌ(gateway: Åë·Î°¡ µÇ´Â ÄÄÇ»ÅÍ)¸¦ ÅëÇØ¼­ ¸î´ëÀÇ ÄÄÇ»Å͵éÀÌ ¼û¾î¼­ ÀÎÅͳÝÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù. Áï, ÀÎÅͳݿ¡ ÀÖ´Â ´Ù¸¥ ÄÄÇ»Å͵鿡°Ô´Â, IP MASQ¸¦ ÅëÇØ¼­ ¹Ù±ùÀ¸·Î ³ª¿À´Â Á¤º¸µéÀº IP MASQ Linux ¼­¹ö ÀÚü°¡ º¸³»´Â °Íó·³ º¸ÀδÙ. ÀÌ·¯ÇÑ ±â´É¿¡ µ¡ºÙ¿©¼­, IP ¸¶½ºÄ¿·¹À̵å´Â ´ë´ÜÈ÷ ¾ÈÀüÇÑ ³×Æ®¿÷ ȯ°æÀ» Á¦°øÇÑ´Ù. Àß ±¸¼ºµÈ ¸¶½ºÄ¿·¹À̵ù ½Ã½ºÅÛ°ú ³»ºÎ LANÀÇ º¸¾ÈÀ» ±ú´Â °ÍÀº, Àß ±¸¼ºµÈ ¹æÈ­º®ÀÇ º¸¾ÈÀ» ±ú´Â °Í ¸¸Å­À̳ª ¾î·Æ´Ù.

2.2 ÇöÀç »óȲ

IP ¸¶½ºÄ¿·¹À̵å´Â óÀ½ °³¹ßµÈÁö ¼ö³âÀÌ Áö³µ°í, ¸®´ª½º Ä¿³ÎÀÌ 2.2.x ·Î µé¾î¼­¸é¼­ ¸Å¿ì ¼º¼÷ÇØÁ³´Ù. ¸®´ª½º Ä¿³ÎÀº 1.3.x ¹öÁ¯ºÎÅÍ MASQ ±â´ÉÀ» ÀÚü Áö¿øÇß´Ù. ÇöÀç´Â ¼ö¸¹Àº °³ÀÎ, ¶Ç´Â »ó¾÷ ±â°üµéÀÌ ÈǸ¢ÇÏ°Ô »ç¿ëÇϰí ÀÖ´Ù.

À¥ ÆäÀÌÁö º¸±â, TELNET Á¢¼Ó, FTP, PING, TRACEROUTE, ±âŸµîµîÀÇ Åë»óÀûÀÎ ³×Æ®¿÷ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼­ Àß ÀÛµ¿ÇÑ´Ù. FTP, IRC¿Í Real Audio¿Í °°Àº °Íµµ, ÀûÀýÇÑ IP MASQ ¸ðµâÀ» ÀûÀçÇϸé Àß ÀÛµ¿ÇÑ´Ù. MP3³ª Æ®·ç ½ºÇÇÄ¡(True Speech)µîÀÇ ½ºÆ®¸®¹Ö ¿Àµð¿À(streaming audio)¿Í °°Àº ³×Æ®¿÷ °ü·Ã ÇÁ·Î±×·¥µéµµ ¿ª½Ã ÀÛµ¿ÇÑ´Ù. ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ¾î¶² µ¿·á »ç¿ëÀÚµéÀº È­»óȸÀÇ ¼ÒÇÁÆ®¿þ¾î¿¡¼­±îÁö ÁÁÀº °á°ú¸¦ ¾òÀº ¹Ù ÀÖ´Ù.

Áö¿øµÇ´Â Àüü ¼ÒÇÁÆ® ¿þ¾î ¸ñ·ÏÀº Supported Client Software section¿¡¼­ È®ÀÎÇϱ⠹ٶõ´Ù.

IP ¸¶½ºÄ¿·¹À̵å´Â ¿©·¯°¡Áö ´Ù¸¥ OS¿Í Çϵå¿þ¾î Ç÷§ÆûÀ» »ç¿ëÇÏ´Â »ç¿ëÀÚ ÄÄÇ»Å͵é(client machines)¿¡°Ôµµ ¼­¹ö·Î¼­ Àß µ¿ÀÛÇÑ´Ù. MASQ ³»ºÎ¿¡¼­ ¼º°øÀûÀ¸·Î µ¿ÀÛÇÑ ½Ã½ºÅÛµéÀº ´ÙÀ½°ú °°´Ù :

  • Unix: Sun Solaris, *BSD, Linux, Digital UNIX, ±âŸµîµî
  • Microsoft Windows 95/98, Windows NT¿Í Windows for Workgroups (TCP/IP ÆÐŰÁö°¡ ¼³Ä¡µÈ »óÅÂ)
  • IBM OS/2
  • MacTCP or Open Transport¸¦ »ç¿ëÇÏ´Â Apple Macintosh MacOS machineµé
  • packet µå¶óÀ̹ö¿Í NCSA Telnet ÆÐŰÁö¸¦ »ç¿ëÇÏ´Â DOS ±â¹Ý ½Ã½ºÅÛ
  • VAXen
  • ¸®´ª½º³ª NT¸¦ »ç¿ëÇÏ´Â Compaq/Digital Alpha ½Ã½ºÅÛ
  • AmiTCP ³ª AS225-stackÀ» »ç¿ëÇÏ´Â Amiga ÄÄÇ»ÅͱîÁö..

¸®½ºÆ®´Â ´õ °è¼ÓµÉ ¼ö ÀÖÁö¸¸ ¿äÁ¡Àº ´ÙÀ½°ú °°´Ù. TCP/IP·Î Åë½ÅÇÒ ¼ö ÀÖ´Â OS¸¦ »ç¿ëÇÑ´Ù¸é ¹Ýµå½Ã IP ¸¶½ºÄ¿·¹À̵å¿Í ÇÔ²² µ¿ÀÛÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù!

2.3 ´©°¡ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇØ¼­ À̵æÀ» ¾ò´Â°¡?

  • ´ç½ÅÀÌ ÀÎÅͳݿ¡ ¿¬°áµÈ ¸®´ª½º È£½ºÆ®¸¦ °¡Áö°í ÀÖ°í,
  • TCP/IP°¡ ¼³Ä¡µÇ¾î ÀÖ°í ·ÎÄà ¼­ºê³Ý(local subnet)À» ÅëÇØ¼­ ¸®´ª½º È£½ºÆ®¿¡ ¿¬°áµÈ ÄÄÇ»ÅÍ ¸î´ë¸¦ °¡Áö°í Àְųª,
  • ´ç½ÅÀÇ ¸®´ª½º È£½ºÆ®°¡ µÎ°³ ÀÌ»óÀÇ ¸ðµ©À» °¡Áö°í PPP³ª SLIP¼­¹ö·Î µ¿ÀÛÇÏ¸é ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»Å͵é°ú ¿¬°áµÇ¾î ÀÖ°í,
  • ±× ´Ù¸¥ ÄÄÇ»Å͵éÀÌ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÁö ¾Ê¾Ò´Ù¸é,
  • ±×¸®°í ¹°·Ð, ISP·ÎºÎÅÍ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´ç¹Þ°í ¸®´ª½º¸¦ ¶ó¿ìÅÍ(router)·Î ¼³Á¤Çϰųª ¿ÜºÎ ¶ó¿ìÅ͸¦ ±¸ÀÔÇϴµîÀÇ Ãß°¡ºñ¿ëÀ» µéÀÌÁö ¾Ê°í ±× ´Ù¸¥ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» »ç¿ëÇϵµ·Ï ÇÏ°í ½Í´Ù¸é.

2.4 ´©±¸¿¡°Ô IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿ä ¾ø´Â°¡?

  • ´ç½ÅÀÇ ÄÄÇ»ÅͰ¡ ´Üµ¶À¸·Î ¼³Ä¡µÇ¾î ÀÖ°í ÀÎÅͳݿ¡ ¿¬°áµÇ¾î Àְųª (±×·¯³ª ´Üµ¶À¸·Î Á¸ÀçÇÏ´õ¶óµµ ¹æÈ­º®À» ¼³Á¤ÇÏ´Â °ÍÀº ÁÁÀº »ý°¢ÀÏ ¼ö ÀÖ´Ù),
  • ´Ù¸¥ ÄÄÇ»Å͵éÀ» À§Çؼ­ ÇÒ´çµÈ ¿©·¯°³ÀÇ IP ÁÖ¼Ò¸¦ °¡Áö°í ÀÖ´Ù¸é,
  • ±×¸®°í ¹°·Ð, ´ç½ÅÀÌ ¸®´ª½ºÀ» »ç¿ëÇÏ´Â '¹«ÀÓ ½ÂÂ÷'¶ó´Â °ÍÀ» ÁÁ¾ÆÇÏÁö ¾Ê°í, ¿ÀÈ÷·Á °°Àº ÀÏÀ» Çϱâ À§ÇØ ºñ½Ñ ´ë°¡¸¦ ÁöºÒÇÏ´Â °ÍÀ» ´õ ÆíÇÏ°Ô »ý°¢ÇÑ´Ù¸é.

2.5 IP ¸¶½ºÄ¿·¹À̵å´Â ¾î¶»°Ô µ¿ÀÛÇϴ°¡?

>Ken EvesÀÇ IP ¸¶½ºÄ¿·¹À̵å FAQ·ÎºÎÅÍ :

  °¡Àå °£´ÜÇÑ ¼³Ä¡ÀÇ ¿¹´Â ´ÙÀ½ ±×¸²°ú °°´Ù:

   SLIP/PPP         +------------+                         +-------------+
   ISP Á¦°øÀÚ·Î     |  Linux     |         SLIP/PPP        | ´Ù¸¥ ÄÄÇ»ÅÍ |
  <---------- modem1|    #1      |modem2 ----------- modem3|             |
    111.222.333.444 |            |           192.168.0.100 |             |
                    +------------+                         +-------------+

    À§ÀÇ ±×¸²¿¡¼­, IP_MASQUERADINGÀÌ ¼³Ä¡µÈ ¸®´ª½º box°¡ Linux #1À¸·Î ¼³Á¤µÇ¾î
  ÀÖ°í modem1À» ÅëÇÑ SLIP ȤÀº PPP·Î ÀÎÅͳݿ¡ ¿¬°áµÇ¾î ÀÖ´Ù. Linux #1Àº  
  111.222.333.444¶ó´Â IP ÁÖ¼Ò°¡ ÇÒ´çµÇ¾î ÀÖ´Ù. Linux #1Àº modom2¸¦ ÅëÇØ¼­ ´Ù¸¥ 
  ÄÄÇ»ÅͰ¡ SLIP ȤÀº PPP·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï µÇ¾î ÀÖ´Ù.

    µÎ¹øÂ° ½Ã½ºÅÛ(´Ù¸¥ ÄÄÇ»ÅÍ: ¹Ýµå½Ã ¸®´ª½º¸¦ »ç¿ëÇÒ ÇÊ¿ä´Â ¾ø´Ù) Linux #1À¸·Î
  SLIP ȤÀº PPP Á¢¼ÓÀ» ÇÑ´Ù. ´Ù¸¥ ÄÄÇ»ÅÍ´Â °ø½ÄÀûÀ¸·Î ÇÒ´çµÈ IP ÁÖ¼Ò¸¦ °¡Áö°í
  ÀÖÁö ¾Ê´Ù. ±×·¡¼­ ³»ºÎ ÁÖ¼ÒÀÎ 192.168.0.100À̶ó´Â ÁÖ¼Ò°¡ ÇÒ´çµÇ¾î ÀÖ´Ù.
  (¾Æ·¡ ÂüÁ¶)

    ¶ó¿ìÆÃ Á¤º¸°¡ Á¦´ë·Î ¼³Á¤µÇ¾î ÀÖÀ¸¸é IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼­ "´Ù¸¥ ÄÄÇ»ÅÍ"´Â
  ¸¶Ä¡ ÀÎÅͳݿ¡ Á÷Á¢ ¿¬°áµÇ¾î ÀÖ´Â °Íó·³(¸î°¡Áö¸¦ Á¦¿ÜÇϰí) ÀÎÅͳÝÀ» »ç¿ë
  ÇÒ ¼ö ÀÖ´Ù.

Pauline Middelink¿¡ ÀÇÇϸé:

  "´Ù¸¥ ÄÄÇ»ÅÍ"´Â Linux #1À» °ÔÀÌÆ®¿þÀÌ(gateway)·Î ¼³Á¤ÇØ¾ß ÇÑ´Ù´Â »ç½ÇÀ» ÀØÁö
  ¸»¾Æ¾ß ÇÑ´Ù(±âº» ¶ó¿ìÅÍ(default route)Àΰ¡ ´ÜÁö ¼­ºê³Ý(subnet)Àΰ¡´Â »ó°ü¾ø´Ù.)
  ¸¸¾à "´Ù¸¥ ÄÄÇ»ÅÍ"°¡ Linux #1À» °ÔÀÌÆ®¿þÀÌ·Î ¼³Á¤ÇÏÁö ¾Ê´Â´Ù¸é, Linux #1Àº 
  proxy arp¸¦ Áö¿øÇϵµ·Ï ¼³Á¤µÇ¾î¾ß Çϴµ¥, proxy arp¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­ÀÇ
  ¹üÁÖ¸¦ ¹þ¾î³ª´Â ³»¿ëÀÌ´Ù.

´ÙÀ½Àº comp.os.linux.networking¿¡ Æ÷½ºÆÃµÈ ±Û¿¡¼­ ¹ßÃéÇÑ °ÍÀ¸·Î À§ÀÇ ¿¹¿¡¼­ÀÇ
À̸§¿¡ ¸Âµµ·Ï ¼öÁ¤µÈ °ÍÀÌ´Ù:

   o ³ª´Â "´Ù¸¥ ÄÄÇ»ÅÍ"°¡ PPPȤÀº SLIPÀ¸·Î ¿¬°áµÈ ³ªÀÇ Linux #1À» gateway·Î ÀνÄ
     Çϵµ·Ï ÇÏ¿´´Ù.
   o "´Ù¸¥ ÄÄÇ»ÅÍ"·ÎºÎÅÍ Linux #1À¸·Î ÆÐŶÀÌ Àü´ÞµÉ ¶§, Linux #1Àº ±× ÆÐŶ¿¡
     »õ·Î¿î ¹ß½ÅÆ÷Æ®¹øÈ£(source port number)¸¦ ÇÒ´çÇÏ°í ¿ø·¡ÀÇ ÁÖ¼Ò´Â µû·Î 
     ÀúÀåÇØ µÐ´Ù. MASQ¼­¹ö´Â ¼öÁ¤µÈ ÆÐŶÀ» SLIP/PPP¸¦ ÅëÇØ¼­ ÀÎÅͳÝÀ¸·Î 
     Àü¼ÛÇÑ´Ù.
   o ÀÎÅͳÝÀ¸·ÎºÎÅÍ Linux #1À¸·Î ÆÐŶÀÌ µÇµ¹¾Æ¿Ã ¶§, Linux #1Àº Æ÷Æ®¹øÈ£(port
     number)¸¦ °Ë»çÇØ¼­ "´Ù¸¥ ÄÄÇ»ÅÍ"·ÎºÎÅÍ ¿äûµÇ¾ú´ø °ÍÀÎÁö È®ÀÎÇÑ´Ù. ¸Â´Ù¸é,
     MASQ ¼­¹ö´Â ÀúÀåÇØµ×´ø ¿ø·¡ÀÇ Æ÷Æ®¹øÈ£¿Í IP ÁÖ¼Ò¸¦ ÀÎÅͳÝÀ¸·ÎºÎÅÍ ¿Â
     ÆÐŶ¿¡ ´Ù½Ã ÇÒ´çÇϰí "´Ù¸¥ ÄÄÇ»ÅÍ"·Î º¸³»ÁØ´Ù.
   o ÀÎÅͳݿ¡¼­ ÆÐŶÀ» º¸³½ È£½ºÆ®´Â ÀÌ·± ÀÏÀÌ ÀϾ´Â °ÍÀ» ÀüÇô ¾Ë ¼ö ¾ø´Ù.

IP MasqueradingÀÇ ¶Ç´Ù¸¥ ¿¹:

¾Æ·¡ ±×¸²¿¡ ÀüÇüÀûÀÎ ¿¹°¡ ÀÖ´Ù:


    +----------+
    |          |  Ethernet
    | A-box    |::::::
    |          |.2   : 192.168.0.x
    +----------+     :
                     :      +----------+   
    +----------+     :   .1 |  Linux   |   PPP Á¢¼Ó
    |          |     :::::::| Masq-Gate|:::::::::::::::::::// Internet
    | B-box    |::::::      |          |  111.222.333.444
    |          |.3   :      +----------+
    +----------+     :
                     :
    +----------+     :
    |          |     :
    | C-box    |::::::
    |          |.4
    +----------+

    |                       |          |
    | <----³»ºÎ ³×Æ®¿÷----> |          | <------¿ÜºÎ ³×Æ®¿÷------>
    |                       |          |

ÀÌ ¿¹¿¡¼­´Â ¸ðµÎ ³×°³ÀÇ ÄÄÇ»ÅͰ¡ ÀÖ´Ù. ÀÌ °æ¿ì¿¡µµ ¸¶Âù°¡Áö·Î ¿À¸¥ÂÊ ³¡¿¡´Â PPPÁ¢¼ÓÀ» ÇÒ ¼ö ÀÖ´Â ¼­¹ö°¡ ÀÖ°í, ´õ ¿À¸¥Á·¿¡´Â Á¤º¸¸¦ ±³È¯ÇϰíÀÚ ÇÏ´Â ÀÎÅͳݻóÀÇ È£½ºÆ®µéÀÌ ÀÖ´Ù°í °¡Á¤ÇÑ´Ù. ¸®´ª½º ½Ã½ºÅÛÀÎ Masq-Gate°¡ ³»ºÎ ³×Æ®¿÷ÀÇ A-box, B-box, C-box¸¦ ¿ÜºÎÀÇ ÀÎÅͳÝÀ¸·Î ¿¬°áÇϵµ·Ï ÇØÁÖ´Â IP Masquerading °ÔÀÌÆ®¿þÀÌÀÌ´Ù. ³»ºÎ ³×Æ®¿÷Àº RFC-1918¿¡ Á¤ÇØÁø ¸î°¡Áö ³»ºÎ ³×Æ®¿÷ ÁÖ¼ÒÁß ÇѰ¡Áö¸¦ »ç¿ë´Âµ¥, ÀÌ °æ¿ì¿¡´Â C Ŭ·¡½º ³×Æ®¿÷ÀÎ 192.168.0.0ÀÌ´Ù. ¸®´ª½º ¹Ú½º°¡ 192.168.0.1ÀÇ IP ÁÖ¼Ò¸¦ »ç¿ëÇϸç, ´Ù¸¥ ½Ã½ºÅÛµéÀº ´ÙÀ½°ú °°Àº ÁÖ¼Ò¸¦ °®´Â´Ù:

  • A-Box: 192.168.0.2
  • B-Box: 192.168.0.3
  • C-Box: 192.168.0.4

¼¼ °³ÀÇ ÄÄÇ»ÅÍ, A-box, B-box and C-box´Â TCP/IP¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù¸é ¾î¶² OS¸¦ »ç¿ëÇϰí ÀÖ´õ¶óµµ »ó°ü ¾ø´Ù. À©µµ¿ìÁî 95, ¸ÅŲÅä½Ã MacTCP ¶Ç´Â OpenTransport³ª ´Ù¸¥ ¸®´ª½º ¹Ú½º¶óµµ IP MASQ¸¦ ÅëÇØ¼­ ÀÎÅͳݿ¡ ¿¬°áµÉ ¼ö ÀÖ´Ù. ¿¬°áµÇ´Â µ¿¾È, ¸¶½ºÄ¿·¹À̵ùÀ» ÇÏ´Â ½Ã½ºÅÛ, ȤÀº MASQ-gate´Â ³»ºÎ·ÎºÎÅÍÀÇ ¿¬°áÀ» ¸ðµÎ MASQ-gate ÀÚü¿¡¼­ º¸³»´Â °Íó·³ ÀüȯÇÏ°Ô µÈ´Ù. MASQ´Â ¿ÜºÎ·ÎºÎÅÍ ½ÅÈ£(¶Ç´Â Á¤º¸)°¡ ¿À¸é, ³»ºÎ¿¡ ÀÖ´Â ¿ø·¡ÀÇ ÄÄÇ»ÅÍ·Î °¡µµ·Ï ÀçÁ¤·ÄÇÑ´Ù. ±×·¡¼­ ³»ºÎ ³×Æ®¿÷¿¡°Ô´Â ¸¶Ä¡ ÀÎÅͳݿ¡ Á÷Á¢ ¿¬°áµÇ¾î ÀÖ´Â °Íó·³ º¸¿©Áö°í, ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ëÇϰí ÀÖ´ÂÁö ¾Æ´ÑÁö¸¦ ±¸º°ÇÒ ¼ö ¾ø°Ô µÈ´Ù. À̰ÍÀ» "Åõ¸íÇÑ" ¿¬°áÀ̶ó ÇÑ´Ù.

NOTE: ´ÙÀ½ »çÇ׿¡ ´ëÇÑ ÀÚ¼¼ÇÑ °ÍÀº FAQ ¸¦ ÂüÁ¶Çϱ⠹ٶ÷:

  • NAT, MASQ, proxy ¼­¹ö°£ÀÇ Â÷ÀÌÁ¡.
  • ÆÐŶ ¹æÈ­º®ÀÌ µ¿ÀÛÇÏ´Â ¹æ¹ý.

2.6 ¸®´ª½º 2.0.x ¹öÁ¯¿¡¼­ IP Masqeurade¸¦ »ç¿ëÇϱâ À§ÇÑ ¿ä±¸»çÇ×µé

** °¡Àå ÃÖ±ÙÀÇ Á¤º¸´Â IP Masquerade Resource¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù. **

  • °¡´ÉÇÑ Çϵå¿þ¾î»ç¾ç. ÀÚ¼¼ÇÑ »çÇ×Àº FAQ-Hardware ÂüÁ¶.

  • Ä¿³Î 2.0.x ¼Ò½º´Â http://www.kernel.org/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
    (·¹µåÇÞ 5.2¿Í °°Àº ÃÖ±ÙÀÇ ¸®´ª½º MASQ-supported-Distributions ¿¡¼­´Â IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµÎ ¸ðµâ·Î Áö¿øµÇµµ·Ï ÄÄÆÄÀϵǾî ÀÖ´Â Ä¿³ÎÀ» Á¦°øÇÑ´Ù. ±×·± °æ¿ì¿¡´Â Ä¿³ÎÀ» »õ·Î ÄÄÆÄÀÏÇÒ Çʿ䰡 ¾ø´Ù. ¸¸¾à ÇöÀç »ç¿ëÇÏ´Â Ä¿³ÎÀ» ¾÷±×·¹À̵å ÇÏ·Á ÇÑ´Ù¸é, °ü·ÃµÈ ´Ù¸¥ ÇÁ·Î±×·¥µéµµ ¾÷±×·¹À̵åÇØ¾ß ÇÑ´Ù.(ÃßÈÄ¿¡ ¾ð±ÞµÊ)

  • ÀûÀç°¡´ÉÇÑ Ä¿³Î ¸ðµâµé, 2.1.85ÀÌ»ó ±ÇÀå. http://www.pi.se/blox/modules/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
    (modules-1.3.57°¡ ÃÖÀú ¿ä±¸»çÇ×ÀÌ´Ù)

  • TCP/IP ³×Æ®¿÷À̳ª LAN ±¸¼ºÀº Linux NET-3 HOWTO¿Í Network Administrator's Guide¿¡¼­ ´Ù·ç°í ÀÖ´Ù.
    TrinityOSµµ È®ÀÎÇØ º¸±â ¹Ù¶õ´Ù. TrinityOS´Â ¸®´ª½º»ó¿¡¼­ÀÇ ³×Æ®¿öÅ·¿¡ ´ëÇÑ ¾ÆÁÖ ÁÁÀº ¾È³»¼­À̸ç, IP MASQ, security, DNS, DHCP, Sendmail, PPP, Diald, NFS, IPSEC±â¹ÝÀÇ VPNs, ±×¸®°í °¢°¢ÀÇ ¼º´É¿¡ °üÇÑ °ÍµéÀ» ´Ù·ç°í ÀÖ´Ù. ¾à 50°³ °¡·®ÀÇ ¼½¼ÇµéÀÌ ÀÖ´Ù!!

  • ¸®´ª½º È£½ºÆ®¸¦ ÀÎÅͳݿ¡ ¿¬°áÇÏ´Â °Í¿¡ °üÇÑ ³»¿ëÀº Linux ISP Hookup HOWTO, Linux PPP HOWTO, TrinityOS, Linux DHCP mini-HOWTO, Linux Cable Modem mini-HOWTO¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • Ipfwadm 2.3 ȤÀº ±× ÀÌ»óÀÇ ¹öÁ¯Àº ftp://ftp.xos.nl/pub/linux/ipfwadm/ipfwadm-2.3.tar.gz¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
    °¢ ÇÁ·Î±×·¥ÀÇ ¹öÁ¯ ¿ä±¸»çÇ׿¡ ´ëÇÑ Ãß°¡Á¤º¸´Â Linux IPFWADM page¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • »õ·Î¿î Ä¿³ÎÀÇ ¼³Á¤, ÄÄÆÄÀÏ, ¼³Ä¡ÇÏ´Â °ÍÀº Linux Kernel HOWTO¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • ´ÙÀ½¿¡ ¾ð±ÞµÈ ¿©·¯°¡Áö ÆÐÄ¡¸¦ »ç¿ëÇØ¼­ IP ¸¶½ºÄ¿·¹À̵忡 ´Ù¸¥ ±â´ÉµéÀ» Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù:

    • TCP/IP port-forwarders ¶Ç´Â re-directors: ÀÌ ÅøµéÀ» »ç¿ëÇØ¼­, ´ë°³´Â MASQ¿Í °°ÀÌ µ¿ÀÛÇÏÁö ¾Ê´Â ÇÁ·Î±×·¥µéÀ» ÀÛµ¿Çϵµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¿Ü¿¡µµ, ¿ÜºÎÀÇ ÀÎÅÍ³Ý »ç¿ëÀÚµéÀÌ ³»ºÎÀÇ WWW, TELNET, SMTP, FTP(ÆÐÄ¡ ÇÊ¿ä) µîµîÀÇ ¼­¹ö¿¡ ¿¬°áÇϵµ·Ï MASQ¼­¹ö¸¦ ¼³Á¤ÇÒ ¼öµµ ÀÖ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº ÀÌ HOWTOÀÇ Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù. 2.0.x Ä¿³ÎÀ» À§ÇÑ IP Masquerading ÆÐÄ¡ ¸®½ºÆ®:

      PORTFWed FTP:

      • ¿ÜºÎ·ÎºÎÅÍÀÇ FTPÁ¢¼ÓÀ» ³»ºÎÀÇ FTP ¼­¹ö·Î ¿¬°áÇÏ°í ½Í´Ù¸é Fred Viles's FTP server patch¸¦ ³»·Á¹Þ¾Æ »ç¿ëÇ϶ó. ÀÌ¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ÀÌ HOWTOÀÇ Forwarders ¼½¼Ç¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

      X-Windows¿¡¼­ÀÇ display ¿¬°á(forwarders):

      MASQ¸¦ ÅëÇÑ ICQ¸¦ »ç¿ëÇϱâ À§ÇÑ ¸ðµâ

      PPTP (GRE)¿Í SWAN (IPSEC) VPNsÀÇ Åͳθµ ¿¬°á(tunneling forwarders):

      °ÔÀÓ °ü·Ã ÆÐÄ¡µé:

      • Glenn LambÀÇ LooseUDP for 2.0.36+ ÆÐÄ¡.

        WWW ºê¶ó¿ìÀú¿¡ µû¶ó¼­, .gz È®ÀåÀÚÀÇ È­ÀÏÀ» ÀÚµ¿À¸·Î ¿­¼öµµ ÀÖ´Ù. ´Ù¿î·Îµå¸¸ Çϱâ À§Çؼ­´Â SHIFT۸¦ ´©¸¥»óÅ¿¡¼­ À§ÀÇ URLÀ» Ŭ¸¯Ç϶ó.

        ´õ ÀÚ¼¼ÇÑ »çÇ×À» ¾Ë·Á¸é Dan KegelÀÇ NAT PageÀ» È®ÀÎÇϱ⠹ٶõ´Ù. Game-Clients ¼½¼Ç°ú FAQ ¼½¼Ç¿¡¼­ ´Ù¸¥ Á¤º¸µµ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

    À§ÀÇ ÆÐÄ¡µé¿¡ ´ëÇÑ ´õ ¸¹Àº Á¤º¸¿Í ±×¿ÜÀÇ ´Ù¸¥ Á¤º¸µéÀ» IP Masquerade Resource ¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

2.7 ¸®´ª½º 2.2.x ¹öÁ¯¿¡¼­ IP Masqeurade¸¦ »ç¿ëÇϱâ À§ÇÑ ¿ä±¸»çÇ×µé

** °¡Àå ÃÖ±ÙÀÇ Á¤º¸´Â IP Masquerade Resource ¸¦ Âü°íÇϱ⠹ٶõ´Ù. **

  • Ä¿³Î 2.2.xÀÇ ¼Ò½º´Â http://www.kernel.org/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
    NOTE #1: ¸®´ª½º 2.2.x ¹öÁ¯Áß¿¡¼­ 2.2.11 ÀÌÇÏÀÇ ¹öÁ¯Àº IPCHAINS fragmentation bug¸¦ °¡Áö°í ÀÖ´Ù. ÀÌ·± ÀÌÀ¯·Î, °­·ÂÇÑ IPCHAINS rulesetµéÀ» ÁöÁ¤ÇÏ¸é °ø°Ý¿¡ ³ëÃâµÇ°Ô µÈ´Ù. Ä¿³ÎÀ» ¾÷±×·¹À̵åÇÏ¿© ¹®Á¦¸¦ ÇØ°áÇϱ⠹ٶõ´Ù.

    NOTE #2: Redhat 5.2¿Í °°Àº ÃÖ±ÙÀÇ MASQ-supported-Distributions Àº 2.2.x Ä¿³ÎÀ» »ç¿ëÇÒ ¼ö ¾øÀ»Áöµµ ¸ð¸¥´Ù. DHCP, NetUtils¿Í °°Àº ÅøµéÀ» ¾÷±×·¹À̵åÇØ¾ß ÇÒ °ÍÀÌ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº ÀÌ HOWTO¿¡¼­ ¾ð±ÞµÉ °ÍÀÌ´Ù.

  • ÀûÀç°¡´ÉÇÑ Ä¿³Î ¸ðµâµé, 2.1.121 ÀÌ»ó ±ÇÀå. http://www.pi.se/blox/modules/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.

  • TCP/IP ³×Æ®¿÷À̳ª LAN ±¸¼ºÀº Linux NET-3 HOWTO¿Í Network Administrator's Guide¿¡¼­ ´Ù·ç°í ÀÖ´Ù.
    TrinityOSµµ È®ÀÎÇØ º¸±â ¹Ù¶õ´Ù. TrinityOS´Â ¸®´ª½º»ó¿¡¼­ÀÇ ³×Æ®¿öÅ·¿¡ ´ëÇÑ ¾ÆÁÖ ÁÁÀº ¾È³»¼­À̸ç, IP MASQ, security, DNS, DHCP, Sendmail, PPP, Diald, NFS, IPSEC±â¹ÝÀÇ VPNs, ±×¸®°í °¢°¢ÀÇ ¼º´É¿¡ °üÇÑ °Í µî ¾à 50°³ °¡·®ÀÇ ¼½¼ÇµéÀÌ ÀÖ´Ù!!

  • ¸®´ª½º È£½ºÆ®¸¦ ÀÎÅͳݿ¡ ¿¬°áÇÏ´Â °Í¿¡ °üÇÑ ³»¿ëÀº Linux ISP Hookup HOWTO, Linux PPP HOWTO, TrinityOS, Linux DHCP mini-HOWTO, Linux Cable Modem mini-HOWTO¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • IP Chains 1.3.9 ȤÀº ±× ÀÌ»óÀÇ ¹öÁ¯Àº http://www.rustcorp.com/linux/ipchains/¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
    °¢ ÇÁ·Î±×·¥ÀÇ ¹öÁ¯ ¿ä±¸»çÇ׿¡ ´ëÇÑ Ãß°¡Á¤º¸´Â Linux IP Firewalling Chains page¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • »õ·Î¿î Ä¿³ÎÀ» ¼³Á¤, ÄÄÆÄÀÏ, ¼³Ä¡ÇÏ´Â °ÍÀº Linux Kernel HOWTO¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  • ´ÙÀ½¿¡ ¾ð±ÞµÈ ¿©·¯°¡Áö ÆÐÄ¡¸¦ »ç¿ëÇØ¼­ IP ¸¶½ºÄ¿·¹À̵忡 ´Ù¸¥ ±â´ÉµéÀ» Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù:

À§ÀÇ ÆÐÄ¡µé¿¡ ´ëÇÑ ´õ ¸¹Àº Á¤º¸¿Í ±×¿ÜÀÇ ´Ù¸¥ Á¤º¸µéÀ» IP Masquerade Resource ¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

3. IP ¸¶½ºÄ¿·¹ÀÌµå ¼³Á¤

¸¸¾à ´ç½ÅÀÇ ³×Æ®¿÷¿¡ Áß¿äÇÑ Á¤º¸°¡ ÀÖ´Ù¸é, IP ¸¶½ºÄ¿·¹À̵带 ±¸ÇöÇϱâ ÀÌÀü¿¡ "º¸¾È"À̶ó´Â °ÍÀ» »ý°¢ÇØ º¸±æ ¹Ù¶õ´Ù. ±âº»ÀûÀ¸·Î, IP MASQ´Â ´ç½ÅÀÌ ÀÎÅͳݿ¡ ¿¬°áÇÒ ¼ö ÀÖµµ·Ï ÇÏ´Â Åë·ÎÀÌÁö¸¸, ÀÎÅͳݻóÀÇ ´©±º°¡°¡ ´ç½ÅÀÇ ³»ºÎ ³×Æ®¿÷À¸·Î µé¾î¿À´Â Åë·Î°¡ µÉ ¼öµµ ÀÖ´Ù.

ÀÏ´Ü IP MASQ°¡ µ¿ÀÛÇÏ°Ô µÇ¸é, IPFWADM/IPCHAINS ¹æÈ­º®¿¡ ¸Å¿ì °­·ÂÇÑ Á¤Ã¥(ruleset)À» »ç¿ëÇÒ °ÍÀ» °­·ÂÈ÷ ±Ç°íÇÑ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â Strong-IPFWADM-Rulesets °ú Strong-IPCHAINS-Rulesets ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

3.1 Ä¿³Î¿¡¼­ IP ¸¶½ºÄ¿·¹À̵带 Áö¿øÇϵµ·Ï ÄÄÆÄÀÏ Çϱâ

¸¸¾à ´ç½ÅÀÇ ¸®´ª½º ¹èÆ÷º»ÀÌ ´ÙÀ½Ç׸ñµéÀ» Áö¿øÇϵµ·Ï ÄÄÆÄÀÏ µÇ¾îÁ® ÀÖ°í ¸¶½ºÄ¿·¹À̵忡 °ü°èµÈ ¸ðµâµéÀÌ ÄÄÆÄÀϵǾ Á¦°øµÇ°í ÀÖ´Ù¸é Ä¿³Î ÄÄÆÄÀÏÀ» ÇÒ Çʿ䰡 ¾ø´Ù(´ëºÎºÐÀÇ ¹èÆ÷º»¿¡ Æ÷ÇԵǾî ÀÖÀ» °ÍÀÌ´Ù.):
  • IPFWADM/IPCHAINS
  • IP forwarding
  • IP masquerading
  • IP Firewalling
  • ±âŸ µîµî
´ç½ÅÀÇ ¹èÆ÷º»ÀÌ ¸¶½ºÄ¿·¹À̵带 Áö¿øÇÏ´ÂÁö È®½ÇÇÏÁö ¾Ê´Ù¸é, MASQ-supported-Distributions ¼½¼ÇÀ̳ª IP Masquerade Resource ¿¡¼­ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇÒ ¼ö ÀÖ´Ù. ´ç½ÅÀÇ ÆÐÆ÷º»ÀÌ IP ¸¶½ºÄ¿·¹À̵ùÀ» Áö¿øÇÏ´ÂÁö ¾Ë ¼ö°¡ ¾ø´Ù¸é, Áö¿øÇÏÁö ¾Ê´Â´Ù°í »ý°¢ÇÏ°í ´ÙÀ½ ´Ü°è·Î ³Ñ¾î°¡¶ó.

Áö¿øÇϵµ·Ï µÇ¾î ÀÖµçÁö ¾Æ´ÏµçÁö »ó°ü¾øÀÌ, ÀÌ ¼½¼Ç¿¡´Â ´Ù¸¥ À¯¿ëÇÑ Á¤º¸µéÀÌ ¸¹ÀÌ ÀÖÀ¸¹Ç·Î ÀоîµÎ±â¸¦ ±ÇÀåÇÑ´Ù.

¸®´ª½º 2.0.x Ä¿³Î

ÇÊ¿äÇÑ ¼ÒÇÁÆ®¿þ¾î¿Í ÆÐÄ¡ µîÀº 2.0.x-Requirements ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

  • ¿ì¼±, Ä¿³Î ¼Ò½º°¡ ÇÊ¿äÇÏ´Ù.(°¡Àå ÃÖ±Ù ¹öÁ¯ÀÎ 2.0.36À̳ª ±× ÀÌ»ó ¹öÁ¯)

  • ¸¸¾à Ä¿³Î ÄÄÆÄÀÏÀÌ Ã³À½ÀÌ¶óµµ °Ì¸ÔÁö ¸»±â ¹Ù¶õ´Ù. ½ÇÁ¦·Î ÇØ º¸¸é, ±×´ÙÁö ¾î·ÆÁö ¾Ê°í 2.0.x-Requirements ¼½¼Ç¿¡ ³ª¿À´Â ¸î¸î URL¿¡¼­ ÄÄÆÄÀÏ ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇϰí ÀÖ´Ù.

  • tar xvzf linux-2.0.x.tar.gz -C /usr/src ¶ó°í ¸í·ÉÇÏ¿© Ä¿³ÎÀ» /usr/src/ ¿¡ Ǭ´Ù.(2.0.x´Â Ä¿³Î ¹öÁ¯) ¾ÐÃàÀ» Ǭ ´ÙÀ½¿¡, /usr/src/linux/ ¶ó´Â µð·ºÅ丮³ª ½Éº¼¸¯ ¸µÅ©°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

  • ÆÐÄ¡¸¦ °¡ÇÒ °ÍÀÌ ÀÖÀ¸¸é ¾ÐÃàÀ» Ǭ Ä¿³Î ¼Ò½º¿¡ ÆÐÄ¡¸¦ °¡ÇÑ´Ù. 2.0.36 ÀÌ»ó ¹öÁ¯¿¡¼­´Â, IP ¸¶½ºÄ¿·¹À̵ùÀ» Çϱâ À§ÇØ Æ¯º°ÇÑ ÆÐÄ¡°¡ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. IPPORTFW, PPTP, Xwindows forwarders ¿Í °°Àº ±â´ÉµéÀº ²À ÇÊ¿äÇÏÁö´Â ¾ÊÀº ¼±ÅûçÇ×µéÀÌ´Ù. URLµéÀº 2.0.x-Requirements ¼½¼ÇÀ» ÂüÁ¶Çϰí, ÃֽŠÁ¤º¸¿Í ±×¿ÜÀÇ ÆÐÄ¡¿¡ °ü·ÃµÈ URLµéÀº IP Masquerade Resources À» ÂüÁ¶ÇÏ±æ ¹Ù¶õ´Ù.

  • ¾Æ·¡¿¡ Ä¿³Î¿¡ Æ÷ÇԵǾî¾ß ÇÏ´Â ÃÖ¼ÒÇÑÀÇ ¿É¼ÇµéÀÇ ¸ñ·ÏÀÌ ÀÖ´Ù. ÇöÀç ¼³Ä¡µÇ¾î ÀÖ´Â ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º(LAN Ä«µå, ¸ðµ© µîµî)¸¦ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï ¼³Á¤ÇÏ´Â °Íµµ ÀØÁö ¸»¾Æ¾ß ÇÑ´Ù. Ä¿³ÎÀ» ÄÄÆÄÀÏÇÏ´Â ´õ ÀÚ¼¼ÇÑ ¹æ¹ý¿¡ ´ëÇØ¼­´Â Linux Kernel HOWTO ¿Í Ä¿³Î ¼Ò½º µð·ºÅ丮 ³»ÀÇ README È­ÀÏÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

    ´ÙÀ½ÀÇ ¿É¼Çµé¿¡¼­ YESÀΰ¡ ¶Ç´Â NOÀΰ¡¸¦ È®ÀÎÇϱ⠹ٶõ´Ù. ÀÌ HOWTO¿¡¼­ ³ªÁß¿¡ ¼³¸íÇÏ´Â ÀûÀýÇÑ ÆÐÄ¡¸¦ °¡ÇÏÁö ¾Ê´Â´Ù¸é ¾Æ·¡ÀÇ ¿É¼ÇµéÀÌ ¸ðµÎ º¸ÀÌÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù:

  * Prompt for development and/or incomplete code/drivers (CONFIG_EXPERIMENTAL) [Y/n/?]
    - YES: ÀÌ·¸°Ô ÇØ¾ß ³ªÁß¿¡ IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀ» ¼±ÅÃÇÒ ¼ö ÀÖ´Ù.

  * Enable loadable module support (CONFIG_MODULES) [Y/n/?]
    - YES: IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµéÀ» ÀûÀçÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.

  * Networking support (CONFIG_NET) [Y/n/?]
    - YES: ³×Æ®¿÷À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * Network firewalls (CONFIG_FIREWALL) [Y/n/?]
    - YES: IPFWADM ¹æÈ­º®À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * TCP/IP networking (CONFIG_INET)
    - YES: TCP/IP ÇÁ·ÎÅäÄÝÀ» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * IP: forwarding/gatewaying (CONFIG_IP_FORWARD)
    - YES: ¸®´ª½º ³×Æ®¿÷ ÆÐŶ Æ÷¿öµù°ú ¶ó¿ìÆÃÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù. 
           - IPFWADM ¿¡ ÀÇÇØ¼­ Á¦¾îµÈ´Ù.

  * IP: syn cookies (CONFIG_SYN_COOKIES) [Y/n/?]
    - YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ­ °­·ÂÈ÷ ±ÇÀåÇÑ´Ù.

  * IP: firewalling (CONFIG_IP_FIREWALL) [Y/n/?]
    - YES: ¹æÈ­º® ±â´ÉÀ» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * IP: firewall packet logging (CONFIG_IP_FIREWALL_VERBOSE) [Y/n/?]
    - YES: (²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸ °­·ÂÈ÷ ±ÇÀå):  ¹æÈ­º®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±æ ¼ö 
           ÀÖµµ·Ï ÇÑ´Ù.

  * IP: masquerading (CONFIG_IP_MASQUERADE [Y/n/?]
    - YES: IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÏ¿© ³»ºÎ ³×Æ®¿÷ÀÇ Æ¯Á¤ ÁּҷκÎÅÍÀÇ 
           ÆÐŶÀ» ÁÖ¼Ò¸¦ º¯°æÇÏ¿© ¿ÜºÎÀÇ TCP/IP³×Æ®¿÷À¸·Î ³»º¸³»°Ô ÇÑ´Ù.

  * IP: ipautofw masquerade support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPAUTOFW) [Y/n/?]
    - NO:  IPautofw Àº TCP/IP Æ÷Å並 Æ÷¿öµùÇÏ´Â ±¸½Ã´ëÀûÀÎ ¹æ¹ýÀÌ´Ù. ¹°·Ð 
           ÀÛµ¿Çϱâ´Â ÇÏÁö¸¸, IPPORTFW °¡ ´õ ³ªÀº ¹æ¹ýÀÌ´Ù. ±×·¯¹Ç·Î IPAUTOFWÀº 
           ÃßõÇÏÁö ¾Ê´Â´Ù.

  * IP: ipportfw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPPORTFW) [Y/n/?]
    - YES: ÀÌ ¿É¼ÇÀ» 2.0.x Ä¿³Î¿¡¼­ »ç¿ëÇϱâ À§Çؼ­´Â ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù. 

           ÀÌ ¿É¼ÇÀ» ¼³Á¤Çϸé, ÀÎÅͳݿ¡ ÀÖ´Â ¿ÜºÎ ÄÄÇ»ÅͰ¡ ¸¶½ºÄ¿·¹À̵åµÈ 
           ³»ºÎÀÇ Æ¯Á¤ ÄÄÇ»ÅÍ·Î Á÷Á¢ ¿¬°áÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ ±â´ÉÀº Åë»óÀûÀ¸·Î
           ³»ºÎÀÇ SMTP, TELNET, WWW ¼­¹ö¿¡ Á¢±ÙÇÏ´Â µ¥ »ç¿ëµÈ´Ù. FTP Æ÷Æ® 
           Æ÷¿öµùÀ» Çϱâ À§Çؼ­´Â FAQ¼½¼Ç¿¡ ¾ð±ÞµÇ¾î ÀÖ´Â Ãß°¡ÀûÀÎ ÆÐÄ¡¸¦ Àû¿ë
           ÇØ¾ß ÇÑ´Ù. Æ÷Æ® Æ÷¿öµù¿¡ ´ëÇÑ Ãß°¡ÀûÀÎ Á¤º¸´Â ÀÌ HOWTOÀÇ 
           Forwards ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

  * IP: ICMP masquerading (CONFIG_IP_MASQUERADE_ICMP) [Y/n/?]
    - YES: ICMP ÆÐŶÀ» ¸¶½ºÄ¿·¹À̵ùÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù. ²À ÇÊ¿äÇÏÁö ¾ÊÀ» ¼öµµ
           ÀÖÀ¸³ª, ICMP Áö¿ø ¾øÀÌ´Â ¸¹Àº ÇÁ·Î±×·¥µéÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾ÊÀ» 
           ¼ö ÀÖ´Ù.

  * IP: loose UDP port managing (EXPERIMENTAL) (CONFIG_IP_MASQ_LOOSE_UDP) [Y/n/?]
    - YES: ÀÌ ¿É¼ÇÀ» 2.0.x Ä¿³Î¿¡¼­ »ç¿ëÇϱâ À§Çؼ­´Â ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù. 

           ÀÌ ¿É¼ÇÀ» ÅëÇØ¼­, ³»ºÎÀÇ ÄÄÇ»Å͵鿡¼­ NAT¿Í °°Àº ½ÄÀ¸·Î ÀÛµ¿ÇÏ´Â
           ³×Æ®¿÷ °ÔÀÓµéÀ» ÀÎÅͳÝÀ» ÅëÇØ Áñ±æ ¼ö ÀÖ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº 
           ÀÌ HOWTOÀÇ FAQ¼½¼Ç¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

  * IP: always defragment (CONFIG_IP_ALWAYS_DEFRAG) [Y/n/?]
    - YES: ÀÌ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵ù Á¢¼ÓÀ» ÃÖÀûÈ­ ÁØ´Ù. - °­·ÂÈ÷ Ãßõ

  * IP: optimize as router not host (CONFIG_IP_ROUTER) [Y/n/?]
    - YES: ÀÌ ±â´ÉÀº Ä¿³ÎÀÇ ³×Æ®¿÷ ±â´ÉÀ» ÃÖÀûÈ­ ÁØ´Ù.

  * IP: Drop source routed frames (CONFIG_IP_NOSR) [Y/n/?]
    - YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ­ °­·ÂÈ÷ ÃßõÇÑ´Ù.

  * Dummy net driver support (CONFIG_DUMMY) [M/n/y/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ¿É¼ÇÀº ¹®Á¦°¡ ¹ß»ýÇØ¼­ µð¹ö±ëÀ» ÇÒ ¶§
           µµ¿òÀ» ÁÙ °ÍÀÌ´Ù.

  * /proc filesystem support (CONFIG_PROC_FS) [Y/n/?]
    - YES: ¸®´ª½º ³×Æ®¿÷ Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ­ ÇÊ¿äÇÏ´Ù.

NOTE: ÀÌ ¿É¼ÇµéÀº ´ÜÁö IP ¸¶½ºÄ¿·¹µùÀÌ µ¿ÀÛÇϱâ À§ÇÑ ¿ä¼ÒµéÀÌ´Ù. ƯÁ¤ÇÑ ³×Æ®¿÷°ú ƯÁ¤ Çϵå¿þ¾î¸¦ ¼³Á¤Çϱâ À§Çؼ­´Â ÇÊ¿äÇÑ ´Ù¸¥ ¿É¼ÇµéÀ» ´õ ¼±ÅÃÇØ¾ß ÇÑ´Ù.

  • Ä¿³Î ÀÚü¸¦ ÄÄÆÄÀÏÇÏ°í ³ª¼­´Â, ´ÙÀ½°ú °°Àº ¸í·ÉÀ¸·Î Ä¿³ÎÀÇ IP ¸¶½ºÄ¿·¹µù °ü·Ã ¸ðµâµéÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇØ¾ß ÇÑ´Ù:
    make modules; make modules_install
    
  • ´ÙÀ½¿¡´Â, /etc/rc.d/rc.local È­ÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ ¸îÁÙÀ» Ãß°¡Çؼ­ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ À§ÇÑ ½ºÅ©¸³Æ®¸¦ loadÇϵµ·Ï ÇØ¾ß ÇÑ´Ù. ÀÌ·¸°Ô ÇÏ¸é ¸®ºÎÆÃÀ» ÇÒ ¶§¸¶´Ù ÀÚµ¿ÀûÀ¸·Î IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù:
            .
            .
            .
            #rc.firewall script - Start IPMASQ and the firewall
            /etc/rc.d/rc.firewall
            .
            .
            .
    

¸®´ª½º 2.2.x Ä¿³Î

ÇÊ¿äÇÑ ¼ÒÇÁÆ®¿þ¾î¿Í ÆÐÄ¡ µîÀº 2.2.x-Requirements ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

  • ¿ì¼±, 2.2.x ¹öÁ¯ÀÇ Ä¿³Î ¼Ò½º°¡ ÇÊ¿äÇÏ´Ù. (ÃÖ±Ù ¹öÁ¯ÀÎ 2.2.11À̳ª ±× ÀÌ»óÀÇ ¹öÁ¯)

    NOTE #1: ¸®´ª½º 2.2.x ¹öÁ¯Áß¿¡¼­ 2.2.11 ÀÌÇÏÀÇ ¹öÁ¯Àº IPCHAINS fragmentation bug¸¦ °¡Áö°í ÀÖ´Ù. ÀÌ·± ÀÌÀ¯·Î, °­·ÂÇÑ IPCHAINS rulesetµéÀ» ÁöÁ¤ÇÏ¸é °ø°Ý¿¡ ³ëÃâµÇ°Ô µÈ´Ù. Ä¿³ÎÀ» ¾÷±×·¹À̵åÇÏ¿© ¹®Á¦¸¦ ÇØ°áÇϱ⠹ٶõ´Ù.

  • ¸¸¾à Ä¿³Î ÄÄÆÄÀÏÀÌ Ã³À½ÀÌ¶óµµ °Ì¸ÔÁö ¸»±â ¹Ù¶õ´Ù. ½ÇÁ¦·Î ÇØ º¸¸é, ±×´ÙÁö ¾î·ÆÁö ¾Ê°í 2.2.x-Requirements ¼½¼Ç¿¡ ³ª¿À´Â ¸î¸î URL¿¡¼­ ÄÄÆÄÀÏ ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇϰí ÀÖ´Ù.

  • tar xvzf linux-2.2.x.tar.gz -C /usr/src ¶ó°í ¸í·ÉÇÏ¿© Ä¿³ÎÀ» /usr/src/ ¿¡ Ǭ´Ù.(2.2.x´Â Ä¿³Î ¹öÁ¯) ¾ÐÃàÀ» Ǭ ´ÙÀ½¿¡, /usr/src/linux/ ¶ó´Â µð·ºÅ丮³ª ½Éº¼¸¯ ¸µÅ©°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

  • ÆÐÄ¡¸¦ °¡ÇÒ °ÍÀÌ ÀÖÀ¸¸é ¾ÐÃàÀ» Ǭ Ä¿³Î ¼Ò½º¿¡ ÆÐÄ¡¸¦ °¡ÇÑ´Ù. 2.2.1 ÀÌ»ó ¹öÁ¯¿¡¼­´Â, IP ¸¶½ºÄ¿·¹À̵ùÀ» Çϱâ À§ÇØ Æ¯º°ÇÑ ÆÐÄ¡°¡ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. PPTP, Xwindows forwarders ¿Í °°Àº ±â´ÉµéÀº ²À ÇÊ¿äÇÏÁö´Â ¾ÊÀº ¼±ÅûçÇ×ÀÌ´Ù. URLµéÀº 2.2.x-Requirements ¼½¼ÇÀ» ÂüÁ¶Çϰí, ÃֽŠÁ¤º¸¿Í ±×¿ÜÀÇ ÆÐÄ¡¿¡ °ü·ÃµÈ URLµéÀº IP Masquerade Resources À» ÂüÁ¶ÇÏ±æ ¹Ù¶õ´Ù.

  • ¾Æ·¡¿¡ Ä¿³Î¿¡ Æ÷ÇԵǾî¾ß ÇÏ´Â ÃÖ¼ÒÇÑÀÇ ¿É¼ÇµéÀÇ ¸ñ·ÏÀÌ ÀÖ´Ù. ÇöÀç ¼³Ä¡µÇ¾î ÀÖ´Â ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º(LAN Ä«µå, ¸ðµ© µîµî)¸¦ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï ¼³Á¤ÇÏ´Â °Íµµ ÀØÁö ¸»¾Æ¾ß ÇÑ´Ù. Ä¿³ÎÀ» ÄÄÆÄÀÏÇÏ´Â ´õ ÀÚ¼¼ÇÑ ¹æ¹ý¿¡ ´ëÇØ¼­´Â Linux Kernel HOWTO ¿Í Ä¿³Î ¼Ò½º µð·ºÅ丮 ³»ÀÇ README È­ÀÏÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

    ´ÙÀ½ÀÇ ¿É¼Çµé¿¡¼­ YESÀΰ¡ ¶Ç´Â NOÀΰ¡¸¦ È®ÀÎÇϱ⠹ٶõ´Ù. ÀÌ HOWTO¿¡¼­ ³ªÁß¿¡ ¼³¸íÇÏ´Â ÀûÀýÇÑ ÆÐÄ¡¸¦ °¡ÇÏÁö ¾Ê´Â´Ù¸é ¾Æ·¡ÀÇ ¿É¼ÇµéÀÌ ¸ðµÎ º¸ÀÌÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù:


  * Prompt for development and/or incomplete code/drivers (CONFIG_EXPERIMENTAL) [Y/n/?]
    - YES: IP ¸¶½ºÄ¿·¹À̵带 À§ÇØ ²À ÇÊ¿äÇÑ °ÍÀº ¾Æ´ÏÁö¸¸, ÀÌ ¿É¼ÇÀ» ¼±ÅÃÇϸé
           ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» »ý¼ºÇÏ°í Æ÷Æ® Æ÷¿öµù(port forwarding)À» ÇÒ ¼ö°¡
           ÀÖ´Ù.

  * Enable loadable module support (CONFIG_MODULES) [Y/n/?]
    - YES: IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµéÀ» ÀûÀçÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.

  * Networking support (CONFIG_NET) [Y/n/?]
    - YES: ³×Æ®¿÷À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * Packet socket (CONFIG_PACKET) [Y/m/n/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº TCPDUMP¸¦ »ç¿ëÇØ¼­ IP ¸¶½ºÄ¿·¹À̵ù°ú
           °ü·ÃÇÑ ¹®Á¦µéÀ» µð¹ö±ëÇÒ ¼ö ÀÖÀ¸¹Ç·Î ¼±ÅÃÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù.

  * Kernel/User netlink socket (CONFIG_NETLINK) [Y/n/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ¹æÈ­º®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±æ ¼ö ÀÖµµ·Ï
           ÇÑ´Ù.

  * Routing messages (CONFIG_RTNETLINK) [Y/n/?]
    - NO:  ÀÌ ¿É¼ÇÀº ÆÐŶ ¹æÈ­º®ÀÌ ±â·ÏÀ» ³²±â´Â °Í°ú ¾Æ¹« »ó°üÀÌ ¾ø´Ù.

  * Network firewalls (CONFIG_FIREWALL) [Y/n/?]
    - YES: IPCHAINS ¹æÈ­º® µµ±¸¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.

  * TCP/IP networking (CONFIG_INET) [Y/n/?]
    - YES: TCP/IP ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. 

  * IP: advanced router (CONFIG_IP_ADVANCED_ROUTER) [Y/n/?]
    - NO:  CONFIG_IP_ROUTE_VERBOSE ¸¦ ¼³Á¤Çϱâ À§Çؼ­ ÇÊ¿äÇÏ°í ±ò²ûÇÑ ¶ó¿ìÆÃÀ»
           À§Çؼ­ ÇÊ¿äÇÏ´Ù. (ipchains/¸¶½ºÄ¿·¹ÀÌµå ¿Í´Â °ü°è¾ø´Ù.)

  * IP: verbose route monitoring (CONFIG_IP_ROUTE_VERBOSE) [Y/n/?]
    - YES: ÀÌ ±â´ÉÀº IP ½ºÇªÇÎ(¼ÓÀÓ) ÆÐŶÀ» Á¦°ÅÇÏ°í ±× ±â·ÏÀ» ³²±â´Â Äڵ带 
           »ç¿ëÇÑ´Ù¸é ¸Å¿ì À¯¿ëÇÒ °ÍÀÌ´Ù.

  * IP: firewalling (CONFIG_IP_FIREWALL) [Y/n/?]
    - YES: ¹æÈ­º® ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.

  * IP: firewall packet netlink device (CONFIG_IP_FIREWALL_NETLINK) [Y/n/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ¹æÈ­º®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±â´Â ±â´ÉÀ»
           Çâ»ó½ÃÄÑ ÁÙ °ÍÀÌ´Ù.

  * IP: always defragment (required for masquerading) (CONFIG_IP_ALWAYS_DEFRAG) [Y/n/?]
    - YES: ÀÌ ±â´ÉÀ» ¼±ÅÃÇØ¾ßÁö IP ¸¶½ºÄ¿·¹À̵å¿Í Åõ¸íÇÑ ÇÁ·Ï½Ã ±â´ÉÀ» ¼±ÅÃÇÒ 
           ¼ö ÀÖ´Ù. ÀÌ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵å Á¢¼ÓÀ» ÃÖÀûÈ­ Çϱ⵵ ÇÑ´Ù.

  * IP: masquerading (CONFIG_IP_MASQUERADE) [Y/n/?]
    - YES: ³»ºÎ ÁÖ¼Ò¸¦ ¿ÜºÎ·Î ³»º¸³¾ ÆÐŶÀ¸·Î º¯È¯ÇØ ÁÖ´Â IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ»
           »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.

  * IP: ICMP masquerading (CONFIG_IP_MASQUERADE_ICMP) [Y/n/?]
    - YES: ICMP ÇÎ ÆÐŶÀ» ¸¶½ºÄ¿·¹À̵å Çϱâ À§ÇØ »ç¿ëµÈ´Ù. (¼±ÅÃÇÏÁö ¾Ê´õ¶óµµ
           ICMP ¿¡·¯ ÄÚµå ÀÚü´Â ¸¶½ºÄ¿·¹ÀÌµå µÉ °ÍÀÌ´Ù.) Á¢¼Ó¿¡ ¹®Á¦°¡ »ý°åÀ»
           ¶§ ÇØ°áÇϱâ À§ÇØ »ç¿ëµÇ´Â Áß¿äÇÑ ±â´ÉÀÌ´Ù.

  * IP: masquerading special modules support (CONFIG_IP_MASQUERADE_MOD) [Y/n/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ³ªÁß¿¡ TCP/IP Æ÷Æ® Æ÷¿öµùÀ» »ç¿ë 
           °¡´ÉÇÏ°Ô Çϱâ À§Çؼ­ ¼±ÅÃÇØ¾ß ÇÑ´Ù. Æ÷Æ® Æ÷¿öµùÀ» ÅëÇØ¼­ ¿ÜºÎ·ÎºÎÅÍ
           ¸¶½ºÄ¿·¹À̵åµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ·Î Á÷Á¢ ¿¬°áÇÒ ¼ö ÀÖ´Ù.

  * IP: ipautofw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPAUTOFW) [N/y/m/?]
    - NO:  IPautofw ±â´ÉÀº Æ÷Æ® Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ­ »ç¿ëµÇ´ø ±¸½Ã´ëÀûÀÎ
           ¹æ¹ýÀÌ´Ù. ÀÌ ±â´ÉÀº ÇÁ·ÎÅäÄÝ ´ÜÀ§ÀÇ ¸ðµâÀ» »ç¿ëÇÏ´Â °ÍÀÌ ´õ ³´´Ù.

  * IP: ipportfw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPPORTFW) [Y/m/n/?]
    - YES: IPPORTFW¸¦ »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.

           ÀÌ ¿É¼ÇÀ» ¼±ÅÃÇϸé, ÀÎÅͳݻóÀÇ ¿ÜºÎÀÇ ÄÄÇ»Å͵éÀÌ ³»ºÎÀÇ 
           ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍ¿Í Á÷Á¢ Åë½ÅÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ ±â´ÉÀº 
           Åë»óÀûÀ¸·Î ³»ºÎÀÇ SMTP, TELNET, WWW ¼­¹ö¿¡ Á¢¼ÓÇϱâ À§Çؼ­ »ç¿ëµÈ´Ù.
           FTP Æ÷Æ® Æ÷¿öµùÀº FAQ ¼½¼Ç¿¡ ¼³¸íµÇ´Â Ãß°¡ ÆÐÄ¡¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù.
           Æ÷Æ® Æ÷¿öµù¿¡ ´ëÇÑ Ãß°¡ÀûÀÎ Á¤º¸´Â ÀÌ HOWTOÀÇ Forwards ¼½¼Ç¿¡¼­
           ´Ù·ç°í ÀÖ´Ù.

  * IP: ip fwmark masq-forwarding support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_MFW) [Y/m/n/?]
    - NO:  IPCHAINS·Î ºÎÅÍ Á÷Á¢ IP Æ÷¿öµùÀ» ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ÇöÀç ÀÌ ÄÚµå´Â 
           ½ÃÇè¿ëÀ̸ç, ±ÇÀåÇÏ´Â ¹æ¹ýÀº IPMASQADM ¿Í IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.

  * IP: optimize as router not host (CONFIG_IP_ROUTER) [Y/n/?]
    - YES: ÀÌ ±â´ÉÀº Ä¿³ÎÀÇ ³×Æ®¿÷ ±â´ÉÀ» ÃÖÀûÈ­ ÇØ ÁØ´Ù.

  * IP: GRE tunnels over IP (CONFIG_NET_IPGRE) [N/y/m/?]
    - NO:  ÀÌ ±â´ÉÀº ²À ÇÊ¿äÇÏÁö´Â ¾ÊÀ¸¸ç, IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼­ PPTP¿Í 
           GRE ÅͳÎÀ» »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.

  * IP: TCP syncookie support (not enabled per default) (CONFIG_SYN_COOKIES) [Y/n/?]
    - YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ­ ¼±ÅÃÇÒ °ÍÀ» °­·ÂÈ÷ ±ÇÀåÇÑ´Ù.

  * Network device support (CONFIG_NETDEVICES) [Y/n/?]
    - YES: ¸®´ª½ºÀÇ ³×Æ®¿÷ ÀåÄ¡¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.

  * Dummy net driver support (CONFIG_DUMMY) [M/n/y/?]
    - YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ¹®Á¦°¡ ¹ß»ýÇßÀ» ¶§ µð¹ö±ë ÇÒ ¶§ µµ¿òÀÌ µÉ 
           °ÍÀÌ´Ù.

  * /proc filesystem support (CONFIG_PROC_FS) [Y/n/?]
    - YES: ¸®´ª½ºÀÇ ³×Æ®¿÷ Æ÷¿öµù ½Ã½ºÅÛÀ» »ç¿ëÇϱâ À§Çؼ­ ÇÊ¿äÇÏ´Ù.

NOTE: ÀÌ ¿É¼ÇµéÀº ´ÜÁö IP ¸¶½ºÄ¿·¹À̵ùÀÌ µ¿ÀÛÇϱâ À§ÇÑ ¿ä¼ÒµéÀÌ´Ù. ƯÁ¤ÇÑ ³×Æ®¿÷°ú ƯÁ¤ Çϵå¿þ¾î¸¦ ¼³Á¤Çϱâ À§Çؼ­´Â ÇÊ¿äÇÑ ´Ù¸¥ ¿É¼ÇµéÀ» ´õ ¼±ÅÃÇØ¾ß ÇÑ´Ù.

  • Ä¿³Î ÀÚü¸¦ ÄÄÆÄÀÏÇÏ°í ³ª¼­´Â, ´ÙÀ½°ú °°Àº ¸í·ÉÀ¸·Î Ä¿³ÎÀÇ IP ¸¶½ºÄ¿·¹À̵ù °ü·Ã ¸ðµâµéÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇØ¾ß ÇÑ´Ù:
      make modules; make modules_install
      
    

  • ´ÙÀ½¿¡´Â, /etc/rc.d/rc.local È­ÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ ¸îÁÙÀ» Ãß°¡Çؼ­ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ À§ÇÑ ½ºÅ©¸³Æ®¸¦ loadÇϵµ·Ï ÇØ¾ß ÇÑ´Ù. ÀÌ·¸°Ô ÇÏ¸é ¸®ºÎÆÃÀ» ÇÒ ¶§¸¶´Ù ÀÚµ¿ÀûÀ¸·Î IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù:

            .
            .
            .
            #rc.firewall script - Start IPMASQ and the firewall
            /etc/rc.d/rc.firewall
            .
            .
            .
      
    

3.2 ³»ºÎ LAN¿¡ ºñ°ø½ÄÀûÀÎ ³»ºÎ IP ÁÖ¼Ò¸¦ ÇÒ´çÇϱâ

¸ðµç ³»ºÎÀÇ ¸¶½ºÄ¿·¹ÀÌµå µÈ ÄÄÇ»Å͵鿡 °ø½ÄÀûÀÎ ÀÎÅÍ³Ý ÁÖ¼Ò°¡ ÇÒ´çµÇ¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®¿¡, ¿ÜºÎÀÇ ÀÎÅÍ³Ý ÁÖ¼Ò¿Í Ãæµ¹ÇÏÁö ¾Êµµ·Ï ±× ÄÄÇ»Å͵鿡 ÁÖ¼Ò¸¦ ÇÒ´çÇÒ ¹æ¹ýÀÌ ÀÖ¾î¾ß ÇÑ´Ù.

>IP ¸¶½ºÄ¿·¹À̵å FAQÀÇ ¿øº»À¸·ÎºÎÅÍ Àοë:

RFC 1918 Àº ¿ÜºÎ¿Í ¿¬°áµÇÁö ¾Ê´Â "°³Àοë" ³×Æ®¿÷¿¡ »ç¿ëµÇ´Â IP Áּҵ鿡 °üÇÑ °ø½ÄÀûÀÎ ¹®¼­ÀÌ´Ù. ÀÌ·¯ÇÑ °æ¿ì¿¡ »ç¿ëµÇ±â À§Çؼ­ ¼¼ °¡ÁöÀÇ ÁÖ¼Ò ¿µ¿ªÀÌ ÀÖ´Ù.


Section 3: °³Àοë ÁÖ¼Ò ¿µ¿ª

ÀÎÅÍ³Ý ÁÖ¼Ò ÇÒ´ç ±â±¸(The Internet Assigned Numbers Authority : IANA)´Â 
IP ÁÖ¼ÒÁß¿¡¼­ ´ÙÀ½ ¼¼°¡Áö ¿µ¿ªÀ» °³ÀÎ¿ë ³×Æ®¿÷À» À§Çؼ­ ¿¹¾àÇØ µÎ¾ú´Ù:

              10.0.0.0        -   10.255.255.255
              172.16.0.0      -   172.31.255.255
              192.168.0.0     -   192.168.255.255

ù¹øÂ° ¿µ¿ªÀº "24-bit ¿µ¿ª", µÎ¹øÂ°´Â "20-bit ¿µ¿ª", ¼¼¹øÂ°´Â "16-bit ¿µ¿ª"À¸·Î
ºÎ¸£±â·Î ÇÑ´Ù. ù¹øÂ° ¿µ¿ªÀº class A ³×Æ®¿÷ ÁÖ¼Ò ¿µ¿ªÀ̸ç, µÎ¹øÂ°´Â class B 
³×Æ®¿÷ ÁÖ¼ÒÀÇ ¿¬¼ÓµÈ 16°³ÀÇ ¹øÈ£µéÀ̰í, ¼¼¹øÂ°´Â class C ³×Æ®¿÷ ÁÖ¼ÒÀÇ ¿¬¼ÓµÈ 
255°³ÀÇ ¹øÈ£µéÀÌ´Ù. 

¼³¸íÀ» À§Çؼ­, ÇÊÀÚ´Â 192.168.0.0 ³×Æ®¿÷°ú 255.255.255.0ÀÇ class-C ¼­ºê³Ý ¸¶½ºÅ©¸¦ »ç¿ëÇß°í, ÀÌ HOWTO¿¡¼­µµ ÀÌ ÁÖ¼Ò¸¦ »ç¿ëÇÒ °ÍÀÌ´Ù. ±×·¯³ª, À§¿¡ ÀÖ´Â °³ÀÎ¿ë ³×Æ®¿÷ ÁÖ¼ÒÁß¿¡¼­ ¾î¶² °ÍÀ» »ç¿ëÇØµµ ¹«¹æÇÏ´Ù. ´Ü, °¢°¢ÀÇ °æ¿ì¿¡ ÀûÀýÇÑ ¼­ºê³Ý ¸¶½ºÅ©¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù.

¸¸¾à Class-C ³×Æ®¿÷À» »ç¿ëÇÑ´Ù¸é, ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ëÇÒ ÄÄÇ»Å͵鿡 192.168.0.1, 192.168.0.2, 192.168.0.3, ..., 192.168.0.x µî°ú °°ÀÌ ÁÖ¼Ò¸¦ ÇÒ´çÇØ¾ß ÇÑ´Ù.

192.168.0.1 Àº º¸Åë ³»ºÎ °ÔÀÌÆ®¿þÀÌ È¤Àº ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¸Ó½ÅÀÇ Áּҷμ­ ¿ÜºÎ·Î ¿¬°áµÇ´Â Åë·ÎÀÌ´Ù. 192.168.0.0°ú 192.168.0.255´Â °¢°¢ "³×Æ®¿÷" ÀÚüÀÇ ÁÖ¼Ò¿Í "ºê·Îµåij½ºÆ®" ÁÖ¼ÒÀÌ´Ù. (ÀÌ ÁÖ¼ÒµéÀº ¿¹¾àµÈ ÁÖ¼ÒµéÀÌ´Ù.) ÀÌ ÁÖ¼ÒµéÀ» ÄÄÇ»Å͵鿡°Ô ÇÒ´ç¸é, ³×Æ®¿÷ÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾ÊÀ» °ÍÀÌ´Ù.

3.3 IP Æ÷¿öµù Á¤Ã¥ ¼³Á¤Çϱâ

ÀÌÁ¦, Ä¿³Î°ú ±âŸ ÇÊ¿äÇÑ ÆÐŰÁöµéÀÌ ÁغñµÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡µµ ¸ðµç ³×Æ®¿÷ IP ÁÖ¼Òµé°ú, °ÔÀÌÆ®¿þÀÌ, DNS ÁÖ¼ÒµéÀ» ¼³Á¤ÇØ¾ß ÇÑ´Ù. ³×Æ®¿÷ Ä«µåµéÀ» ¼³Á¤ÇÏ´Â ¹æ¹ýÀ» ¸ð¸¥´Ù¸é, 2.0.x-Requirements ȤÀº 2.2.x-Requirements ¼½¼Ç¿¡ ¾ð±ÞµÈ HOWTOµéÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

ÀÌÁ¦ ³²Àº °ÍÀº IP ¹æÈ­º® µµ±¸µéÀ» ¼³Á¤Çؼ­ Æ÷¿öµù°ú ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇÏ´Â °ÍÀÌ´Ù:

** ¼³Á¤Àº ¿©·¯°¡Áö ¹æ¹ýÀ¸·Î ÇÒ ¼ö°¡ ÀÖÁö¸¸, ÇÊÀÚ´Â ´ÙÀ½¿¡ ¿¹·Î µç ¹æ¹ýÀ» »ç¿ëÇØ¼­ ¼º°øÇß´Ù. ÇÏÁö¸¸, ¿©·¯ºÐÀº ´Ù¸¥ ¹æ¹ýÀ» »ç¿ëÇÒ ¼öµµ ÀÖÀ» °ÍÀÌ´Ù.

** ÀÌ ¼½¼Ç¿¡¼­ Á¦°øÇÏ´Â °ÍÀº IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀÌ ÀÛµ¿Çϱâ À§ÇÑ ÃÖ¼ÒÇÑÀÇ ¹æÈ­º® Á¤Ã¥ÀÌ´Ù. ÀÏ´Ü IP ¸¶½ºÄ¿·¹À̵尡 Á¦´ë·Î µ¿ÀÛÇϸé(ÀÌ HOWTO¿¡¼­ ³ªÁß¿¡ ¾ð±ÞÇÑ´Ù) Strong-IPFWADM-Rulesets ¿Í Strong-IPCHAINS-Rulesets ¼½¼Ç¿¡¼­ º¸¾È °­µµ°¡ º¸´Ù ³ôÀº Á¤Ã¥µé¿¡ ´ëÇØ ¾Ë¾Æº¸±â ¹Ù¶õ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº IPFWADM (2.0.x) ȤÀº IPCHAINS(2.2.x) man ÆäÀÌÁö¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.

¸®´ª½º 2.0.x Ä¿³Î

´ÙÀ½°ú °°Àº "°£´ÜÇÑ" Ãʱâ Á¤Ã¥À¸·Î /etc/rc.d/rc.firewall È­ÀÏÀ» »ý¼ºÇÑ´Ù:


# rc.firewall - Initial SIMPLE IP Masquerade setup for 2.0.x kernels using IPFWADM
#
# Load all required IP MASQ modules
#
#   NOTE:  Only load the IP MASQ modules you need.  All current available IP MASQ modules
#          are shown below but are commented out from loading.

# Needed to initially load modules
#
/sbin/depmod -a

# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp

# Supports the masquerading of RealAudio over UDP.  Without this module,
#       RealAudio WILL function but in TCP mode.  This can cause a reduction
#       in sound quality
#
#/sbin/modprobe ip_masq_raudio

# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc

# Supports the masquerading of Quake and QuakeWorld by default.  This modules is
#   for for multiple users behind the Linux MASQ server.  If you are going to play
#   Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960

# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme

#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive


#CRITICAL:  Enable IP forwarding since it is disabled by default since
#
#           Redhat Users:  you may try changing the options in /etc/sysconfig/network from:
#
#                       FORWARD_IPV4=false
#                             to
#                       FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward

# Dynamic IP users:
#
#   If you get your Internet IP address dynamically from SLIP, PPP, or DHCP, enable this following
#       option.  This enables dynamic-ip address hacking in IP MASQ, making the life
#       with DialD, PPPd, and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr


# MASQ timeouts
#
#   2 hrs timeout for TCP session timeouts
#  10 sec timeout for traffic after the TCP/IP "FIN" packet is received
#  160 sec timeout for UDP traffic (Important for MASQ'ed ICQ users)
#
/sbin/ipfwadm -M -s 7200 10 160


# DHCP:  For people who receive their external IP address from either DHCP or BOOTP
#        such as ADSL or Cablemodem users, it is necessary to use the following
#        before the deny command.  The "bootp_client_net_if_name" should be replaced
#        the name of the link that the DHCP/BOOTP server will put an address on to?
#        This will be something like "eth0", "eth1", etc.
#
#        This example is currently commented out.
#
#
#/sbin/ipfwadm -I -a accept -S 0/0 67 -D 0/0 68 -W bootp_clients_net_if_name -P udp


# Enable simple IP forwarding and Masquerading
#
#  NOTE:  The following is an example for an internal LAN address in the 192.168.0.x
#         network with a 255.255.255.0 or a "24" bit subnet mask.
#
#         Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipfwadm -F -p deny
/sbin/ipfwadm -F -a m -S 192.168.0.0/24 -D 0.0.0.0/0

/etc/rc.d/rc.firewall È­ÀÏÀ» ÆíÁýÇØ¼­ Á¤Ã¥À» »ý¼ºÇÏ°í ³ª¸é, "chmod 700 /etc/rc.d/rc.firewall" ¶ó°í ¸í·ÉÇØ¼­ ½ÇÇà°¡´ÉÇÑ È­ÀÏ·Î ¸¸µç´Ù.

À§ÀÇ ¹æ¹ýó·³ Àüü TCP/IP ³×Æ®¿÷¿¡ ´ëÇØ¼­°¡ ¾Æ´Ï¶ó, °¢°¢ÀÇ ¸Ó½Åº°·Î IP ¸¶½ºÄ¿·¹À̵ùÀ» ¼³Á¤ÇÒ ¼öµµ ÀÖ´Ù. ¿¹¸¦ µé¾î¼­, 192.168.0.2¿Í 192.168.0.8ÀÇ ÁÖ¼Ò¸¦ °®´Â È£½ºÆ®´Â ÀÎÅͳݿ¡ Á¢±Ù°¡´ÉÇϵµ·Ï ÇÏ°í ´Ù¸¥ ³»ºÎÀÇ ¸Ó½ÅµéÀº Á¢±ÙÇÏÁö ¸øÇϵµ·Ï ÇϰíÀÚ ÇÑ´Ù¸é, À§ÀÇ /etc/rc.d/rc.firewall È­ÀÏ¿¡¼­ "Enable simple IP forwarding and Masquerading" À̶ó°í µÇ¾î ÀÖ´Â ºÎºÐÀ» ¹Ù²ãÁÖ¸é µÈ´Ù.

# Enable simple IP forwarding and Masquerading
#
#  NOTE:  The following is an example to only allow IP Masquerading for the 192.168.0.2
#         and 192.168.0.8 machines with a 255.255.255.0 or a "24" bit subnet mask.
#
#         Please use the following in ADDITION to the simple ruleset above for specific
#         MASQ networks.  Also change the network numbers and subnet masks to match your
#         internal LAN setup
#
/sbin/ipfwadm -F -p deny
/sbin/ipfwadm -F -a m -S 192.168.0.2/32 -D 0.0.0.0/0
/sbin/ipfwadm -F -a m -S 192.168.0.8/32 -D 0.0.0.0/0

IP ¸¶½ºÄ¿·¹À̵ùÀ» óÀ½ »ç¿ëÇÏ´Â »ç¶÷µéÀÌ ÈçÈ÷ ÀúÁö¸£´Â ½Ç¼ö´Â ´ÙÀ½°ú °°ÀÌ ¸í·ÉÇÏ´Â °ÍÀÌ´Ù:

ipfwadm -F -p masquerade

µðÆúÆ®·Î ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇØ¼­´Â ¾ÈµÈ´Ù. ¸¸¾à ±×·¸°Ô ¼³Á¤ÇÏ¸é ¶ó¿ìÆÃ Å×À̺íÀ» ´Ù·ê ÁÙ ¾Æ´Â ¾î¶² ´©±º°¡°¡ ¿©·¯ºÐÀÇ °ÔÀÌÆ®¿þÀ̸¦ ÅëÇØ¼­ ÀÚ½ÅÀÇ ½ÅºÐÀ» ¼û±â°í¼­ ¾îµò°¡·Î Á¢¼ÓÇÒ ¼ö°¡ ÀÖ°Ô µÈ´Ù!

À§ÀÇ ¼³Á¤È­ÀÏ ³»¿ëÀº, /etc/rc.d/rc.firewall È­ÀÏÀ̳ª ȤÀº ¿øÇÏ´Â ´Ù¸¥ rc È­ÀÏ¿¡ ³ÖÀ» ¼öµµ ÀÖ°í, ¾Æ´Ï¸é IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿äÇÒ ¶§¸¶´Ù ¼öµ¿À¸·Î ¸í·ÉÇÒ ¼öµµ ÀÖ´Ù.

Strong-IPFWADM-Rulesets °ú Strong-IPCHAINS-Rulesets ¼½¼Ç¿¡¼­ IPFWADM¿¡ °üÇÑ ÀÚ¼¼ÇÑ ¾È³»¿Í ´õ °­·ÂÇÑ IPFWADM Á¤Ã¥µéÀÇ ¿¹¸¦ º¼¼ö°¡ ÀÖ´Ù.

¸®´ª½º 2.2.x Ä¿³Î

2.1.x ³ª 2.2.x Ä¿³Î¿¡¼­ IP ¸¶½ºÄ¿·¹À̵ù Á¤Ã¥µéÀ» ´Ù·ç±â À§ÇÑ ¹æÈ­º® µµ±¸·Î¼­ IPFWADMÀº ´õÀÌ»ó »ç¿ëµÇÁö ¾Ê´Â´Ù ÀÌ »õ ¹öÁ¯ÀÇ Ä¿³ÎµéÀº ÀÌÁ¦ IPCHAINS¶ó´Â µµ±¸¸¦ »ç¿ëÇÑ´Ù. ÀÌ·¸°Ô µÈ ÀÚ¼¼ÇÑ ÀÌÀ¯´Â FAQ ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

´ÙÀ½°ú °°Àº "°£´ÜÇÑ" Ãʱâ Á¤Ã¥À¸·Î /etc/rc.d/rc.firewall È­ÀÏÀ» »ý¼ºÇÑ´Ù:


#!/bin/sh
#
# rc.firewall - Initial SIMPLE IP Masquerade test for 2.1.x and 2.2.x kernels using IPCHAINS
#
# Load all required IP MASQ modules
#
#   NOTE:  Only load the IP MASQ modules you need.  All current IP MASQ modules
#          are shown below but are commented out from loading.

# Needed to initially load modules
#
/sbin/depmod -a

# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp

# Supports the masquerading of RealAudio over UDP.  Without this module,
#       RealAudio WILL function but in TCP mode.  This can cause a reduction
#       in sound quality
#
#/sbin/modprobe ip_masq_raudio

# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc


# Supports the masquerading of Quake and QuakeWorld by default.  This modules is
#   for for multiple users behind the Linux MASQ server.  If you are going to play
#   Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960


# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme

#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive


#CRITICAL:  Enable IP forwarding since it is disabled by default since
#
#           Redhat Users:  you may try changing the options in /etc/sysconfig/network from:
#
#                       FORWARD_IPV4=false
#                             to
#                       FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward


# Dynamic IP users:
#
#   If you get your IP address dynamically from SLIP, PPP, or DHCP, enable this following
#       option.  This enables dynamic-ip address hacking in IP MASQ, making the life
#       with Diald and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr


# MASQ timeouts
#
#   2 hrs timeout for TCP session timeouts
#  10 sec timeout for traffic after the TCP/IP "FIN" packet is received
#  160 sec timeout for UDP traffic (Important for MASQ'ed ICQ users)
#
/sbin/ipchains -M -S 7200 10 160


# DHCP:  For people who receive their external IP address from either DHCP or BOOTP
#        such as ADSL or Cablemodem users, it is necessary to use the following
#        before the deny command.  The "bootp_client_net_if_name" should be replaced
#        the name of the link that the DHCP/BOOTP server will put an address on to?
#        This will be something like "eth0", "eth1", etc.
#
#        This example is currently commented out.
#
#
#/sbin/ipchains -A input -j ACCEPT -i bootp_clients_net_if_name -s 0/0 67 -d 0/0 68 -p udp

# Enable simple IP forwarding and Masquerading
#
#  NOTE:  The following is an example for an internal LAN address in the 192.168.0.x
#         network with a 255.255.255.0 or a "24" bit subnet mask.
#
#         Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipchains -P forward DENY
/sbin/ipchains -A forward -s 192.168.0.0/24 -j MASQ

/etc/rc.d/rc.firewall È­ÀÏÀ» ÆíÁýÇØ¼­ Á¤Ã¥À» »ý¼ºÇÏ°í ³ª¸é, chmod 700 /etc/rc.d/rc.firewall¶ó°í ¸í·ÉÇØ¼­ ½ÇÇà°¡´ÉÇÑ È­ÀÏ·Î ¸¸µç´Ù.

À§ÀÇ ¹æ¹ýó·³ Àüü TCP/IP ³×Æ®¿÷¿¡ ´ëÇØ¼­°¡ ¾Æ´Ï¶ó, °¢°¢ÀÇ ¸Ó½Åº°·Î IP ¸¶½ºÄ¿·¹À̵ùÀ» ¼³Á¤ÇÒ ¼öµµ ÀÖ´Ù. ¿¹¸¦ µé¾î¼­, 192.168.0.2¿Í 192.168.0.8ÀÇ ÁÖ¼Ò¸¦ °®´Â È£½ºÆ®´Â ÀÎÅͳݿ¡ Á¢±Ù°¡´ÉÇϵµ·Ï ÇÏ°í ´Ù¸¥ ³»ºÎÀÇ ¸Ó½ÅµéÀº Á¢±ÙÇÏÁö ¸øÇϵµ·Ï ÇϰíÀÚ ÇÑ´Ù¸é, À§ÀÇ /etc/rc.d/rc.firewall È­ÀÏ¿¡¼­ "Enable simple IP forwarding and Masquerading" À̶ó°í µÇ¾î ÀÖ´Â ºÎºÐÀ» ¹Ù²ãÁÖ¸é µÈ´Ù.


#!/bin/sh
#
# Enable simple IP forwarding and Masquerading
#
#  NOTE:  The following is an example to only allow IP Masquerading for the 192.168.0.2
#         and 192.168.0.8 machines with a 255.255.255.0 or a "24" bit subnet mask.
#
#         Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipchains -P forward deny
/sbin/ipchains -A forward -s 192.168.0.2/32 -j MASQ
/sbin/ipchains -A forward -s 192.168.0.8/32 -j MASQ

IP ¸¶½ºÄ¿·¹À̵ùÀ» óÀ½ »ç¿ëÇÏ´Â »ç¶÷µéÀÌ ÈçÈ÷ ÀúÁö¸£´Â ½Ç¼ö´Â ´ÙÀ½°ú °°ÀÌ ¸í·ÉÇÏ´Â °ÍÀÌ´Ù:

/sbin/ipchains -P forward masquerade

µðÆúÆ®·Î ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇØ¼­´Â ¾ÈµÈ´Ù. ¸¸¾à ±×·¸°Ô ¼³Á¤ÇÏ¸é ¶ó¿ìÆÃ Å×À̺íÀ» ´Ù·ê ÁÙ ¾Æ´Â ¾î¶² ´©±º°¡°¡ ¿©·¯ºÐÀÇ °ÔÀÌÆ®¿þÀ̸¦ ÅëÇØ¼­ ÀÚ½ÅÀÇ ½ÅºÐÀ» ¼û±â°í¼­ ¾îµò°¡·Î Á¢¼ÓÇÒ ¼ö°¡ ÀÖ°Ô µÈ´Ù!

À§ÀÇ ¼³Á¤È­ÀÏ ³»¿ëÀº, /etc/rc.d/rc.firewall È­ÀÏÀ̳ª ȤÀº ¿øÇÏ´Â ´Ù¸¥ rc È­ÀÏ¿¡ ³ÖÀ» ¼öµµ ÀÖ°í, ¾Æ´Ï¸é IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿äÇÒ ¶§¸¶´Ù ¼öµ¿À¸·Î ¸í·ÉÇÒ ¼öµµ ÀÖ´Ù.

Strong-IPFWADM-Rulesets °ú Strong-IPCHAINS-Rulesets ¼½¼Ç¿¡¼­ IPCHAINS¿¡ °üÇÑ ÀÚ¼¼ÇÑ ¾È³»¿Í ´õ °­·ÂÇÑ IPCHAINS Á¤Ã¥µéÀÇ ¿¹¸¦ º¼ ¼ö°¡ ÀÖ´Ù. IPCHAINSÀÇ »ç¿ë¹ý¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº Linux IP CHAINS HOWTOÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

4. ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»Å͵éÀ» ¼³Á¤Çϱâ

³»ºÎÀÇ ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â ÄÄÇ»Å͵éÀÇ IP ÁÖ¼Ò¸¦ ÀûÀýÈ÷ ¼³Á¤ÇÏ´Â °Í ¿Ü¿¡, ³»ºÎÀÇ °¢ ÄÄÇ»Å͵éÀÌ ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹öÀÇ ÁÖ¼Ò¸¦ °ÔÀÌÆ®¿þÀÌ ÁÖ¼Ò·Î ¼³Á¤Çϰí DNS ¼­¹ö ÁÖ¼Ò¸¦ ÀûÀýÈ÷ ¼³Á¤ÇØ¾ß ÇÑ´Ù. ´ë°³ÀÇ °æ¿ì¿¡ À̰ÍÀº ²Ï ¼ö¿ùÇÏ´Ù. °£´ÜÈ÷, °ÔÀÌÆ®¿þÀÌ ÁÖ¼Ò¿¡ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(ÀϹÝÀûÀ¸·Î 192.168.0.1)¸¦ ÀÔ·ÂÇÏ¸é µÈ´Ù.

µµ¸ÞÀÎ ³×ÀÓ ¼­ºñ½º(DNS)ÀÇ °æ¿ì¿¡´Â, »ç¿ë °¡´ÉÇÑ ¾î¶² DNS ¼­¹öÀÇ ÁÖ¼Ò¶óµµ Ãß°¡ÇÒ ¼ö ÀÖ´Ù. °¡Àå ±ú²ýÇÑ ¹æ¹ýÀº ¸®´ª½º ¼­¹ö°¡ »ç¿ëÇϰí ÀÖ´Â DNS ¼­¹ö¸¦ ÀÔ·ÂÇÏ´Â °ÍÀÌ´Ù. Ãß°¡·Î, "µµ¸ÞÀÎ °Ë»ö" Á¢¹Ì»ç¸¦ Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù.

¸¶½ºÄ¿·¹ÀÌµå µÇ´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀ» Á¦´ë·Î ¼³Á¤ÇÏ°í ³ª¸é, ÇØ´ç ÄÄÇ»ÅÍÀÇ ³×Æ®¿÷À» Àç½Ãµ¿ÇϵçÁö ¾Æ´Ï¸é ÀçºÎÆÃÇÑ´Ù.

´ÙÀ½ÀÇ ¼³Á¤ °úÁ¤¿¡¼­´Â, ¿©·¯ºÐÀÌ Class C ³×Æ®¿÷ ÁÖ¼ÒµéÀ» »ç¿ëÇϰí, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹öÀÇ ÁÖ¼Ò°¡ 192.168.0.1À̶ó°í °¡Á¤ÇÑ´Ù. 192.168.0.0°ú 192.168.0.255´Â ¿¹¾àµÈ ÁÖ¼ÒÀÌ´Ï °¢ ÄÄÇ»ÅÍÀÇ ÁÖ¼Ò·Î »ç¿ëÇØ¼­´Â ¾ÈµÈ´Ù.

´ÙÀ½°ú °°Àº Ç÷§ÆûµéÀÌ ¸¶½ºÄ¿·¹À̵ù ³»ºÎ¿¡¼­ Å×½ºÆ®µÇ¾ú´Ù:

  • Linux 1.2.x, 1.3.x, 2.0.x, 2.1.x, 2.2.x
  • Solaris 2.51, 2.6, 7
  • Windows 95, OSR2, 98
  • Windows NT 3.51, 4.0, 2000 (¿÷½ºÅ×À̼ǰú ¼­¹ö ¸ðµÎ)
  • Windows For Workgroup 3.11 (TCP/IP ÆÐŰÁö ¼³Ä¡)
  • Windows 3.1 (Netmanage Chameleon ÆÐŰÁö ¼³Ä¡)
  • TCP/IP ¼­ºñ½º¸¦ ¼³Ä¡ÇÑ Novell 4.01 ¼­¹ö
  • OS/2 (Warp v3 Æ÷ÇÔ)
  • Macintosh OS (MacTCP ȤÀº Open Transport ¼³Ä¡)
  • DOS (NCSA Telnet ÆÐŰÁö ¼³Ä¡, DOS TrumpetÀº ºÎºÐÀûÀ¸·Î µ¿ÀÛ)
  • Amiga (AmiTCP ȤÀº AS225-stack ¼³Ä¡)
  • UCX¸¦ ¼³Ä¡ÇÑ VAX Stations 3520°ú 3100 (VMSÀÇ °æ¿ì¿¡´Â TCP/IP stack)
  • Linux/RedhatÀ» ¼³Ä¡ÇÑ Alpha/AXP
  • SCO Openserver (v3.2.4.2¿Í 5)
  • AIX¸¦ ¼³Ä¡ÇÑ IBM RS/6000

4.1 Microsoft Windows 95 ¼³Á¤

  1. ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. 'Á¦¾îÆÇ' --> '³×Æ®¿÷' À» ¼±ÅÃÇÑ´Ù.

  3. TCP/IP ÇÁ·ÎÅäÄÝÀÌ ¼³Ä¡µÇÁö ¾Ê¾Ò´Ù¸é, Ãß°¡ --> ÇÁ·ÎÅäÄÝ --> Á¦Á¶È¸»ç: Microsoft --> ÇÁ·ÎÅäÄÝ: 'TCP/IP ÇÁ·ÎÅäÄÝ' À» Â÷·Ê·Î ¼±ÅÃÇØ¼­ ¼³Ä¡ÇÑ´Ù.

  4. TCP/IP Ç׸ñÀ» Windows95 ³×Æ®¿÷ Ä«µå·Î ¿¬°á(bound)µÇµµ·Ï Çϰí 'µî·ÏÁ¤º¸'¸¦ ¼±Ã¥ÇÑ´Ù. 'IP ÁÖ¼Ò' ÅÇÀ» Ŭ¸¯Çϰí IP ÁÖ¼Ò¸¦ 192.168.0.x(1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. ±×¸®°í ¼­ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0À¸·Î ¼³Á¤ÇÑ´Ù.

  5. "°ÔÀÌÆ®¿þÀÌ" ÅÇÀ» Ŭ¸¯Çϰí '°ÔÀÌÆ®¿þÀÌ'¿¡ 192.168.0.1À̶ó°í ÀÔ·ÂÇÑÈÄ "Ãß°¡"¸¦ Ŭ¸¯ÇÑ´Ù.

  6. 'DNS ¼³Á¤' ÅÇÀ» Ŭ¸¯Çϰí, ÄÄÇ»ÅÍÀÇ À̸§°ú µµ¸ÞÀÎ ¸íÀ» ÀÔ·ÂÇÑ´Ù. µµ¸ÞÀÎÀÌ ¾ø´Ù¸é, ¿©·¯ºÐÀÌ »ç¿ëÇÏ´Â ISPÀÇ µµ¸ÞÀÎÀ» ÀÔ·ÂÇÑ´Ù. ÀÌÁ¦, DNS ¼­¹ö ÁÖ¼Ò¿¡ ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â DNS ¼­¹ö(´ë°³ÀÇ °æ¿ì /etc/resolv.confÈ­ÀÏ¿¡ ÀúÀåµÇ¾î ÀÖ´Ù)¸¦ ÀÔ·ÂÇÑ´Ù. ÀÌ DNS ¼­¹öµéÀº ISP°¡ ¿î¿µÇϰí ÀÖÁö¸¸, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡ ¿©·¯ºÐ ÀÚ½ÅÀÇ "ij½¬"¼­¹ö³ª DNS ¼­¹ö¸¦ ¿î¿µÇÒ ¼öµµ ÀÖ´Ù. ¿øÇÏ´Â µµ¸ÞÀÎ °Ë»ö Á¢¹Ì»ç(ãÀ» µµ¸ÞÀÎ ¸í)À» Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù.

  7. ³ª¸ÓÁö ¼³Á¤µéÀº Àß ¾ËÁö ¸øÇÑ´Ù¸é ±×´ë·Î µÎµµ·Ï ÇÑ´Ù.

  8. ¸ðµç ´ëÈ­»óÀÚ¿¡¼­ 'È®ÀÎ(OK)' À» Ŭ¸¯Çϰí ÀçºÎÆÃÇÑ´Ù.

  9. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ­ ¸®´ª½º È£½ºÆ®·Î Ping À» ÇØº»´Ù: '½ÃÀÛ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
    (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

  10. C:\Windows µð·ºÅ丮¿¡ HOSTS È­ÀÏÀ» ¸¸µé¸é, DNS ¼­¹ö°¡ ¾ø¾îµµ "È£½ºÆ®¸í"À¸·Î LAN ¾È¿¡ ÀÖ´Â ÄÄÇ»Å͵鿡°Ô PINGÀ» ÇÒ ¼ö°¡ ÀÖ´Ù. C:\windows µð·ºÅ丮¿¡ HOSTS.SAM ¶ó´Â ¿¹Á¦ È­ÀÏÀÌ ÀÖÀ» °ÍÀÌ´Ù.

4.2 Windows NT ¼³Á¤

  1. ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. 'Á¦¾îÆÇ' --> '³×Æ®¿÷' --> ÇÁ·ÎÅäÄÝ À» ¼±ÅÃÇÑ´Ù.

  3. TCP/IP ¼­ºñ½º°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é '¼ÒÇÁÆ®¿þ¾î Ãß°¡' ¸Þ´º¿¡¼­ TCP/IP ÇÁ·ÎÅäÄݰú ±×¿Ü Ç׸ñµéÀ» Ãß°¡ÇÑ´Ù.

  4. '³×Æ®¿÷ ¼ÒÇÁÆ®¿þ¾î¿Í ¾î´ðÅÍ Ä«µå' ºÎºÐ¿¡¼­, '¼³Ä¡µÈ ³×Æ®¿÷ ¼ÒÇÁ¿þ¾î'¿¡ ÀÖ´Â 'TCP/IP ÇÁ·ÎÅäÄÝ'À» ¼±ÅÃÇÑ´Ù.

  5. 'TCP/IP ¼³Á¤'¿¡¼­ ÀûÀýÇÑ ¾î´ðÅ͸¦ ¼±ÅÃÇÑ´Ù. ¿¹¸¦ µé¸é [1]Novell NE2000 ¾î´ðÅÍ. ±×¸®°í IP ÁÖ¼Ò¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤Çϰí, ¼­ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0, µðÆúÆ® °ÔÀÌÆ®¿þÀ̸¦ 192.168.0.1·Î ¼³Á¤ÇÑ´Ù.

  6. Windows NT µµ¸ÞÀÎ ³»¿¡ ÀÖÁö ¾Ê°Å³ª °¢ Ç׸ñÀÌ ¹«¾ùÀ» ÀǹÌÇÏ´ÂÁö Àß ¸ð¸¦ ¶§¿¡´Â 'Automatic DHCP Configuration'ÀÇ È°¼ºÈ­¸¦ ÇØÁ¦Çϰí, 'WINS Server' ºÎºÐ¿¡ ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»°í, Enable IP ForwardingsÀÇ È°¼ºÈ­¸¦ ÇØÁ¦ÇÑ´Ù.

  7. 'DNS'¸¦ Ŭ¸¯Çϰí, ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â ÀûÀýÇÑ Á¤º¸µé(´ë°³´Â /etc/resolv.conf¿¡ ÀúÀåµÇ¾î ÀÖÀ½)À» ÀÔ·ÂÇÑ´Ù. ´Ù µÇ¾úÀ¸¸é 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.

  8. '°í±Þ'À» Ŭ¸¯Çϰí, ÀÌ ¿É¼ÇµéÀÌ ¾î¶² ¿ªÇÒÀ» ÇÏ´Â Áö Àß ¸ð¸£¸é 'DNS for Windows Name Resolution'°ú 'Enable LMHOSTS lookup'ÀÇ È°¼ºÈ­¸¦ ÇØÁ¦ÇÑ´Ù. ¸¸¾à¿¡ LMHOSTS È­ÀÏÀ» »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, C:\winnt\system32\drivers\etc¿¡ ÀúÀåµÇ¾î ÀÖ´Â °ÍÀ» ÂüÁ¶ÇÑ´Ù.

  9. ¸ðµç ´ëÈ­»óÀÚ¿¡¼­ 'È®ÀÎ'À» Ŭ¸¯ÇÏ°í ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.

  10. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ­ ¸®´ª½º È£½ºÆ®·Î Ping À» ÇØº»´Ù: 'È­ÀÏ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
    (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

4.3 Windows¿¡¼­ Workgroup 3.11 ¼³Á¤

  1. ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. TCP/IP 32b ÆÐŰÁö°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ¼³Ä¡ÇÑ´Ù.

  3. 'Main'/'Windows Setup'/'Network Setup'¿¡¼­, 'Drivers'¸¦ Ŭ¸¯ÇÑ´Ù.

  4. 'Network Drivers' ºÎºÐ¿¡¼­ 'Microsoft TCP/IP-32 3.11b'¸¦ ¼±ÅÃÇÑ´Ù. 'Setup'À» Ŭ¸¯ÇÑ´Ù.

  5. IP ÁÖ¼Ò¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. ±×¸®°í ¼­ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0À¸·Î µðÆúÆ® °ÔÀÌÆ®¿þÀ̸¦ 192.168.0.1·Î ¼³Á¤ÇÑ´Ù.

  6. Windows NT µµ¸ÞÀÎ ³»¿¡ ÀÖÁö ¾Ê°Å³ª °¢ Ç׸ñÀÌ ¹«¾ùÀ» ÀǹÌÇÏ´ÂÁö Àß ¸ð¸¦ ¶§¿¡´Â 'Automatic DHCP Configuration'ÀÇ È°¼ºÈ­¸¦ ÇØÁ¦Çϰí, 'WINS Server' ºÎºÐ¿¡ ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»µµ·Ï ÇÑ´Ù.

  7. 'DNS'¸¦ Ŭ¸¯Çϰí, ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â ÀûÀýÇÑ Á¤º¸µé(´ë°³´Â /etc/resolv.conf¿¡ ÀúÀåµÇ¾î ÀÖÀ½)À» ÀÔ·ÂÇÑ´Ù. ´Ù µÇ¾úÀ¸¸é 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.

  8. '°í±Þ'À» Ŭ¸¯Çϰí, 'Enable DNS for Windows Name Resolution'°ú 'Enable LMHOSTS lookup'¸¦ ¼±ÅÃÇÑ´Ù. ¸¸¾à¿¡ LMHOSTS È­ÀÏÀ» »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, C:\winnt\system32\drivers\etc¿¡ ÀúÀåµÇ¾î ÀÖ´Â °ÍÀ» ÂüÁ¶ÇÑ´Ù.

  9. ¸ðµç ´ëÈ­»óÀÚ¿¡¼­ 'È®ÀÎ'À» Ŭ¸¯ÇÏ°í ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.

  10. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ­ ¸®´ª½º È£½ºÆ®·Î Ping À» ÇØº»´Ù: 'È­ÀÏ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
    (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

4.4 UNIX ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤

  1. ¾ÆÁ÷ ³×Æ®¿÷ Ä«µå¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò°Å³ª ÇØ´ç µå¶óÀ̹ö¸¦ Áö¿øÇϵµ·Ï Ä¿³ÎÀ» ´Ù½Ã ÄÄÆÄÀÏ ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ÇÑ´Ù. ÀÌ ¹®¼­¿¡¼­ ÀÌ ³»¿ëÀº ´Ù·çÁö ¾Ê´Â´Ù.
  2. TCP/IP ³×Æ®¿÷ÀÌ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, net-tools ÆÐŰÁö¿Í °°Àº TCP/IP ³×Æ®¿÷ ÅøÀ» ¼³Ä¡ÇÑ´Ù.

  3. IPADDR¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. NETMASK¸¦ 255.255.255.0, GATEWAY¸¦ 192.168.0.1, ±×¸®°í BROADCAST¸¦ 192.168.0.255·Î ¼³Á¤ÇÑ´Ù.

    ¿¹¸¦ µé¾î¼­ ·¡µåÇÞ ¸®´ª½º ½Ã½ºÅÛÀ̶ó¸é, /etc/sysconfig/network-scripts/ifcfg-eth0È­ÀÏÀ» ÆíÁýÇϰųª, °£´ÜÇÏ°Ô Control Panel¿¡¼­ ÇØ°áÇÒ ¼ö ÀÖ´Ù. SunOS, BSDi, Slackware Linux, Solaris, SuSe, Debian µîµî.. ´Ù¸¥ UNIX¿¡¼­´Â ¹æ¹ýÀÌ ´Ù¸¦ ¼öµµ ÀÖ´Ù. Á¤º¸¸¦ ´õ ¾ò°íÀÚ ÇÑ´Ù¸é ¿©·¯ºÐÀÇ ÇØ´ç UNIX ¹®¼­¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.

  4. /etc/resolv.confÈ­ÀÏ¿¡ µµ¸ÞÀÎ ³×ÀÓ ¼­ºñ½º(DNS)¸¦ Ãß°¡ÇÏ°í µµ¸ÞÀÎ °Ë»ö Á¢¹Ì»ç¸¦ Ãß°¡ÇÑ´Ù. UNIX ¹öÁ¯°ú Á¾·ù¿¡ µû¶ó¼­´Â, /etc/nsswitch.conf È­ÀÏÀ» ÆíÁýÇØ¼­ DNS ¼­ºñ½º¸¦ »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.

  5. ¼³Á¤¿¡ µû¶ó¼­´Â /etc/networks È­ÀÏÀ» ÆíÁýÇØ¼­ ¹Ù²Ù¾îÁà¾ß ÇÒ ¼öµµ ÀÖ´Ù.

  6. ÀûÀýÇÑ ¼­ºñ½ºµéÀ» Àç½Ãµ¿Çϰųª, ȤÀº °£´ÜÇÏ°Ô ¾Æ¿¹ ½Ã½ºÅÛ ÀÚü¸¦ Àç½ÃÀÛÇÑ´Ù.

  7. °ÔÀÌÆ®¿þÀ̰¡ µÇ´Â ÄÄÇ»ÅÍ·ÎÀÇ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ­ ´ÙÀ½°ú °°ÀÌ ping ¸í·ÉÀ» ³»¸°´Ù: ping 192.168.0.1.
    (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

4.5 NCSA ÅÚ³Ý ÆÐŰÁö¸¦ »ç¿ëÇÏ´Â DOSÀÇ ¼³Á¤

  1. ¾ÆÁ÷ ³×Æ®¿÷ Ä«µå¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. ³×Æ®¿÷ Ä«µå ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. ÀûÀýÇÑ ÆÐŶ µå¶óÀ̹ö¸¦ ·ÎµåÇÑ´Ù. ¿¹¸¦ µé¾î¼­: NE2000 ÀÌ´õ³Ý Ä«µå¸¦ I/O Æ÷Æ® 300, IRQ 10À¸·Î »ç¿ëÇÑ´Ù¸é, nwpd 0x60 10 0x300¶ó°í ¸í·ÉÇÑ´Ù.

  3. »õ·Î¿î µð·ºÅ丮¸¦ ¸¸µé°í, ±× µð·ºÅ丮¿¡ NCSA ÅÚ³Ý ÆÐŰÁö¸¦ Ç®¾î ³õ´Â´Ù: pkunzip tel2308b.zip

  4. ÅØ½ºÆ® ¿¡µðÅÍ·Î config.tel È­ÀÏÀ» ¿¬´Ù.

  5. myip=192.168.0.x (1 < x < 255)·Î, netmask=255.255.255.0·Î ¼³Á¤ÇÑ´Ù.

  6. ÀÌ ¿¹¿¡¼­´Â, hardware=packet, interrupt=10, ioaddr=60¶ó°í ¼³Á¤ÇØ¾ß ÇÑ´Ù.

  7. °ÔÀÌÆ® ¿þÀ̷μ­ Àû¾îµµ ÇѰ³ÀÇ ÄÄÇ»ÅÍ¿¡ ´ëÇÑ ¼³Á¤ÀÌ ÀÖ¾î¾ß ÇÑ´Ù(¿¹¸¦ µé¸é ÀÌ °æ¿ì¿¡´Â ¸®´ª½º È£½ºÆ®):

    name=default
    host=¸®´ª½ºÈ£½ºÆ®À̸§
    hostip=192.168.0.1
    gateway=1
    

  8. µµ¸ÞÀÎ ³×ÀÓ ¼­ºñ½º¸¦ À§Çؼ­ ¶Ç ÇϳªÀÇ ¼³Á¤À» ÇØÁà¾ß ÇÑ´Ù:

    name=dns.domain.com ; hostip=123.123.123.123; nameserver=1
    

    Note: ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â Á¤º¸´ë·Î À§ÀÇ ³»¿ëÀ» ¼öÁ¤ÇØ ÁØ´Ù.

  9. config.tel È­ÀÏÀ» ÀúÀåÇÑ´Ù.

  10. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ­ ¸®´ª½º È£½ºÆ®·Î ÅÚ³Ý ¿¬°áÀ» ÇØ º»´Ù: telnet 192.168.0.1 ¸¸¾à ·Î±ä ÇÁ·ÒÇÁÆ®°¡ ³ª¿ÀÁö ¾Ê´Â´Ù¸é, ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

4.6 MacTCP¸¦ »ç¿ëÇÏ´Â MacOS ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤

  1. ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ¼ÒÇÁÆ®¿þ¾î¸¦ ¾ÆÁ÷ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. ¾î´ðÅÍ ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. MacTCP control panelÀ» ¿¬´Ù. ÀûÀýÇÑ ³×Æ®¿÷ µå¶óÀ̹ö¸¦ ¼±ÅÃÇÑ´Ù(EtherTalkÀÌ ¾Æ´Ï°í EthernetÀ» ¼±ÅÃ). ±×¸®°í 'More...' ¹öưÀ» Ŭ¸¯ÇÑ´Ù.

  3. 'Obtain Address:' ºÎºÐ¿¡¼­, 'Manually'¸¦ Ŭ¸¯ÇÑ´Ù.

  4. 'IP Address:' ºÎºÐ¿¡¼­, ÆË¾÷ ¸Þ´º¿¡¼­ class C¸¦ ¼±ÅÃÇÑ´Ù. ÀÌ ´ëÈ­»óÀÚÀÇ ³ª¸ÓÁö ºÎºÐÀº ¹«½ÃÇÑ´Ù.

  5. 'Domain Name Server Information:'¿¡¼­ DNS Á¤º¸¸¦ ÀÔ·ÂÇÑ´Ù.

  6. 'Gateway Address:'¿¡¼­, 192.168.0.1¸¦ ÀÔ·ÂÇÑ´Ù.

  7. 'OK'¸¦ Ŭ¸¯Çؼ­ ¼³Á¤À» ÀúÀåÇÑ´Ù. MacTCP control panelÀÇ ¸ÞÀÎ À©µµ¿ì¿¡¼­, 'IP Address:'ºÎºÐ¿¡ Mac ÄÄÇ»ÅÍÀÇ IP ÁÖ¼Ò (192.168.0.x, 1 < x < 255)¸¦ ÀÔ·ÂÇÑ´Ù.

  8. MacTCP control panelÀ» ´Ý´Â´Ù. Àç½ÃÀÛÀ» ¹¯´Â ´ëÈ­»óÀÚ°¡ ³ªÅ¸³ª¸é ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.

  9. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ­ ¸®´ª½º È£½ºÆ®¿¡ pingÀ» º¸³¾ ¼ö ÀÖ´Ù. MacTCP Watcher¶ó´Â ÇÁ¸®¿þ¾î ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, 'Ping' ¹öưÀ» ´©¸£°í, ³ªÅ¸³ª´Â ´ëÈ­»óÀÚ¿¡¼­ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(192.168.0.1)¸¦ ÀÔ·ÂÇÑ´Ù. (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

  10. ³»ºÎ LAN¿¡¼­ IP ÁÖ¼Ò ´ë½Å È£½ºÆ® À̸§À» »ç¿ëÇϱâ À§Çؼ­, ½Ã½ºÅÛ Æú´õ¿¡ Hosts È­ÀÏÀ» ¸¸µé ¼öµµ ÀÖ´Ù. ½Ã½ºÅÛ Æú´õ¿¡´Â ÀÌ È­ÀÏÀÌ ÀÌ¹Ì Á¸ÀçÇϰí ÀÖÀ» °ÍÀÌ´Ù. ÀÌ È­ÀÏ¿¡´Â ¿©·¯ºÐÀÇ °æ¿ì¿¡ ¸ÂÃç¼­ ¼öÁ¤Çؼ­ »ç¿ëÇÒ ¼öÀÖ´Â »ùÇÃÀÌ µé¾î ÀÖÀ» °ÍÀÌ´Ù.

4.7 Open Transport¸¦ »ç¿ëÇÏ´Â MacOS ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤

  1. ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ÀûÀýÇÑ µå¶óÀ̹ö°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. TCP/IP Control PanelÀ» ¿­¾î¼­ Edit ¸Þ´º¿¡¼­ 'User Mode ...'¸¦ ¼±ÅÃÇÑ´Ù. user mode °¡ ÃÖ¼ÒÇÑ 'Advanced' ÀÌ»ó¿¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇϰí 'OK' ¹öưÀ» ´©¸¥´Ù.

  3. File ¸Þ´º¿¡¼­ 'Configurations...'¸¦ ¼±ÅÃÇÑ´Ù. 'Default' ·Î µÇ¾î ÀÖ´Â ¼³Á¤À» ¼±ÅÃÇϰí 'Duplicate...' ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 'Duplicate Configuration' ´ëÈ­»óÀÚ¿¡¼­, 'IP Masq' (ȤÀº º¸ÅëÀÇ °æ¿ì¿¡¼­ÀÇ ¼³Á¤ÀÌ ¾Æ´Ï¶ó´Â °ÍÀ» ÀǹÌÇÏ´Â °Í)À» ÀÔ·ÂÇÑ´Ù. ÀÌ·¸°Ô Çϸé 'Default copy'¿Í °°Àº °ÍÀÌ ³ªÅ¸³¯ °ÍÀÌ´Ù. ±×·¯¸é 'OK' ¹öưÀ» Ŭ¸¯Çϰí, 'Make Active' ¹öưÀ» Ŭ¸¯ÇÑ´Ù.

  4. 'Connect via:' ´ëÈ­»óÀÚ¿¡¼­ 'Ethernet'À» ¼±ÅÃÇÑ´Ù.

  5. 'Configure:' ´ëÈ­»óÀÚ¿¡¼­ ÀûÀýÇÑ Ç׸ñÀ» ¼±ÅÃÇÑ´Ù. ¾î¶² °ÍÀ» ¼±ÅÃÇØ¾ß ÇÏ´ÂÁö Àß ¸ð¸£°Ú´Ù¸é, ¾Æ¸¶µµ 'Default' ¼³Á¤À» ´Ù½Ã ¼±ÅÃÇÏ°í ³ª°¡¾ß ÇÒ °ÍÀÌ´Ù. ÇÊÀÚÀÇ °æ¿ì¿¡´Â 'Manually' ¸¦ ¼±ÅÃÇØ¼­ ¼³Á¤Çß´Ù.

  6. 'IP Address:' ´ëÈ­»óÀÚ¿¡¼­ Mac ÄÄÇ»ÅÍÀÇ IP ÁÖ¼Ò(192.168.0.x, 1 < x < 255)¸¦ ÀÔ·ÂÇÑ´Ù.

  7. 'Subnet mask:' ´ëÈ­»óÀÚ¿¡¼­ 255.255.255.0¸¦ ÀÔ·ÂÇÑ´Ù.

  8. 'Router address:' ´ëÈ­»óÀÚ¿¡¼­ 192.168.0.1À» ÀÔ·ÂÇÑ´Ù.

  9. 'Name server addr.:' ´ëÈ­»óÀÚ¿¡¼­ DNS ¼­¹öÀÇ IP ÁÖ¼Ò¸¦ ÀÔ·ÂÇÑ´Ù.

  10. 'Implicit Search Path:' ºÎºÐÀÇ 'Starting domain name' ´ëÈ­»óÀÚ¿¡¼­ ÀÎÅÍ³Ý µµ¸ÞÀÎÀ» ÀÔ·ÂÇÑ´Ù.

  11. ´ÙÀ½ °úÁ¤Àº ¼±ÅÃÀûÀÌ´Ù. À߸ø ¼³Á¤Çϸé Á¤»ó µ¿ÀÛÇÏÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. Àß ¸ð¸£°Ú´Ù¸é, ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»°í ºñ¿öµÎ°Å³ª, ¾Æ¹«°Íµµ ¼±ÅõÇÁö ¾ÊÀº ä·Î µÎ´Â °ÍÀÌ ÁÁÀ» °ÍÀÌ´Ù. ÇÊ¿äÇÏ´Ù¸é, ÀԷµǾî ÀÖ´Â Á¤º¸¸¦ ¸ðµÎ ¾ø¾Öµµ·Ï ÇÑ´Ù. ÇÊÀÚ°¡ ¾Æ´Â ÇÑ, TCP/IP ´ëÈ­»óÀÚ¸¦ ÅëÇØ¼­ ½Ã½ºÅÛÀÌ ÀÌÀü¿¡ ¼±ÅõǾî ÀÖ´Â ´Ù¸¥ "Hosts" È­ÀÏÀ» »ç¿ëÇÏÁö ¾Êµµ·Ï ÇÏ´Â ¹æ¹ýÀº ¾ø´Ù. ¸¸¾à ¿©·¯ºÐÀÌ ±× ¹æ¹ýÀ» ¾Ë°í ÀÖ´Ù¸é, ÇÊÀÚ¿¡°Ô ¾Ë·ÁÁÖ±æ ¹Ù¶õ´Ù.

    ¿©·¯ºÐÀÇ ³×Æ®¿÷ÀÌ 802.3 ŸÀÔÀÇ ÇÁ·¹ÀÓÀ» ÇÊ¿ä·Î ÇÑ´Ù¸é '802.3'À» üũÇÑ´Ù.

  12. 'Options...' ¹öưÀ» Ŭ¸¯Çؼ­ TCP/IP °¡ Ȱ¼ºÈ­ µÇµµ·Ï ÇÑ´Ù. ÇÊÀÚÀÇ °æ¿ì¿¡´Â 'Load only when needed' ¿É¼ÇÀ» »ç¿ëÇß´Ù. ¿©·¯ºÐÀÌ ÄÄÇ»Å͸¦ ÀçºÎÆÃ ÇÏÁö ¾Ê´Âä·Î TCP/IP ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ½ÇÇà°ú Á¾·á¸¦ ¹Ýº¹À» ¿©·¯¹ø ¹Ýº¹ÇÏ´Â °æ¿ì¿¡´Â, 'Load only when needed' ¿É¼ÇÀ» üũÇÏÁö ¾Ê´Â °ÍÀÌ ¿©·¯ºÐÀÇ ÄÄÇ»ÅÍÀÇ ¸Þ¸ð¸® °ü¸®¿¡ µµ¿òÀ» ÁÙ °ÍÀÌ´Ù. ±× Ç׸ñÀ» üũÇÏÁö ¾ÊÀº ä·Î µÎ¸é, TCP/IP ÇÁ·ÎÅäÄÝ ½ºÅÃÀº Ç×»ó ·ÎµåµÇ¾î¼­ »ç¿ë °¡´ÉÇÑ »óŰ¡ µÈ´Ù. ¸¸¾à Ã¼Å©ÇØ µÐ´Ù¸é, TCP/IP ½ºÅÃÀº ÇÊ¿äÇÒ ¶§ ÀÚµ¿ÀûÀ¸·Î ·ÎµåµÇ°í ÇÊ¿ä¾ø¾îÁö¸é ÀÚµ¿ÀûÀ¸·Î Á¦°ÅµÈ´Ù. ÀÌ·¸°Ô µÇ¸é, °è¼ÓÀûÀÎ loading°ú unloadingÀ» ÇÔÀ¸·Î½á ¸Þ¸ð¸®°¡ ÆÄÆíÀ¸·Î Á¶ÀÛ³ª°Ô µÈ´Ù. (¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ µð½ºÅ© Á¶°¢ ¸ðÀÓÀÌ ÇÊ¿äÇÑ ÀÌÀ¯¿Í ºñ½ÁÇÏ´Ù.)

  13. ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ­ ¸®´ª½º È£½ºÆ®¿¡ pingÀ» º¸³¾ ¼ö ÀÖ´Ù. MacTCP Watcher¶ó´Â ÇÁ¸®¿þ¾î ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, 'Ping' ¹öưÀ» ´©¸£°í, ³ªÅ¸³ª´Â ´ëÈ­»óÀÚ¿¡¼­ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(192.168.0.1)¸¦ ÀÔ·ÂÇÑ´Ù. (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

  14. ³»ºÎ LAN¿¡¼­ IP ÁÖ¼Ò ´ë½Å È£½ºÆ® À̸§À» »ç¿ëÇϱâ À§Çؼ­, ½Ã½ºÅÛ Æú´õ¿¡ Hosts È­ÀÏÀ» ¸¸µé ¼öµµ ÀÖ´Ù. ÀÌ È­ÀÏÀº ½Ã½ºÅÛ Æú´õ¿¡ ÀÖÀ» ¼öµµ ÀÖ°í ¾øÀ» ¼öµµ ÀÖ´Ù. ÀÌ È­ÀÏÀÌ Á¸ÀçÇÑ´Ù¸é, ¿©·¯ºÐÀÇ °æ¿ì¿¡ ¸ÂÃç¼­ ¼öÁ¤Çؼ­ »ç¿ëÇÒ ¼öÀÖ´Â »ùÇÃÀÌ µé¾î ÀÖÀ» °ÍÀÌ´Ù. Á¸ÀçÇÏÁö ¾Ê´Â´Ù¸é, MacTCP¸¦ »ç¿ëÇϰí ÀÖ´Â ½Ã½ºÅÛÀ¸·ÎºÎÅÍ º¹»çÇØ ¿Í¼­ ¼öÁ¤ÇØ ¾²°Å³ª, ±×³É ¿©·¯ºÐ ÀÚ½ÅÀÌ ¸¸µé¾î¼­ »ç¿ëÇØµµ µÈ´Ù(ÀÌ È­ÀÏÀÇ Çü½ÄÀº UNIXÀÇ /etc/hosts È­ÀÏ Çü½ÄÀÇ ÀϺθ¦ »ç¿ëÇϸç, RFC952¿¡ ¼³¸íµÇ¾î ÀÖ´Ù). ÀÏ´Ü È­ÀÏÀ» ¸¸µé°í ³ª¸é, TCP/IP control panelÀ» ¿­¾î¼­, 'Select Hosts File...' ¹öưÀ» ´©¸£°í Hosts È­ÀÏÀ» ¿¬´Ù.

  15. ´Ý±â »óÀÚ¸¦ Ŭ¸¯Çϰųª File ¸Þ´º¿¡¼­ 'Close' ȤÀº 'Quit' À» ¼±ÅÃÇÑ´Ù. ±×¸®°í 'Save' ¹öưÀ» Ŭ¸¯Çؼ­ º¯°æ»çÇ×À» ÀúÀåÇÑ´Ù.

  16. º¯°æ »çÇ×Àº Áï½Ã ¹Ý¿µµÇÁö¸¸, ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÏ´Â °Íµµ ÁÁ´Ù.

4.8 DNS¸¦ »ç¿ëÇÏ´Â Novell ³×Æ®¿÷ÀÇ ¼³Á¤

  1. ÀÌ´õ³Ý ¾î´ðÅÍÀ» À§ÇÑ µå¶óÀ̹ö ¼ÒÇÁÆ®¿þ¾î°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. The Novell LanWorkPlace page¿¡¼­ tcpip16.exe¸¦ ´Ù¿î·ÎµåÇÑ´Ù.

  3. c:\nwclient\startnet.bat¸¦ ÆíÁýÇÑ´Ù
    
    : (ÇÊÀÚ°¡ ¾²´Â È­ÀÏ ³»¿ëÀÌ´Ù)
    SET NWLANGUAGE=ENGLISH
    LH LSL.COM
    LH KTC2000.COM
    LH IPXODI.COM
    LH tcpip
    LH VLM.EXE
    F:
    

  4. c:\nwclient\net.cfg¸¦ ÆíÁýÇÑ´Ù
    
    : (link driver´Â ¿©·¯ºÐ¿¡ ¸Â°Ô ¼öÁ¤ÇÑ´Ù. ¿¹¸¦ µé¸é NE2000)
    Link Driver KTC2000
            Protocol IPX 0 ETHERNET_802.3
            Frame ETHERNET_802.3
            Frame Ethernet_II
            FRAME Ethernet_802.2
    
    NetWare DOS Requester
               FIRST NETWORK DRIVE = F
               USE DEFAULTS = OFF
               VLM = CONN.VLM
               VLM = IPXNCP.VLM
               VLM = TRAN.VLM
               VLM = SECURITY.VLM
               VLM = NDS.VLM
               VLM = BIND.VLM
               VLM = NWP.VLM
               VLM = FIO.VLM
               VLM = GENERAL.VLM
               VLM = REDIR.VLM
               VLM = PRINT.VLM
               VLM = NETX.VLM
    
    Link Support
            Buffers 8 1500
            MemPool 4096
    
    Protocol TCPIP
            PATH SCRIPT     C:\NET\SCRIPT
            PATH PROFILE    C:\NET\PROFILE
            PATH LWP_CFG    C:\NET\HSTACC
            PATH TCP_CFG    C:\NET\TCP
            ip_address      192.168.0.xxx
            ip_router       192.168.0.1
    
    À§ÀÇ "ip_address" ºÎºÐÀº ¿©·¯ºÐÀÇ IP ÁÖ¼Ò·Î ÇÑ´Ù (192.168.0.x, 1 < x < 255)
    ±×¸®°í ¸¶Áö¸·À¸·Î c:\bin\resolv.cfg¸¦ ÆíÁýÇÑ´Ù:
    
    SEARCH DNS HOSTS SEQUENTIAL
    NAMESERVER xxx.xxx.xxx.xxx
    NAMESERVER yyy.yyy.yyy.yyy
    
  5. À§ÀÇ "NAMESERVER" ºÎºÐÀº ¿©·¯ºÐÀÌ »ç¿ëÇÏ´Â DNS ¼­¹ö·Î ´ëüÇÑ´Ù.

  6. °ÔÀÌÆ®¿þÀÌ ÄÄÇ»ÅÍ·ÎÀÇ ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ­ ping ¸í·ÉÀ» ÇÑ´Ù: ping 192.168.0.1
    (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.

4.9 OS/2 WarpÀÇ ¼³Á¤

  1. ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ÀûÀýÇÑ µå¶óÀ̹ö ¼ÒÇÁÆ®¿þ¾î°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼­¿¡¼­ ´Ù·çÁö ¾Ê´Â´Ù.

  2. TCP/IP ÇÁ·ÎÅäÄÝÀÌ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù.

  3. Programs/TCP/IP (LAN) / TCP/IP ¼³Á¤À¸·Î °£´Ù.

  4. 'Network'¿¡¼­ TCP/IP ÁÖ¼Ò(192.168.0.x)¸¦ ÀÔ·ÂÇÏ°í ³×Æ®¿÷ ¸¶½ºÅ©¸¦ ¼³Á¤ÇÑ´Ù(255.255.255.0).

  5. 'Routing'¿¡¼­ 'Add'¸¦ ´©¸¥´Ù. TypeÀº 'default'·Î Çϰí 'Router Address' ºÎºÐ¿¡¼­ ¸®´ª½º È£½ºÆ®ÀÇ IP ÁÖ¼Ò¸¦ ÀÔ·ÂÇÑ´Ù(192.168.0.1).

  6. 'Hosts'¿¡ ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â DNS (Nameserver) ÁÖ¼Ò¿Í °°ÀÌ ¼³Á¤ÇØ ÁØ´Ù.

  7. TCP/IP control panelÀ» ´Ý°í µÚÀÌ¾î ³ª¿À´Â Áú¹®µé¿¡ yes¸¦ ´äÇÑ´Ù.

  8. ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÑ´Ù.

  9. ³×Æ®¿÷ ¼³Á¤À» ½ÃÇèÇϱâ À§Çؼ­ ¸®´ª½º È£½ºÆ®¸¦ ping ÇÒ ¼öµµ ÀÖ´Ù. 'OS/2 Command prompt Window'¿¡¼­ 'ping 192.168.0.1'¶ó°í ÀÔ·ÂÇÑ´Ù. ping ÆÐŶÀÌ µ¹¾Æ¿À¸é ¸ðµç°Ô Á¦´ë·Î ¼³Á¤µÈ °ÍÀÌ´Ù.

4.10 ±×¿Ü ´Ù¸¥ ½Ã½ºÅÛÀÇ ¼³Á¤

±×¿Ü ´Ù¸¥ ½Ã½ºÅÛÀ» ¼³Á¤ÇÒ ¶§¿¡µµ Áö±Ý±îÁö¿Í °°Àº ¹æ½ÄÀ» »ç¿ëÇÑ´Ù. À§ÀÇ ¼½¼ÇµéÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù. À§¿¡¼­ ´Ù·çÁö ÀÖÁö ¾Ê´Â ½Ã½ºÅÛ¿¡¼­ÀÇ ¼³Á¤¿¡ ´ëÇØ¼­ ±ÛÀ» ½á ÁÖ½Ç ºÐÀº, ±× ÀÚ¼¼ÇÑ ¼³Á¤°úÁ¤À» ambrose@writeme.com°ú dranch@trinnet.netÀ¸·Î º¸³»Áֱ⠹ٶõ´Ù.

5. IP ¸¶½ºÄ¿·¹À̵åÀÇ ½ÃÇè

ÀÌÁ¦ ¸¶Áö¸·À¸·Î, IP ¸¶½ºÄ¿·¹À̵ùÀ» ½ÃÇèÇÒ ¶§´Ù. ¸®´ª½º È£½ºÆ®¸¦ ¾ÆÁ÷ ÀçºÎÆÃÇØº¸Áö ¾Ê¾Ò´Ù¸é, Áö±Ý ÀçºÎÆÃÇÏ°í ºÎÆÃÀÌ ¼º°øÇÏ´ÂÁö È®ÀÎÇϰí, /etc/rc.d/rc.firewall Á¤Ã¥À» ½ÇÇàÇÑ´Ù. ´ÙÀ½À¸·Î, ³»ºÎ LAN°úÀÇ ¿¬°á°ú ¿ÜºÎ ÀÎÅͳÝÀ¸·ÎÀÇ ¿¬°áÀÌ Á¦´ë·Î µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

ÀÌÁ¦ ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù:

  • ù¹øÂ°: ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼­, ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»ÅÍ·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.10 °ú °°ÀÌ). À̰ÍÀ¸·Î ³»ºÎ LANÀÇ ÄÄÇ»ÅÍ¿¡¼­ TCP/IP°¡ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à Á¦´ë·Î µÇÁö ¾Ê´Â´Ù¸é, ³»ºÎ ÄÄÇ»Å͵鿡¼­ TCP/IP ¼³Á¤À» ÀÌ HOWTO¿¡¼­ ¼³¸íÇÑ ´ë·Î Á¦´ë·Î Çß´ÂÁö ´Ù½Ã È®ÀÎÇÑ´Ù.

  • µÎ¹øÂ°: ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö ÀÚü¿¡¼­, ¸¶½ºÄ¿·¹ÀÌµå ³»Æ®¿÷ ³»ºÎÀÇ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.1°ú °°ÀÌ). ÀÌÁ¦ ÀÎÅÍ³Ý »óÀÇ ¿ÜºÎ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù. ÀÌ ¿ÜºÎÀÇ ÁÖ¼Ò´Â ISP¿¡ ¿¬°áµÈ ÀÚ±â ÀÚ½ÅÀÇ PPP, ÀÌ´õ³Ý µîÀÇ ÁÖ¼Ò¿©µµ µÈ´Ù. ÀÌ IP ÁÖ¼Ò¸¦ ¸ð¸¥´Ù¸é, "/sbin/ifconfig"¶ó°í ¸í·ÉÇØ¼­ ÀÎÅÍ³Ý ÁÖ¼Ò¸¦ ¾Ë¾Æ³½´Ù. À̰ÍÀ¸·Î ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡ ³×Æ®¿÷ÀÌ ¿ÂÀüÈ÷ ¿¬°áµÇ¾î ÀÖ´ÂÁö ¾Ë ¼ö°¡ ÀÖ´Ù.

  • ¼¼¹øÂ°: ´Ù½Ã ¸¶½ºÄ¿·¹À̵ù µÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼­, ¸¶½ºÄ¿·¹À̵ù ¸®´ª½º È£½ºÆ®ÀÇ ³»ºÎ ÀÌ´õ³Ý Ä«µå¿¡ ¿¬°áµÈ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.1°ú °°ÀÌ). À̰ÍÀ¸·Î ³»ºÎ ³×Æ®¿÷°ú ¶ó¿ìÆÃÀÌ Á¦´ë·Î µÇ°í ÀÖ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à À̰ÍÀÌ ½ÇÆÐÇÑ´Ù¸é, ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿Í ³»ºÎ ÄÄÇ»ÅÍÀÇ ÀÌ´õ³Ý Ä«µå°¡ "¹°¸®ÀûÀ¸·Î" ¿¬°áµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ÀÌ´Â ÀÌ´õ³Ý Ä«µå µÞ¸éÀ̳ª ÀÌ´õ³Ý Çãºê/½ºÀ§Ä¡(¸¸¾à ÀÖ´Ù¸é)ÀÇ LED°¡ Á¡µîÇÏ´ÂÁö È®ÀÎÇÏ¸é µÈ´Ù.

  • ³×¹øÂ°: ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼­, ¸¶½ºÄ¿·¹ÀÌµå ¼­¹öÀÇ ¿ÜºÎ·Î ¿¬°áµÈ TCP/IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù. ÀÌ ÁÖ¼Ò´Â ISP¿¡ ¿¬°áµÈ ¿©·¯ºÐÀÇ PPP, ÀÌ´õ³Ý µîÀÇ ÁÖ¼ÒÀÏ °ÍÀÌ´Ù. ÀÌ ping Å×½ºÆ®·Î, ¸¶½ºÄ¿·¹À̵ù(ƯÈ÷ ICMP ¸¶½ºÄ¿·¹À̵ù)ÀÌ Á¦´ë·Î ÀÛµ¿Çϰí ÀÖ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à À̰ÍÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê´Â´Ù¸é, Ä¿³ÎÀÌ "ICMP Masquerading"À» Áö¿øÇϵµ·Ï µÇ¾î ÀÖ´ÂÁö¿Í /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¿¡¼­ "IP Forwarding"À» Çã¿ëÇß´ÂÁö È®ÀÎÇÑ´Ù. /etc/rc.d/rc.firewall Á¤Ã¥ÀÌ Á¦´ë·Î ·ÎµåµÇ¾ú´ÂÁöµµ È®ÀÎÇÑ´Ù. /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¸¦ ¼öµ¿À¸·Î ½ÇÇàÇØ¼­ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁöµµ È®ÀÎÇÑ´Ù.

¿©ÀüÈ÷ Á¦´ë·Î ÀÛµ¿ÇÏÁö ¾Ê´Â´Ù¸é, ´ÙÀ½ ¸í·ÉÀÇ Ãâ·ÂÀ» Àß È®ÀÎÇØ º»´Ù.

  • "ifconfig" : ÀÎÅÍ³Ý ¿¬°áÀÌ UP µÇ¾î ÀÖ´ÂÁö¿Í ÀÎÅÍ³Ý ¿¬°á¿¡ Á¦´ë·Î µÈ IP ÁÖ¼Ò°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö¸¦ È®ÀÎÇÑ´Ù.

  • "netstat -rn" : µðÆúÆ® °ÔÀÌÆ®¿þÀÌ(Gateway ºÎºÐ¿¡ 0.0.0.0ÀÌ ¾Æ´Ñ IP ÁÖ¼Ò°¡ ÀÖ´Â °Í)°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

  • "cat /proc/sys/net/ipv4/ip_forward" : "1"À» Ãâ·ÂÇÏ¸é ¸®´ª½º Æ÷¿öµùÀÌ Çã¿ëµÇ¾î ÀÖ´Â °ÍÀε¥ ÀÌ·¸°Ô ³ª¿À´ÂÁö È®ÀÎÇÑ´Ù.

  • Ä¿³Î 2.0.x¿¡¼­´Â "/sbin/ipfwadm -F -l", Ä¿³Î 2.2.x¿¡¼­´Â "/sbin/ipchains -F -L" : ¸¶½ºÄ¿·¹À̵ùÀÌ È°¼ºÈ­ µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

  • ´Ù¼¸¹øÂ°: ¸¶½ºÄ¿·¹À̵ùµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼­, ÀÎÅÍ³Ý»ó¿¡ ÀÖ´Â °íÁ¤ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù (¿¹¸¦ µé¸é, ping 152.19.254.81 ¿Í °°ÀÌ (ÀÌ ÁÖ¼Ò´Â LDP ȨÆäÀÌÁöÀÎ http://metalab.unc.edu ÀÇ ÁÖ¼ÒÀÌ´Ù). À̰ÍÀÌ µ¿ÀÛÇϸé, ÀÎÅͳÝÀ» ÇâÇÑ ICMP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î ÀÌ·ç¾îÁö°í ÀÖ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. ¸¸¾à µ¿ÀÛÇÏÁö ¾ÊÀ¸¸é, ÀÎÅÍ³Ý ¿¬°áÀ» ´Ù½Ã È®ÀÎÇÑ´Ù. ´Ù½Ã È®ÀÎÇߴµ¥µµ µ¿ÀÛÇÏÁö ¾ÊÀ¸¸é, ¿¹·Î µç °£´ÜÇÑ rc.firewall Á¤Ã¥À» »ç¿ëÇϰí ÀÖ´ÂÁö¿Í Ä¿³ÎÀ» ICMP ¸¶½ºÄ¿·¹À̵ùÀ» Æ÷ÇÔÇÏ¿© ÄÄÆÄÀÏÇß´ÂÁö È®ÀÎÇÑ´Ù.

  • ¿©¼¸¹øÂ°: ÀÌÁ¦ ¿ÜºÎÀÇ "IP ÁÖ¼Ò"·Î telnetÀ» ÇØº»´Ù(¿¹¸¦ µé¸é telnet 152.2.254.81 (metalab.unc.edu - ÀÌ ¼­¹ö´Â ºÎÇϰ¡ ¸¹ÀÌ °É¸®±â ¶§¹®¿¡ ·Î±ä ÇÁ·ÒÇÁÆ®¸¦ ¹Þ±â±îÁö ½Ã°£ÀÌ °É¸± ¼öµµ ÀÖ´Ù). ¾î´ÀÁ¤µµ ½Ã°£ÀÌ Áö³­ ÈÄ¿¡ ·Î±ä ÇÁ·ÒÇÁÆ®¸¦ ¹Þ´Â°¡? À̰ÍÀÌ ¼º°øÇϸé, TCP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù. ¸¸¾à ¼º°øÇÏÁö ¸øÇß´Ù¸é, telnetÀ» Áö¿øÇÏ´Â °Í Áß¿¡¼­ ¿©·¯ºÐÀÌ ¾Ë°í ÀÖ´Â °÷À» ½ÃµµÇØ º»´Ù. (¿¹¸¦ µé¸é 198.182.196.55 (www.linux.org). ¿©ÀüÈ÷ µ¿ÀÛÇÏÁö ¾Ê´Â´Ù¸é, ÇöÀç ¿¹·Î µç °£´ÜÇÑ rc.firewall Á¤Ã¥À» »ç¿ëÇϰí ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

  • Àϰö¹øÂ°: ÀÌÁ¦ ¿ÜºÎÀÇ "È£½ºÆ® À̸§"À¸·Î telnetÀ» ÇØº»´Ù(¿¹¸¦ µé¸é "telnet metalab.unc.edu" (152.2.254.81). À̰ÍÀÌ ¼º°øÇϸé, DNS°¡ Á¦´ë·Î µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù. À̰ÍÀº ¼º°øÇÏÁö ¸øÇßÁö¸¸ "³×¹øÂ°" ´Ü°è´Â ¼º°øÇß´Ù¸é, ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡ DNS ¼­¹ö°ü·Ã ¼³Á¤À» Á¦´ë·Î Çß´ÂÁö È®ÀÎÇÑ´Ù.

  • ¿©´ü¹øÂ°: ¸¶Áö¸· ½ÃÇèÀ¸·Î½á, ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼­ À¥ ºê¶ó¿ìÁ®¸¦ ÅëÇØ¼­ 'INTERNET'»óÀÇ WWW »çÀÌÆ®¸¦ ¿­¾îº¸°í ºê¶ó¿ìÁ®¿¡ Ç¥½Ã°¡ µÇ´ÂÁö È®ÀÎÇÑ´Ù. ¿¹¸¦ µé¾î¼­, Linux Documentation Project site¸¦ Á¢¼ÓÇØ º»´Ù. À̰ÍÀÌ ¼º°øÇϸé, ¸ðµç °ÍÀÌ ÈǸ¢ÇÏ°Ô µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù!

¸®´ª½º ¹®¼­ ÇÁ·ÎÁ§Æ®ÀÇ È¨ÆäÀÌÁö¸¦ º¼ ¼ö ÀÖ´Ù¸é, ÃàÇÏÇÑ´Ù! ¼º°øÇß´Ù! ÀÌ À¥ »çÀÌÆ®¸¦ Á¦´ë·Î º¼ ¼ö ÀÖ´Ù¸é, PING, TELNET, SSHµîÀÇ Ç¥ÁØ ³×Æ®¿÷ Åë½Åµé°ú, °ü·ÃµÈ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» ÀûÀçÇϸé FTP, Real Audio, IRC DCCs, Quake I/II/III, CuSeeme, VDOLiveµîµµ Á¦´ë·Î µ¿ÀÛÇÒ °ÍÀÌ´Ù! FTP, IRC, RealAudio, Quake I/II/IIIµîÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê°Å³ª ºÎ½ÇÇÏ°Ô µ¿ÀÛÇÑ´Ù¸é, "lsmod"¸í·ÉÀ¸·Î °ü·ÃµÈ ¸¶½ºÄ¿·¹À̵ù ¸ðµâµéÀÌ Á¦´ë·Î ÀûÀçµÇ¾î ÀÖ´ÂÁö È®ÀÎÇϰųª ºÎÀûÀýÇÑ ¼­¹ö Æ÷Æ®·Î ÀûÀçµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ÇÊ¿äÇÑ ¸ðµâÀÌ ÀûÀçµÇ¾î ÀÖÁö ¾Ê´Ù¸é, /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®°¡ ±× ¸ðµâµéÀ» ÀûÀçÇϵµ·Ï µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. (¿¹¸¦ µé¸é ÇØ´ç IP ¸¶½ºÄ¿·¹À̵ù ¸ðµâÀÌ ÀÖ´Â ºÎºÐÀÌ "#" ¹®ÀÚ¸¦ Á¦°Å)

6. ±×¿ÜÀÇ IP ¸¶½ºÄ¿·¹ÀÌµå °ü·Ã »çÇ×°ú ¼ÒÇÁÆ®¿þ¾î Áö¿ø

6.1 IP ¸¶½ºÄ¿·¹À̵åÀÇ ¹®Á¦Á¡

¾î¶² TCP/IP ÀÀ¿ë ÇÁ·Î±×·¥µéÀÇ ÇÁ·ÎÅäÄÝÀº, Æ÷Æ® ¹øÈ£¿¡ ´ëÇÑ °ÍµéÀ» Àڱ⠳ª¸§´ë·Î °¡Á¤Çϰųª ±×µé µ¥ÀÌÅÍÀÇ TCP/IP ÁÖ¼Ò³ª Æ÷Æ® ¹øÈ£¸¦ ¾ÏȣȭÇϱ⠶§¹®¿¡, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼­´Â Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. ¾Ïȣȭ ¶§¹®¿¡ ¹®Á¦°¡ µÇ´Â ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µéÀº, ƯÁ¤ÇÑ ÇÁ·Ï½Ã ¼­¹ö¶óµç°¡, ¸¶½ºÄ¿·¹À̵ù ÄÚµå ³»¿¡ ƯÁ¤ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» Ãß°¡ÇØ¾ß ÀÛµ¿ÇÑ´Ù.

6.2 ¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼­ºñ½º

±âº»ÀûÀ¸·Î, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀº ¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼­ºñ½ºµéÀ» ÀüÇô ó¸®ÇÏÁö ¸øÇÑ´Ù. ÇÏÁö¸¸, À̰ÍÀ» ó¸®ÇÒ ¼ö ÀÖ´Â ¸î°¡Áö ¹æ¹ýÀÌ ÀÖ´Ù.

¸¸¾à ³ôÀº ¼öÁØÀÇ º¸¾ÈÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù¸é, °£´ÜÈ÷ ¿äûÀÌ µé¾î¿À´Â IP Æ÷Æ®¸¦ Æ÷¿öµùÇØ ÁÖ¸é µÈ´Ù. À̸¦ ¼öÇàÇÏ´Â ¹æ¹ýÀº ¿©·¯°¡Áö°¡ ÀÖÁö¸¸, °¡Àå ¾ÈÁ¤ÀûÀÎ ¹æ¹ýÀº IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â Forwarders ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼­ºñ½ºµé¿¡ ´ëÇØ¼­ ¾î´ÀÁ¤µµÀÇ ÀÎÁõÀýÂ÷¸¦ °®°Ô ÇÏ·Á¸é, TCP-wrappers³ª Xinetd µîÀ» »ç¿ëÇØ¼­ ƯÁ¤ÇÑ IP ÁÖ¼Ò¸¸ Åë°ú½Ãų ¼ö ÀÖ´Ù. ±× µµ±¸³ª Á¤º¸¸¦ ¾ò±â À§Çؼ­´Â TIS Firewall ToolkitÀ» »ìÆìº¸¸é ÁÁÀ» °ÍÀÌ´Ù.

¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼­ºñ½ºÀÇ º¸¾È¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº TrinityOS ¹®¼­¿Í IP Masquerade Resource¿¡¼­ ãÀ» ¼ö ÀÖÀ» °ÍÀÌ´Ù.

6.3 Áö¿øµÇ´Â Ŭ¶óÀÌ¾ðÆ® ¼ÒÇÁÆ®¿þ¾î¿Í ±×¿Ü ¼³Á¤¿¡ ´ëÇØ ¾Ë¾ÆµÑ Á¡

** Linux Masquerade Application list¿¡¼­ ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼­ µ¿ÀÛÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µé¿¡ °üÇÑ ´Ù·®ÀÇ ¿ì¼öÇÑ Á¤º¸µéÀ» ¾òÀ» ¼ö ÀÖ´Ù. ÀÌ »çÀÌÆ®´Â ÇöÀç Steve Grevemeyer°¡ °ü¸®Çϰí ÀÖÀ¸¸ç, ±×´Â dzºÎÇÑ µ¥ÀÌŸº£À̽º¸¦ ±¸ÃàÇØ ³õ¾Ò´Ù. ¾ÆÁÖ ÈǸ¢ÇÑ Á¤º¸ÀÚ¿øÀÌ´Ù!

ÀϹÝÀûÀ¸·Î, Ç¥ÁØ TCP¿Í UDP¸¦ »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µéÀº Àß ÀÛµ¿ÇÒ °ÍÀÌ´Ù. ¸¸¾à ¾î¶°ÇÑ Á¦¾ÈÀ̳ª ÈùÆ®µîÀÌ ÀÖ´Ù¸é IP Masquerade Resource¸¦ È®ÀÎÇØ¼­ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇϱ⠹ٶõ´Ù.

IP ¸¶½ºÄ¿·¹À̵å¿Í ÇÔ²² -µ¿ÀÛÇÏ´Â- ³×Æ®¿÷ Ŭ¶óÀÌ¾ðÆ®µé

ÀϹÝÀûÀΠŬ¶óÀÌ¾ðÆ®µé:

Archie

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, È­ÀÏ °Ë»ö Ŭ¶óÀÌ¾ðÆ® (¸ðµç archie Ŭ¶óÀÌ¾ðÆ®°¡ Áö¿øµÇÁö´Â ¾Ê´Â´Ù).

FTP

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, active FTP Á¢¼ÓÀ» À§Çؼ­ ip_masq_ftp.o Ä¿³Î ¸ðµâ »ç¿ë.

Gopher client

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû.

HTTP

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, À¥ ¼­ÇÎ.

IRC

Áö¿øµÇ´Â ¿©·¯°¡Áö Ç÷§Æû¿¡¼­ µ¿ÀÛÇÏ´Â ¸ðÀº IRC Ŭ¶óÀ̾ðÆ®, DCC´Â ip_masq_irc.o ¸ðµâÀ» ÅëÇØ¼­ Áö¿ø.

NNTP (USENET)

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, USENET ´º½º Ŭ¶óÀ̾ðÆ®.

PING

¸ðµç Ç÷§Æû, ICMP ¸¶½ºÄ¿·¹À̵ù Ä¿³Î ¿É¼Ç »ç¿ë

POP3

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, À̸ÞÀÏ Å¬¶óÀ̾ðÆ®.

SSH

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, º¸¾È»ó ¾ÈÀüÇÑ TELNET/FTP Ŭ¶óÀ̾ðÆ®.

SMTP

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, Sendmail, Qmail, PostFixµîÀÇ À̸ÞÀÏ ¼­¹ö.

TELNET

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, ¿ø°Ý Á¢¼Ó.

TRACEROUTE

UNIX¿Í Windows ±â¹Ý Ç÷§Æû, ¸î°¡Áö º¯Á¾µéÀº µ¿ÀÛÇÏÁö ¾ÊÀ» ¼ö ÀÖ´Ù.

VRML

Windows(Áö¿øµÇ´Â ¸ðµç Ç÷§Æû¿¡¼­µµ ¾î¼¸é °¡´É), °¡»ó Çö½Ç.

WAIS client

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû.

¸ÖƼ¹Ìµð¾î¿Í Åë½Å Ŭ¶óÀ̾ðÆ®:

Alpha Worlds

Windows, Ŭ¶óÀ̾ðÆ®-¼­¹ö ¹æ½ÄÀÇ 3D äÆÃ ÇÁ·Î±×·¥.

CU-SeeMe

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, ip_masq_cuseeme ¸ðµâ »ç¿ë, ÀÚ¼¼ÇÑ »çÇ×Àº CuSeeme ¼½¼Ç ÂüÁ¶.

ICQ

Áö¿øµÇ´Â ¸ðµç Ç÷§Æû. ¸®´ª½º Ä¿³ÎÀÌ IPPORTFW¸¦ Áö¿øÇϵµ·Ï ÄÄÆÄÀϵǾî¾ß Çϸç, ICQ°¡ NON-SOCKS ÇÁ·Ï½Ã µÚÂÊ¿¡¼­ µ¿ÀÛÇϵµ·Ï ¼³Á¤µÇ¾î¾ß ÇÑ´Ù. ÀÌ ¼³Á¤¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ¼³¸íÀº ICQ ¼½¼Ç¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ´Ù.

Internet Phone 3.2

Windows, Peer-to-peer ¹æ½ÄÀÇ À½¼º Åë½Å, ´ç½ÅÀÌ ÅëÈ­¸¦ ¿äûÇÏ´Â °æ¿ì¿¡´Â Åë½ÅÀÌ °¡´ÉÇÏÁö¸¸, ´Ù¸¥ »ç¶÷µéÀÌ ´ç½Å¿¡°Ô ÅëÈ­¸¦ ¿äûÇÒ ¼ö ÀÖ°Ô ÇÏ·Á¸é ƯÁ¤ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

Internet Wave Player

Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio).

Powwow

Windows, Peer-to-peer ¹æ½ÄÀÇ ÅØ½ºÆ®, À½¼º, ÂÊÁö Åë½Å, ´ç½ÅÀÌ ÅëÈ­¸¦ ¿äûÇÏ´Â °æ¿ì¿¡´Â Åë½ÅÀÌ °¡´ÉÇÏÁö¸¸, ´Ù¸¥ »ç¶÷µéÀÌ ´ç½Å¿¡°Ô ÅëÈ­¸¦ ¿äûÇÒ ¼ö ÀÖ°Ô ÇÏ·Á¸é ƯÁ¤ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

Real Audio Player

Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio), ip_masq_raudio UDP ¸ðµâÀ» »ç¿ëÇÏ¸é ´õ ÁÁÀº À½ÁúÀ» ¾òÀ» ¼ö ÀÖ´Ù.

True Speech Player 1.1b

Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio)

VDOLive

Windows, ip_masq_vdolive ÆÐÄ¡ Àû¿ë.

Worlds Chat 0.9a

Windows, Ŭ¶óÀ̾ðÆ®-¼­¹ö ¹æ½ÄÀÇ 3D äÆÃ ÇÁ·Î±×·¥.

°ÔÀÓ - LooseUDP ÆÐÄ¡¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº LooseUDP ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

Battle.net

µ¿ÀÛÀº ÇÏÁö¸¸, TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù. FSGS¿Í Bnetd ¼­¹ö´Â NAT¿Í Àß µ¿ÀÛÇϵµ·Ï ¸¸µé¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®¿¡ IPPORTFW¸¦ ÇÊ¿ä·Î ÇÑ´Ù.

BattleZone 1.4

LooseUDP ÆÐÄ¡¸¦ ÇÏ°í »õ·Î¿î NAT¿Í Àß µ¿ÀÛÇÏ´Â .DLLs from Activision¸¦ »ç¿ëÇÏ¸é µ¿ÀÛÇÑ´Ù.

Dark Reign 1.4

LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

Diablo

LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. DiabloÀÇ »õ·Î¿î ¹öÁ¯Àº TCP Æ÷Æ® 6112¿Í UDP Æ÷Æ® 6112¸¸À» »ç¿ëÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

Heavy Gear 2

LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

Quake I/II/III

¹Ù·Î ÀÛµ¿ÇÏÁö¸¸, ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö µÚÂÊ¿¡ Quake I/II/III Ç÷¹À̾ µÎ ¸í ÀÌ»ó ÀÖÀ» ¶§¿¡´Â ip_masq_quake ¸ðµâÀÌ ÇÊ¿äÇÏ´Ù. ¶Ç,, ÀÌ ¸ðµâÀº ±âº»ÀûÀ¸·Î´Â Quake I°ú QuakeWorld¸¸ Áö¿øÇÑ´Ù. Quake II¸¦ Áö¿øÇÏ°Ô Çϰųª ¼­¹ö¿¡ ±âº»À¸·Î Á¤ÇØÁø ÀÌ¿ÜÀÇ Æ÷Æ®·Î Á¢¼ÓÇϰíÀÚ ÇÒ ¶§¿¡´Â, rc.firewall-2.0.x ¿Í rc.firewall-2.2.x ÀÇ ¸ðµâ ¼³Ä¡ ¼½¼ÇÀ» ÂüÁ¶Ç϶ó.

StarCraft

LooseUDP ÆÐÄ¡¸¦ Çϰí TCP¿Í UDPÀÇ 6112¹ø Æ÷Æ®¸¦ ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ °ÔÀÓÀ» ½ÇÇàÇÏ·Á´Â ÄÄÇ»ÅÍ·Î Æ÷¿öµù(IPPORTFW)ÇØÁÖ¾î¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

WorldCraft

LooseUDP ÆÐÄ¡¸¦ ÇÏ¸é µ¿ÀÛÇÑ´Ù.

±×¿ÜÀÇ Å¬¶óÀÌ¾ðÆ®µé:

Linux net-acct package

Linux, ³×Æ®¿÷ °ü¸®-¾îÄ«¿îÆÃ °ü·Ã ÆÐŰÁö

NCSA Telnet 2.3.08

DOS, TELNET, FTP, PINGµîÀÌ Æ÷ÇÔµÈ ÆÐŰÁö

PC-anywhere for Windows

MS-Windows, TCP/IP¸¦ ÅëÇØ¼­ ¿ø°ÝÀ¸·Î PC¸¦ Á¦¾îÇÑ´Ù. ƯÁ¤ÇÑ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇÏÁö ¾ÊÀ¸¸é, Ŭ¶óÀÌ¾ðÆ®·Î´Â µ¿ÀÛÇÏÁö¸¸ È£½ºÆ®(¼­¹ö)·Î´Â µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

Socket Watch

NTP »ç¿ë - ³×Æ®¿÷ ½Ã°£Á¶Àý ÇÁ·ÎÅäÄÝ

µ¿ÀÛÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®:

All H.323 programs

- MS Netmeeting, Intel Internet Phone Beta 2 - ¿¬°áÀº µÇÁö¸¸ ¸ñ¼Ò¸®´Â ÇÑÂÊÀ¸·Î¸¸(³ª°¡´Â ÂÊ) Àü´ÞµÈ´Ù. À̸¦ ÇØ°á °¡´ÉÇÑ ¹æ¹ýÀ¸·Î½á, Equivalence's PhonePatch H.323 gateway¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.

Intel Streaming Media Viewer Beta 1

¼­¹ö¿¡ ¿¬°áÇÒ ¼ö ¾ø´Ù.

Netscape CoolTalk

»ó´ëÆí¿¡ ¿¬°áÇÒ ¼ö ¾ø´Ù.

WebPhone

ÇöÀç´Â µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. (ÀÌ ÀÀ¿ëÇÁ·Î±×·¥Àº IP ÁÖ¼Ò¿¡ ´ëÇÑ À߸øµÈ °¡Á¤À» ÇÑ´Ù.)

6.4 º¸¾È °­µµ°¡ º¸´Ù ³ôÀº IP ¹æÈ­º®(IPFWADM) Á¤Ã¥

ÀÌ ¼½¼Ç¿¡´Â Ä¿³Î 2.0.x¿¡¼­ »ç¿ëµÇ´Â ¹æÈ­º® µµ±¸ÀÎ IPFWADM¿¡ ´ëÇÑ ´õ ½Éµµ ÀÖ´Â ¾È³»°¡ ½Ç·Á ÀÖ´Ù. IPCHAINS(2.2.x ¿ë)ÀÇ Á¤Ã¥µé¿¡ ´ëÇØ¼­´Â ´ÙÀ½ ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

ÀÌ ¿¹´Â ¹æÈ­º®/¸¶½ºÄ¿·¹ÀÌµå ½Ã½ºÅÛÀ» °íÁ¤ ÁÖ¼Ò¸¦ °¡Áø PPP Á¢¼ÓÀ» ÅëÇØ¼­ ±¸ÃàÇÏ´Â °ÍÀÌ´Ù.(µ¿Àû PPP¿¡ °üÇÑ °Íµµ Æ÷ÇԵǾî ÀÖÁö¸¸ ÄÚ¸àÆ® 󸮵Ǿî ÀÖ´Ù.) »ç¿ëµÈ ÀÎÅÍÆäÀ̽º´Â 192.168.0.1À̰í, PPP ÀÎÅÍÆäÀ̽ºÀÇ IP ÁÖ¼Ò´Â À߸øµÈ »ç¿ëÀ» ¿ì·ÁÇØ¼­ ½ÇÁ¦¿Í ´Ù¸¥ ÁÖ¼Ò·Î ´ëüµÇ¾ú´Ù :) IP ½ºÇªÇÎ(¼ÓÀÓ)°ú ºÎÁ¤ÀûÀÎ ¶ó¿ìÆÃÀ̳ª ¸¶½ºÄ¿·¹À̵ùÀ» °ËÃâÇϱâ À§Çؼ­ µé¾î¿À°í ³ª°¡´Â ÀÎÅÍÆäÀ̽º¸¦ µû·Î µû·Î Àû¾ú´Ù. ¸í½ÃÀûÀ¸·Î Çã¿ëµÇÁö ¾ÊÀº °ÍÀº ±ÝÁöµÇ¾î ÀÖ´Ù (½ÇÁ¦ÀûÀ¸·Î´Â °ÅºÎµÈ´Ù). ¿©±â¿¡ ³ª¿Â rc.firewall ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ°í ³ª¼­ IP ¸¶½ºÄ¿·¹ÀÌµå ¹Ú½º°¡ Á״´ٸé, ¿©·¯ºÐÀÇ »óȲ¿¡ ¸Âµµ·Ï ÆíÁýÀ» Çß´ÂÁö¸¦ È®ÀÎÇϰí, /var/log/messages³ª /var/adm/messagesÀÇ ½Ã½ºÅÛ ·Î±×È­ÀÏÀ» °ËÅäÇÑ´Ù.

PPP, ÄÉÀ̺í¸ðµ© µî¿¡ ´ëÇØ¼­ Á»´õ ÀÌÇØÇϱ⠽¬¿î, "°­µµ ³ôÀº IP ¸¶½ºÄ¿·¹À̵ùÀÇ IPFWADM Á¤Ã¥"¿¡ ´ëÇØ¼­´Â, TrinityOS - Section 10¿Í GreatCircle's Firewall WWW page¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.

ÁÖÀÇ: ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ© µî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Ò´Ù¸é ºÎÆÃ½Ã¿¡ ÀÌ "°­µµ ³ôÀº" Á¤Ã¥À» ·ÎµåÇÒ ¼ö ¾ø´Ù. µ¿ÀûÀ¸·Î IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÀ» ¶§¸¶´Ù ¹æÈ­º® Á¤Ã¥È­ÀÏÀ» ´Ù½Ã ·ÎµåÇϰųª, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. PPP À¯ÀúÀÇ °æ¿ì¿¡´Â, "Dynamic PPP IP fetch" ºÎºÐÀ» ÁÖÀÇ ±í°Ô ´Ù½Ã ÀÐ¾î º¸°í¼­ ÀûÀýÇÑ ºÎºÐÀÇ ÄÚ¸ÇÆ®¸¦ ÇØÁ¦ÇØ ÁØ´Ù. °­µµ ³ôÀº ¹æÈ­º® Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ´õ ÀÚ¼¼ÇÑ »çÇ×Àº TrinityOS - Section 10 ¹®¼­¸¦ ÂüÁ¶ÇÑ´Ù.

¶ÇÇÑ ¸î°¡ÁöÀÇ GUI ¹æ½ÄÀÇ ¹æÈ­º® ¼³Á¤ µµ±¸°¡ ÀÖ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº FAQ ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

¸¶Áö¸·À¸·Î, °íÁ¤ PPP IP ÁÖ¼Ò¸¦ »ç¿ëÇϰí ÀÖ´Ù¸é, "ppp_ip = "your.static.PPP.address"" ¶ó°í µÇ¾î ÀÖ´Â ÁÙÀ» ¿©·¯ºÐÀÇ IP ÁÖ¼Ò¿¡ ¸Â°Ô ¹Ù²Û´Ù.

----------------------------------------------------------------

#!/bin/sh
#
# /etc/rc.d/rc.firewall: An example of a semi-STRONG IPFWADM firewall ruleset
#

PATH=/sbin:/bin:/usr/sbin:/usr/bin

# testing, wait a bit then clear all firewall rules.
# uncomment following lines if you want the firewall to automatically
# disable after 10 minutes.
# (sleep 600; \
# ipfwadm -I -f; \
# ipfwadm -I -p accept; \
# ipfwadm -O -f; \
# ipfwadm -O -p accept; \
# ipfwadm -F -f; \
# ipfwadm -F -p accept; \
# ) &

# Load all required IP MASQ modules
#
#   NOTE:  Only load the IP MASQ modules you need.  All current IP MASQ modules
#          are shown below but are commented from loading.

# Needed to initially load modules
#
/sbin/depmod -a

# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp

# Supports the masquerading of RealAudio over UDP.  Without this module,
#       RealAudio WILL function but in TCP mode.  This can cause a reduction
#       in sound quality
#
#/sbin/modprobe ip_masq_raudio

# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc


# Supports the masquerading of Quake and QuakeWorld by default.  This modules is
#   for for multiple users behind the Linux MASQ server.  If you are going to play
#   Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960


# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme

#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive


#CRITICAL:  Enable IP forwarding since it is disabled by default since
#
#           Redhat Users:  you may try changing the options in /etc/sysconfig/network from:
#
#                       FORWARD_IPV4=false
#                             to
#                       FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward


# Dynamic IP users:
#
#   If you get your IP address dynamically from SLIP, PPP, or DHCP, enable this following
#       option.  This enables dynamic-ip address hacking in IP MASQ, making the life
#       with Diald and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr


# Specify your Static IP address here.
#
#   If you have a DYNAMIC IP address, you need to make this ruleset understand your
#   IP address everytime you get a new IP.  To do this, enable the following one-line
#   script.  (Please note that the different single and double quote characters MATTER).
#
#   You will also need to either create the following link or have your existing
#   /etc/ppp/ip-up script run the /etc/rc.d/rc.firewall script.
#
#       ln -s /etc/rc.d/rc.firewall /etc/ppp/ip-up
#
#   If the /etc/ppp/ip-up file already exists, you should edit it and add a line
#   containing "/etc/rc.d/rc.firewall" near the end of the file.
#
#   If you aren't already aware, the /etc/ppp/ip-up script is always run when a PPP
#   connection comes up.  Because of this, we can make the ruleset go and get the
#   new PPP IP address and update the strong firewall ruleset.
#
#   PPP users:  If your Internet connect is via a PPP connection, the following
                one-line script will work fine.
#
#   DHCP users:  If you get your TCP/IP address via DHCP, you will need to replace
#                the word "ppp0" with the name of your external Internet connection
#               (eth0, eth1, etc).  It should be also noted that DHCP can change
#               IP addresses on you.  To fix this, users should configure their
#               DHCPc or DHCP client to re-run the firewall ruleset when their
#               DHCP lease is renewed.  For DHCPcd users, use the "-c" option.
#
#ppp_ip = "`/sbin/ifconfig ppp0 | grep 'inet addr' | awk '{print $2}' | sed -e 's/.*://'`"
#
ppp_ip = "your.static.PPP.address"


# MASQ timeouts
#
#   2 hrs timeout for TCP session timeouts
#  10 sec timeout for traffic after the TCP/IP "FIN" packet is received
#  60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself)
#
/sbin/ipfwadm -M -s 7200 10 60


#############################################################################
# Incoming, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -I -f
/sbin/ipfwadm -I -p reject

# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0

# remote interface, claiming to be local machines, IP spoofing, get lost
#
/sbin/ipfwadm -I -a reject -V $ppp_ip -S 192.168.0.0/24 -D 0.0.0.0/0 -o

# remote interface, any source, going to permanent PPP address is valid
#
/sbin/ipfwadm -I -a accept -V $ppp_ip -S 0.0.0.0/0 -D $ppp_ip/32

# loopback interface is valid.
#
/sbin/ipfwadm -I -a accept -V 127.0.0.1 -S 0.0.0.0/0 -D 0.0.0.0/0

# catch all rule, all other incoming is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -I -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o


#############################################################################
# Outgoing, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -O -f
/sbin/ipfwadm -O -p reject

# local interface, any source going to local net is valid
#
/sbin/ipfwadm -O -a accept -V 192.168.0.1 -S 0.0.0.0/0 -D 192.168.0.0/24

# outgoing to local net on remote interface, stuffed routing, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 0.0.0.0/0 -D 192.168.0.0/24 -o

# outgoing from local net on remote interface, stuffed masquerading, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 192.168.0.0/24 -D 0.0.0.0/0 -o

# outgoing from local net on remote interface, stuffed masquerading, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 0.0.0.0/0 -D 192.168.0.0/24 -o

# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip /32 -D 0.0.0.0/0

# loopback interface is valid.
#
/sbin/ipfwadm -O -a accept -V 127.0.0.1 -S 0.0.0.0/0 -D 0.0.0.0/0

# catch all rule, all other outgoing is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -O -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o


#############################################################################
# Forwarding, flush and set default policy of deny. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -F -f
/sbin/ipfwadm -F -p deny

# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0
#
# catch all rule, all other forwarding is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -F -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o

IPFWADMÀ» »ç¿ëÇϸé, ¿©·¯ºÐÀº -I, -O, -F µîÀÇ ¿É¼ÇÀ» ÀÌ¿ëÇØ¼­ ƯÁ¤ »çÀÌÆ®·ÎÀÇ Á¢±ÙÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. °¢ Á¤Ã¥ ¸í·ÉµéÀº À§¿¡¼­ºÎÅÍ ¾Æ·¡·Î ÀÐÇôÁö°í, "-a" ´Â ±âÁ¸ÀÇ Á¤Ã¥¿¡ "µ¡ºÙÀδÙ"´Â °ÍÀ» À¯³äÇÑ´Ù. ±×·¯¹Ç·Î, ƯÁ¤ÇÑ Á¦ÇÑ »çÇ×Àº Àü¹ÝÀûÀÎ Á¤Ã¥º¸´Ù ¾Õ¿¡ ¿Í¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é:

-I ¸¦ »ç¿ëÇϸé, °¡Àå ºü¸£Áö¸¸ Á¦ÇÑ »çÇ×Àº ³»ºÎÀÇ ÄÄÇ»Å͵鿡°Ô¸¸ Àû¿ëµÈ´Ù. ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚü´Â ¿©ÀüÈ÷ "±ÝÁöµÈ" »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù. ¹°·Ð ¿©·¯ºÐÀº À̰͵éÀ» Á¶ÇÕÇØ¼­ »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.

/etc/rc.d/rc.firewall Á¤Ã¥ È­ÀÏ Áß¿¡¼­:

... start of -I rules ...

# reject and log local interface, local machines going to 204.50.10.13
#
/sbin/ipfwadm -I -a reject -V 192.168.0.1 -S 192.168.0.0/24 -D 204.50.10.13/32 -o

# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0

... end of -I rules ...

-O ¸¦ »ç¿ëÇϸé, ÆÐŶµéÀÌ ¸¶½ºÄ¿·¹À̵ùÀ» ¸ÕÀú Åë°úÇϱ⠶§¹®¿¡ ¼Óµµ´Â °¡Àå ´À¸®Áö¸¸, ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚüµµ ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ¾ø´Ù.

... start of -O rules ...

# reject and log outgoing to 204.50.10.13
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S $ppp_ip/32 -D 204.50.10.13/32 -o

# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip/32 -D 0.0.0.0/0

... end of -O rules ...

-F ¸¦ »ç¿ëÇϸé, -I ¸¦ »ç¿ëÇÑ °Íº¸´Ù´Â Á¶±Ý ´õ ´À¸®°í ¿ª½Ã ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â (³»ºÎÀÇ) ÄÄÇ»Å͵鸸 Á¦ÇÑÇÏ°í ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚü´Â ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù.

... start of -F rules ...

# Reject and log from local net on PPP interface to 204.50.10.13.
#
/sbin/ipfwadm -F -a reject -W ppp0 -S 192.168.0.0/24 -D 204.50.10.13/32 -o

# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0

... end of -F rules ...

192.168.0.0/24°¡ 204.50.11.0·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇϱâ À§ÇØ Æ¯º°ÇÑ Á¤Ã¥ÀÌ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. Àü¹ÝÀûÀÎ Á¤Ã¥¿¡ Æ÷ÇԵǾî Àֱ⠶§¹®ÀÌ´Ù.

À§ÀÇ Á¤Ã¥È­ÀÏ¿¡¼­ ÀÎÅÍÆäÀ̽º¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀº ¿©·¯°¡Áö°¡ ÀÖÀ» ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î¼­, "-V 192.168.255.1" ´ë½Å¿¡ "-W eth0"¶ó°í ÀûÀ» ¼ö ÀÖ°í, "-V $ppp_ip" ´ë½Å¿¡ "-W ppp0"¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù. "-V" ¸¦ »ç¿ëÇÏ´Â °ÍÀº IPCHAINS¿ÍÀÇ È£È¯À» À§Çؼ­ »ç¿ëµÈ °ÍÀ̰í, IPFWADM¸¸À» »ç¿ëÇÑ´Ù¸é ÀüÀûÀ¸·Î »ç¿ëÀÚÀÇ ¼±ÅÃÀÌ´Ù.

6.5 º¸¾È °­µµ°¡ º¸´Ù ³ôÀº IP ¹æÈ­º®(IPCHAINS) Á¤Ã¥

ÀÌ ¼½¼Ç¿¡´Â Ä¿³Î 2.2.x¿¡¼­ »ç¿ëµÇ´Â ¹æÈ­º® µµ±¸ÀÎ IPCHAINS¿¡ ´ëÇÑ ´õ ½Éµµ ÀÖ´Â ¾È³»°¡ ½Ç·Á ÀÖ´Ù. IPFWADM(2.0.x ¿ë)ÀÇ Á¤Ã¥µé¿¡ ´ëÇØ¼­´Â ÀÌÀü ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

ÀÌ ¿¹´Â ¹æÈ­º®/¸¶½ºÄ¿·¹ÀÌµå ½Ã½ºÅÛÀ» °íÁ¤ ÁÖ¼Ò¸¦ °¡Áø PPP Á¢¼ÓÀ» ÅëÇØ¼­ ±¸ÃàÇÏ´Â °ÍÀÌ´Ù.(µ¿Àû PPP¿¡ °üÇÑ °Íµµ Æ÷ÇԵǾî ÀÖÁö¸¸ ÄÚ¸àÆ® 󸮵Ǿî ÀÖ´Ù.) »ç¿ëµÈ ÀÎ>ÅÍÆäÀ̽º´Â 192.168.0.1À̰í, PPP ÀÎÅÍÆäÀ̽ºÀÇ IP ÁÖ¼Ò´Â À߸øµÈ »ç¿ëÀ» ¿ì·ÁÇØ¼­ ½ÇÁ¦¿Í ´Ù¸¥ ÁÖ¼Ò·Î ´ëüµÇ¾ú´Ù :) IP ½ºÇªÇÎ(¼ÓÀÓ)°ú ºÎÁ¤ÀûÀÎ ¶ó¿ìÆÃÀ̳ª ¸¶½ºÄ¿·¹À̵ùÀ» °ËÃâÇϱâ À§Çؼ­ µé¾î¿À°í ³ª°¡´Â ÀÎÅÍÆäÀ̽º¸¦ µû·Î µû·Î Àû¾ú´Ù. ¸í½ÃÀûÀ¸·Î Çã¿ëµÇÁö ¾ÊÀº °ÍÀº ±ÝÁöµÇ¾î ÀÖ´Ù (½ÇÁ¦ÀûÀ¸·Î´Â °ÅºÎµÈ´Ù). ¿©±â¿¡ ³ª¿Â rc.firewall ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ°í ³ª¼­ IP ¸¶½ºÄ¿·¹ÀÌµå ¹Ú½º°¡ Á״´ٸé, ¿©·¯ºÐÀÇ >»óȲ¿¡ ¸Âµµ·Ï ÆíÁýÀ» Çß´ÂÁö¸¦ È®ÀÎÇϰí, /var/log/messages³ª /var/adm/messagesÀÇ ½Ã½ºÅÛ ·Î±×È­ÀÏÀ» °ËÅäÇÑ´Ù.

PPP, ÄÉÀ̺í¸ðµ© µî¿¡ ´ëÇØ¼­ Á»´õ ÀÌÇØÇϱ⠽¬¿î, "°­µµ ³ôÀº IP ¸¶½ºÄ¿·¹À̵ùÀÇ IPFWADM Á¤Ã¥"¿¡ ´ëÇØ¼­´Â, TrinityOS - Section 10¿Í GreatCircle's Firewall WWW page¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.

ÁÖÀÇ #1: 2.2.11º¸´Ù ¹öÁ¯ÀÌ ³·Àº ¸®´ª½º 2.2.x Ä¿³ÎÀº IPCHAINS fragmentation bug¸¦ °¡Áö°í ÀÖ´Ù. ÀÌ ¶§¹®¿¡, °­µµ ³ôÀº IPCHAINS Á¤Ã¥À» »ç¿ëÇÏ¸é °ø°Ý¿¡ ³ëÃâµÇ°Ô µÈ´Ù. ¹ö±×°¡ ¼öÁ¤µÈ Ä¿³Î·Î ¾÷±×·¹À̵åÇϱ⠹ٶõ´Ù.

ÁÖÀÇ #2: ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ© µî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Ò´Ù¸é ºÎÆÃ½Ã¿¡ ÀÌ "°­µµ ³ôÀº" Á¤Ã¥À» ·ÎµåÇÒ ¼ö ¾ø´Ù. µ¿ÀûÀ¸·Î IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÀ» ¶§¸¶´Ù ¹æÈ­º® Á¤Ã¥È­ÀÏÀ» ´Ù½Ã ·ÎµåÇϰųª, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. PPP À¯ÀúÀÇ °æ¿ì¿¡´Â, "Dynamic PPP IP fetch" >ºÎºÐÀ» ÁÖÀÇ ±í°Ô ´Ù½Ã ÀÐ¾î º¸°í¼­ ÀûÀýÇÑ ºÎºÐÀÇ ÄÚ¸ÇÆ®¸¦ ÇØÁ¦ÇØ ÁØ´Ù. °­µµ ³ôÀº ¹æÈ­º® Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ´õ ÀÚ¼¼ÇÑ »çÇ×Àº TrinityOS - Section 10 >¹®¼­¸¦ ÂüÁ¶ÇÑ´Ù.

¶ÇÇÑ ¸î°¡ÁöÀÇ GUI ¹æ½ÄÀÇ ¹æÈ­º® ¼³Á¤ µµ±¸°¡ ÀÖ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº FAQ ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

¸¶Áö¸·À¸·Î, °íÁ¤ PPP IP ÁÖ¼Ò¸¦ »ç¿ëÇϰí ÀÖ´Ù¸é, "ppp_ip = "your.static.PPP.address"" ¶ó°í µÇ¾î ÀÖ´Â ÁÙÀ» ¿©·¯ºÐÀÇ IP ÁÖ¼Ò¿¡ ¸Â°Ô ¹Ù²Û´Ù.

----------------------------------------------------------------


#!/bin/sh
#
# /etc/rc.d/rc.firewall: An example of a Semi-Strong IPCHAINS firewall ruleset.
#

PATH=/sbin:/bin:/usr/sbin:/usr/bin

# Load all required IP MASQ modules
#
#   NOTE:  Only load the IP MASQ modules you need.  All current IP MASQ modules
#          are shown below but are commented from loading.

# Needed to initially load modules
#
/sbin/depmod -a

# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp

# Supports the masquerading of RealAudio over UDP.  Without this module,
#       RealAudio WILL function but in TCP mode.  This can cause a reduction
#       in sound quality
#
/sbin/modprobe ip_masq_raudio

# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc


# Supports the masquerading of Quake and QuakeWorld by default.  This modules is
#   for for multiple users behind the Linux MASQ server.  If you are going to play
#   Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960


# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme

#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive


#CRITICAL:  Enable IP forwarding since it is disabled by default since
#
#           Redhat Users:  you may try changing the options in /etc/sysconfig/network from:
#
#                       FORWARD_IPV4=false
#                             to
#                       FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward


# Get the dynamic IP address assigned via DHCP
#
extip="`/sbin/ifconfig eth1 | grep 'inet addr' | awk '{print $2}' | sed -e 's/.*://'`"
extint="eth1"

# Assign the internal IP
intint="eth0"
intnet="192.168.1.0/24"


# MASQ timeouts
#
#   2 hrs timeout for TCP session timeouts
#  10 sec timeout for traffic after the TCP/IP "FIN" packet is received
#  60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself)
#
ipchains -M -S 7200 10 60

#############################################################################
# Incoming, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F input
ipchains -P input REJECT

# local interface, local machines, going anywhere is valid
#
ipchains -A input -i $intint -s $intnet -d 0.0.0.0/0 -j ACCEPT

# remote interface, claiming to be local machines, IP spoofing, get lost
#
ipchains -A input -i $extint -s $intnet -d 0.0.0.0/0 -l -j REJECT

# remote interface, any source, going to permanent PPP address is valid
#
ipchains -A input -i $extint -s 0.0.0.0/0 -d $extip/32 -j ACCEPT

# loopback interface is valid.
#
ipchains -A input -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT

# catch all rule, all other incoming is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A input -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT

#############################################################################
# Outgoing, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F output
ipchains -P output REJECT

# local interface, any source going to local net is valid
#
ipchains -A output -i $intint -s 0.0.0.0/0 -d $intnet -j ACCEPT

# outgoing to local net on remote interface, stuffed routing, deny
#
ipchains -A output -i $extint -s 0.0.0.0/0 -d $intnet -l -j REJECT

# outgoing from local net on remote interface, stuffed masquerading, deny
#
ipchains -A output -i $extint -s $intnet -d 0.0.0.0/0 -l -j REJECT

# anything else outgoing on remote interface is valid
#
ipchains -A output -i $extint -s $extip/32 -d 0.0.0.0/0 -j ACCEPT

# loopback interface is valid.
#
ipchains -A output -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT

# catch all rule, all other outgoing is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A output -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT

#############################################################################
# Forwarding, flush and set default policy of deny. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F forward
ipchains -P forward DENY

# Masquerade from local net on local interface to anywhere.
#
ipchains -A forward -i $extint -s $intnet -d 0.0.0.0/0 -j MASQ
#
# catch all rule, all other forwarding is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A forward -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT

IPCHAINS¸¦ »ç¿ëÇϸé, ¿©·¯ºÐÀº "input", "output", "forward" ±ÔÄ¢À» ÅëÇØ¼­ ƯÁ¤ »çÀÌÆ®¿ÍÀÇ Åë½ÅÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. °¢ Á¤Ã¥ ¸í·ÉµéÀº À§¿¡¼­ºÎÅÍ ¾Æ·¡·Î ÀÐÇôÁö°í, "-A" ´Â ±âÁ¸ÀÇ Á¤Ã¥¿¡ "µ¡ºÙÀδÙ"´Â °ÍÀ» À¯³äÇÑ´Ù. ±×·¯¹Ç·Î, ƯÁ¤ÇÑ Á¦ÇÑ »çÇ×Àº Àü¹ÝÀûÀÎ Á¤Ã¥º¸´Ù ¾Õ¿¡ ¿Í¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é:

"input" ±ÔÄ¢: °¡Àå ºü¸£Áö¸¸ Á¦ÇÑÀº ³»ºÎÀÇ ÄÄÇ»Å͵鿡°Ô¸¸ Àû¿ëµÈ´Ù. ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚü´Â ¿©ÀüÈ÷ "±ÝÁöµÈ" »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù. ¹°·Ð ¿©·¯ºÐÀº À̰͵éÀ» Á¶ÇÕÇØ¼­ »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.

/etc/rc.d/rc.firewall Á¤Ã¥ È­ÀÏ Áß¿¡¼­:

... start of "input" rules ...

# reject and log local interface, local machines going to 204.50.10.13
#
/sbin/ipfwadm -I -a reject -V 192.168.0.1 -S 192.168.0.0/24 -D 204.50.10.13/32 -o

# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0

... end of "input" rules ...

"output"À» »ç¿ëÇϸé, ÆÐŶµéÀÌ ¸¶½ºÄ¿·¹À̵ùÀ» ¸ÕÀú Åë°úÇϱ⠶§¹®¿¡ ¼Óµµ´Â °¡Àå ´À¸®Áö¸¸, ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚüµµ ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ¾ø´Ù.

... start of "output" rules ...

# reject and log outgoing to 204.50.10.13
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S $ppp_ip/32 -D 204.50.10.13/32 -o

# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip/32 -D 0.0.0.0/0

... end of "output" rules ...

"forward"¸¦ »ç¿ëÇϸé, "input"À» »ç¿ëÇÑ °Íº¸´Ù´Â Á¶±Ý ´õ ´À¸®°í ¿ª½Ã ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â (³»ºÎÀÇ) ÄÄÇ»Å͵鸸 Á¦ÇÑÇÏ°í ¹æÈ­º® ÄÄÇ»ÅÍ ÀÚü´Â ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù.

... start of "forward" rules ...

# Reject and log from local net on PPP interface to 204.50.10.13.
#
/sbin/ipfwadm -F -a reject -W ppp0 -S 192.168.0.0/24 -D 204.50.10.13/32 -o

# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0

... end of "forward" rules ...

192.168.0.0/24°¡ 204.50.11.0·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇϱâ À§ÇØ Æ¯º°ÇÑ Á¤Ã¥ÀÌ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. Àü¹ÝÀûÀÎ Á¤Ã¥¿¡ Æ÷ÇԵǾî Àֱ⠶§¹®ÀÌ´Ù.

IPFWADM¿Í´Â ´Ù¸£°Ô, À§ÀÇ Á¤Ã¥È­ÀÏ¿¡¼­ ÀÎÅÍÆäÀ̽º¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀº ¿ÀÁ÷ ÇѰ¡Áö »ÓÀÌ´Ù. IPCHAINS´Â "-i eth0" ¿É¼ÇÀ» »ç¿ëÇÑ´Ù. "-V"´Â IPFWADMÀÇ ¹æ¹ýÀ¸·Î IPCHAINS¿ÍÀÇ È£È¯À» À§Çؼ­ »ç¿ëµÈ °ÍÀ̰í, IPFWADM¸¸À» »ç¿ëÇÑ´Ù¸é ÀüÀûÀ¸·Î »ç¿ëÀÚÀÇ ¼±ÅÃÀÌ´Ù.

6.6 ¿©·¯°³ÀÇ ³»ºÎ ³×Æ®¿÷À» IP ¸¶½ºÄ¿·¹À̵ùÇÏ´Â ¹ý

¿©·¯°³ÀÇ ³»ºÎ ³×Æ®¿÷À» ¸¶½ºÄ¿·¹À̵ùÇÏ´Â °ÍÀÌ ¸Å¿ì °£´ÜÇÏ´Ù. ¿ì¼± ³»ºÎ¿Í ¿ÜºÎÀÇ ¸ðµç ³×Æ®¿÷ÀÌ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁö È®ÀÎÇØ¾ß ÇÑ´Ù. ±×·± ÈÄ¿¡ ³×Æ®¿÷ Æ®·¡ÇÈÀÌ ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»Å͵鿡°Ôµµ Àü´ÞµÇ°í ÀÎÅͳÝÀ¸·Î ¸¶½ºÄ¿·¹À̵ùµÇµµ·Ï ¸¸µé¾î¾ß ÇÑ´Ù.

´ÙÀ½À¸·Î, ³»ºÎÀÇ ÀÎÅÍÆäÀ̽º¿¡ ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ë°¡´ÉÇϵµ·Ï ÇØÁà¾ß ÇÑ´Ù. ÀÌ ¿¹´Â eth1 (192.168.0.1)¿Í eth2 (192.168.1.1)ÀÇ µÎ°³ÀÇ ³»ºÎ ÀÎÅÍÆäÀ̽º°¡ ¿ÜºÎ·Î ÇâÇÏ´Â eth0 ÀÎÅÍÆäÀ̽º·Î ¸¶½ºÄ¿·¹À̵ùµÇµµ·Ï ¼³Á¤ÇÏ´Â °ÍÀÌ´Ù. rc.firewall Á¤Ã¥È­ÀÏ¿¡ ´ÙÀ½ ³»¿ëÀ» Ãß°¡ÇÑ´Ù:

  • IPFWADMÀ» »ç¿ëÇÏ´Â 2.0.x Ä¿³Î¿ë
      #Enable internal interfaces to communication between each other
      /sbin/ipfwadm -F -a accept -V 192.168.0.1 -D 192.168.1.0/24
      /sbin/ipfwadm -F -a accept -V 192.168.1.1 -D 192.168.0.0/24
    
      #Enable internal interfaces to MASQ out to the Internet
      /sbin/ipfwadm -F -a masq -W eth0 -S 192.168.0.0/24 -D 0.0.0.0/0
      /sbin/ipfwadm -F -a masq -W eth0 -S 192.168.1.0/24 -D 0.0.0.0/0
    

  • IPCHAINS¸¦ »ç¿ëÇÏ´Â 2.2.x Ä¿³Î¿ë
      #Enable internal interfaces to communication between each other
      /sbin/ipchains -A forward -i eth1 -d 192.168.1.0/24
      /sbin/ipchains -A forward -i eth2 -d 192.168.0.0/24
    
      #Enable internal interfaces to MASQ out to the Internet
      /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.0.0/24 -d 0.0.0.0/0
      /sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.1.0/24 -d 0.0.0.0/0
    

6.7 IP ¸¶½ºÄ¿·¹À̵å¿Í ÀüÈ­ Á¢¼Ó

  1. ÀÎÅͳݿ¡ ¿¬°áÇϱâ À§Çؼ­ ÀÚµ¿À¸·Î ÀüÈ­ Á¢¼ÓÀ» Çϵµ·Ï ¼³Á¤ÇϰíÀÚ ÇÑ´Ù¸é, Diald¸¦ »ç¿ëÇÑ ÀüÈ­°É±â³ª PPPdÀÇ »õ ¹öÁ¯À» »ç¿ëÇÏ´Â °ÍÀÌ ÁÁÀ» °ÍÀÌ´Ù. ±¸¼ºÀÌ ´õ ³ªÀº Diald¸¦ »ç¿ëÇÏ´Â °ÍÀ» ±ÇÀåÇÑ´Ù.

  2. Diald¸¦ ¼³Á¤Çϱâ À§Çؼ­´Â, Setting Up Diald for Linux Page³ª TrinityOS - Section 23¸¦ »ìÆìº¸±â ¹Ù¶õ´Ù.

  3. ÀÏ´Ü Diald¿Í IP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î ¼³Á¤µÇ°í ³ª¸é, ¸¶½ºÄ¿·¹À̵åµÇ´Â Ŭ¶óÀÌ¾ðÆ®µéÀÌ À¥À̳ª telnet, ftpµîÀÇ Á¢¼ÓÀ» ÇÏ·Á°í ÇÏ¸é ¸®´ª½º box°¡ ÀÚµ¿À¸·Î ÀÎÅÍ³Ý ¿¬°áÀ» ÇÒ °ÍÀÌ´Ù.

  4. óÀ½ Á¢¼Ó ¶§´Â ½Ã°£ Ãʰú°¡ ÀÖÀ» ¼öµµ Àִµ¥, ¾Æ³¯·Î±× ¸ðµ©À» »ç¿ëÇÑ´Ù¸é ¾î¿ ¼ö ¾ø´Ù. ¸ðµ© ÀÚüÀÇ Á¢¼Ó°ú PPP Á¢¼ÓÀ» À§ÇÑ ½Ã°£ ¶§¹®¿¡, Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥µé(À¥ ºê¶ó¿ìÀú µî)ÀÌ ½Ã°£ Ãʰú¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ÇÏÁö¸¸ ´Ã ±×·± °ÍÀº ¾Æ´Ï´Ù. ¸¸¾à ÀÌ·± Çö»óÀÌ ÀϾ¸é, ´ÜÁö Àç½Ãµµ(À̸¦Å׸é, À¥ ÆäÀÌÁö¸¦ ´Ù½Ã º¸±â)¸¦ ÇÏ¸é ±× ´ÙÀ½ºÎÅÍ´Â Àß µ¿ÀÛÇÒ °ÍÀÌ´Ù. ¶Ç´Â, echo "1" > /proc/sys/net/ipv4/ip_dynaddr¶ó°í Ä¿³Î¿¡ ¿É¼ÇÀ» Á־ ÀÌ·¯ÇÑ Ãʱ⠼³Á¤¿¡ °üÇÑ °ÍÀ» ÇØ°áÇÒ ¼öµµ ÀÖ´Ù.

6.8 IPPORTFW, IPMASQADM, IPAUTOFW, REDIR, UDPRED µî°ú ±âŸÀÇ Æ÷Æ® Æ÷¿öµù µµ±¸µé

IPPORTFW, IPAUTOFW, REDIR, UDPRED µî°ú ±âŸ ´Ù¸¥ ÇÁ·Î±×·¥µéÀº ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵带 À§ÇÑ ÀϹÝÀûÀº TCP¶Ç´Â UDP Æ÷Æ® Æ÷¿öµù µµ±¸µéÀÌ´Ù. ÀÌ·¯ÇÑ µµ±¸µéÀº ÀϹÝÀûÀ¸·Î, ÇöÀçÀÇ FTP, Quake µîÀ» À§ÇÑ Æ¯Á¤ÇÑ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµé°ú ÇÔ²² »ç¿ëµÇ°Å³ª ´ëÃ¼ÇØ¼­ »ç¿ëµÈ´Ù. Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇϸé, ÀÎÅͳÝÀ¸·ÎºÎÅÍ ¿À´Â Á¢¼ÓµéÀ», IP ¸¶½ºÄ¿·¹À̵ù µÚ¿¡¼­ ³»ºÎ ÁÖ¼Ò¸¸ °¡Áö°í ÀÖ´Â ÄÄÇ»ÅÍ·Î Àü´ÞÇØ ÁÙ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ Æ÷¿öµù ±â´ÉÀº TELNET, WWW, SMTP, FTP (Ưº°ÇÑ ÆÐÄ¡¸¦ ÇÊ¿ä·Î ÇÑ´Ù - ¾Æ·¡¸¦ º¼ °Í), ICQ ¿Í ´Ù¸¥ ¸¹Àº ³×Æ®¿÷ ÇÁ·ÎÅäÄݵéÀ» ó¸®ÇÒ ¼ö ÀÖ´Ù.

ÁÖÀÇ: ¸¸¾à IP ¸¶½ºÄ¿·¹À̵ù ¾øÀÌ ´ÜÁö Æ÷Æ® Æ÷¿öµù¸¸À» ÇÏ±æ ¿øÇÑ´Ù ÇØµµ, ¿©ÀüÈ÷ Ä¿³Î°ú IPFWADM³ª IPCHAINS Á¤Ã¥ ³»¿¡ IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» Ãß°¡ÇÏ°í¼­ ¸®´ª½ºÀÇ Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇØ¾ß ÇÑ´Ù.

±×·¯¸é À̰͵éÀÇ Â÷ÀÌ´Â ¹«¾ùÀΰ¡? IPAUTOFW, REDIR¿Í UDPRED(¸ðµç URLµéÀº 2.0.x-Requirements ¼½¼Ç¿¡ ÀÖ´Ù)µîÀº IP ¸¶½ºÄ¿·¹ÀÌµå »ç¿ëÀÚ°¡ ÀÌ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ­ ÇÊ¿äÇÑ ÃʱâÀÇ µµ±¸µéÀ̾ú´Ù. ½Ã°£ÀÌ È帣°í, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵尡 ¹ßÀüÇϸ鼭, ÀÌ µµ±¸µéÀº ´õ Áö´ÉÀûÀÎ ÇØ°áÃ¥ÀÎ IPPORTFW·Î ´ëüµÇ¾ú´Ù. »õ·Î¿î µµ±¸µéÀ» »ç¿ë°¡´ÉÇÏ°Ô µÇ¾ú±â ¶§¹®¿¡, IPQUTOFW¿Í REDIR¿Í °°Àº ¿¹ÀüÀÇ µµ±¸µéÀ» »ç¿ëÇÏ´Â °ÍÀº *¸Å¿ì ¹Ù¶÷Á÷ÇÏÁö ¾Ê´Ù*. À̵éÀº Ä¿³Î°ú ÇÔ²² Á¦´ë·Î µ¿ÀÛÇÏÁö ¸øÇϰųª ½ÉÁö¾î ¿©·¯ºÐÀÇ ¸®´ª½º ¼­¹ö¸¦ ÆÄ±«ÇÒ ¼öµµ ÀÖ´Ù.

2.0.x ¹öÁ¯ÀÇ IPPORTFW³ª 2.2.x ¹öÁ¯ÀÇ IPMASQADMÀ» IPPORTFW¿Í ÇÔ²² »ç¿ëÇϱâ Àü¿¡, ´Ù¸¥ Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇÏ¸é ³×Æ®¿÷ º¸¾È ¹®Á¦¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ±× ÀÌÀ¯´Â ÀÌ·¯ÇÑ µµ±¸µéÀº TCP/UDP Æ÷Æ®¸¦ Æ÷¿öµùÇϱâ À§Çؼ­ ±âº»ÀûÀ¸·Î ÆÐŶ ¹æÈ­º®¿¡ ±¸¸ÛÀ» ¸¸µé±â ¶§¹®ÀÌ´Ù. À̰ÍÀÌ ¸®´ª½º ¸Ó½Å¿¡ À§ÇùÀ» ÁÖÁö´Â ¾ÊÁö¸¸, ÆÐŶÀÌ Æ÷¿öµùµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡°Ô´Â ¹®Á¦°¡ µÉ ¼öµµ ÀÖ´Ù. Å« ¹®Á¦´Â ¾Æ´ÏÁö¸¸, IPPORTFWÀÇ Á¦ÀÛÀÚÀÎ Steven ClarkeÀº ´ÙÀ½°ú °°ÀÌ ¸»ÇÑ´Ù:

        "ÇØ´çÇÏ´Â IPFWADM/IPCHAINS Á¤Ã¥¿¡ µé¾î¸Âµµ·Ï, Æ÷Æ® Æ÷¿öµùÀº 
        ¸¶½ºÄ¿·¹À̵ù ÇÔ¼ö¿¡¼­¸¸ ºÒ·ÁÁø´Ù. ¸¶½ºÄ¿·¹À̵ùÀº IP Æ÷¿öµùÀ¸·Î 
        È®ÀåµÈ´Ù. ±×·¡¼­, ipportfw´Â ÀԷ°ú ipfwadm Á¤Ã¥ ¸ðµÎ¿¡ µé¾î¸Â´Â 
        ÆÐŶ¸¸À» º¼ ¼ö ÀÖ´Ù."

ÀÌ·¯ÇÑ ÀÌÀ¯·Î, °­·ÂÇÑ ¹æÈ­º® Á¤Ã¥À» »ç¿ëÇÏ´Â °ÍÀÌ Áß¿äÇÏ´Ù. °­·ÂÇÑ ¹æÈ­º® Á¤Ã¥¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ °ÍÀº Strong-IPFWADM-Rulesets °ú Strong-IPCHAINS-Rulesets ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.

ÀÌÁ¦, IPPORTFW Æ÷¿öµùÀ» 2.0.x³ª 2.2.x Ä¿³Î¿¡ »ç¿ëÇϱâ À§Çؼ­´Â, ¸®´ª½º Ä¿³ÎÀÌ IPPORTFW¸¦ Áö¿øÇϵµ·Ï ÀçÄÄÆÄÀÏÇØ¾ß ÇÑ´Ù.

  • 2.0.x Ä¿³Î »ç¿ëÀÚµéÀº ¾Æ·¡¿Í °°Àº °£´ÜÇÑ Ä¿³Î ¿É¼Ç ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù.
  • 2.2.x Ä¿³Î »ç¿ëÀÚµéÀº IPMASQADMÀ» ÅëÇØ¼­ ÀÌ¹Ì IPPORTFW Ä¿³Î ¿É¼ÇÀ» »ç¿ëÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù.

2.0.x Ä¿³Î¿¡¼­ IPPORTFW »ç¿ë

¿ì¼±, /usr/src/linux µð·ºÅ丮¿¡ °¡Àå ÃÖ½ÅÀÇ 2.0.x Ä¿³ÎÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇÑ´Ù. ¸¸¾à ¾ø´Ù¸é, Kernel-Compile ¼½¼Ç¿¡¼­ ÀÚ¼¼ÇÑ »çÇ×À» ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À¸·Î, 2.0.x-Requirements ¼½¼Ç¿¡¼­ "ipportfw.c" ÇÁ·Î±×·¥°ú "subs-patch-x.gz" Ä¿³Î ÆÐÄ¡¸¦ ´Ù¿î·ÎµåÇØ¼­ /usr/src/ µð·ºÅ丮¿¡ ¾ÐÃàÀ» Ǭ´Ù.

ÁÖÀÇ: "subs-patch-x.gz"ÀÇ È­ÀÏ¸í¿¡¼­ "x"´Â ±× »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ ¹öÁ¯À¸·Î ´ëÄ¡ÇÑ´Ù.

ÀÌÁ¦, IPPORTFW ÆÐÄ¡(subs-patch-x.gz)¸¦ ¸®´ª½º µð·ºÅ丮·Î º¹»çÇÑ´Ù.

        cp /usr/src/subs-patch-1.37.gz /usr/src/linux

´ÙÀ½¿¡, IPPORTFW Ä¿³Î ¿É¼ÇÀ» »ý¼ºÇϱâ À§Çؼ­ Ä¿³Î ÆÐÄ¡¸¦ ÇÑ´Ù:

        cd /usr/src/linux
        zcat subs-patch-1.3x.gz | patch -p1

´ÙÀ½À¸·Î, FTP Á¢¼ÓÀ» ³»ºÎÀÇ ¼­¹ö·Î Æ÷Æ® Æ÷¿öµùÇϰíÀÚ ÇÑ´Ù¸é, 2.0.x-Requirements ¼½¼Ç¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â »õ·Î¿î IP_MASQ_FTP ¸ðµâ ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº ÀÌ ¼½¼ÇÀÇ ³ªÁß ºÎºÐ¿¡ ³ª¿Í ÀÖ´Ù.

ÀÚ, Kernel-Compile ¼½¼Ç¿¡ ÀÖ´Â °Íó·³ Ä¿³ÎÀ» ÄÄÆÄÀÏÇÒ Â÷·ÊÀÌ´Ù. Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼­ IPPORTFW ¿É¼Ç¿¡ YES¶ó°í Çϵµ·Ï ÇÑ´Ù. ÀÏ´Ü ÄÄÆÄÀÏÀÌ ³¡³ª°í »õ·Î¿î Ä¿³Î·Î ¸®ºÎÆ®ÇÏ°í ³ª¸é, ´Ù½Ã ÀÌ ¼½¼ÇÀ¸·Î µ¹¾Æ¿Â´Ù.

ÀÌÁ¦ »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇØ¼­, ½ÇÁ¦ÀÇ "IPPORTFW" ÇÁ·Î±×·¥À» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇÑ´Ù.

        cd /usr/src
        gcc ipportfw.c -o ipportfw
        mv ipportfw /usr/local/sbin

ÀÌÁ¦, ¿¹¸¦ µé¾î¼­ ¸ðµç À¥ Á¢¼Ó(Æ÷Æ® 80)À» ¸¶½ºÄ¿·¹À̵åµÇ´Â ³»ºÎÀÇ ¸Ó½Å Áß¿¡¼­ 192.168.0.10À» ÁÖ¼Ò·Î °°Àº ¸Ó½ÅÀ¸·Î Æ÷¿öµåÇÏ·Á ÇÑ´Ù°í ÇÏÀÚ.

ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 80À» Æ÷Æ® Æ÷¿öµùÇϸé, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö´Â ±× Æ÷Æ®¸¦ ´õÀÌ»ó »ç¿ëÇÏÁö ¸øÇÑ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¿©·¯ºÐÀÌ ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡ ÀÌ¹Ì À¥ ¼­¹ö¸¦ ¿î¿µÇϰí ÀÖ°í Æ÷Æ® 80À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍ·Î Æ÷Æ® Æ÷¿öµùÇÑ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº IP ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡¼­ º¸³»´Â ÆäÀÌÁö°¡ ¾Æ´Ñ -³»ºÎÀÇ- À¥ ¼­¹ö¿¡¼­ º¸³»´Â ÆäÀÌÁö¸¦ º¼ °ÍÀÌ´Ù. À̸¦ ÇØ°áÇϱâ À§ÇÑ À¯ÀÏÇÑ ¹æ¹ýÀº ¿¹¸¦ µé¾î 8080°ú °°Àº ´Ù¸¥ Æ÷Æ®¸¦ ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÏ´Â °ÍÀÌ´Ù. ÀÌ·¸°Ô ÇÏ¸é µÇ±ä ÇÏÁö¸¸, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â À¥ ¼­¹ö¿¡ Á¢¼ÓÇϱâ À§Çؼ­ URL¿¡ :8080À» µ¡ºÙ¿©¾ß ÇÑ´Ù.

¾î·µç, Æ÷Æ® Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ­´Â, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ÆíÁýÇÑ´Ù. ´ÙÀ½¿¡ ÀÖ´Â ³»¿ëÀ» Ãß°¡ÇϵÇ, "$extip"´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.

ÁÖÀÇ: ¸¸¾à ¿©·¯ºÐÀÌ ISP ·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼­ »ç¿ëÇÑ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ´õ Áö´ÉÀûÀ¸·Î ¸¸µé¾î¾ß ÇÒ °ÍÀÌ´Ù. °­·ÂÇÑ Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù.

        /etc/rc.d/rc.firewall
        --

        #echo "Enabling IPPORTFW Redirection on the external LAN.."
        #
        /usr/local/sbin/ipportfw -C
        /usr/local/sbin/ipportfw -A -t$extip/80 -R 192.168.0.10/80

        --

ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!

¸¸¾à¿¡ "ipfwadm: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù.

FTP ¼­¹öÀÇ Æ÷Æ® Æ÷¿öµù:

FTP¸¦ ³»ºÎÀÇ ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇϰíÀÚ ÇÑ´Ù¸é, ÀÏÀÌ Á» ´õ º¹ÀâÇØÁø´Ù. ±× ÀÌÀ¯´Â Ç¥ÁØÀÇ IP_MASQ_FTP Ä¿³Î ¸ðµâÀÌ ÀÌ·¯ÇÑ ¸ñÀûÀ¸·Î ¸¸µé¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®ÀÌ´Ù. ´ÙÇàÈ÷ Fred Viles°¡ ÀÌ·¯ÇÑ ¸ñÀûÀ¸·Î µ¿ÀÛÇϵµ·Ï ¼öÁ¤µÈ IP_MASQ_FTP ¸ðµâÀ» ÀÛ¼ºÇß´Ù. Á¤È®È÷ ¹«¾ùÀÌ ¹®Á¦ÀÎÁö ¾Ë°í ½Í´Ù¸é, Fred°¡ ¹®¼­¸¦ ¸Å¿ì Àß ÀÛ¼ºÇØ ³õ¾ÒÀ¸´Ï ±×°ÍÀ» ´Ù¿î·ÎµåÇØ º¸±â ¹Ù¶õ´Ù. ÀÌ ÆÐÄ¡´Â ´Ù¼Ò ½ÇÇèÀûÀÎ ¸éÀÌ ÀÖ´Ù´Â °Íµµ ¾Ë¾ÆµÎ±â ¹Ù¶õ´Ù. ¶ÇÇÑ ÇöÀç ÀÌ ÆÐÄ¡´Â 2.0.x Ä¿³Î¿ë¿¡¼­¸¸ »ç¿ëÇÒ ¼ö ÀÖ´Ù´Â °Íµµ ¾Ë¾ÆµÎ±â ¹Ù¶õ´Ù. 2.2.x Ä¿³Î·ÎÀÇ Æ÷ÆÃµµ ¾î´À Á¤µµ ÀÌ·ç¾îÁ® ÀÖÁö¸¸, ¿©±â¿¡ µµ¿òÀ» ÁÖ°í ½Í´Ù¸é Fred Viles - fv@episupport.com·Î Á÷Á¢ À̸ÞÀÏÀ» º¸³»±â ¹Ù¶õ´Ù.

ÀÌÁ¦ ´ÙÀ½ °úÁ¤À» °ÅÃļ­ 2.0.x ÆÐÄ¡¸¦ ÇÑ´Ù:

  • ¿ì¼± ÀÌ ¼½¼ÇÀÇ ¾Õ ºÎºÐ¿¡ ÀÖ´Â °Í°ú °°ÀÌ IPPORTFW Ä¿³Î ÆÐÄ¡¸¦ °¡ÇÑ´Ù.

  • 2.0.x-Requirements ¼½¼Ç¿¡ ¼ö·ÏµÈ Fred VilesÀÇ FTP ¼­¹ö¿¡¼­ "msqsrv-patch-36"¸¦ ´Ù¿î·ÎµåÇϰí /usr/src/linux¿¡ ³Ö´Â´Ù.

  • "cat msqsrv-patch-36 | patch -p1"¶ó°í ¸í·ÉÇØ¼­ ÀÌ »õ·Î¿î ÄÚµå·Î Ä¿³ÎÀ» ÆÐÄ¡ÇÑ´Ù.

  • ÀÌÁ¦, ¿ø·¡ÀÇ "ip_masq_ftp.c" Ä¿³Î ¸ðµâÀ» »õ·Î¿î °ÍÀ¸·Î ´ëüÇÑ´Ù.

    • mv /usr/src/linux/net/ipv4/ip_masq_ftp.c /usr/src/linux/net/ipv4/ip_masq_ftp.c.orig
    • mv /usr/src/linux/ip_masq_ftp.c /usr/src/linux/net/ipv4/ip_masq_ftp.c

  • ¸¶Áö¸·À¸·Î »õ·Î¿î Äڵ尡 Àû¿ëµÈ Ä¿³ÎÀ» »ý¼ºÇؼ­ ÀνºÅçÇÑ´Ù.

´Ù µÆÀ¸¸é, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ÆíÁýÇØ¼­ ´ÙÀ½ ³»¿ëÀ» Ãß°¡Ç쵂 "$extip"´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.

ÁÖÀÇ: ¸¸¾à ¿©·¯ºÐÀÌ ISP ·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼­ »ç¿ëÇÑ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ´õ Áö´ÉÀûÀ¸·Î ¸¸µé¾î¾ß ÇÒ °ÍÀÌ´Ù. °­·ÂÇÑ Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù.

ÀÌ ¿¹´Â À§¿¡¼­¿Í °°ÀÌ ¸ðµç FTP Á¢¼Ó(Æ÷Æ® 21)À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½Å Áß 192.168.0.10ÀÇ ÁÖ¼Ò¸¦ °®´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÒ °ÍÀÌ´Ù.

ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 21À» Æ÷Æ® Æ÷¿öµùÇϸé, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö´Â ±× Æ÷Æ®¸¦ ´õ ÀÌ»ó »ç¿ëÇÏÁö ¸øÇÒ °ÍÀÌ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡ ÀÌ¹Ì FTP ¼­¹ö¸¦ ¿î¿µÇϰí ÀÖ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚÀÇ FTP Á¢¼ÓÀº IP ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö°¡ ¾Æ´Ï¶ó -³»ºÎÀÇ- FTP ¼­¹ö·Î °¥ °ÍÀÌ´Ù.

        /etc/rc.d/rc.firewall
        --

        #echo "Enabling IPPORTFW Redirection on the external LAN.."
        #
        /usr/local/sbin/ipportfw -C
        /usr/local/sbin/ipportfw -A -t$extip/21 -R 192.168.0.10/21

        --

ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!

¸¸¾à¿¡ "ipchains: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù. »õ·Î¿î Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖ´Â °ÍÀÌ È®½ÇÇÏ´Ù¸é, "ls /proc/net"À̶ó°í ¸í·ÉÇØ¼­ "ip_portfw" È­ÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é, Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼­ ¹«¾ùÀΰ¡ ºüÆ®·ÈÀ» °ÍÀÌ´Ù. Ä¿³ÎÀ» ´Ù½Ã ¸¸µç´Ù.

2.2.x Ä¿³Î¿¡¼­ IPPORTFW¿Í ÇÔ²² IPMASQADM »ç¿ë

¿ì¼±, /usr/src/linux µð·ºÅ丮¿¡ ÃÖ½ÅÀÇ 2.2.x Ä¿³ÎÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é, Kernel-Compile ¼½¼Ç¿¡¼­ ÀÚ¼¼ÇÑ »çÇ×À» ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À¸·Î, 2.2.x-Requirements ¼½¼Ç¿¡¼­ "ipmasqadm.c" ÇÁ·Î±×·¥À» ´Ù¿î·ÎµåÇØ¼­ /usr/src/ µð·ºÅ丮¿¡ ³Ö´Â´Ù.

´ÙÀ½À¸·Î, Kernel-Compile ¼½¼Ç¿¡ ÀÖ´Â °Í°ú °°ÀÌ 2.2.x Ä¿³ÎÀ» ÄÄÆÄÀÏÇØ¾ß ÇÑ´Ù. Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼­ IPPORTFW ¿É¼Ç¿¡ YES ¶ó°í ÇÑ´Ù. ÀÏ´Ü Ä¿³ÎÀ» ÄÄÆÄÀÏÇØ¼­ ¸®ºÎÆ®ÇÑ ÈÄ¿¡ ÀÌ ¼½¼ÇÀ¸·Î µ¹¾Æ¿Â´Ù.

ÀÌÁ¦, IPMASQADM µµ±¸¸¦ ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇÑ´Ù:

        cd /usr/src
        tar xzvf ipmasqadm-x.tgz
        cd ipmasqadm-x
        make
        make install

ÀÌÁ¦, ¿¹¸¦ µé¾î¼­ ¸ðµç À¥ Á¢¼Ó(Æ÷Æ® 80)À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½ÅÁß¿¡¼­ 192.168.0.10À» ÁÖ¼Ò·Î °®´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÑ´Ù°í ÇÏÀÚ.

ÁÖÀÇ: FTP Á¢¼ÓÀ» Æ÷Æ® Æ÷¿öµùÇϱâ À§Çؼ­ ¼öÁ¤µÈ IP_MASQ_FTP ¸ðµâÀÌ ÇöÀç·Î´Â 2.2.x Ä¿³Î¿¡¼­ µ¿ÀÛÇÏÁö ¾ÊÀ» Áöµµ ¸ð¸¥´Ù. ÇÏÁö¸¸ À̸¦ ½ÃÇèÇØ º¸°í ½Í´Ù¸é, ÀÌ ¸ðµâÀ» 2.2.x Ä¿³Î¿ëÀ¸·Î Æ÷ÆÃÇØ º¸¶ó. ±×¸®°í Ambrose ¿Í David¿¡°Ô ¿©·¯ºÐÀÇ °á°ú¹°À» ¸ÞÀÏ·Î º¸³» Áֱ⠹ٶõ´Ù.

ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 80À» Æ÷Æ® Æ÷¿öµùÇÏ°í ³ª¸é, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö´Â ±× Æ÷Æ®¸¦ »ç¿ëÇÏÁö ¸øÇÑ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿¡ ÀÌ¹Ì À¥ ¼­¹ö¸¦ ¿î¿µÇϰí ÀÖ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº ¿©·¯ºÐÀÇ IP ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö°¡ ¾Æ´Ñ -³»ºÎÀÇ- À¥ ¼­¹ö¿¡¼­ À¥ ÆäÀÌÁö¸¦ ¹Þ¾Æ º¼ °ÍÀÌ´Ù.

¾î·µç, Æ÷Æ® Æ÷¿öµùÀ» Çϱâ À§Çؼ­´Â /etc/rc.d/rc.firewall Á¤Ã¥ È­ÀÏÀ» ÆíÁýÇÑ´Ù. ´ÙÀ½ÀÇ ³»¿ëÀ» Ãß°¡ÇϵÇ, "$extip"¸¦ ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.

ÁÖÀÇ: ¸¸¾à ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼­ »ç¿ëÇϰí ÀÖ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. °­·ÂÇÑ ¹æÈ­º® Á¤Ã¥°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ׿¡ ´ëÇØ¼­´Â TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù. ¿©±â¿¡ ÈùÆ®¸¦ ÇѰ¡Áö Á¦°øÇÑ´Ù: PPP »ç¿ëÀÚµéÀ» À§ÇÑ /etc/ppp/ip-up È­ÀÏ.

        /etc/rc.d/rc.firewall
        --

        #echo "Enabling IPPORTFW Redirection on the external LAN.."
        #
        /usr/sbin/ipmasqadm portfw -f
        /usr/sbin/ipmasqadm portfw -a -P tcp -L $extip 80 -R 192.168.0.10 80

        --

ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥È­ÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!

¸¸¾à¿¡ "ipchains: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù. »õ·Î¿î Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖ´Â °ÍÀÌ È®½ÇÇÏ´Ù¸é, "ls /proc/net/ip_masq"¶ó°í ¸í·ÉÇØ¼­ "portfw" È­ÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é, Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼­ ¹«¾ùÀΰ¡ ºüÆ®·ÈÀ» °ÍÀÌ´Ù. Ä¿³ÎÀ» ´Ù½Ã ¸¸µç´Ù.

6.9 CU-SeeMe¿Í ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵å

¸®´ª½º IP ¸¶½ºÄ¿·¹À̵å´Â "ip_masq_cuseeme" Ä¿³Î ¸ðµâÀ» ÅëÇØ¼­ CuSeeme¸¦ Áö¿øÇÑ´Ù. ÀÌ Ä¿³Î ¸ðµâÀº /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¿¡¼­ ¸Þ¸ð¸®¿¡ ÀûÀçµÇ¾î¾ß ÇÑ´Ù. ÀÏ´Ü "ip_masq_cuseeme" ¸ðµâÀÏ ¼³Ä¡µÇ¸é, ¿ø°ÝÀÇ reflectorµéÀ̳ª »ç¿ëÀڵ鿡°Ô Á¢¼Ó ½ÅÈ£¸¦ º¸³»°Å³ª Á¢¼ÓÀ» ¹Þ¾ÆµéÀÏ ¼ö ÀÖ°Ô µÈ´Ù.

ÁÖÀÇ: CuSeeme¸¦ »ç¿ëÇϱâ À§Çؼ­´Â ¿¹ÀüÀÇ IPAUTOFW µµ±¸ ´ë½Å¿¡ IPPORTFW µµ±¸¸¦ »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù.

CuSeeme¸¦ ¼³Á¤ÇÏ´Â µ¥ À־ ´õ È®½ÇÇÑ Á¤º¸°¡ ÇÊ¿äÇÏ´Ù¸é, Michael Owings's CuSeeMe page¿¡¼­ ¹Ì´Ï-ÇÏ¿ìÅõ¸¦ º¸°Å³ª The IP Masquerade Resources¿¡¼­ ¹Ì´Ï-ÇÏ¿ìÅõÀÇ ¹Ì·¯ ÆäÀÌÁö¸¦ º¼ ¼ö ÀÖÀ» °ÍÀÌ´Ù.

6.10 Mirabilis ICQ

¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼­¹öÀÇ µÚ¿¡¼­ ICQ¸¦ »ç¿ëÇÏ´Â ¹æ¹ýÀº µÎ°¡Áö°¡ ÀÖ´Ù. ÇѰ¡Áö ¹æ¹ýÀº »õ·Î¿î ICQ ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» »ç¿ëÇÏ´Â °ÍÀ̰í, ´Ù¸¥ ÇѰ¡Áö´Â IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.

ICQ ¸ðµâÀº ¸î°¡Áö À̵æ°ú ÇÔ²² Á¦Çѵµ ÀÖ´Ù. ÀÌ ¸ðµâÀº °£´ÜÇÑ ¼³Á¤À¸·Î ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö µÚ¿¡¼­ ¿©·¯¸íÀÌ ICQ¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ICQ Ŭ¶óÀÌ¾ðÆ®¿¡¼­ Ưº°ÇÑ ¼³Á¤À» ÇÊ¿ä·Î ÇÏÁöµµ ¾Ê´Â´Ù. ±×·¯³ª, ÇöÀç´Â È­ÀÏ Àü¼Û°ú ½Ç½Ã°£ äÆÃÀÌ µÇÁö ¾Ê´Â´Ù.

IPPORTFW¸¦ ¼³Á¤Çؼ­ »ç¿ëÇϸé, ¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö¿Í ICQ Ŭ¶óÀÌ¾ðÆ® ¸ðµÎ¿¡ ¸î°¡Áö ¼³Á¤À» º¯°æ½ÃÄÑÁà¾ß ÇÏÁö¸¸, ICQÀÇ ¸Þ½ÃÁö ±â´É, URL ±â´É, äÆÃ, È­ÀÏ Àü¼Û µî ¸ðµç °ÍÀÌ µ¿ÀÛÇÒ °ÍÀÌ´Ù.

Andrew DeryabinÀÇ djsf@usa.net 2.2.x Ä¿³ÎÀ» À§ÇÑ ICQ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâ¿¡ °ü½ÉÀÌ ÀÖ´Ù¸é, 2.2.x-Requirements ¼½¼Ç¿¡¼­ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇϱ⠹ٶõ´Ù.

¸¶½ºÄ¿·¹ÀÌµå ¼­¹ö µÚ¿¡¼­ ICQ¸¦ »ç¿ëÇϱâ À§ÇØ ´Ù¼Ò °íÀüÀûÀÎ ¹æ¹ýÀ» ¾²±æ ¿øÇÑ´Ù¸é ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù:

  • ¿ì¼±, ¸®´ª½º Ä¿³Î¿¡ IPPORTFW ±â´ÉÀ» Æ÷ÇÔ½ÃŲ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.

    • ´ÙÀ½À¸·Î, ´ÙÀ½ÀÇ ³»¿ëÀ» /etc/rc.d/rc.firewall È­ÀÏ¿¡ Ãß°¡ÇÑ´Ù. ÀÌ ¿¹´Â ¿ÜºÎ·Î ÅëÇÏ´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ 10.1.2.3À¸·Î, ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ICQ Ŭ¶óÀÌ¾ðÆ®¸¦ 192.168.0.10À¸·Î °¡Á¤Çß´Ù:

      IPFWADMÀ» »ç¿ëÇÏ´Â 2.0.x Ä¿³ÎÀÇ ¿¹:

        µÎ°¡Áö ¿¹¸¦ Æ÷ÇÔ½ÃÄ×´Ù: ¾î¶² °ÍÀ̵ç Àß µ¿ÀÛÇÒ °ÍÀÌ´Ù:
      
        ¿¹ #1
        --
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2000 -R 192.168.0.10/2000
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2001 -R 192.168.0.10/2001
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2002 -R 192.168.0.10/2002
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2003 -R 192.168.0.10/2003
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2004 -R 192.168.0.10/2004
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2005 -R 192.168.0.10/2005
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2006 -R 192.168.0.10/2006
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2007 -R 192.168.0.10/2007
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2008 -R 192.168.0.10/2008
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2009 -R 192.168.0.10/2009
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2010 -R 192.168.0.10/2010
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2011 -R 192.168.0.10/2011
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2012 -R 192.168.0.10/2012
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2013 -R 192.168.0.10/2013
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2014 -R 192.168.0.10/2014
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2015 -R 192.168.0.10/2015
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2016 -R 192.168.0.10/2016
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2017 -R 192.168.0.10/2017
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2018 -R 192.168.0.10/2018
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2019 -R 192.168.0.10/2019
        /usr/local/sbin/ipportfw -A -t10.1.2.3/2020 -R 192.168.0.10/2020
        --
      
        ¿¹ #2
        --
        port=2000
        while [ $port -lt 2020 ]
          do
              /usr/local/sbin/ipportfw -A t10.1.2.3/$port