Linux IP Masquerade HOWTO
Linux IP Masquerade HOWTO
v1.79, 21 October 1999
ÀÌ ¹®¼´Â ¸®´ª½º È£½ºÆ®¿¡¼ IP ¸¶½ºÄ¿·¹À̵å¶ó´Â ±â´ÉÀ» »ç¿ëÇÏ´Â ¹æ¹ýÀ» ±â¼úÇϰí ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵å´Â Network Address Translation(NAT)ÀÇ ÇÑ ÇüÅ·Î, ¸®´ª½º box¿¡ ¿¬°áµÈ ÇѰ³ÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ ÅëÇØ¼ µî·ÏµÈ IP ÁÖ¼Ò°¡ ¾ø´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» ÀÌ¿ëÇϵµ·Ï ÇÏ´Â ±â´ÉÀÌ´Ù.
1.1 IP Masquerading(ÁÙ¿©¼ IP MASQ) ¿¡ ´ëÇÑ ¼Ò°³
(¿ªÀÚÁÖ: [ masquerade ] n, °¡Àå ¹«µµÈ¸, °¡Àå, ±¸½Ç [ masquerade ] v, °¡Àå ¹«µµ¸¦ ÇÏ´Ù, °¡ÀåÇÏ´Ù, üÇÏ´Ù)
ÀÌ ¹®¼´Â ¸®´ª½º È£½ºÆ®¿¡¼ IP ¸¶½ºÄ¿·¹À̵å¶ó´Â ±â´ÉÀ» »ç¿ëÇÏ´Â ¹æ¹ýÀ» ±â¼úÇϰí ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵å´Â Network Address Translation(NAT)ÀÇ ÇÑ ÇüÅ·Î, ¸®´ª½º box¿¡ ¿¬°áµÈ ÇѰ³ÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ ÅëÇØ¼ µî·ÏµÈ IP ÁÖ¼Ò°¡ ¾ø´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» ÀÌ¿ëÇϵµ·Ï ÇÏ´Â ±â´ÉÀÌ´Ù. ³»ºÎÀÇ ÄÄÇ»Å͵éÀº ÀÌ´õ³Ý(Ethernet), ÅäÅ« ¸µ(TokenRing), FDDI°°Àº LAN ¿¬°áÀ̳ª ´ÙÀ̾ó¾÷ PPP(¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ ÀüÈÁ¢¼Ó ³×Æ®¿öÅ·), ȤÀº SLIP °°Àº ¹æ¹ýÀ» ÅëÇØ¼ ¸®´ª½º È£½ºÆ®¿¡ ¿¬°áÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®¼´Â ÀÌ´õ³Ý(Ethernet)À» ÀÌ¿ëÇÏ´Â ¹æ¹ýÀ» ¿ì¼±ÀûÀ¸·Î ´Ù·é´Ù.
ÀÌ ¹®¼´Â IBM ȣȯ PC¿¡¼ 2.0.36ÀÌ»ó, 2.2.9ÀÌ»óÀÇ ¾ÈÁ¤ Ä¿³ÎÀ» »ç¿ëÇÏ´Â »ç¿ëÀÚµéÀ» À§Çؼ ¾²¿©Á³´Ù. 1.2.x ³ª 1.3.xÀÇ ¿À·¡µÈ Ä¿³ÎÀº ´Ù·çÁö ¾Ê°í, ¾î¶² ¹öÁ¯ÀÇ Ä¿³Î¿¡¼´Â À߸øµÈ °á°ú¸¦ ³¾ ¼öµµ ÀÖ´Ù. IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ ÀÌÀü¿¡ »õ·Î¿î ¾ÈÁ¤ Ä¿³Î·Î ¾÷±×·¹À̵åÇϱ⠹ٶõ´Ù.
IP ¸¶½ºÄ¿·¹À̵带 ¸ÅŲÅä½Ã¿¡¼ »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, Taro Fukunaga,
tarozax@earthlink.net ¿¡°Ô ¸ÞÀÏÀ» º¸³»¼ ÀÌ HOWTOÀÇ °£·«ÇÑ MkLinux¿ë ¹öÁ¯À» ¾ò±æ ¹Ù¶õ´Ù..
1.2 ¸Ó¸®¸», ÀÇ°ß ¹× °ø·Î
»õ·Î¿î »ç¿ëÀڵ鿡°Ô´Â ¸®´ª½º Ä¿³Î(1.2.x ÀÌÀü ¹öÁ¯ Æ÷ÇÔ)¿¡¼ IP Masq¸¦ ¼³Á¤ÇÏ´Â °ÍÀÌ ¸Å¿ì È¥µ¿½º·´´Ù. FAQ¿Í ¸ÞÀϸµ ¸®½ºÆ®°¡ ÀÖÁö¸¸, IP Masq¸¦ À§Çؼ ¾²¿©Áø ¹®¼´Â ¾ø¾ú´Ù. ±×¸®°í, ¸ÞÀϸµ ¸®½ºÆ®¿¡µµ IP Masq¸¦ À§ÇÑ HOWTO¸¦ ¿äûÇÏ´Â ±ÛÀÌ ÀÖ¾ú´Ù. ±×·¡¼, »õ·Î¿î »ç¿ëÀÚµéÀÌ Ãâ¹ßÁ¡À¸·Î »ïÀ» ¼ö ÀÖµµ·Ï ÀÌ HOWTO¸¦ ¾²±â·Î °áÁ¤Çß°í, ¼÷·ÃµÈ »ç¿ëÀÚµéÀÌ ÃßÈÄ¿¡ ´õ Ãß°¡ÇÒ ¼ö ÀÖ±æ ¹Ù¶õ´Ù. ÀÌ ¹®¼¿¡ ´ëÇØ ¾î¶² Á¾·ùÀÇ ¾ÆÀ̵ð¾î³ª, ¼öÁ¤»çÇ׵鵵 ȯ¿µÇÑ´Ù. ±×·¡¼ ÀÌ ¹®¼°¡ ´õ ÁÁÀº ¹®¼°¡ µÇ±æ ¹Ù¶õ´Ù.
ÀÌ ¹®¼´Â Ken EvesÀÇ FAQ¿Í IP ¸¶½ºÄ¿·¹ÀÌµå ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ¼ö¸¹Àº ¸Þ½ÃÁöµéÀ» Âü°íÇÏ¿© ¸¸µé¾îÁ³´Ù. ³»°¡ IP Masq¸¦ ¼³Á¤Çϴµ¥ µµ¿òÀ» ÁÖ°í, ¸¶Ä§³»´Â ÀÌ ¹®¼¸¦ ¾²´Âµ¥ ¿µ°¨À» ÁØ Mr. Matthew Driver ¿¡°Ô Ưº°ÇÑ °¨»ç¸¦ Ç¥ÇÑ´Ù. ÃÖ±Ù¿¡´Â David Ranch°¡ HOWTO¸¦ ÀçÀÛ¼ºÇßÀ¸¸ç ,HOWOT¿¡ ¸¹Àº sectionµéÀ» Ãß°¡ÇÏ¿© ÀÌ ¹®¼°¡ ´õ¿í ¿Ïº®ÇØ Áöµµ·Ï Çß´Ù.
¼öÁ¤ÇØ¾ß ÇÒ Á¡À̳ª, Á¤º¸, URL, ±âŸÀÇ ¾î¶°ÇÑ ÀǰßÀÌ¶óµµ ±âź¾øÀÌ
ambrose@writeme.com °ú
dranch@trinnet.net·Î º¸³»Áֱ⠹ٶõ´Ù. ¿©·¯ºÐÀÇ Âü¿©°¡ ÀÌ HOWTO¿¡ ¸¹Àº µµ¿òÀ» ÁÙ °ÍÀÌ´Ù.
ÀÌ HOWTO´Â ¿©·¯ºÐÀÌ °¡´ÉÇÑ ºü¸¥ ½Ã°£¾È¿¡ ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ³×Æ®¿÷À» ÀÛµ¿Çϵµ·Ï Çϴµ¥ µµ¿òÀ» ÁÙ Àǵµ·Î ¾²¿©Á³´Ù. Ambrose³ª David°¡ Á÷¾÷ÀûÀÎ ÀúÀÚ°¡ ¾Æ´Ï±â ¶§¹®¿¡, ¿©·¯ºÐÀº ÀÌ ¹®¼¿¡¼ ÀϹÝÀûÀÌÁö ¾Ê°Å³ª ¾ÖÃÊÀÇ ¸ñÀûÀÌ ¸ÂÁö ¾Ê´Â ³»¿ëÀ» ¹ß°ß ÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù. ÀÌ HOWTO¿¡ °üÇÑ ÃֽŠÁ¤º¸³ª ±âŸ IP ¸¶½ºÄ¿·¹À̵忡 °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº ¿ì¸®°¡ ÀÇ¿åÀûÀ¸·Î °ü¸®Çϰí ÀÖ´Â web page
IP Masquerade Resource ¿¡¼ ¾òÀ» ¼ö ÀÖ´Ù. ¿©·¯ºÐÀÌ IP ¸¶½ºÄ¿·¹À̵忡 ´ëÇØ¼ ±â¼úÀûÀÎ Àǹ®»çÇ×ÀÌ ÀÖ´Ù¸é, Amrose³ª David¿¡°Ô ¸ÞÀÏÀ» º¸³»´Â ´ë½Å¿¡ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ÞÀϸµ ¸®½ºÆ®¿¡ Âü°¡Çϱ⠹ٶõ´Ù. IP ¸¶½ºÄ¿·¹À̵忡 °üÇÑ ¸ðµç ¹®Á¦Á¡Àº ´ëºÎºÐÀÇ À¯Àúµé¿¡°Ô °øÅëµÈ °ÍÀ̰í, ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ´©±º°¡¿¡°Ô¼ °£´ÜÇÑ ´äÀ» ¾òÀ» ¼öµµ ÀÖÀ» °ÍÀÌ´Ù. µ¡ºÙ¿©¼, Ambrose³ª David·ÎºÎÅÍ ´äÀåÀ» ¹Þ´Â ½Ã°£º¸´Ù ¸ÞÀϸµ ¸®½ºÆ®·ÎºÎÅÍ ´äÀ» ¾ò´Â ½Ã°£ÀÌ ÈξÀ Àû°Ô °É¸± °ÍÀÌ´Ù.
ÀÌ ¹®¼ÀÇ ÃֽйöÁ¯Àº ´ÙÀ½ »çÀÌÆ®¿¡¼ ¾òÀ» ¼ö ÀÖ°í, ±×°÷¿¡¼ HTMLÀ̳ª postscript¹öÁ¯ÀÇ ¹®¼µµ ¾òÀ» ¼ö ÀÖ´Ù.
1.3 ÆÇ±Ç°ú Æ÷±â
ÀÌ ¹®¼´Â Ambrose Au¿Í David Ranch¿¡°Ô ÆÇ±ÇÀÌ ÀÖ°í, ÀÚÀ¯·Ó°Ô ÀÌ¿ë °¡´ÉÇÑ ¹®¼ÀÌ´Ù. ÀÌ ¹®¼´Â GNU General Public License¿¡ ÀÇÇØ¼ Àç ¹èÆ÷ÇÒ ¼ö ÀÖ´Ù.
This document is copyright(c) 1999 Ambrose Au and David Ranch and it is a FREE document. You may redistribute it under the terms of the GNU General Public License.
ÀÌ ¹®¼´Â Ambrose¿Í David°¡ ÃÖ¼±À» ´ÙÇÑ ¹®¼·Î¼, ¿Ç¹Ù¸¥ ³»¿ëÀ» ´ã°í ÀÖ´Ù. ±×·¯³ª, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀº »ç¶÷¿¡ ÀÇÇØ¼ °³¹ßµÈ °ÍÀ̹ǷÎ, ¶§¶§·Î ½Ç¼ö³ª ¹ö±×µîÀÌ ÀÖÀ» ¼ö ÀÖ´Ù.
ÀÌ ¹®¼¿¡ ¾²¿©Áø Á¤º¸¸¦ »ç¿ëÇØ¼ »ý±â´Â, ¿©·¯ºÐÀÇ ÄÄÇ»ÅÍÀÇ ¼Õ»óÀ̳ª ¾î¶°ÇÑ ¼Õ½Ç¿¡ ´ëÇØ¼µµ ¾Æ¹«µµ Ã¥ÀÓÀ» ÁöÁö ¾Ê´Â´Ù.
ÀÌ ¹®¼ÀÇ Á¤º¸¿¡ ÀÇÇØ ÇàÇØÁø ÇàÀ§ ¶§¹®¿¡ ¹ß»ýµÈ ¾î¶² ¼Õ»óµµ ÀúÀڴ åÀÓÁöÁö ¾Ê´Â´Ù.
No person, group, or other body is responsible for any damage on your computer(s) and any other losses by using the information on this document. i.e.
THE AUTHORS AND ALL MAINTAINERS ARE NOT RESPONSIBLE FOR ANY DAMAGES INCURRED DUE TO ACTIONS TAKEN BASED ON THE INFORMATION IN THIS DOCUMENT.
ÀÚ, ÀÌ »óÀÇ ³»¿ëÀ» ¼÷ÁöÇϰí... ½ÃÀÛÇØ º¸µµ·Ï ÇÏÀÚ..
2.1 IP ¸¶½ºÄ¿·¹À̵å¶õ ¹«¾ùÀΰ¡?
IP ¸¶½ºÄ¿·¹À̵å´Â ¸®´ª½ºÀÇ ³×Æ®¿öÅ· ±â´ÉÀ¸·Î, »ó¿ë ¹æÈº®(firewall)À̳ª ³×Æ®¿÷ ¶ó¿ìÅÍ(network router)¿¡¼ ÈçÈ÷ º¼ ¼ö ÀÖ´Â 1 ´ë ´Ù(one-to-many) ¹æ½ÄÀÇ NAT(Network Address Translation: ³×Æ®¿÷ ÁÖ¼Ò ÇØ¼®)¿Í À¯»çÇÏ´Ù. ¿¹À» µé¾î¼, ¾î¶² ¸®´ª½º È£½ºÆ®°¡ PPP(¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ ÀüÈÁ¢¼Ó ³×Æ®¿öÅ·¿¡ ÇØ´çÇÔ), ÀÌ´õ³Ý(Ethernet), ±âŸµîµîÀÇ ¹æ¹ýÀ¸·Î ÀÎÅͳݿ¡ ¿¬°áµÇ¾î ÀÖ´Ù¸é, ÀÌ ¸®´ª½º ¹Ú½º¿¡ ¿¬°áµÈ(PPP, Ethernet, ±âŸµîµî) ³»ºÎÀÇ ÄÄÇ»Å͵鵵 IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼ ÀÎÅͳݿ¡ ¿¬°áÇÒ ¼ö ÀÖ´Ù. ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵带 ÅëÇϸé, ³»ºÎÀÇ ÄÄÇ»Å͵éÀÌ °ø½ÄÀûÀ¸·Î ÇÒ´çµÈ IP ÁÖ¼Ò°¡ ¾ø´õ¶óµµ °¡´ÉÇÏ´Ù.
MASQ¸¦ »ç¿ëÇϸé, MASQ °ÔÀÌÆ®¿þÀÌ(gateway: Åë·Î°¡ µÇ´Â ÄÄÇ»ÅÍ)¸¦ ÅëÇØ¼ ¸î´ëÀÇ ÄÄÇ»Å͵éÀÌ ¼û¾î¼ ÀÎÅͳÝÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù. Áï, ÀÎÅͳݿ¡ ÀÖ´Â ´Ù¸¥ ÄÄÇ»Å͵鿡°Ô´Â, IP MASQ¸¦ ÅëÇØ¼ ¹Ù±ùÀ¸·Î ³ª¿À´Â Á¤º¸µéÀº IP MASQ Linux ¼¹ö ÀÚü°¡ º¸³»´Â °Íó·³ º¸ÀδÙ. ÀÌ·¯ÇÑ ±â´É¿¡ µ¡ºÙ¿©¼, IP ¸¶½ºÄ¿·¹À̵å´Â ´ë´ÜÈ÷ ¾ÈÀüÇÑ ³×Æ®¿÷ ȯ°æÀ» Á¦°øÇÑ´Ù. Àß ±¸¼ºµÈ ¸¶½ºÄ¿·¹À̵ù ½Ã½ºÅÛ°ú ³»ºÎ LANÀÇ º¸¾ÈÀ» ±ú´Â °ÍÀº, Àß ±¸¼ºµÈ ¹æÈº®ÀÇ º¸¾ÈÀ» ±ú´Â °Í ¸¸ÅÀ̳ª ¾î·Æ´Ù.
2.2 ÇöÀç »óȲ
IP ¸¶½ºÄ¿·¹À̵å´Â óÀ½ °³¹ßµÈÁö ¼ö³âÀÌ Áö³µ°í, ¸®´ª½º Ä¿³ÎÀÌ 2.2.x ·Î µé¾î¼¸é¼ ¸Å¿ì ¼º¼÷ÇØÁ³´Ù. ¸®´ª½º Ä¿³ÎÀº 1.3.x ¹öÁ¯ºÎÅÍ MASQ ±â´ÉÀ» ÀÚü Áö¿øÇß´Ù. ÇöÀç´Â ¼ö¸¹Àº °³ÀÎ, ¶Ç´Â »ó¾÷ ±â°üµéÀÌ ÈǸ¢ÇÏ°Ô »ç¿ëÇϰí ÀÖ´Ù.
À¥ ÆäÀÌÁö º¸±â, TELNET Á¢¼Ó, FTP, PING, TRACEROUTE, ±âŸµîµîÀÇ Åë»óÀûÀÎ ³×Æ®¿÷ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼ Àß ÀÛµ¿ÇÑ´Ù. FTP, IRC¿Í Real Audio¿Í °°Àº °Íµµ, ÀûÀýÇÑ IP MASQ ¸ðµâÀ» ÀûÀçÇϸé Àß ÀÛµ¿ÇÑ´Ù. MP3³ª Æ®·ç ½ºÇÇÄ¡(True Speech)µîÀÇ ½ºÆ®¸®¹Ö ¿Àµð¿À(streaming audio)¿Í °°Àº ³×Æ®¿÷ °ü·Ã ÇÁ·Î±×·¥µéµµ ¿ª½Ã ÀÛµ¿ÇÑ´Ù. ¸ÞÀϸµ ¸®½ºÆ®ÀÇ ¾î¶² µ¿·á »ç¿ëÀÚµéÀº È»óȸÀÇ ¼ÒÇÁÆ®¿þ¾î¿¡¼±îÁö ÁÁÀº °á°ú¸¦ ¾òÀº ¹Ù ÀÖ´Ù.
Áö¿øµÇ´Â Àüü ¼ÒÇÁÆ® ¿þ¾î ¸ñ·ÏÀº
Supported Client Software
section¿¡¼ È®ÀÎÇϱ⠹ٶõ´Ù.
IP ¸¶½ºÄ¿·¹À̵å´Â ¿©·¯°¡Áö ´Ù¸¥ OS¿Í Çϵå¿þ¾î Ç÷§ÆûÀ» »ç¿ëÇÏ´Â »ç¿ëÀÚ ÄÄÇ»Å͵é(client machines)¿¡°Ôµµ ¼¹ö·Î¼ Àß µ¿ÀÛÇÑ´Ù. MASQ ³»ºÎ¿¡¼ ¼º°øÀûÀ¸·Î µ¿ÀÛÇÑ ½Ã½ºÅÛµéÀº ´ÙÀ½°ú °°´Ù :
- Unix: Sun Solaris, *BSD, Linux, Digital UNIX, ±âŸµîµî
- Microsoft Windows 95/98, Windows NT¿Í Windows for Workgroups (TCP/IP ÆÐŰÁö°¡ ¼³Ä¡µÈ »óÅÂ)
- IBM OS/2
- MacTCP or Open Transport¸¦ »ç¿ëÇÏ´Â Apple Macintosh MacOS machineµé
- packet µå¶óÀ̹ö¿Í NCSA Telnet ÆÐŰÁö¸¦ »ç¿ëÇÏ´Â DOS ±â¹Ý ½Ã½ºÅÛ
- VAXen
- ¸®´ª½º³ª NT¸¦ »ç¿ëÇÏ´Â Compaq/Digital Alpha ½Ã½ºÅÛ
- AmiTCP ³ª AS225-stackÀ» »ç¿ëÇÏ´Â Amiga ÄÄÇ»ÅͱîÁö..
¸®½ºÆ®´Â ´õ °è¼ÓµÉ ¼ö ÀÖÁö¸¸ ¿äÁ¡Àº ´ÙÀ½°ú °°´Ù. TCP/IP·Î Åë½ÅÇÒ ¼ö ÀÖ´Â OS¸¦ »ç¿ëÇÑ´Ù¸é ¹Ýµå½Ã IP ¸¶½ºÄ¿·¹À̵å¿Í ÇÔ²² µ¿ÀÛÇÒ ¼ö ÀÖ¾î¾ß ÇÑ´Ù!
2.3 ´©°¡ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇØ¼ À̵æÀ» ¾ò´Â°¡?
- ´ç½ÅÀÌ ÀÎÅͳݿ¡ ¿¬°áµÈ ¸®´ª½º È£½ºÆ®¸¦ °¡Áö°í ÀÖ°í,
- TCP/IP°¡ ¼³Ä¡µÇ¾î ÀÖ°í ·ÎÄà ¼ºê³Ý(local subnet)À» ÅëÇØ¼ ¸®´ª½º È£½ºÆ®¿¡ ¿¬°áµÈ ÄÄÇ»ÅÍ ¸î´ë¸¦ °¡Áö°í Àְųª,
- ´ç½ÅÀÇ ¸®´ª½º È£½ºÆ®°¡ µÎ°³ ÀÌ»óÀÇ ¸ðµ©À» °¡Áö°í PPP³ª SLIP¼¹ö·Î µ¿ÀÛÇÏ¸é ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»Å͵é°ú ¿¬°áµÇ¾î ÀÖ°í,
- ±× ´Ù¸¥ ÄÄÇ»Å͵éÀÌ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÁö ¾Ê¾Ò´Ù¸é,
- ±×¸®°í ¹°·Ð, ISP·ÎºÎÅÍ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´ç¹Þ°í ¸®´ª½º¸¦ ¶ó¿ìÅÍ(router)·Î ¼³Á¤Çϰųª ¿ÜºÎ ¶ó¿ìÅ͸¦ ±¸ÀÔÇϴµîÀÇ Ãß°¡ºñ¿ëÀ» µéÀÌÁö ¾Ê°í ±× ´Ù¸¥ ÄÄÇ»Å͵éÀÌ ÀÎÅͳÝÀ» »ç¿ëÇϵµ·Ï ÇÏ°í ½Í´Ù¸é.
2.4 ´©±¸¿¡°Ô IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿ä ¾ø´Â°¡?
- ´ç½ÅÀÇ ÄÄÇ»ÅͰ¡ ´Üµ¶À¸·Î ¼³Ä¡µÇ¾î ÀÖ°í ÀÎÅͳݿ¡ ¿¬°áµÇ¾î Àְųª (±×·¯³ª ´Üµ¶À¸·Î Á¸ÀçÇÏ´õ¶óµµ ¹æÈº®À» ¼³Á¤ÇÏ´Â °ÍÀº ÁÁÀº »ý°¢ÀÏ ¼ö ÀÖ´Ù),
- ´Ù¸¥ ÄÄÇ»Å͵éÀ» À§Çؼ ÇÒ´çµÈ ¿©·¯°³ÀÇ IP ÁÖ¼Ò¸¦ °¡Áö°í ÀÖ´Ù¸é,
- ±×¸®°í ¹°·Ð, ´ç½ÅÀÌ ¸®´ª½ºÀ» »ç¿ëÇÏ´Â '¹«ÀÓ ½ÂÂ÷'¶ó´Â °ÍÀ» ÁÁ¾ÆÇÏÁö ¾Ê°í, ¿ÀÈ÷·Á °°Àº ÀÏÀ» Çϱâ À§ÇØ ºñ½Ñ ´ë°¡¸¦ ÁöºÒÇÏ´Â °ÍÀ» ´õ ÆíÇÏ°Ô »ý°¢ÇÑ´Ù¸é.
2.5 IP ¸¶½ºÄ¿·¹À̵å´Â ¾î¶»°Ô µ¿ÀÛÇϴ°¡?
>Ken EvesÀÇ IP ¸¶½ºÄ¿·¹À̵å FAQ·ÎºÎÅÍ :
°¡Àå °£´ÜÇÑ ¼³Ä¡ÀÇ ¿¹´Â ´ÙÀ½ ±×¸²°ú °°´Ù:
SLIP/PPP +------------+ +-------------+
ISP Á¦°øÀÚ·Î | Linux | SLIP/PPP | ´Ù¸¥ ÄÄÇ»ÅÍ |
<---------- modem1| #1 |modem2 ----------- modem3| |
111.222.333.444 | | 192.168.0.100 | |
+------------+ +-------------+
À§ÀÇ ±×¸²¿¡¼, IP_MASQUERADINGÀÌ ¼³Ä¡µÈ ¸®´ª½º box°¡ Linux #1À¸·Î ¼³Á¤µÇ¾î
ÀÖ°í modem1À» ÅëÇÑ SLIP ȤÀº PPP·Î ÀÎÅͳݿ¡ ¿¬°áµÇ¾î ÀÖ´Ù. Linux #1Àº
111.222.333.444¶ó´Â IP ÁÖ¼Ò°¡ ÇÒ´çµÇ¾î ÀÖ´Ù. Linux #1Àº modom2¸¦ ÅëÇØ¼ ´Ù¸¥
ÄÄÇ»ÅͰ¡ SLIP ȤÀº PPP·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï µÇ¾î ÀÖ´Ù.
µÎ¹øÂ° ½Ã½ºÅÛ(´Ù¸¥ ÄÄÇ»ÅÍ: ¹Ýµå½Ã ¸®´ª½º¸¦ »ç¿ëÇÒ ÇÊ¿ä´Â ¾ø´Ù) Linux #1À¸·Î
SLIP ȤÀº PPP Á¢¼ÓÀ» ÇÑ´Ù. ´Ù¸¥ ÄÄÇ»ÅÍ´Â °ø½ÄÀûÀ¸·Î ÇÒ´çµÈ IP ÁÖ¼Ò¸¦ °¡Áö°í
ÀÖÁö ¾Ê´Ù. ±×·¡¼ ³»ºÎ ÁÖ¼ÒÀÎ 192.168.0.100À̶ó´Â ÁÖ¼Ò°¡ ÇÒ´çµÇ¾î ÀÖ´Ù.
(¾Æ·¡ ÂüÁ¶)
¶ó¿ìÆÃ Á¤º¸°¡ Á¦´ë·Î ¼³Á¤µÇ¾î ÀÖÀ¸¸é IP ¸¶½ºÄ¿·¹À̵带 ÅëÇØ¼ "´Ù¸¥ ÄÄÇ»ÅÍ"´Â
¸¶Ä¡ ÀÎÅͳݿ¡ Á÷Á¢ ¿¬°áµÇ¾î ÀÖ´Â °Íó·³(¸î°¡Áö¸¦ Á¦¿ÜÇϰí) ÀÎÅͳÝÀ» »ç¿ë
ÇÒ ¼ö ÀÖ´Ù.
Pauline Middelink¿¡ ÀÇÇϸé:
"´Ù¸¥ ÄÄÇ»ÅÍ"´Â Linux #1À» °ÔÀÌÆ®¿þÀÌ(gateway)·Î ¼³Á¤ÇØ¾ß ÇÑ´Ù´Â »ç½ÇÀ» ÀØÁö
¸»¾Æ¾ß ÇÑ´Ù(±âº» ¶ó¿ìÅÍ(default route)Àΰ¡ ´ÜÁö ¼ºê³Ý(subnet)Àΰ¡´Â »ó°ü¾ø´Ù.)
¸¸¾à "´Ù¸¥ ÄÄÇ»ÅÍ"°¡ Linux #1À» °ÔÀÌÆ®¿þÀÌ·Î ¼³Á¤ÇÏÁö ¾Ê´Â´Ù¸é, Linux #1Àº
proxy arp¸¦ Áö¿øÇϵµ·Ï ¼³Á¤µÇ¾î¾ß Çϴµ¥, proxy arp¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼ÀÇ
¹üÁÖ¸¦ ¹þ¾î³ª´Â ³»¿ëÀÌ´Ù.
´ÙÀ½Àº comp.os.linux.networking¿¡ Æ÷½ºÆÃµÈ ±Û¿¡¼ ¹ßÃéÇÑ °ÍÀ¸·Î À§ÀÇ ¿¹¿¡¼ÀÇ
À̸§¿¡ ¸Âµµ·Ï ¼öÁ¤µÈ °ÍÀÌ´Ù:
o ³ª´Â "´Ù¸¥ ÄÄÇ»ÅÍ"°¡ PPPȤÀº SLIPÀ¸·Î ¿¬°áµÈ ³ªÀÇ Linux #1À» gateway·Î ÀνÄ
Çϵµ·Ï ÇÏ¿´´Ù.
o "´Ù¸¥ ÄÄÇ»ÅÍ"·ÎºÎÅÍ Linux #1À¸·Î ÆÐŶÀÌ Àü´ÞµÉ ¶§, Linux #1Àº ±× ÆÐŶ¿¡
»õ·Î¿î ¹ß½ÅÆ÷Æ®¹øÈ£(source port number)¸¦ ÇÒ´çÇÏ°í ¿ø·¡ÀÇ ÁÖ¼Ò´Â µû·Î
ÀúÀåÇØ µÐ´Ù. MASQ¼¹ö´Â ¼öÁ¤µÈ ÆÐŶÀ» SLIP/PPP¸¦ ÅëÇØ¼ ÀÎÅͳÝÀ¸·Î
Àü¼ÛÇÑ´Ù.
o ÀÎÅͳÝÀ¸·ÎºÎÅÍ Linux #1À¸·Î ÆÐŶÀÌ µÇµ¹¾Æ¿Ã ¶§, Linux #1Àº Æ÷Æ®¹øÈ£(port
number)¸¦ °Ë»çÇØ¼ "´Ù¸¥ ÄÄÇ»ÅÍ"·ÎºÎÅÍ ¿äûµÇ¾ú´ø °ÍÀÎÁö È®ÀÎÇÑ´Ù. ¸Â´Ù¸é,
MASQ ¼¹ö´Â ÀúÀåÇØµ×´ø ¿ø·¡ÀÇ Æ÷Æ®¹øÈ£¿Í IP ÁÖ¼Ò¸¦ ÀÎÅͳÝÀ¸·ÎºÎÅÍ ¿Â
ÆÐŶ¿¡ ´Ù½Ã ÇÒ´çÇϰí "´Ù¸¥ ÄÄÇ»ÅÍ"·Î º¸³»ÁØ´Ù.
o ÀÎÅͳݿ¡¼ ÆÐŶÀ» º¸³½ È£½ºÆ®´Â ÀÌ·± ÀÏÀÌ ÀϾ´Â °ÍÀ» ÀüÇô ¾Ë ¼ö ¾ø´Ù.
IP MasqueradingÀÇ ¶Ç´Ù¸¥ ¿¹:
¾Æ·¡ ±×¸²¿¡ ÀüÇüÀûÀÎ ¿¹°¡ ÀÖ´Ù:
+----------+
| | Ethernet
| A-box |::::::
| |.2 : 192.168.0.x
+----------+ :
: +----------+
+----------+ : .1 | Linux | PPP Á¢¼Ó
| | :::::::| Masq-Gate|:::::::::::::::::::// Internet
| B-box |:::::: | | 111.222.333.444
| |.3 : +----------+
+----------+ :
:
+----------+ :
| | :
| C-box |::::::
| |.4
+----------+
| | |
| <----³»ºÎ ³×Æ®¿÷----> | | <------¿ÜºÎ ³×Æ®¿÷------>
| | |
ÀÌ ¿¹¿¡¼´Â ¸ðµÎ ³×°³ÀÇ ÄÄÇ»ÅͰ¡ ÀÖ´Ù. ÀÌ °æ¿ì¿¡µµ ¸¶Âù°¡Áö·Î ¿À¸¥ÂÊ ³¡¿¡´Â
PPPÁ¢¼ÓÀ» ÇÒ ¼ö ÀÖ´Â ¼¹ö°¡ ÀÖ°í, ´õ ¿À¸¥Á·¿¡´Â Á¤º¸¸¦ ±³È¯ÇϰíÀÚ ÇÏ´Â
ÀÎÅͳݻóÀÇ È£½ºÆ®µéÀÌ ÀÖ´Ù°í °¡Á¤ÇÑ´Ù. ¸®´ª½º ½Ã½ºÅÛÀÎ Masq-Gate°¡
³»ºÎ ³×Æ®¿÷ÀÇ A-box, B-box, C-box¸¦
¿ÜºÎÀÇ ÀÎÅͳÝÀ¸·Î ¿¬°áÇϵµ·Ï ÇØÁÖ´Â IP Masquerading °ÔÀÌÆ®¿þÀÌÀÌ´Ù.
³»ºÎ ³×Æ®¿÷Àº
RFC-1918¿¡ Á¤ÇØÁø ¸î°¡Áö ³»ºÎ ³×Æ®¿÷ ÁÖ¼ÒÁß ÇѰ¡Áö¸¦ »ç¿ë´Âµ¥,
ÀÌ °æ¿ì¿¡´Â C Ŭ·¡½º ³×Æ®¿÷ÀÎ 192.168.0.0ÀÌ´Ù. ¸®´ª½º ¹Ú½º°¡ 192.168.0.1ÀÇ
IP ÁÖ¼Ò¸¦ »ç¿ëÇϸç, ´Ù¸¥ ½Ã½ºÅÛµéÀº ´ÙÀ½°ú °°Àº ÁÖ¼Ò¸¦ °®´Â´Ù:
- A-Box: 192.168.0.2
- B-Box: 192.168.0.3
- C-Box: 192.168.0.4
¼¼ °³ÀÇ ÄÄÇ»ÅÍ, A-box, B-box and C-box´Â TCP/IP¸¦
»ç¿ëÇÒ ¼ö ÀÖ´Ù¸é ¾î¶² OS¸¦ »ç¿ëÇϰí ÀÖ´õ¶óµµ »ó°ü ¾ø´Ù. À©µµ¿ìÁî 95,
¸ÅŲÅä½Ã MacTCP ¶Ç´Â OpenTransport³ª ´Ù¸¥ ¸®´ª½º ¹Ú½º¶óµµ
IP MASQ¸¦ ÅëÇØ¼ ÀÎÅͳݿ¡ ¿¬°áµÉ ¼ö ÀÖ´Ù. ¿¬°áµÇ´Â µ¿¾È, ¸¶½ºÄ¿·¹À̵ùÀ» ÇÏ´Â
½Ã½ºÅÛ, ȤÀº MASQ-gate´Â ³»ºÎ·ÎºÎÅÍÀÇ ¿¬°áÀ» ¸ðµÎ MASQ-gate
ÀÚü¿¡¼ º¸³»´Â °Íó·³ ÀüȯÇÏ°Ô µÈ´Ù. MASQ´Â ¿ÜºÎ·ÎºÎÅÍ ½ÅÈ£(¶Ç´Â Á¤º¸)°¡ ¿À¸é,
³»ºÎ¿¡ ÀÖ´Â ¿ø·¡ÀÇ ÄÄÇ»ÅÍ·Î °¡µµ·Ï ÀçÁ¤·ÄÇÑ´Ù. ±×·¡¼ ³»ºÎ ³×Æ®¿÷¿¡°Ô´Â ¸¶Ä¡
ÀÎÅͳݿ¡ Á÷Á¢ ¿¬°áµÇ¾î ÀÖ´Â °Íó·³ º¸¿©Áö°í, ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ëÇϰí ÀÖ´ÂÁö
¾Æ´ÑÁö¸¦ ±¸º°ÇÒ ¼ö ¾ø°Ô µÈ´Ù. À̰ÍÀ» "Åõ¸íÇÑ" ¿¬°áÀ̶ó ÇÑ´Ù.
NOTE: ´ÙÀ½ »çÇ׿¡ ´ëÇÑ ÀÚ¼¼ÇÑ °ÍÀº
FAQ
¸¦ ÂüÁ¶Çϱ⠹ٶ÷:
- NAT, MASQ, proxy ¼¹ö°£ÀÇ Â÷ÀÌÁ¡.
- ÆÐŶ ¹æÈº®ÀÌ µ¿ÀÛÇÏ´Â ¹æ¹ý.
2.6 ¸®´ª½º 2.0.x ¹öÁ¯¿¡¼ IP Masqeurade¸¦ »ç¿ëÇϱâ À§ÇÑ ¿ä±¸»çÇ×µé
** °¡Àå ÃÖ±ÙÀÇ Á¤º¸´Â
IP Masquerade Resource¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù. **
2.7 ¸®´ª½º 2.2.x ¹öÁ¯¿¡¼ IP Masqeurade¸¦ »ç¿ëÇϱâ À§ÇÑ ¿ä±¸»çÇ×µé
** °¡Àå ÃÖ±ÙÀÇ Á¤º¸´Â
IP Masquerade Resource ¸¦ Âü°íÇϱ⠹ٶõ´Ù. **
À§ÀÇ ÆÐÄ¡µé¿¡ ´ëÇÑ ´õ ¸¹Àº Á¤º¸¿Í ±×¿ÜÀÇ ´Ù¸¥ Á¤º¸µéÀ»
IP Masquerade Resource ¿¡¼ È®ÀÎÇÒ ¼ö ÀÖ´Ù.
¸¸¾à ´ç½ÅÀÇ ³×Æ®¿÷¿¡ Áß¿äÇÑ Á¤º¸°¡ ÀÖ´Ù¸é, IP ¸¶½ºÄ¿·¹À̵带 ±¸ÇöÇϱâ ÀÌÀü¿¡ "º¸¾È"À̶ó´Â °ÍÀ» »ý°¢ÇØ º¸±æ ¹Ù¶õ´Ù. ±âº»ÀûÀ¸·Î, IP MASQ´Â ´ç½ÅÀÌ ÀÎÅͳݿ¡ ¿¬°áÇÒ ¼ö ÀÖµµ·Ï ÇÏ´Â Åë·ÎÀÌÁö¸¸, ÀÎÅͳݻóÀÇ ´©±º°¡°¡ ´ç½ÅÀÇ ³»ºÎ ³×Æ®¿÷À¸·Î µé¾î¿À´Â Åë·Î°¡ µÉ ¼öµµ ÀÖ´Ù.
ÀÏ´Ü IP MASQ°¡ µ¿ÀÛÇÏ°Ô µÇ¸é, IPFWADM/IPCHAINS ¹æÈº®¿¡ ¸Å¿ì °·ÂÇÑ Á¤Ã¥(ruleset)À» »ç¿ëÇÒ °ÍÀ» °·ÂÈ÷ ±Ç°íÇÑ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â
Strong-IPFWADM-Rulesets
°ú
Strong-IPCHAINS-Rulesets
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
3.1 Ä¿³Î¿¡¼ IP ¸¶½ºÄ¿·¹À̵带 Áö¿øÇϵµ·Ï ÄÄÆÄÀÏ Çϱâ
¸¸¾à ´ç½ÅÀÇ ¸®´ª½º ¹èÆ÷º»ÀÌ ´ÙÀ½Ç׸ñµéÀ» Áö¿øÇϵµ·Ï ÄÄÆÄÀÏ µÇ¾îÁ® ÀÖ°í ¸¶½ºÄ¿·¹À̵忡 °ü°èµÈ ¸ðµâµéÀÌ ÄÄÆÄÀÏµÇ¾î¼ Á¦°øµÇ°í ÀÖ´Ù¸é Ä¿³Î ÄÄÆÄÀÏÀ» ÇÒ Çʿ䰡 ¾ø´Ù(´ëºÎºÐÀÇ ¹èÆ÷º»¿¡ Æ÷ÇԵǾî ÀÖÀ» °ÍÀÌ´Ù.):
- IPFWADM/IPCHAINS
- IP forwarding
- IP masquerading
- IP Firewalling
- ±âŸ µîµî
´ç½ÅÀÇ ¹èÆ÷º»ÀÌ ¸¶½ºÄ¿·¹À̵带 Áö¿øÇÏ´ÂÁö È®½ÇÇÏÁö ¾Ê´Ù¸é,
MASQ-supported-Distributions
¼½¼ÇÀ̳ª
IP Masquerade Resource ¿¡¼ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇÒ ¼ö ÀÖ´Ù. ´ç½ÅÀÇ ÆÐÆ÷º»ÀÌ IP ¸¶½ºÄ¿·¹À̵ùÀ» Áö¿øÇÏ´ÂÁö ¾Ë ¼ö°¡ ¾ø´Ù¸é, Áö¿øÇÏÁö ¾Ê´Â´Ù°í »ý°¢ÇÏ°í ´ÙÀ½ ´Ü°è·Î ³Ñ¾î°¡¶ó.
Áö¿øÇϵµ·Ï µÇ¾î ÀÖµçÁö ¾Æ´ÏµçÁö »ó°ü¾øÀÌ, ÀÌ ¼½¼Ç¿¡´Â ´Ù¸¥ À¯¿ëÇÑ Á¤º¸µéÀÌ ¸¹ÀÌ ÀÖÀ¸¹Ç·Î ÀоîµÎ±â¸¦ ±ÇÀåÇÑ´Ù.
¸®´ª½º 2.0.x Ä¿³Î
ÇÊ¿äÇÑ ¼ÒÇÁÆ®¿þ¾î¿Í ÆÐÄ¡ µîÀº
2.0.x-Requirements
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
* Prompt for development and/or incomplete code/drivers (CONFIG_EXPERIMENTAL) [Y/n/?]
- YES: ÀÌ·¸°Ô ÇØ¾ß ³ªÁß¿¡ IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀ» ¼±ÅÃÇÒ ¼ö ÀÖ´Ù.
* Enable loadable module support (CONFIG_MODULES) [Y/n/?]
- YES: IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµéÀ» ÀûÀçÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.
* Networking support (CONFIG_NET) [Y/n/?]
- YES: ³×Æ®¿÷À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* Network firewalls (CONFIG_FIREWALL) [Y/n/?]
- YES: IPFWADM ¹æÈº®À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* TCP/IP networking (CONFIG_INET)
- YES: TCP/IP ÇÁ·ÎÅäÄÝÀ» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* IP: forwarding/gatewaying (CONFIG_IP_FORWARD)
- YES: ¸®´ª½º ³×Æ®¿÷ ÆÐŶ Æ÷¿öµù°ú ¶ó¿ìÆÃÀ» °¡´ÉÇÏ°Ô ÇÑ´Ù.
- IPFWADM ¿¡ ÀÇÇØ¼ Á¦¾îµÈ´Ù.
* IP: syn cookies (CONFIG_SYN_COOKIES) [Y/n/?]
- YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ °·ÂÈ÷ ±ÇÀåÇÑ´Ù.
* IP: firewalling (CONFIG_IP_FIREWALL) [Y/n/?]
- YES: ¹æÈº® ±â´ÉÀ» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* IP: firewall packet logging (CONFIG_IP_FIREWALL_VERBOSE) [Y/n/?]
- YES: (²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸ °·ÂÈ÷ ±ÇÀå): ¹æÈº®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±æ ¼ö
ÀÖµµ·Ï ÇÑ´Ù.
* IP: masquerading (CONFIG_IP_MASQUERADE [Y/n/?]
- YES: IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÏ¿© ³»ºÎ ³×Æ®¿÷ÀÇ Æ¯Á¤ ÁּҷκÎÅÍÀÇ
ÆÐŶÀ» ÁÖ¼Ò¸¦ º¯°æÇÏ¿© ¿ÜºÎÀÇ TCP/IP³×Æ®¿÷À¸·Î ³»º¸³»°Ô ÇÑ´Ù.
* IP: ipautofw masquerade support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPAUTOFW) [Y/n/?]
- NO: IPautofw Àº TCP/IP Æ÷Å並 Æ÷¿öµùÇÏ´Â ±¸½Ã´ëÀûÀÎ ¹æ¹ýÀÌ´Ù. ¹°·Ð
ÀÛµ¿Çϱâ´Â ÇÏÁö¸¸, IPPORTFW °¡ ´õ ³ªÀº ¹æ¹ýÀÌ´Ù. ±×·¯¹Ç·Î IPAUTOFWÀº
ÃßõÇÏÁö ¾Ê´Â´Ù.
* IP: ipportfw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPPORTFW) [Y/n/?]
- YES: ÀÌ ¿É¼ÇÀ» 2.0.x Ä¿³Î¿¡¼ »ç¿ëÇϱâ À§Çؼ´Â ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù.
ÀÌ ¿É¼ÇÀ» ¼³Á¤Çϸé, ÀÎÅͳݿ¡ ÀÖ´Â ¿ÜºÎ ÄÄÇ»ÅͰ¡ ¸¶½ºÄ¿·¹À̵åµÈ
³»ºÎÀÇ Æ¯Á¤ ÄÄÇ»ÅÍ·Î Á÷Á¢ ¿¬°áÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ ±â´ÉÀº Åë»óÀûÀ¸·Î
³»ºÎÀÇ SMTP, TELNET, WWW ¼¹ö¿¡ Á¢±ÙÇÏ´Â µ¥ »ç¿ëµÈ´Ù. FTP Æ÷Æ®
Æ÷¿öµùÀ» Çϱâ À§Çؼ´Â FAQ¼½¼Ç¿¡ ¾ð±ÞµÇ¾î ÀÖ´Â Ãß°¡ÀûÀÎ ÆÐÄ¡¸¦ Àû¿ë
ÇØ¾ß ÇÑ´Ù. Æ÷Æ® Æ÷¿öµù¿¡ ´ëÇÑ Ãß°¡ÀûÀÎ Á¤º¸´Â ÀÌ HOWTOÀÇ
Forwards ¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
* IP: ICMP masquerading (CONFIG_IP_MASQUERADE_ICMP) [Y/n/?]
- YES: ICMP ÆÐŶÀ» ¸¶½ºÄ¿·¹À̵ùÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù. ²À ÇÊ¿äÇÏÁö ¾ÊÀ» ¼öµµ
ÀÖÀ¸³ª, ICMP Áö¿ø ¾øÀÌ´Â ¸¹Àº ÇÁ·Î±×·¥µéÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾ÊÀ»
¼ö ÀÖ´Ù.
* IP: loose UDP port managing (EXPERIMENTAL) (CONFIG_IP_MASQ_LOOSE_UDP) [Y/n/?]
- YES: ÀÌ ¿É¼ÇÀ» 2.0.x Ä¿³Î¿¡¼ »ç¿ëÇϱâ À§Çؼ´Â ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù.
ÀÌ ¿É¼ÇÀ» ÅëÇØ¼, ³»ºÎÀÇ ÄÄÇ»Å͵鿡¼ NAT¿Í °°Àº ½ÄÀ¸·Î ÀÛµ¿ÇÏ´Â
³×Æ®¿÷ °ÔÀÓµéÀ» ÀÎÅͳÝÀ» ÅëÇØ Áñ±æ ¼ö ÀÖ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº
ÀÌ HOWTOÀÇ FAQ¼½¼Ç¿¡¼ È®ÀÎÇÒ ¼ö ÀÖ´Ù.
* IP: always defragment (CONFIG_IP_ALWAYS_DEFRAG) [Y/n/?]
- YES: ÀÌ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵ù Á¢¼ÓÀ» ÃÖÀûÈ ÁØ´Ù. - °·ÂÈ÷ Ãßõ
* IP: optimize as router not host (CONFIG_IP_ROUTER) [Y/n/?]
- YES: ÀÌ ±â´ÉÀº Ä¿³ÎÀÇ ³×Æ®¿÷ ±â´ÉÀ» ÃÖÀûÈ ÁØ´Ù.
* IP: Drop source routed frames (CONFIG_IP_NOSR) [Y/n/?]
- YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ °·ÂÈ÷ ÃßõÇÑ´Ù.
* Dummy net driver support (CONFIG_DUMMY) [M/n/y/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ¿É¼ÇÀº ¹®Á¦°¡ ¹ß»ýÇØ¼ µð¹ö±ëÀ» ÇÒ ¶§
µµ¿òÀ» ÁÙ °ÍÀÌ´Ù.
* /proc filesystem support (CONFIG_PROC_FS) [Y/n/?]
- YES: ¸®´ª½º ³×Æ®¿÷ Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ ÇÊ¿äÇÏ´Ù.
NOTE: ÀÌ ¿É¼ÇµéÀº ´ÜÁö IP ¸¶½ºÄ¿·¹µùÀÌ µ¿ÀÛÇϱâ À§ÇÑ ¿ä¼ÒµéÀÌ´Ù. ƯÁ¤ÇÑ ³×Æ®¿÷°ú ƯÁ¤ Çϵå¿þ¾î¸¦ ¼³Á¤Çϱâ À§Çؼ´Â ÇÊ¿äÇÑ ´Ù¸¥ ¿É¼ÇµéÀ» ´õ ¼±ÅÃÇØ¾ß ÇÑ´Ù.
- Ä¿³Î ÀÚü¸¦ ÄÄÆÄÀÏÇÏ°í ³ª¼´Â, ´ÙÀ½°ú °°Àº ¸í·ÉÀ¸·Î Ä¿³ÎÀÇ IP ¸¶½ºÄ¿·¹µù °ü·Ã ¸ðµâµéÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇØ¾ß ÇÑ´Ù:
make modules; make modules_install
- ´ÙÀ½¿¡´Â,
/etc/rc.d/rc.local ÈÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ ¸îÁÙÀ» Ãß°¡Çؼ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ À§ÇÑ ½ºÅ©¸³Æ®¸¦ loadÇϵµ·Ï ÇØ¾ß ÇÑ´Ù. ÀÌ·¸°Ô ÇÏ¸é ¸®ºÎÆÃÀ» ÇÒ ¶§¸¶´Ù ÀÚµ¿ÀûÀ¸·Î IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù:
.
.
.
#rc.firewall script - Start IPMASQ and the firewall
/etc/rc.d/rc.firewall
.
.
.
¸®´ª½º 2.2.x Ä¿³Î
ÇÊ¿äÇÑ ¼ÒÇÁÆ®¿þ¾î¿Í ÆÐÄ¡ µîÀº
2.2.x-Requirements
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- ¿ì¼±, 2.2.x ¹öÁ¯ÀÇ Ä¿³Î ¼Ò½º°¡ ÇÊ¿äÇÏ´Ù. (ÃÖ±Ù ¹öÁ¯ÀÎ 2.2.11À̳ª ±× ÀÌ»óÀÇ ¹öÁ¯)
NOTE #1: ¸®´ª½º 2.2.x ¹öÁ¯Áß¿¡¼ 2.2.11 ÀÌÇÏÀÇ ¹öÁ¯Àº
IPCHAINS fragmentation bug¸¦ °¡Áö°í ÀÖ´Ù. ÀÌ·± ÀÌÀ¯·Î, °·ÂÇÑ IPCHAINS rulesetµéÀ» ÁöÁ¤ÇÏ¸é °ø°Ý¿¡ ³ëÃâµÇ°Ô µÈ´Ù. Ä¿³ÎÀ» ¾÷±×·¹À̵åÇÏ¿© ¹®Á¦¸¦ ÇØ°áÇϱ⠹ٶõ´Ù.
- ¸¸¾à Ä¿³Î ÄÄÆÄÀÏÀÌ Ã³À½ÀÌ¶óµµ °Ì¸ÔÁö ¸»±â ¹Ù¶õ´Ù. ½ÇÁ¦·Î ÇØ º¸¸é, ±×´ÙÁö ¾î·ÆÁö ¾Ê°í
2.2.x-Requirements
¼½¼Ç¿¡ ³ª¿À´Â ¸î¸î URL¿¡¼ ÄÄÆÄÀÏ ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇϰí ÀÖ´Ù.
tar xvzf linux-2.2.x.tar.gz -C /usr/src ¶ó°í ¸í·ÉÇÏ¿© Ä¿³ÎÀ» /usr/src/ ¿¡ Ǭ´Ù.(2.2.x´Â Ä¿³Î ¹öÁ¯) ¾ÐÃàÀ» Ǭ ´ÙÀ½¿¡, /usr/src/linux/ ¶ó´Â µð·ºÅ丮³ª ½Éº¼¸¯ ¸µÅ©°¡ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- ÆÐÄ¡¸¦ °¡ÇÒ °ÍÀÌ ÀÖÀ¸¸é ¾ÐÃàÀ» Ǭ Ä¿³Î ¼Ò½º¿¡ ÆÐÄ¡¸¦ °¡ÇÑ´Ù. 2.2.1 ÀÌ»ó ¹öÁ¯¿¡¼´Â, IP ¸¶½ºÄ¿·¹À̵ùÀ» Çϱâ À§ÇØ Æ¯º°ÇÑ ÆÐÄ¡°¡ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. PPTP, Xwindows forwarders ¿Í °°Àº ±â´ÉµéÀº ²À ÇÊ¿äÇÏÁö´Â ¾ÊÀº ¼±ÅûçÇ×ÀÌ´Ù. URLµéÀº
2.2.x-Requirements
¼½¼ÇÀ» ÂüÁ¶Çϰí, ÃֽŠÁ¤º¸¿Í ±×¿ÜÀÇ ÆÐÄ¡¿¡ °ü·ÃµÈ URLµéÀº
IP Masquerade Resources À» ÂüÁ¶ÇÏ±æ ¹Ù¶õ´Ù.
- ¾Æ·¡¿¡ Ä¿³Î¿¡ Æ÷ÇԵǾî¾ß ÇÏ´Â ÃÖ¼ÒÇÑÀÇ ¿É¼ÇµéÀÇ ¸ñ·ÏÀÌ ÀÖ´Ù. ÇöÀç ¼³Ä¡µÇ¾î ÀÖ´Â ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º(LAN Ä«µå, ¸ðµ© µîµî)¸¦ »ç¿ëÇÒ ¼ö ÀÖµµ·Ï ¼³Á¤ÇÏ´Â °Íµµ ÀØÁö ¸»¾Æ¾ß ÇÑ´Ù. Ä¿³ÎÀ» ÄÄÆÄÀÏÇÏ´Â ´õ ÀÚ¼¼ÇÑ ¹æ¹ý¿¡ ´ëÇØ¼´Â
Linux Kernel HOWTO ¿Í Ä¿³Î ¼Ò½º µð·ºÅ丮 ³»ÀÇ README ÈÀÏÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
´ÙÀ½ÀÇ ¿É¼Çµé¿¡¼ YESÀΰ¡ ¶Ç´Â NOÀΰ¡¸¦ È®ÀÎÇϱ⠹ٶõ´Ù. ÀÌ HOWTO¿¡¼ ³ªÁß¿¡ ¼³¸íÇÏ´Â ÀûÀýÇÑ ÆÐÄ¡¸¦ °¡ÇÏÁö ¾Ê´Â´Ù¸é ¾Æ·¡ÀÇ ¿É¼ÇµéÀÌ ¸ðµÎ º¸ÀÌÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù:
* Prompt for development and/or incomplete code/drivers (CONFIG_EXPERIMENTAL) [Y/n/?]
- YES: IP ¸¶½ºÄ¿·¹À̵带 À§ÇØ ²À ÇÊ¿äÇÑ °ÍÀº ¾Æ´ÏÁö¸¸, ÀÌ ¿É¼ÇÀ» ¼±ÅÃÇϸé
¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» »ý¼ºÇÏ°í Æ÷Æ® Æ÷¿öµù(port forwarding)À» ÇÒ ¼ö°¡
ÀÖ´Ù.
* Enable loadable module support (CONFIG_MODULES) [Y/n/?]
- YES: IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµéÀ» ÀûÀçÇÒ ¼ö ÀÖµµ·Ï ÇÑ´Ù.
* Networking support (CONFIG_NET) [Y/n/?]
- YES: ³×Æ®¿÷À» »ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* Packet socket (CONFIG_PACKET) [Y/m/n/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº TCPDUMP¸¦ »ç¿ëÇØ¼ IP ¸¶½ºÄ¿·¹À̵ù°ú
°ü·ÃÇÑ ¹®Á¦µéÀ» µð¹ö±ëÇÒ ¼ö ÀÖÀ¸¹Ç·Î ¼±ÅÃÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù.
* Kernel/User netlink socket (CONFIG_NETLINK) [Y/n/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ¹æÈº®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±æ ¼ö ÀÖµµ·Ï
ÇÑ´Ù.
* Routing messages (CONFIG_RTNETLINK) [Y/n/?]
- NO: ÀÌ ¿É¼ÇÀº ÆÐŶ ¹æÈº®ÀÌ ±â·ÏÀ» ³²±â´Â °Í°ú ¾Æ¹« »ó°üÀÌ ¾ø´Ù.
* Network firewalls (CONFIG_FIREWALL) [Y/n/?]
- YES: IPCHAINS ¹æÈº® µµ±¸¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
* TCP/IP networking (CONFIG_INET) [Y/n/?]
- YES: TCP/IP ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
* IP: advanced router (CONFIG_IP_ADVANCED_ROUTER) [Y/n/?]
- NO: CONFIG_IP_ROUTE_VERBOSE ¸¦ ¼³Á¤Çϱâ À§Çؼ ÇÊ¿äÇÏ°í ±ò²ûÇÑ ¶ó¿ìÆÃÀ»
À§Çؼ ÇÊ¿äÇÏ´Ù. (ipchains/¸¶½ºÄ¿·¹ÀÌµå ¿Í´Â °ü°è¾ø´Ù.)
* IP: verbose route monitoring (CONFIG_IP_ROUTE_VERBOSE) [Y/n/?]
- YES: ÀÌ ±â´ÉÀº IP ½ºÇªÇÎ(¼ÓÀÓ) ÆÐŶÀ» Á¦°ÅÇÏ°í ±× ±â·ÏÀ» ³²±â´Â Äڵ带
»ç¿ëÇÑ´Ù¸é ¸Å¿ì À¯¿ëÇÒ °ÍÀÌ´Ù.
* IP: firewalling (CONFIG_IP_FIREWALL) [Y/n/?]
- YES: ¹æÈº® ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
* IP: firewall packet netlink device (CONFIG_IP_FIREWALL_NETLINK) [Y/n/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ¹æÈº®ÀÇ Á¢±Ù ±â·ÏÀ» ³²±â´Â ±â´ÉÀ»
Çâ»ó½ÃÄÑ ÁÙ °ÍÀÌ´Ù.
* IP: always defragment (required for masquerading) (CONFIG_IP_ALWAYS_DEFRAG) [Y/n/?]
- YES: ÀÌ ±â´ÉÀ» ¼±ÅÃÇØ¾ßÁö IP ¸¶½ºÄ¿·¹À̵å¿Í Åõ¸íÇÑ ÇÁ·Ï½Ã ±â´ÉÀ» ¼±ÅÃÇÒ
¼ö ÀÖ´Ù. ÀÌ ±â´ÉÀº IP ¸¶½ºÄ¿·¹À̵å Á¢¼ÓÀ» ÃÖÀûÈ Çϱ⵵ ÇÑ´Ù.
* IP: masquerading (CONFIG_IP_MASQUERADE) [Y/n/?]
- YES: ³»ºÎ ÁÖ¼Ò¸¦ ¿ÜºÎ·Î ³»º¸³¾ ÆÐŶÀ¸·Î º¯È¯ÇØ ÁÖ´Â IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ»
»ç¿ë °¡´ÉÇÏ°Ô ÇÑ´Ù.
* IP: ICMP masquerading (CONFIG_IP_MASQUERADE_ICMP) [Y/n/?]
- YES: ICMP ÇÎ ÆÐŶÀ» ¸¶½ºÄ¿·¹À̵å Çϱâ À§ÇØ »ç¿ëµÈ´Ù. (¼±ÅÃÇÏÁö ¾Ê´õ¶óµµ
ICMP ¿¡·¯ ÄÚµå ÀÚü´Â ¸¶½ºÄ¿·¹ÀÌµå µÉ °ÍÀÌ´Ù.) Á¢¼Ó¿¡ ¹®Á¦°¡ »ý°åÀ»
¶§ ÇØ°áÇϱâ À§ÇØ »ç¿ëµÇ´Â Áß¿äÇÑ ±â´ÉÀÌ´Ù.
* IP: masquerading special modules support (CONFIG_IP_MASQUERADE_MOD) [Y/n/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ÀÌ ±â´ÉÀº ³ªÁß¿¡ TCP/IP Æ÷Æ® Æ÷¿öµùÀ» »ç¿ë
°¡´ÉÇÏ°Ô Çϱâ À§Çؼ ¼±ÅÃÇØ¾ß ÇÑ´Ù. Æ÷Æ® Æ÷¿öµùÀ» ÅëÇØ¼ ¿ÜºÎ·ÎºÎÅÍ
¸¶½ºÄ¿·¹À̵åµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ·Î Á÷Á¢ ¿¬°áÇÒ ¼ö ÀÖ´Ù.
* IP: ipautofw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPAUTOFW) [N/y/m/?]
- NO: IPautofw ±â´ÉÀº Æ÷Æ® Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ »ç¿ëµÇ´ø ±¸½Ã´ëÀûÀÎ
¹æ¹ýÀÌ´Ù. ÀÌ ±â´ÉÀº ÇÁ·ÎÅäÄÝ ´ÜÀ§ÀÇ ¸ðµâÀ» »ç¿ëÇÏ´Â °ÍÀÌ ´õ ³´´Ù.
* IP: ipportfw masq support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_IPPORTFW) [Y/m/n/?]
- YES: IPPORTFW¸¦ »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.
ÀÌ ¿É¼ÇÀ» ¼±ÅÃÇϸé, ÀÎÅͳݻóÀÇ ¿ÜºÎÀÇ ÄÄÇ»Å͵éÀÌ ³»ºÎÀÇ
¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍ¿Í Á÷Á¢ Åë½ÅÇÒ ¼ö ÀÖ°Ô µÈ´Ù. ÀÌ ±â´ÉÀº
Åë»óÀûÀ¸·Î ³»ºÎÀÇ SMTP, TELNET, WWW ¼¹ö¿¡ Á¢¼ÓÇϱâ À§Çؼ »ç¿ëµÈ´Ù.
FTP Æ÷Æ® Æ÷¿öµùÀº FAQ ¼½¼Ç¿¡ ¼³¸íµÇ´Â Ãß°¡ ÆÐÄ¡¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù.
Æ÷Æ® Æ÷¿öµù¿¡ ´ëÇÑ Ãß°¡ÀûÀÎ Á¤º¸´Â ÀÌ HOWTOÀÇ Forwards ¼½¼Ç¿¡¼
´Ù·ç°í ÀÖ´Ù.
* IP: ip fwmark masq-forwarding support (EXPERIMENTAL) (CONFIG_IP_MASQUERADE_MFW) [Y/m/n/?]
- NO: IPCHAINS·Î ºÎÅÍ Á÷Á¢ IP Æ÷¿öµùÀ» ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ÇöÀç ÀÌ ÄÚµå´Â
½ÃÇè¿ëÀ̸ç, ±ÇÀåÇÏ´Â ¹æ¹ýÀº IPMASQADM ¿Í IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.
* IP: optimize as router not host (CONFIG_IP_ROUTER) [Y/n/?]
- YES: ÀÌ ±â´ÉÀº Ä¿³ÎÀÇ ³×Æ®¿÷ ±â´ÉÀ» ÃÖÀûÈ ÇØ ÁØ´Ù.
* IP: GRE tunnels over IP (CONFIG_NET_IPGRE) [N/y/m/?]
- NO: ÀÌ ±â´ÉÀº ²À ÇÊ¿äÇÏÁö´Â ¾ÊÀ¸¸ç, IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼ PPTP¿Í
GRE ÅͳÎÀ» »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.
* IP: TCP syncookie support (not enabled per default) (CONFIG_SYN_COOKIES) [Y/n/?]
- YES: ±âº»ÀûÀÎ ³×Æ®¿÷ º¸¾ÈÀ» À§Çؼ ¼±ÅÃÇÒ °ÍÀ» °·ÂÈ÷ ±ÇÀåÇÑ´Ù.
* Network device support (CONFIG_NETDEVICES) [Y/n/?]
- YES: ¸®´ª½ºÀÇ ³×Æ®¿÷ ÀåÄ¡¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù.
* Dummy net driver support (CONFIG_DUMMY) [M/n/y/?]
- YES: ²À ÇÊ¿äÇÏÁö´Â ¾ÊÁö¸¸, ¹®Á¦°¡ ¹ß»ýÇßÀ» ¶§ µð¹ö±ë ÇÒ ¶§ µµ¿òÀÌ µÉ
°ÍÀÌ´Ù.
* /proc filesystem support (CONFIG_PROC_FS) [Y/n/?]
- YES: ¸®´ª½ºÀÇ ³×Æ®¿÷ Æ÷¿öµù ½Ã½ºÅÛÀ» »ç¿ëÇϱâ À§Çؼ ÇÊ¿äÇÏ´Ù.
NOTE: ÀÌ ¿É¼ÇµéÀº ´ÜÁö IP ¸¶½ºÄ¿·¹À̵ùÀÌ µ¿ÀÛÇϱâ À§ÇÑ ¿ä¼ÒµéÀÌ´Ù. ƯÁ¤ÇÑ ³×Æ®¿÷°ú ƯÁ¤ Çϵå¿þ¾î¸¦ ¼³Á¤Çϱâ À§Çؼ´Â ÇÊ¿äÇÑ ´Ù¸¥ ¿É¼ÇµéÀ» ´õ ¼±ÅÃÇØ¾ß ÇÑ´Ù.
- Ä¿³Î ÀÚü¸¦ ÄÄÆÄÀÏÇÏ°í ³ª¼´Â, ´ÙÀ½°ú °°Àº ¸í·ÉÀ¸·Î Ä¿³ÎÀÇ IP ¸¶½ºÄ¿·¹À̵ù °ü·Ã ¸ðµâµéÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇØ¾ß ÇÑ´Ù:
make modules; make modules_install
- ´ÙÀ½¿¡´Â,
/etc/rc.d/rc.local ÈÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ ¸îÁÙÀ» Ãß°¡Çؼ IP ¸¶½ºÄ¿·¹À̵带 »ç¿ëÇϱâ À§ÇÑ ½ºÅ©¸³Æ®¸¦ loadÇϵµ·Ï ÇØ¾ß ÇÑ´Ù. ÀÌ·¸°Ô ÇÏ¸é ¸®ºÎÆÃÀ» ÇÒ ¶§¸¶´Ù ÀÚµ¿ÀûÀ¸·Î IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» »ç¿ëÇÒ ¼ö ÀÖ´Ù:
.
.
.
#rc.firewall script - Start IPMASQ and the firewall
/etc/rc.d/rc.firewall
.
.
.
3.2 ³»ºÎ LAN¿¡ ºñ°ø½ÄÀûÀÎ ³»ºÎ IP ÁÖ¼Ò¸¦ ÇÒ´çÇϱâ
¸ðµç ³»ºÎÀÇ ¸¶½ºÄ¿·¹ÀÌµå µÈ ÄÄÇ»Å͵鿡 °ø½ÄÀûÀÎ ÀÎÅÍ³Ý ÁÖ¼Ò°¡ ÇÒ´çµÇ¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®¿¡, ¿ÜºÎÀÇ ÀÎÅÍ³Ý ÁÖ¼Ò¿Í Ãæµ¹ÇÏÁö ¾Êµµ·Ï ±× ÄÄÇ»Å͵鿡 ÁÖ¼Ò¸¦ ÇÒ´çÇÒ ¹æ¹ýÀÌ ÀÖ¾î¾ß ÇÑ´Ù.
>IP ¸¶½ºÄ¿·¹À̵å FAQÀÇ ¿øº»À¸·ÎºÎÅÍ Àοë:
RFC 1918 Àº ¿ÜºÎ¿Í ¿¬°áµÇÁö ¾Ê´Â "°³Àοë" ³×Æ®¿÷¿¡ »ç¿ëµÇ´Â IP Áּҵ鿡 °üÇÑ °ø½ÄÀûÀÎ ¹®¼ÀÌ´Ù. ÀÌ·¯ÇÑ °æ¿ì¿¡ »ç¿ëµÇ±â À§Çؼ ¼¼ °¡ÁöÀÇ ÁÖ¼Ò ¿µ¿ªÀÌ ÀÖ´Ù.
Section 3: °³Àοë ÁÖ¼Ò ¿µ¿ª
ÀÎÅÍ³Ý ÁÖ¼Ò ÇÒ´ç ±â±¸(The Internet Assigned Numbers Authority : IANA)´Â
IP ÁÖ¼ÒÁß¿¡¼ ´ÙÀ½ ¼¼°¡Áö ¿µ¿ªÀ» °³ÀÎ¿ë ³×Æ®¿÷À» À§Çؼ ¿¹¾àÇØ µÎ¾ú´Ù:
10.0.0.0 - 10.255.255.255
172.16.0.0 - 172.31.255.255
192.168.0.0 - 192.168.255.255
ù¹øÂ° ¿µ¿ªÀº "24-bit ¿µ¿ª", µÎ¹øÂ°´Â "20-bit ¿µ¿ª", ¼¼¹øÂ°´Â "16-bit ¿µ¿ª"À¸·Î
ºÎ¸£±â·Î ÇÑ´Ù. ù¹øÂ° ¿µ¿ªÀº class A ³×Æ®¿÷ ÁÖ¼Ò ¿µ¿ªÀ̸ç, µÎ¹øÂ°´Â class B
³×Æ®¿÷ ÁÖ¼ÒÀÇ ¿¬¼ÓµÈ 16°³ÀÇ ¹øÈ£µéÀ̰í, ¼¼¹øÂ°´Â class C ³×Æ®¿÷ ÁÖ¼ÒÀÇ ¿¬¼ÓµÈ
255°³ÀÇ ¹øÈ£µéÀÌ´Ù.
¼³¸íÀ» À§Çؼ, ÇÊÀÚ´Â 192.168.0.0 ³×Æ®¿÷°ú 255.255.255.0ÀÇ class-C ¼ºê³Ý ¸¶½ºÅ©¸¦ »ç¿ëÇß°í, ÀÌ HOWTO¿¡¼µµ ÀÌ ÁÖ¼Ò¸¦ »ç¿ëÇÒ °ÍÀÌ´Ù. ±×·¯³ª, À§¿¡ ÀÖ´Â °³ÀÎ¿ë ³×Æ®¿÷ ÁÖ¼ÒÁß¿¡¼ ¾î¶² °ÍÀ» »ç¿ëÇØµµ ¹«¹æÇÏ´Ù. ´Ü, °¢°¢ÀÇ °æ¿ì¿¡ ÀûÀýÇÑ ¼ºê³Ý ¸¶½ºÅ©¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù.
¸¸¾à Class-C ³×Æ®¿÷À» »ç¿ëÇÑ´Ù¸é, ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ëÇÒ ÄÄÇ»Å͵鿡 192.168.0.1, 192.168.0.2, 192.168.0.3, ..., 192.168.0.x µî°ú °°ÀÌ ÁÖ¼Ò¸¦ ÇÒ´çÇØ¾ß ÇÑ´Ù.
192.168.0.1 Àº º¸Åë ³»ºÎ °ÔÀÌÆ®¿þÀÌ È¤Àº ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¸Ó½ÅÀÇ Áּҷμ ¿ÜºÎ·Î ¿¬°áµÇ´Â Åë·ÎÀÌ´Ù. 192.168.0.0°ú 192.168.0.255´Â °¢°¢ "³×Æ®¿÷" ÀÚüÀÇ ÁÖ¼Ò¿Í "ºê·Îµåij½ºÆ®" ÁÖ¼ÒÀÌ´Ù. (ÀÌ ÁÖ¼ÒµéÀº ¿¹¾àµÈ ÁÖ¼ÒµéÀÌ´Ù.) ÀÌ ÁÖ¼ÒµéÀ» ÄÄÇ»Å͵鿡°Ô ÇÒ´ç¸é, ³×Æ®¿÷ÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾ÊÀ» °ÍÀÌ´Ù.
3.3 IP Æ÷¿öµù Á¤Ã¥ ¼³Á¤Çϱâ
ÀÌÁ¦, Ä¿³Î°ú ±âŸ ÇÊ¿äÇÑ ÆÐŰÁöµéÀÌ ÁغñµÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡µµ ¸ðµç ³×Æ®¿÷ IP ÁÖ¼Òµé°ú, °ÔÀÌÆ®¿þÀÌ, DNS ÁÖ¼ÒµéÀ» ¼³Á¤ÇØ¾ß ÇÑ´Ù. ³×Æ®¿÷ Ä«µåµéÀ» ¼³Á¤ÇÏ´Â ¹æ¹ýÀ» ¸ð¸¥´Ù¸é,
2.0.x-Requirements
ȤÀº
2.2.x-Requirements
¼½¼Ç¿¡ ¾ð±ÞµÈ HOWTOµéÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
ÀÌÁ¦ ³²Àº °ÍÀº IP ¹æÈº® µµ±¸µéÀ» ¼³Á¤Çؼ Æ÷¿öµù°ú ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇÏ´Â °ÍÀÌ´Ù:
** ¼³Á¤Àº ¿©·¯°¡Áö ¹æ¹ýÀ¸·Î ÇÒ ¼ö°¡ ÀÖÁö¸¸, ÇÊÀÚ´Â ´ÙÀ½¿¡ ¿¹·Î µç ¹æ¹ýÀ» »ç¿ëÇØ¼ ¼º°øÇß´Ù. ÇÏÁö¸¸, ¿©·¯ºÐÀº ´Ù¸¥ ¹æ¹ýÀ» »ç¿ëÇÒ ¼öµµ ÀÖÀ» °ÍÀÌ´Ù.
** ÀÌ ¼½¼Ç¿¡¼ Á¦°øÇÏ´Â °ÍÀº IP ¸¶½ºÄ¿·¹ÀÌµå ±â´ÉÀÌ ÀÛµ¿Çϱâ À§ÇÑ ÃÖ¼ÒÇÑÀÇ ¹æÈº® Á¤Ã¥ÀÌ´Ù. ÀÏ´Ü IP ¸¶½ºÄ¿·¹À̵尡 Á¦´ë·Î µ¿ÀÛÇϸé(ÀÌ HOWTO¿¡¼ ³ªÁß¿¡ ¾ð±ÞÇÑ´Ù)
Strong-IPFWADM-Rulesets
¿Í
Strong-IPCHAINS-Rulesets
¼½¼Ç¿¡¼ º¸¾È °µµ°¡ º¸´Ù ³ôÀº Á¤Ã¥µé¿¡ ´ëÇØ ¾Ë¾Æº¸±â ¹Ù¶õ´Ù. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº IPFWADM (2.0.x) ȤÀº IPCHAINS(2.2.x) man ÆäÀÌÁö¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.
¸®´ª½º 2.0.x Ä¿³Î
´ÙÀ½°ú °°Àº "°£´ÜÇÑ" Ãʱâ Á¤Ã¥À¸·Î /etc/rc.d/rc.firewall ÈÀÏÀ» »ý¼ºÇÑ´Ù:
# rc.firewall - Initial SIMPLE IP Masquerade setup for 2.0.x kernels using IPFWADM
#
# Load all required IP MASQ modules
#
# NOTE: Only load the IP MASQ modules you need. All current available IP MASQ modules
# are shown below but are commented out from loading.
# Needed to initially load modules
#
/sbin/depmod -a
# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp
# Supports the masquerading of RealAudio over UDP. Without this module,
# RealAudio WILL function but in TCP mode. This can cause a reduction
# in sound quality
#
#/sbin/modprobe ip_masq_raudio
# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc
# Supports the masquerading of Quake and QuakeWorld by default. This modules is
# for for multiple users behind the Linux MASQ server. If you are going to play
# Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960
# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme
#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive
#CRITICAL: Enable IP forwarding since it is disabled by default since
#
# Redhat Users: you may try changing the options in /etc/sysconfig/network from:
#
# FORWARD_IPV4=false
# to
# FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward
# Dynamic IP users:
#
# If you get your Internet IP address dynamically from SLIP, PPP, or DHCP, enable this following
# option. This enables dynamic-ip address hacking in IP MASQ, making the life
# with DialD, PPPd, and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr
# MASQ timeouts
#
# 2 hrs timeout for TCP session timeouts
# 10 sec timeout for traffic after the TCP/IP "FIN" packet is received
# 160 sec timeout for UDP traffic (Important for MASQ'ed ICQ users)
#
/sbin/ipfwadm -M -s 7200 10 160
# DHCP: For people who receive their external IP address from either DHCP or BOOTP
# such as ADSL or Cablemodem users, it is necessary to use the following
# before the deny command. The "bootp_client_net_if_name" should be replaced
# the name of the link that the DHCP/BOOTP server will put an address on to?
# This will be something like "eth0", "eth1", etc.
#
# This example is currently commented out.
#
#
#/sbin/ipfwadm -I -a accept -S 0/0 67 -D 0/0 68 -W bootp_clients_net_if_name -P udp
# Enable simple IP forwarding and Masquerading
#
# NOTE: The following is an example for an internal LAN address in the 192.168.0.x
# network with a 255.255.255.0 or a "24" bit subnet mask.
#
# Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipfwadm -F -p deny
/sbin/ipfwadm -F -a m -S 192.168.0.0/24 -D 0.0.0.0/0
/etc/rc.d/rc.firewall ÈÀÏÀ» ÆíÁýÇØ¼ Á¤Ã¥À» »ý¼ºÇÏ°í ³ª¸é,
"chmod 700 /etc/rc.d/rc.firewall" ¶ó°í ¸í·ÉÇØ¼ ½ÇÇà°¡´ÉÇÑ ÈÀÏ·Î
¸¸µç´Ù.
À§ÀÇ ¹æ¹ýó·³ Àüü TCP/IP ³×Æ®¿÷¿¡ ´ëÇØ¼°¡ ¾Æ´Ï¶ó, °¢°¢ÀÇ ¸Ó½Åº°·Î IP ¸¶½ºÄ¿·¹À̵ùÀ» ¼³Á¤ÇÒ ¼öµµ ÀÖ´Ù. ¿¹¸¦ µé¾î¼, 192.168.0.2¿Í 192.168.0.8ÀÇ ÁÖ¼Ò¸¦ °®´Â È£½ºÆ®´Â ÀÎÅͳݿ¡ Á¢±Ù°¡´ÉÇϵµ·Ï ÇÏ°í ´Ù¸¥ ³»ºÎÀÇ ¸Ó½ÅµéÀº Á¢±ÙÇÏÁö ¸øÇϵµ·Ï ÇϰíÀÚ ÇÑ´Ù¸é, À§ÀÇ /etc/rc.d/rc.firewall ÈÀÏ¿¡¼ "Enable simple IP forwarding and Masquerading" À̶ó°í µÇ¾î ÀÖ´Â ºÎºÐÀ» ¹Ù²ãÁÖ¸é µÈ´Ù.
# Enable simple IP forwarding and Masquerading
#
# NOTE: The following is an example to only allow IP Masquerading for the 192.168.0.2
# and 192.168.0.8 machines with a 255.255.255.0 or a "24" bit subnet mask.
#
# Please use the following in ADDITION to the simple ruleset above for specific
# MASQ networks. Also change the network numbers and subnet masks to match your
# internal LAN setup
#
/sbin/ipfwadm -F -p deny
/sbin/ipfwadm -F -a m -S 192.168.0.2/32 -D 0.0.0.0/0
/sbin/ipfwadm -F -a m -S 192.168.0.8/32 -D 0.0.0.0/0
IP ¸¶½ºÄ¿·¹À̵ùÀ» óÀ½ »ç¿ëÇÏ´Â »ç¶÷µéÀÌ ÈçÈ÷ ÀúÁö¸£´Â ½Ç¼ö´Â ´ÙÀ½°ú °°ÀÌ ¸í·ÉÇÏ´Â °ÍÀÌ´Ù:
ipfwadm -F -p masquerade
µðÆúÆ®·Î ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇØ¼´Â ¾ÈµÈ´Ù. ¸¸¾à ±×·¸°Ô ¼³Á¤Çϸé
¶ó¿ìÆÃ Å×À̺íÀ» ´Ù·ê ÁÙ ¾Æ´Â ¾î¶² ´©±º°¡°¡ ¿©·¯ºÐÀÇ °ÔÀÌÆ®¿þÀ̸¦ ÅëÇØ¼
ÀÚ½ÅÀÇ ½ÅºÐÀ» ¼û±â°í¼ ¾îµò°¡·Î Á¢¼ÓÇÒ ¼ö°¡ ÀÖ°Ô µÈ´Ù!
À§ÀÇ ¼³Á¤ÈÀÏ ³»¿ëÀº, /etc/rc.d/rc.firewall ÈÀÏÀ̳ª ȤÀº ¿øÇÏ´Â ´Ù¸¥ rc ÈÀÏ¿¡ ³ÖÀ» ¼öµµ ÀÖ°í, ¾Æ´Ï¸é IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿äÇÒ ¶§¸¶´Ù ¼öµ¿À¸·Î ¸í·ÉÇÒ ¼öµµ ÀÖ´Ù.
Strong-IPFWADM-Rulesets
°ú
Strong-IPCHAINS-Rulesets
¼½¼Ç¿¡¼ IPFWADM¿¡ °üÇÑ ÀÚ¼¼ÇÑ ¾È³»¿Í ´õ °·ÂÇÑ IPFWADM Á¤Ã¥µéÀÇ ¿¹¸¦ º¼¼ö°¡ ÀÖ´Ù.
¸®´ª½º 2.2.x Ä¿³Î
2.1.x ³ª 2.2.x Ä¿³Î¿¡¼ IP ¸¶½ºÄ¿·¹À̵ù Á¤Ã¥µéÀ» ´Ù·ç±â À§ÇÑ ¹æÈº® µµ±¸·Î¼ IPFWADMÀº ´õÀÌ»ó »ç¿ëµÇÁö ¾Ê´Â´Ù ÀÌ »õ ¹öÁ¯ÀÇ Ä¿³ÎµéÀº ÀÌÁ¦ IPCHAINS¶ó´Â µµ±¸¸¦ »ç¿ëÇÑ´Ù. ÀÌ·¸°Ô µÈ ÀÚ¼¼ÇÑ ÀÌÀ¯´Â
FAQ
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
´ÙÀ½°ú °°Àº "°£´ÜÇÑ" Ãʱâ Á¤Ã¥À¸·Î /etc/rc.d/rc.firewall ÈÀÏÀ» »ý¼ºÇÑ´Ù:
#!/bin/sh
#
# rc.firewall - Initial SIMPLE IP Masquerade test for 2.1.x and 2.2.x kernels using IPCHAINS
#
# Load all required IP MASQ modules
#
# NOTE: Only load the IP MASQ modules you need. All current IP MASQ modules
# are shown below but are commented out from loading.
# Needed to initially load modules
#
/sbin/depmod -a
# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp
# Supports the masquerading of RealAudio over UDP. Without this module,
# RealAudio WILL function but in TCP mode. This can cause a reduction
# in sound quality
#
#/sbin/modprobe ip_masq_raudio
# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc
# Supports the masquerading of Quake and QuakeWorld by default. This modules is
# for for multiple users behind the Linux MASQ server. If you are going to play
# Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960
# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme
#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive
#CRITICAL: Enable IP forwarding since it is disabled by default since
#
# Redhat Users: you may try changing the options in /etc/sysconfig/network from:
#
# FORWARD_IPV4=false
# to
# FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward
# Dynamic IP users:
#
# If you get your IP address dynamically from SLIP, PPP, or DHCP, enable this following
# option. This enables dynamic-ip address hacking in IP MASQ, making the life
# with Diald and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr
# MASQ timeouts
#
# 2 hrs timeout for TCP session timeouts
# 10 sec timeout for traffic after the TCP/IP "FIN" packet is received
# 160 sec timeout for UDP traffic (Important for MASQ'ed ICQ users)
#
/sbin/ipchains -M -S 7200 10 160
# DHCP: For people who receive their external IP address from either DHCP or BOOTP
# such as ADSL or Cablemodem users, it is necessary to use the following
# before the deny command. The "bootp_client_net_if_name" should be replaced
# the name of the link that the DHCP/BOOTP server will put an address on to?
# This will be something like "eth0", "eth1", etc.
#
# This example is currently commented out.
#
#
#/sbin/ipchains -A input -j ACCEPT -i bootp_clients_net_if_name -s 0/0 67 -d 0/0 68 -p udp
# Enable simple IP forwarding and Masquerading
#
# NOTE: The following is an example for an internal LAN address in the 192.168.0.x
# network with a 255.255.255.0 or a "24" bit subnet mask.
#
# Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipchains -P forward DENY
/sbin/ipchains -A forward -s 192.168.0.0/24 -j MASQ
/etc/rc.d/rc.firewall ÈÀÏÀ» ÆíÁýÇØ¼ Á¤Ã¥À» »ý¼ºÇÏ°í ³ª¸é, chmod 700 /etc/rc.d/rc.firewall¶ó°í ¸í·ÉÇØ¼ ½ÇÇà°¡´ÉÇÑ ÈÀÏ·Î ¸¸µç´Ù.
À§ÀÇ ¹æ¹ýó·³ Àüü TCP/IP ³×Æ®¿÷¿¡ ´ëÇØ¼°¡ ¾Æ´Ï¶ó, °¢°¢ÀÇ ¸Ó½Åº°·Î IP ¸¶½ºÄ¿·¹À̵ùÀ» ¼³Á¤ÇÒ ¼öµµ ÀÖ´Ù. ¿¹¸¦ µé¾î¼, 192.168.0.2¿Í 192.168.0.8ÀÇ ÁÖ¼Ò¸¦ °®´Â È£½ºÆ®´Â ÀÎÅͳݿ¡ Á¢±Ù°¡´ÉÇϵµ·Ï ÇÏ°í ´Ù¸¥ ³»ºÎÀÇ ¸Ó½ÅµéÀº Á¢±ÙÇÏÁö ¸øÇϵµ·Ï ÇϰíÀÚ ÇÑ´Ù¸é, À§ÀÇ /etc/rc.d/rc.firewall ÈÀÏ¿¡¼ "Enable simple IP forwarding and Masquerading" À̶ó°í µÇ¾î ÀÖ´Â ºÎºÐÀ» ¹Ù²ãÁÖ¸é µÈ´Ù.
#!/bin/sh
#
# Enable simple IP forwarding and Masquerading
#
# NOTE: The following is an example to only allow IP Masquerading for the 192.168.0.2
# and 192.168.0.8 machines with a 255.255.255.0 or a "24" bit subnet mask.
#
# Please change this network number and subnet mask to match your internal LAN setup
#
/sbin/ipchains -P forward deny
/sbin/ipchains -A forward -s 192.168.0.2/32 -j MASQ
/sbin/ipchains -A forward -s 192.168.0.8/32 -j MASQ
IP ¸¶½ºÄ¿·¹À̵ùÀ» óÀ½ »ç¿ëÇÏ´Â »ç¶÷µéÀÌ ÈçÈ÷ ÀúÁö¸£´Â ½Ç¼ö´Â ´ÙÀ½°ú °°ÀÌ ¸í·ÉÇÏ´Â °ÍÀÌ´Ù:
/sbin/ipchains -P forward masquerade
µðÆúÆ®·Î ¸¶½ºÄ¿·¹À̵ùÀ» Çϵµ·Ï ÇØ¼´Â ¾ÈµÈ´Ù. ¸¸¾à ±×·¸°Ô ¼³Á¤ÇÏ¸é ¶ó¿ìÆÃ Å×À̺íÀ» ´Ù·ê ÁÙ ¾Æ´Â ¾î¶² ´©±º°¡°¡ ¿©·¯ºÐÀÇ °ÔÀÌÆ®¿þÀ̸¦ ÅëÇØ¼ ÀÚ½ÅÀÇ ½ÅºÐÀ» ¼û±â°í¼ ¾îµò°¡·Î Á¢¼ÓÇÒ ¼ö°¡ ÀÖ°Ô µÈ´Ù!
À§ÀÇ ¼³Á¤ÈÀÏ ³»¿ëÀº, /etc/rc.d/rc.firewall ÈÀÏÀ̳ª ȤÀº ¿øÇÏ´Â ´Ù¸¥ rc ÈÀÏ¿¡ ³ÖÀ» ¼öµµ ÀÖ°í, ¾Æ´Ï¸é IP ¸¶½ºÄ¿·¹À̵尡 ÇÊ¿äÇÒ ¶§¸¶´Ù ¼öµ¿À¸·Î ¸í·ÉÇÒ ¼öµµ ÀÖ´Ù.
Strong-IPFWADM-Rulesets
°ú
Strong-IPCHAINS-Rulesets
¼½¼Ç¿¡¼ IPCHAINS¿¡ °üÇÑ ÀÚ¼¼ÇÑ ¾È³»¿Í ´õ °·ÂÇÑ IPCHAINS Á¤Ã¥µéÀÇ ¿¹¸¦ º¼ ¼ö°¡ ÀÖ´Ù. IPCHAINSÀÇ »ç¿ë¹ý¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº
Linux IP CHAINS HOWTOÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
³»ºÎÀÇ ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â ÄÄÇ»Å͵éÀÇ IP ÁÖ¼Ò¸¦ ÀûÀýÈ÷ ¼³Á¤ÇÏ´Â °Í ¿Ü¿¡, ³»ºÎÀÇ °¢ ÄÄÇ»Å͵éÀÌ ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹öÀÇ ÁÖ¼Ò¸¦ °ÔÀÌÆ®¿þÀÌ ÁÖ¼Ò·Î ¼³Á¤Çϰí DNS ¼¹ö ÁÖ¼Ò¸¦ ÀûÀýÈ÷ ¼³Á¤ÇØ¾ß ÇÑ´Ù. ´ë°³ÀÇ °æ¿ì¿¡ À̰ÍÀº ²Ï ¼ö¿ùÇÏ´Ù. °£´ÜÈ÷, °ÔÀÌÆ®¿þÀÌ ÁÖ¼Ò¿¡ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(ÀϹÝÀûÀ¸·Î 192.168.0.1)¸¦ ÀÔ·ÂÇÏ¸é µÈ´Ù.
µµ¸ÞÀÎ ³×ÀÓ ¼ºñ½º(DNS)ÀÇ °æ¿ì¿¡´Â, »ç¿ë °¡´ÉÇÑ ¾î¶² DNS ¼¹öÀÇ ÁÖ¼Ò¶óµµ Ãß°¡ÇÒ ¼ö ÀÖ´Ù. °¡Àå ±ú²ýÇÑ ¹æ¹ýÀº ¸®´ª½º ¼¹ö°¡ »ç¿ëÇϰí ÀÖ´Â DNS ¼¹ö¸¦ ÀÔ·ÂÇÏ´Â °ÍÀÌ´Ù. Ãß°¡·Î, "µµ¸ÞÀÎ °Ë»ö" Á¢¹Ì»ç¸¦ Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù.
¸¶½ºÄ¿·¹ÀÌµå µÇ´Â ³»ºÎÀÇ ÄÄÇ»Å͵éÀ» Á¦´ë·Î ¼³Á¤ÇÏ°í ³ª¸é, ÇØ´ç ÄÄÇ»ÅÍÀÇ ³×Æ®¿÷À» Àç½Ãµ¿ÇϵçÁö ¾Æ´Ï¸é ÀçºÎÆÃÇÑ´Ù.
´ÙÀ½ÀÇ ¼³Á¤ °úÁ¤¿¡¼´Â, ¿©·¯ºÐÀÌ Class C ³×Æ®¿÷ ÁÖ¼ÒµéÀ» »ç¿ëÇϰí, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹öÀÇ ÁÖ¼Ò°¡ 192.168.0.1À̶ó°í °¡Á¤ÇÑ´Ù. 192.168.0.0°ú 192.168.0.255´Â ¿¹¾àµÈ ÁÖ¼ÒÀÌ´Ï °¢ ÄÄÇ»ÅÍÀÇ ÁÖ¼Ò·Î »ç¿ëÇØ¼´Â ¾ÈµÈ´Ù.
´ÙÀ½°ú °°Àº Ç÷§ÆûµéÀÌ ¸¶½ºÄ¿·¹À̵ù ³»ºÎ¿¡¼ Å×½ºÆ®µÇ¾ú´Ù:
- Linux 1.2.x, 1.3.x, 2.0.x, 2.1.x, 2.2.x
- Solaris 2.51, 2.6, 7
- Windows 95, OSR2, 98
- Windows NT 3.51, 4.0, 2000 (¿÷½ºÅ×À̼ǰú ¼¹ö ¸ðµÎ)
- Windows For Workgroup 3.11 (TCP/IP ÆÐŰÁö ¼³Ä¡)
- Windows 3.1 (Netmanage Chameleon ÆÐŰÁö ¼³Ä¡)
- TCP/IP ¼ºñ½º¸¦ ¼³Ä¡ÇÑ Novell 4.01 ¼¹ö
- OS/2 (Warp v3 Æ÷ÇÔ)
- Macintosh OS (MacTCP ȤÀº Open Transport ¼³Ä¡)
- DOS (NCSA Telnet ÆÐŰÁö ¼³Ä¡, DOS TrumpetÀº ºÎºÐÀûÀ¸·Î µ¿ÀÛ)
- Amiga (AmiTCP ȤÀº AS225-stack ¼³Ä¡)
- UCX¸¦ ¼³Ä¡ÇÑ VAX Stations 3520°ú 3100 (VMSÀÇ °æ¿ì¿¡´Â TCP/IP stack)
- Linux/RedhatÀ» ¼³Ä¡ÇÑ Alpha/AXP
- SCO Openserver (v3.2.4.2¿Í 5)
- AIX¸¦ ¼³Ä¡ÇÑ IBM RS/6000
4.1 Microsoft Windows 95 ¼³Á¤
- ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- 'Á¦¾îÆÇ' --> '³×Æ®¿÷' À» ¼±ÅÃÇÑ´Ù.
- TCP/IP ÇÁ·ÎÅäÄÝÀÌ ¼³Ä¡µÇÁö ¾Ê¾Ò´Ù¸é, Ãß°¡ --> ÇÁ·ÎÅäÄÝ --> Á¦Á¶È¸»ç: Microsoft --> ÇÁ·ÎÅäÄÝ: 'TCP/IP ÇÁ·ÎÅäÄÝ' À» Â÷·Ê·Î ¼±ÅÃÇØ¼ ¼³Ä¡ÇÑ´Ù.
- TCP/IP Ç׸ñÀ» Windows95 ³×Æ®¿÷ Ä«µå·Î ¿¬°á(bound)µÇµµ·Ï Çϰí 'µî·ÏÁ¤º¸'¸¦ ¼±Ã¥ÇÑ´Ù. 'IP ÁÖ¼Ò' ÅÇÀ» Ŭ¸¯Çϰí IP ÁÖ¼Ò¸¦ 192.168.0.x(1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. ±×¸®°í ¼ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0À¸·Î ¼³Á¤ÇÑ´Ù.
- "°ÔÀÌÆ®¿þÀÌ" ÅÇÀ» Ŭ¸¯Çϰí '°ÔÀÌÆ®¿þÀÌ'¿¡ 192.168.0.1À̶ó°í ÀÔ·ÂÇÑÈÄ "Ãß°¡"¸¦ Ŭ¸¯ÇÑ´Ù.
- 'DNS ¼³Á¤' ÅÇÀ» Ŭ¸¯Çϰí, ÄÄÇ»ÅÍÀÇ À̸§°ú µµ¸ÞÀÎ ¸íÀ» ÀÔ·ÂÇÑ´Ù. µµ¸ÞÀÎÀÌ ¾ø´Ù¸é, ¿©·¯ºÐÀÌ »ç¿ëÇÏ´Â ISPÀÇ µµ¸ÞÀÎÀ» ÀÔ·ÂÇÑ´Ù. ÀÌÁ¦, DNS ¼¹ö ÁÖ¼Ò¿¡ ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â DNS ¼¹ö(´ë°³ÀÇ °æ¿ì
/etc/resolv.confÈÀÏ¿¡ ÀúÀåµÇ¾î ÀÖ´Ù)¸¦ ÀÔ·ÂÇÑ´Ù. ÀÌ DNS ¼¹öµéÀº ISP°¡ ¿î¿µÇϰí ÀÖÁö¸¸, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ ¿©·¯ºÐ ÀÚ½ÅÀÇ "ij½¬"¼¹ö³ª DNS ¼¹ö¸¦ ¿î¿µÇÒ ¼öµµ ÀÖ´Ù. ¿øÇÏ´Â µµ¸ÞÀÎ °Ë»ö Á¢¹Ì»ç(ãÀ» µµ¸ÞÀÎ ¸í)À» Ãß°¡ÇÒ ¼öµµ ÀÖ´Ù.
- ³ª¸ÓÁö ¼³Á¤µéÀº Àß ¾ËÁö ¸øÇÑ´Ù¸é ±×´ë·Î µÎµµ·Ï ÇÑ´Ù.
- ¸ðµç ´ëÈ»óÀÚ¿¡¼ 'È®ÀÎ(OK)' À» Ŭ¸¯Çϰí ÀçºÎÆÃÇÑ´Ù.
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ ¸®´ª½º È£½ºÆ®·Î
Ping À» ÇØº»´Ù: '½ÃÀÛ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
(À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
- C:\Windows µð·ºÅ丮¿¡
HOSTS ÈÀÏÀ» ¸¸µé¸é, DNS ¼¹ö°¡ ¾ø¾îµµ "È£½ºÆ®¸í"À¸·Î LAN ¾È¿¡ ÀÖ´Â ÄÄÇ»Å͵鿡°Ô PINGÀ» ÇÒ ¼ö°¡ ÀÖ´Ù. C:\windows µð·ºÅ丮¿¡ HOSTS.SAM ¶ó´Â ¿¹Á¦ ÈÀÏÀÌ ÀÖÀ» °ÍÀÌ´Ù.
4.2 Windows NT ¼³Á¤
- ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- 'Á¦¾îÆÇ' --> '³×Æ®¿÷' --> ÇÁ·ÎÅäÄÝ À» ¼±ÅÃÇÑ´Ù.
- TCP/IP ¼ºñ½º°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é '¼ÒÇÁÆ®¿þ¾î Ãß°¡' ¸Þ´º¿¡¼ TCP/IP ÇÁ·ÎÅäÄݰú ±×¿Ü Ç׸ñµéÀ» Ãß°¡ÇÑ´Ù.
- '³×Æ®¿÷ ¼ÒÇÁÆ®¿þ¾î¿Í ¾î´ðÅÍ Ä«µå' ºÎºÐ¿¡¼, '¼³Ä¡µÈ ³×Æ®¿÷ ¼ÒÇÁ¿þ¾î'¿¡ ÀÖ´Â 'TCP/IP ÇÁ·ÎÅäÄÝ'À» ¼±ÅÃÇÑ´Ù.
- 'TCP/IP ¼³Á¤'¿¡¼ ÀûÀýÇÑ ¾î´ðÅ͸¦ ¼±ÅÃÇÑ´Ù. ¿¹¸¦ µé¸é
[1]Novell NE2000 ¾î´ðÅÍ. ±×¸®°í IP ÁÖ¼Ò¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤Çϰí, ¼ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0, µðÆúÆ® °ÔÀÌÆ®¿þÀ̸¦ 192.168.0.1·Î ¼³Á¤ÇÑ´Ù.
- Windows NT µµ¸ÞÀÎ ³»¿¡ ÀÖÁö ¾Ê°Å³ª °¢ Ç׸ñÀÌ ¹«¾ùÀ» ÀǹÌÇÏ´ÂÁö Àß ¸ð¸¦ ¶§¿¡´Â 'Automatic DHCP Configuration'ÀÇ È°¼ºÈ¸¦ ÇØÁ¦Çϰí, 'WINS Server' ºÎºÐ¿¡ ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»°í, Enable IP ForwardingsÀÇ È°¼ºÈ¸¦ ÇØÁ¦ÇÑ´Ù.
- 'DNS'¸¦ Ŭ¸¯Çϰí, ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â ÀûÀýÇÑ Á¤º¸µé(´ë°³´Â /etc/resolv.conf¿¡ ÀúÀåµÇ¾î ÀÖÀ½)À» ÀÔ·ÂÇÑ´Ù. ´Ù µÇ¾úÀ¸¸é 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.
- '°í±Þ'À» Ŭ¸¯Çϰí, ÀÌ ¿É¼ÇµéÀÌ ¾î¶² ¿ªÇÒÀ» ÇÏ´Â Áö Àß ¸ð¸£¸é 'DNS for Windows Name Resolution'°ú 'Enable LMHOSTS lookup'ÀÇ È°¼ºÈ¸¦ ÇØÁ¦ÇÑ´Ù. ¸¸¾à¿¡ LMHOSTS ÈÀÏÀ» »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, C:\winnt\system32\drivers\etc¿¡ ÀúÀåµÇ¾î ÀÖ´Â °ÍÀ» ÂüÁ¶ÇÑ´Ù.
- ¸ðµç ´ëÈ»óÀÚ¿¡¼ 'È®ÀÎ'À» Ŭ¸¯ÇÏ°í ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ ¸®´ª½º È£½ºÆ®·Î
Ping À» ÇØº»´Ù: 'ÈÀÏ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
(À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
4.3 Windows¿¡¼ Workgroup 3.11 ¼³Á¤
- ³×Æ®¿÷ ÀåÄ¡ µå¶óÀ̹ö¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- TCP/IP 32b ÆÐŰÁö°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ¼³Ä¡ÇÑ´Ù.
- 'Main'/'Windows Setup'/'Network Setup'¿¡¼, 'Drivers'¸¦ Ŭ¸¯ÇÑ´Ù.
- 'Network Drivers' ºÎºÐ¿¡¼ 'Microsoft TCP/IP-32 3.11b'¸¦ ¼±ÅÃÇÑ´Ù. 'Setup'À» Ŭ¸¯ÇÑ´Ù.
- IP ÁÖ¼Ò¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. ±×¸®°í ¼ºê³Ý ¸¶½ºÅ©¸¦ 255.255.255.0À¸·Î µðÆúÆ® °ÔÀÌÆ®¿þÀ̸¦ 192.168.0.1·Î ¼³Á¤ÇÑ´Ù.
- Windows NT µµ¸ÞÀÎ ³»¿¡ ÀÖÁö ¾Ê°Å³ª °¢ Ç׸ñÀÌ ¹«¾ùÀ» ÀǹÌÇÏ´ÂÁö Àß ¸ð¸¦ ¶§¿¡´Â 'Automatic DHCP Configuration'ÀÇ È°¼ºÈ¸¦ ÇØÁ¦Çϰí, 'WINS Server' ºÎºÐ¿¡ ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»µµ·Ï ÇÑ´Ù.
- 'DNS'¸¦ Ŭ¸¯Çϰí, ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â ÀûÀýÇÑ Á¤º¸µé(´ë°³´Â /etc/resolv.conf¿¡ ÀúÀåµÇ¾î ÀÖÀ½)À» ÀÔ·ÂÇÑ´Ù. ´Ù µÇ¾úÀ¸¸é 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.
- '°í±Þ'À» Ŭ¸¯Çϰí, 'Enable DNS for Windows Name Resolution'°ú 'Enable LMHOSTS lookup'¸¦ ¼±ÅÃÇÑ´Ù. ¸¸¾à¿¡ LMHOSTS ÈÀÏÀ» »ç¿ëÇϰíÀÚ ÇÑ´Ù¸é, C:\winnt\system32\drivers\etc¿¡ ÀúÀåµÇ¾î ÀÖ´Â °ÍÀ» ÂüÁ¶ÇÑ´Ù.
- ¸ðµç ´ëÈ»óÀÚ¿¡¼ 'È®ÀÎ'À» Ŭ¸¯ÇÏ°í ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇØ º¸±â À§Çؼ ¸®´ª½º È£½ºÆ®·Î
Ping À» ÇØº»´Ù: 'ÈÀÏ/½ÇÇà', ping 192.168.0.1¶ó°í ÀÔ·Â.
(À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
4.4 UNIX ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤
- ¾ÆÁ÷ ³×Æ®¿÷ Ä«µå¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò°Å³ª ÇØ´ç µå¶óÀ̹ö¸¦ Áö¿øÇϵµ·Ï Ä¿³ÎÀ» ´Ù½Ã ÄÄÆÄÀÏ ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ÇÑ´Ù. ÀÌ ¹®¼¿¡¼ ÀÌ ³»¿ëÀº ´Ù·çÁö ¾Ê´Â´Ù.
- TCP/IP ³×Æ®¿÷ÀÌ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, net-tools ÆÐŰÁö¿Í °°Àº TCP/IP ³×Æ®¿÷ ÅøÀ» ¼³Ä¡ÇÑ´Ù.
- IPADDR¸¦ 192.168.0.x (1 < x < 255)·Î ¼³Á¤ÇÑ´Ù. NETMASK¸¦ 255.255.255.0, GATEWAY¸¦ 192.168.0.1, ±×¸®°í BROADCAST¸¦ 192.168.0.255·Î ¼³Á¤ÇÑ´Ù.
¿¹¸¦ µé¾î¼ ·¡µåÇÞ ¸®´ª½º ½Ã½ºÅÛÀ̶ó¸é, /etc/sysconfig/network-scripts/ifcfg-eth0ÈÀÏÀ» ÆíÁýÇϰųª, °£´ÜÇÏ°Ô Control Panel¿¡¼ ÇØ°áÇÒ ¼ö ÀÖ´Ù. SunOS, BSDi, Slackware Linux, Solaris, SuSe, Debian µîµî.. ´Ù¸¥ UNIX¿¡¼´Â ¹æ¹ýÀÌ ´Ù¸¦ ¼öµµ ÀÖ´Ù. Á¤º¸¸¦ ´õ ¾ò°íÀÚ ÇÑ´Ù¸é ¿©·¯ºÐÀÇ ÇØ´ç UNIX ¹®¼¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.
/etc/resolv.confÈÀÏ¿¡ µµ¸ÞÀÎ ³×ÀÓ ¼ºñ½º(DNS)¸¦ Ãß°¡ÇÏ°í µµ¸ÞÀÎ °Ë»ö Á¢¹Ì»ç¸¦ Ãß°¡ÇÑ´Ù. UNIX ¹öÁ¯°ú Á¾·ù¿¡ µû¶ó¼´Â, /etc/nsswitch.conf ÈÀÏÀ» ÆíÁýÇØ¼ DNS ¼ºñ½º¸¦ »ç¿ë°¡´ÉÇÏ°Ô ÇÑ´Ù.
- ¼³Á¤¿¡ µû¶ó¼´Â
/etc/networks ÈÀÏÀ» ÆíÁýÇØ¼ ¹Ù²Ù¾îÁà¾ß ÇÒ ¼öµµ ÀÖ´Ù.
- ÀûÀýÇÑ ¼ºñ½ºµéÀ» Àç½Ãµ¿Çϰųª, ȤÀº °£´ÜÇÏ°Ô ¾Æ¿¹ ½Ã½ºÅÛ ÀÚü¸¦ Àç½ÃÀÛÇÑ´Ù.
- °ÔÀÌÆ®¿þÀ̰¡ µÇ´Â ÄÄÇ»ÅÍ·ÎÀÇ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ ´ÙÀ½°ú °°ÀÌ
ping ¸í·ÉÀ» ³»¸°´Ù: ping 192.168.0.1.
(À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
4.5 NCSA ÅÚ³Ý ÆÐŰÁö¸¦ »ç¿ëÇÏ´Â DOSÀÇ ¼³Á¤
- ¾ÆÁ÷ ³×Æ®¿÷ Ä«µå¸¦ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. ³×Æ®¿÷ Ä«µå ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- ÀûÀýÇÑ ÆÐŶ µå¶óÀ̹ö¸¦ ·ÎµåÇÑ´Ù. ¿¹¸¦ µé¾î¼: NE2000 ÀÌ´õ³Ý Ä«µå¸¦ I/O Æ÷Æ® 300, IRQ 10À¸·Î »ç¿ëÇÑ´Ù¸é,
nwpd 0x60 10 0x300¶ó°í ¸í·ÉÇÑ´Ù.
- »õ·Î¿î µð·ºÅ丮¸¦ ¸¸µé°í, ±× µð·ºÅ丮¿¡ NCSA ÅÚ³Ý ÆÐŰÁö¸¦ Ç®¾î ³õ´Â´Ù:
pkunzip tel2308b.zip
- ÅØ½ºÆ® ¿¡µðÅÍ·Î
config.tel ÈÀÏÀ» ¿¬´Ù.
myip=192.168.0.x (1 < x < 255)·Î, netmask=255.255.255.0·Î ¼³Á¤ÇÑ´Ù.
- ÀÌ ¿¹¿¡¼´Â,
hardware=packet, interrupt=10, ioaddr=60¶ó°í ¼³Á¤ÇØ¾ß ÇÑ´Ù.
- °ÔÀÌÆ® ¿þÀ̷μ Àû¾îµµ ÇѰ³ÀÇ ÄÄÇ»ÅÍ¿¡ ´ëÇÑ ¼³Á¤ÀÌ ÀÖ¾î¾ß ÇÑ´Ù(¿¹¸¦ µé¸é ÀÌ °æ¿ì¿¡´Â ¸®´ª½º È£½ºÆ®):
name=default
host=¸®´ª½ºÈ£½ºÆ®À̸§
hostip=192.168.0.1
gateway=1
- µµ¸ÞÀÎ ³×ÀÓ ¼ºñ½º¸¦ À§Çؼ ¶Ç ÇϳªÀÇ ¼³Á¤À» ÇØÁà¾ß ÇÑ´Ù:
name=dns.domain.com ; hostip=123.123.123.123; nameserver=1
Note: ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â Á¤º¸´ë·Î À§ÀÇ ³»¿ëÀ» ¼öÁ¤ÇØ ÁØ´Ù.
config.tel ÈÀÏÀ» ÀúÀåÇÑ´Ù.
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ ¸®´ª½º È£½ºÆ®·Î ÅÚ³Ý ¿¬°áÀ» ÇØ º»´Ù:
telnet 192.168.0.1 ¸¸¾à ·Î±ä ÇÁ·ÒÇÁÆ®°¡ ³ª¿ÀÁö ¾Ê´Â´Ù¸é, ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
4.6 MacTCP¸¦ »ç¿ëÇÏ´Â MacOS ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤
- ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ¼ÒÇÁÆ®¿þ¾î¸¦ ¾ÆÁ÷ ¼³Ä¡ÇÏÁö ¾Ê¾Ò´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. ¾î´ðÅÍ ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- MacTCP control panelÀ» ¿¬´Ù. ÀûÀýÇÑ ³×Æ®¿÷ µå¶óÀ̹ö¸¦ ¼±ÅÃÇÑ´Ù(EtherTalkÀÌ ¾Æ´Ï°í EthernetÀ» ¼±ÅÃ). ±×¸®°í 'More...' ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
- 'Obtain Address:' ºÎºÐ¿¡¼, 'Manually'¸¦ Ŭ¸¯ÇÑ´Ù.
- 'IP Address:' ºÎºÐ¿¡¼, ÆË¾÷ ¸Þ´º¿¡¼ class C¸¦ ¼±ÅÃÇÑ´Ù. ÀÌ ´ëÈ»óÀÚÀÇ ³ª¸ÓÁö ºÎºÐÀº ¹«½ÃÇÑ´Ù.
- 'Domain Name Server Information:'¿¡¼ DNS Á¤º¸¸¦ ÀÔ·ÂÇÑ´Ù.
- 'Gateway Address:'¿¡¼, 192.168.0.1¸¦ ÀÔ·ÂÇÑ´Ù.
- 'OK'¸¦ Ŭ¸¯Çؼ ¼³Á¤À» ÀúÀåÇÑ´Ù. MacTCP control panelÀÇ ¸ÞÀÎ À©µµ¿ì¿¡¼, 'IP Address:'ºÎºÐ¿¡ Mac ÄÄÇ»ÅÍÀÇ IP ÁÖ¼Ò (192.168.0.x, 1 < x < 255)¸¦ ÀÔ·ÂÇÑ´Ù.
- MacTCP control panelÀ» ´Ý´Â´Ù. Àç½ÃÀÛÀ» ¹¯´Â ´ëÈ»óÀÚ°¡ ³ªÅ¸³ª¸é ½Ã½ºÅÛÀ» Àç½ÃÀÛÇÑ´Ù.
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ ¸®´ª½º È£½ºÆ®¿¡ pingÀ» º¸³¾ ¼ö ÀÖ´Ù. MacTCP Watcher¶ó´Â ÇÁ¸®¿þ¾î ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, 'Ping' ¹öưÀ» ´©¸£°í, ³ªÅ¸³ª´Â ´ëÈ»óÀÚ¿¡¼ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(192.168.0.1)¸¦ ÀÔ·ÂÇÑ´Ù. (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î
ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
- ³»ºÎ LAN¿¡¼ IP ÁÖ¼Ò ´ë½Å È£½ºÆ® À̸§À» »ç¿ëÇϱâ À§Çؼ, ½Ã½ºÅÛ Æú´õ¿¡
Hosts ÈÀÏÀ» ¸¸µé ¼öµµ ÀÖ´Ù. ½Ã½ºÅÛ Æú´õ¿¡´Â ÀÌ ÈÀÏÀÌ ÀÌ¹Ì Á¸ÀçÇϰí ÀÖÀ» °ÍÀÌ´Ù. ÀÌ ÈÀÏ¿¡´Â ¿©·¯ºÐÀÇ °æ¿ì¿¡ ¸ÂÃç¼ ¼öÁ¤Çؼ »ç¿ëÇÒ ¼öÀÖ´Â »ùÇÃÀÌ µé¾î ÀÖÀ» °ÍÀÌ´Ù.
4.7 Open Transport¸¦ »ç¿ëÇÏ´Â MacOS ±â¹Ý ½Ã½ºÅÛÀÇ ¼³Á¤
- ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ÀûÀýÇÑ µå¶óÀ̹ö°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- TCP/IP Control PanelÀ» ¿¾î¼ Edit ¸Þ´º¿¡¼ 'User Mode ...'¸¦ ¼±ÅÃÇÑ´Ù. user mode °¡ ÃÖ¼ÒÇÑ 'Advanced' ÀÌ»ó¿¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇϰí 'OK' ¹öưÀ» ´©¸¥´Ù.
- File ¸Þ´º¿¡¼ 'Configurations...'¸¦ ¼±ÅÃÇÑ´Ù. 'Default' ·Î µÇ¾î ÀÖ´Â ¼³Á¤À» ¼±ÅÃÇϰí 'Duplicate...' ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 'Duplicate Configuration' ´ëÈ»óÀÚ¿¡¼, 'IP Masq' (ȤÀº º¸ÅëÀÇ °æ¿ì¿¡¼ÀÇ ¼³Á¤ÀÌ ¾Æ´Ï¶ó´Â °ÍÀ» ÀǹÌÇÏ´Â °Í)À» ÀÔ·ÂÇÑ´Ù. ÀÌ·¸°Ô Çϸé 'Default copy'¿Í °°Àº °ÍÀÌ ³ªÅ¸³¯ °ÍÀÌ´Ù. ±×·¯¸é 'OK' ¹öưÀ» Ŭ¸¯Çϰí, 'Make Active' ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
- 'Connect via:' ´ëÈ»óÀÚ¿¡¼ 'Ethernet'À» ¼±ÅÃÇÑ´Ù.
- 'Configure:' ´ëÈ»óÀÚ¿¡¼ ÀûÀýÇÑ Ç׸ñÀ» ¼±ÅÃÇÑ´Ù. ¾î¶² °ÍÀ» ¼±ÅÃÇØ¾ß ÇÏ´ÂÁö Àß ¸ð¸£°Ú´Ù¸é, ¾Æ¸¶µµ 'Default' ¼³Á¤À» ´Ù½Ã ¼±ÅÃÇÏ°í ³ª°¡¾ß ÇÒ °ÍÀÌ´Ù. ÇÊÀÚÀÇ °æ¿ì¿¡´Â 'Manually' ¸¦ ¼±ÅÃÇØ¼ ¼³Á¤Çß´Ù.
- 'IP Address:' ´ëÈ»óÀÚ¿¡¼ Mac ÄÄÇ»ÅÍÀÇ IP ÁÖ¼Ò(192.168.0.x, 1 < x < 255)¸¦ ÀÔ·ÂÇÑ´Ù.
- 'Subnet mask:' ´ëÈ»óÀÚ¿¡¼ 255.255.255.0¸¦ ÀÔ·ÂÇÑ´Ù.
- 'Router address:' ´ëÈ»óÀÚ¿¡¼ 192.168.0.1À» ÀÔ·ÂÇÑ´Ù.
- 'Name server addr.:' ´ëÈ»óÀÚ¿¡¼ DNS ¼¹öÀÇ IP ÁÖ¼Ò¸¦ ÀÔ·ÂÇÑ´Ù.
- 'Implicit Search Path:' ºÎºÐÀÇ 'Starting domain name' ´ëÈ»óÀÚ¿¡¼ ÀÎÅÍ³Ý µµ¸ÞÀÎÀ» ÀÔ·ÂÇÑ´Ù.
- ´ÙÀ½ °úÁ¤Àº ¼±ÅÃÀûÀÌ´Ù. À߸ø ¼³Á¤Çϸé Á¤»ó µ¿ÀÛÇÏÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. Àß ¸ð¸£°Ú´Ù¸é, ¾Æ¹«°Íµµ ÀÔ·ÂÇÏÁö ¸»°í ºñ¿öµÎ°Å³ª, ¾Æ¹«°Íµµ ¼±ÅõÇÁö ¾ÊÀº ä·Î µÎ´Â °ÍÀÌ ÁÁÀ» °ÍÀÌ´Ù. ÇÊ¿äÇÏ´Ù¸é, ÀԷµǾî ÀÖ´Â Á¤º¸¸¦ ¸ðµÎ ¾ø¾Öµµ·Ï ÇÑ´Ù. ÇÊÀÚ°¡ ¾Æ´Â ÇÑ, TCP/IP ´ëÈ»óÀÚ¸¦ ÅëÇØ¼ ½Ã½ºÅÛÀÌ ÀÌÀü¿¡ ¼±ÅõǾî ÀÖ´Â ´Ù¸¥ "Hosts" ÈÀÏÀ» »ç¿ëÇÏÁö ¾Êµµ·Ï ÇÏ´Â ¹æ¹ýÀº ¾ø´Ù. ¸¸¾à ¿©·¯ºÐÀÌ ±× ¹æ¹ýÀ» ¾Ë°í ÀÖ´Ù¸é, ÇÊÀÚ¿¡°Ô ¾Ë·ÁÁÖ±æ ¹Ù¶õ´Ù.
¿©·¯ºÐÀÇ ³×Æ®¿÷ÀÌ 802.3 ŸÀÔÀÇ ÇÁ·¹ÀÓÀ» ÇÊ¿ä·Î ÇÑ´Ù¸é '802.3'À» üũÇÑ´Ù.
- 'Options...' ¹öưÀ» Ŭ¸¯Çؼ TCP/IP °¡ Ȱ¼ºÈ µÇµµ·Ï ÇÑ´Ù. ÇÊÀÚÀÇ °æ¿ì¿¡´Â 'Load only when needed' ¿É¼ÇÀ» »ç¿ëÇß´Ù. ¿©·¯ºÐÀÌ ÄÄÇ»Å͸¦ ÀçºÎÆÃ ÇÏÁö ¾Ê´Âä·Î TCP/IP ÀÀ¿ëÇÁ·Î±×·¥ÀÇ ½ÇÇà°ú Á¾·á¸¦ ¹Ýº¹À» ¿©·¯¹ø ¹Ýº¹ÇÏ´Â °æ¿ì¿¡´Â, 'Load only when needed' ¿É¼ÇÀ» üũÇÏÁö ¾Ê´Â °ÍÀÌ ¿©·¯ºÐÀÇ ÄÄÇ»ÅÍÀÇ ¸Þ¸ð¸® °ü¸®¿¡ µµ¿òÀ» ÁÙ °ÍÀÌ´Ù. ±× Ç׸ñÀ» üũÇÏÁö ¾ÊÀº ä·Î µÎ¸é, TCP/IP ÇÁ·ÎÅäÄÝ ½ºÅÃÀº Ç×»ó ·ÎµåµÇ¾î¼ »ç¿ë °¡´ÉÇÑ »óŰ¡ µÈ´Ù. ¸¸¾à Ã¼Å©ÇØ µÐ´Ù¸é, TCP/IP ½ºÅÃÀº ÇÊ¿äÇÒ ¶§ ÀÚµ¿ÀûÀ¸·Î ·ÎµåµÇ°í ÇÊ¿ä¾ø¾îÁö¸é ÀÚµ¿ÀûÀ¸·Î Á¦°ÅµÈ´Ù. ÀÌ·¸°Ô µÇ¸é, °è¼ÓÀûÀÎ loading°ú unloadingÀ» ÇÔÀ¸·Î½á ¸Þ¸ð¸®°¡ ÆÄÆíÀ¸·Î Á¶ÀÛ³ª°Ô µÈ´Ù. (¿ªÀÚÁÖ: À©µµ¿ìÁîÀÇ µð½ºÅ© Á¶°¢ ¸ðÀÓÀÌ ÇÊ¿äÇÑ ÀÌÀ¯¿Í ºñ½ÁÇÏ´Ù.)
- ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ ¸®´ª½º È£½ºÆ®¿¡ pingÀ» º¸³¾ ¼ö ÀÖ´Ù. MacTCP Watcher¶ó´Â ÇÁ¸®¿þ¾î ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é, 'Ping' ¹öưÀ» ´©¸£°í, ³ªÅ¸³ª´Â ´ëÈ»óÀÚ¿¡¼ ¸®´ª½º È£½ºÆ®ÀÇ ÁÖ¼Ò(192.168.0.1)¸¦ ÀÔ·ÂÇÑ´Ù. (À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î
ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
- ³»ºÎ LAN¿¡¼ IP ÁÖ¼Ò ´ë½Å È£½ºÆ® À̸§À» »ç¿ëÇϱâ À§Çؼ, ½Ã½ºÅÛ Æú´õ¿¡
Hosts ÈÀÏÀ» ¸¸µé ¼öµµ ÀÖ´Ù. ÀÌ ÈÀÏÀº ½Ã½ºÅÛ Æú´õ¿¡ ÀÖÀ» ¼öµµ ÀÖ°í ¾øÀ» ¼öµµ ÀÖ´Ù. ÀÌ ÈÀÏÀÌ Á¸ÀçÇÑ´Ù¸é, ¿©·¯ºÐÀÇ °æ¿ì¿¡ ¸ÂÃç¼ ¼öÁ¤Çؼ »ç¿ëÇÒ ¼öÀÖ´Â »ùÇÃÀÌ µé¾î ÀÖÀ» °ÍÀÌ´Ù. Á¸ÀçÇÏÁö ¾Ê´Â´Ù¸é, MacTCP¸¦ »ç¿ëÇϰí ÀÖ´Â ½Ã½ºÅÛÀ¸·ÎºÎÅÍ º¹»çÇØ ¿Í¼ ¼öÁ¤ÇØ ¾²°Å³ª, ±×³É ¿©·¯ºÐ ÀÚ½ÅÀÌ ¸¸µé¾î¼ »ç¿ëÇØµµ µÈ´Ù(ÀÌ ÈÀÏÀÇ Çü½ÄÀº UNIXÀÇ /etc/hosts ÈÀÏ Çü½ÄÀÇ ÀϺθ¦ »ç¿ëÇϸç, RFC952¿¡ ¼³¸íµÇ¾î ÀÖ´Ù). ÀÏ´Ü ÈÀÏÀ» ¸¸µé°í ³ª¸é, TCP/IP control panelÀ» ¿¾î¼, 'Select Hosts File...' ¹öưÀ» ´©¸£°í Hosts ÈÀÏÀ» ¿¬´Ù.
- ´Ý±â »óÀÚ¸¦ Ŭ¸¯Çϰųª File ¸Þ´º¿¡¼ 'Close' ȤÀº 'Quit' À» ¼±ÅÃÇÑ´Ù. ±×¸®°í 'Save' ¹öưÀ» Ŭ¸¯Çؼ º¯°æ»çÇ×À» ÀúÀåÇÑ´Ù.
- º¯°æ »çÇ×Àº Áï½Ã ¹Ý¿µµÇÁö¸¸, ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÏ´Â °Íµµ ÁÁ´Ù.
4.8 DNS¸¦ »ç¿ëÇÏ´Â Novell ³×Æ®¿÷ÀÇ ¼³Á¤
- ÀÌ´õ³Ý ¾î´ðÅÍÀ» À§ÇÑ µå¶óÀ̹ö ¼ÒÇÁÆ®¿þ¾î°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é, Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
-
The Novell LanWorkPlace page¿¡¼ tcpip16.exe¸¦ ´Ù¿î·ÎµåÇÑ´Ù.
-
c:\nwclient\startnet.bat¸¦ ÆíÁýÇÑ´Ù
: (ÇÊÀÚ°¡ ¾²´Â ÈÀÏ ³»¿ëÀÌ´Ù)
SET NWLANGUAGE=ENGLISH
LH LSL.COM
LH KTC2000.COM
LH IPXODI.COM
LH tcpip
LH VLM.EXE
F:
-
c:\nwclient\net.cfg¸¦ ÆíÁýÇÑ´Ù
: (link driver´Â ¿©·¯ºÐ¿¡ ¸Â°Ô ¼öÁ¤ÇÑ´Ù. ¿¹¸¦ µé¸é NE2000)
Link Driver KTC2000
Protocol IPX 0 ETHERNET_802.3
Frame ETHERNET_802.3
Frame Ethernet_II
FRAME Ethernet_802.2
NetWare DOS Requester
FIRST NETWORK DRIVE = F
USE DEFAULTS = OFF
VLM = CONN.VLM
VLM = IPXNCP.VLM
VLM = TRAN.VLM
VLM = SECURITY.VLM
VLM = NDS.VLM
VLM = BIND.VLM
VLM = NWP.VLM
VLM = FIO.VLM
VLM = GENERAL.VLM
VLM = REDIR.VLM
VLM = PRINT.VLM
VLM = NETX.VLM
Link Support
Buffers 8 1500
MemPool 4096
Protocol TCPIP
PATH SCRIPT C:\NET\SCRIPT
PATH PROFILE C:\NET\PROFILE
PATH LWP_CFG C:\NET\HSTACC
PATH TCP_CFG C:\NET\TCP
ip_address 192.168.0.xxx
ip_router 192.168.0.1
À§ÀÇ "ip_address" ºÎºÐÀº ¿©·¯ºÐÀÇ IP ÁÖ¼Ò·Î ÇÑ´Ù (192.168.0.x, 1 < x < 255)
±×¸®°í ¸¶Áö¸·À¸·Î c:\bin\resolv.cfg¸¦ ÆíÁýÇÑ´Ù:
SEARCH DNS HOSTS SEQUENTIAL
NAMESERVER xxx.xxx.xxx.xxx
NAMESERVER yyy.yyy.yyy.yyy
- À§ÀÇ "NAMESERVER" ºÎºÐÀº ¿©·¯ºÐÀÌ »ç¿ëÇÏ´Â DNS ¼¹ö·Î ´ëüÇÑ´Ù.
- °ÔÀÌÆ®¿þÀÌ ÄÄÇ»ÅÍ·ÎÀÇ ³×Æ®¿÷ ¿¬°áÀ» ½ÃÇèÇϱâ À§Çؼ
ping ¸í·ÉÀ» ÇÑ´Ù: ping 192.168.0.1
(À̰ÍÀº ´ÜÁö ³»ºÎ LAN ¿¬°áÀ» ½ÃÇèÇÏ´Â °ÍÀÌ´Ù. ¾ÆÁ÷Àº ¹Ù±ù ¼¼°è·Î ping À» ÇÒ ¼ö°¡ ¾ø´Ù.) PING ÇÑ °Í¿¡ ´ëÇØ ÀÀ´äÀÌ ¾ø´Ù¸é ³×Æ®¿÷ ¼³Á¤À» ´Ù½Ã È®ÀÎÇÑ´Ù.
4.9 OS/2 WarpÀÇ ¼³Á¤
- ÀÌ´õ³Ý ¾î´ðÅ͸¦ À§ÇÑ ÀûÀýÇÑ µå¶óÀ̹ö ¼ÒÇÁÆ®¿þ¾î°¡ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù. µå¶óÀ̹ö ¼³Ä¡¿¡ °üÇÑ °ÍÀº ÀÌ ¹®¼¿¡¼ ´Ù·çÁö ¾Ê´Â´Ù.
- TCP/IP ÇÁ·ÎÅäÄÝÀÌ ¾ÆÁ÷ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é Áö±Ý ¼³Ä¡ÇÑ´Ù.
- Programs/TCP/IP (LAN) / TCP/IP ¼³Á¤À¸·Î °£´Ù.
- 'Network'¿¡¼ TCP/IP ÁÖ¼Ò(192.168.0.x)¸¦ ÀÔ·ÂÇÏ°í ³×Æ®¿÷ ¸¶½ºÅ©¸¦ ¼³Á¤ÇÑ´Ù(255.255.255.0).
- 'Routing'¿¡¼ 'Add'¸¦ ´©¸¥´Ù. TypeÀº 'default'·Î Çϰí 'Router Address' ºÎºÐ¿¡¼ ¸®´ª½º È£½ºÆ®ÀÇ IP ÁÖ¼Ò¸¦ ÀÔ·ÂÇÑ´Ù(192.168.0.1).
- 'Hosts'¿¡ ¸®´ª½º È£½ºÆ®°¡ »ç¿ëÇϰí ÀÖ´Â DNS (Nameserver) ÁÖ¼Ò¿Í °°ÀÌ ¼³Á¤ÇØ ÁØ´Ù.
- TCP/IP control panelÀ» ´Ý°í µÚÀÌ¾î ³ª¿À´Â Áú¹®µé¿¡ yes¸¦ ´äÇÑ´Ù.
- ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÑ´Ù.
- ³×Æ®¿÷ ¼³Á¤À» ½ÃÇèÇϱâ À§Çؼ ¸®´ª½º È£½ºÆ®¸¦ ping ÇÒ ¼öµµ ÀÖ´Ù. 'OS/2 Command prompt Window'¿¡¼
'ping 192.168.0.1'¶ó°í ÀÔ·ÂÇÑ´Ù. ping ÆÐŶÀÌ µ¹¾Æ¿À¸é ¸ðµç°Ô Á¦´ë·Î ¼³Á¤µÈ °ÍÀÌ´Ù.
4.10 ±×¿Ü ´Ù¸¥ ½Ã½ºÅÛÀÇ ¼³Á¤
±×¿Ü ´Ù¸¥ ½Ã½ºÅÛÀ» ¼³Á¤ÇÒ ¶§¿¡µµ Áö±Ý±îÁö¿Í °°Àº ¹æ½ÄÀ» »ç¿ëÇÑ´Ù. À§ÀÇ ¼½¼ÇµéÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù. À§¿¡¼ ´Ù·çÁö ÀÖÁö ¾Ê´Â ½Ã½ºÅÛ¿¡¼ÀÇ ¼³Á¤¿¡ ´ëÇØ¼ ±ÛÀ» ½á ÁÖ½Ç ºÐÀº, ±× ÀÚ¼¼ÇÑ ¼³Á¤°úÁ¤À»
ambrose@writeme.com°ú
dranch@trinnet.netÀ¸·Î º¸³»Áֱ⠹ٶõ´Ù.
ÀÌÁ¦ ¸¶Áö¸·À¸·Î, IP ¸¶½ºÄ¿·¹À̵ùÀ» ½ÃÇèÇÒ ¶§´Ù. ¸®´ª½º È£½ºÆ®¸¦ ¾ÆÁ÷ ÀçºÎÆÃÇØº¸Áö ¾Ê¾Ò´Ù¸é, Áö±Ý ÀçºÎÆÃÇÏ°í ºÎÆÃÀÌ ¼º°øÇÏ´ÂÁö È®ÀÎÇϰí, /etc/rc.d/rc.firewall Á¤Ã¥À» ½ÇÇàÇÑ´Ù. ´ÙÀ½À¸·Î, ³»ºÎ LAN°úÀÇ ¿¬°á°ú ¿ÜºÎ ÀÎÅͳÝÀ¸·ÎÀÇ ¿¬°áÀÌ Á¦´ë·Î µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
ÀÌÁ¦ ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù:
- ù¹øÂ°: ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼, ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»ÅÍ·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.10 °ú °°ÀÌ). À̰ÍÀ¸·Î ³»ºÎ LANÀÇ ÄÄÇ»ÅÍ¿¡¼ TCP/IP°¡ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à Á¦´ë·Î µÇÁö ¾Ê´Â´Ù¸é, ³»ºÎ ÄÄÇ»Å͵鿡¼ TCP/IP ¼³Á¤À» ÀÌ HOWTO¿¡¼ ¼³¸íÇÑ ´ë·Î Á¦´ë·Î Çß´ÂÁö ´Ù½Ã È®ÀÎÇÑ´Ù.
- µÎ¹øÂ°: ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö ÀÚü¿¡¼, ¸¶½ºÄ¿·¹ÀÌµå ³»Æ®¿÷ ³»ºÎÀÇ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.1°ú °°ÀÌ). ÀÌÁ¦ ÀÎÅÍ³Ý »óÀÇ ¿ÜºÎ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù. ÀÌ ¿ÜºÎÀÇ ÁÖ¼Ò´Â ISP¿¡ ¿¬°áµÈ ÀÚ±â ÀÚ½ÅÀÇ PPP, ÀÌ´õ³Ý µîÀÇ ÁÖ¼Ò¿©µµ µÈ´Ù. ÀÌ IP ÁÖ¼Ò¸¦ ¸ð¸¥´Ù¸é, "/sbin/ifconfig"¶ó°í ¸í·ÉÇØ¼ ÀÎÅÍ³Ý ÁÖ¼Ò¸¦ ¾Ë¾Æ³½´Ù. À̰ÍÀ¸·Î ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ ³×Æ®¿÷ÀÌ ¿ÂÀüÈ÷ ¿¬°áµÇ¾î ÀÖ´ÂÁö ¾Ë ¼ö°¡ ÀÖ´Ù.
- ¼¼¹øÂ°: ´Ù½Ã ¸¶½ºÄ¿·¹À̵ù µÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼, ¸¶½ºÄ¿·¹À̵ù ¸®´ª½º È£½ºÆ®ÀÇ ³»ºÎ ÀÌ´õ³Ý Ä«µå¿¡ ¿¬°áµÈ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù(¿¹¸¦ µé¸é ping 192.168.0.1°ú °°ÀÌ). À̰ÍÀ¸·Î ³»ºÎ ³×Æ®¿÷°ú ¶ó¿ìÆÃÀÌ Á¦´ë·Î µÇ°í ÀÖ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à À̰ÍÀÌ ½ÇÆÐÇÑ´Ù¸é, ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿Í ³»ºÎ ÄÄÇ»ÅÍÀÇ ÀÌ´õ³Ý Ä«µå°¡ "¹°¸®ÀûÀ¸·Î" ¿¬°áµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ÀÌ´Â ÀÌ´õ³Ý Ä«µå µÞ¸éÀ̳ª ÀÌ´õ³Ý Çãºê/½ºÀ§Ä¡(¸¸¾à ÀÖ´Ù¸é)ÀÇ LED°¡ Á¡µîÇÏ´ÂÁö È®ÀÎÇÏ¸é µÈ´Ù.
- ³×¹øÂ°: ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼, ¸¶½ºÄ¿·¹ÀÌµå ¼¹öÀÇ ¿ÜºÎ·Î ¿¬°áµÈ TCP/IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù. ÀÌ ÁÖ¼Ò´Â ISP¿¡ ¿¬°áµÈ ¿©·¯ºÐÀÇ PPP, ÀÌ´õ³Ý µîÀÇ ÁÖ¼ÒÀÏ °ÍÀÌ´Ù. ÀÌ ping Å×½ºÆ®·Î, ¸¶½ºÄ¿·¹À̵ù(ƯÈ÷ ICMP ¸¶½ºÄ¿·¹À̵ù)ÀÌ Á¦´ë·Î ÀÛµ¿Çϰí ÀÖ´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù. ¸¸¾à À̰ÍÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê´Â´Ù¸é, Ä¿³ÎÀÌ "ICMP Masquerading"À» Áö¿øÇϵµ·Ï µÇ¾î ÀÖ´ÂÁö¿Í /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¿¡¼ "IP Forwarding"À» Çã¿ëÇß´ÂÁö È®ÀÎÇÑ´Ù. /etc/rc.d/rc.firewall Á¤Ã¥ÀÌ Á¦´ë·Î ·ÎµåµÇ¾ú´ÂÁöµµ È®ÀÎÇÑ´Ù. /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¸¦ ¼öµ¿À¸·Î ½ÇÇàÇØ¼ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁöµµ È®ÀÎÇÑ´Ù.
¿©ÀüÈ÷ Á¦´ë·Î ÀÛµ¿ÇÏÁö ¾Ê´Â´Ù¸é, ´ÙÀ½ ¸í·ÉÀÇ Ãâ·ÂÀ» Àß È®ÀÎÇØ º»´Ù.
- "ifconfig" : ÀÎÅÍ³Ý ¿¬°áÀÌ UP µÇ¾î ÀÖ´ÂÁö¿Í ÀÎÅÍ³Ý ¿¬°á¿¡ Á¦´ë·Î µÈ IP ÁÖ¼Ò°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö¸¦ È®ÀÎÇÑ´Ù.
- "netstat -rn" : µðÆúÆ® °ÔÀÌÆ®¿þÀÌ(Gateway ºÎºÐ¿¡ 0.0.0.0ÀÌ ¾Æ´Ñ IP ÁÖ¼Ò°¡ ÀÖ´Â °Í)°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- "cat /proc/sys/net/ipv4/ip_forward" : "1"À» Ãâ·ÂÇÏ¸é ¸®´ª½º Æ÷¿öµùÀÌ Çã¿ëµÇ¾î ÀÖ´Â °ÍÀε¥ ÀÌ·¸°Ô ³ª¿À´ÂÁö È®ÀÎÇÑ´Ù.
- Ä¿³Î 2.0.x¿¡¼´Â "/sbin/ipfwadm -F -l", Ä¿³Î 2.2.x¿¡¼´Â "/sbin/ipchains -F -L" : ¸¶½ºÄ¿·¹À̵ùÀÌ È°¼ºÈ µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- ´Ù¼¸¹øÂ°: ¸¶½ºÄ¿·¹À̵ùµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼, ÀÎÅÍ³Ý»ó¿¡ ÀÖ´Â °íÁ¤ IP ÁÖ¼Ò·Î pingÀ» ÇØº»´Ù (¿¹¸¦ µé¸é, ping 152.19.254.81 ¿Í °°ÀÌ (ÀÌ ÁÖ¼Ò´Â LDP ȨÆäÀÌÁöÀÎ http://metalab.unc.edu ÀÇ ÁÖ¼ÒÀÌ´Ù). À̰ÍÀÌ µ¿ÀÛÇϸé, ÀÎÅͳÝÀ» ÇâÇÑ ICMP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î ÀÌ·ç¾îÁö°í ÀÖ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. ¸¸¾à µ¿ÀÛÇÏÁö ¾ÊÀ¸¸é, ÀÎÅÍ³Ý ¿¬°áÀ» ´Ù½Ã È®ÀÎÇÑ´Ù. ´Ù½Ã È®ÀÎÇߴµ¥µµ µ¿ÀÛÇÏÁö ¾ÊÀ¸¸é, ¿¹·Î µç °£´ÜÇÑ rc.firewall Á¤Ã¥À» »ç¿ëÇϰí ÀÖ´ÂÁö¿Í Ä¿³ÎÀ» ICMP ¸¶½ºÄ¿·¹À̵ùÀ» Æ÷ÇÔÇÏ¿© ÄÄÆÄÀÏÇß´ÂÁö È®ÀÎÇÑ´Ù.
- ¿©¼¸¹øÂ°: ÀÌÁ¦ ¿ÜºÎÀÇ "IP ÁÖ¼Ò"·Î telnetÀ» ÇØº»´Ù(¿¹¸¦ µé¸é telnet 152.2.254.81 (metalab.unc.edu - ÀÌ ¼¹ö´Â ºÎÇϰ¡ ¸¹ÀÌ °É¸®±â ¶§¹®¿¡ ·Î±ä ÇÁ·ÒÇÁÆ®¸¦ ¹Þ±â±îÁö ½Ã°£ÀÌ °É¸± ¼öµµ ÀÖ´Ù). ¾î´ÀÁ¤µµ ½Ã°£ÀÌ Áö³ ÈÄ¿¡ ·Î±ä ÇÁ·ÒÇÁÆ®¸¦ ¹Þ´Â°¡? À̰ÍÀÌ ¼º°øÇϸé, TCP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù. ¸¸¾à ¼º°øÇÏÁö ¸øÇß´Ù¸é, telnetÀ» Áö¿øÇÏ´Â °Í Áß¿¡¼ ¿©·¯ºÐÀÌ ¾Ë°í ÀÖ´Â °÷À» ½ÃµµÇØ º»´Ù. (¿¹¸¦ µé¸é 198.182.196.55 (www.linux.org). ¿©ÀüÈ÷ µ¿ÀÛÇÏÁö ¾Ê´Â´Ù¸é, ÇöÀç ¿¹·Î µç °£´ÜÇÑ rc.firewall Á¤Ã¥À» »ç¿ëÇϰí ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.
- Àϰö¹øÂ°: ÀÌÁ¦ ¿ÜºÎÀÇ "È£½ºÆ® À̸§"À¸·Î telnetÀ» ÇØº»´Ù(¿¹¸¦ µé¸é "telnet metalab.unc.edu" (152.2.254.81). À̰ÍÀÌ ¼º°øÇϸé, DNS°¡ Á¦´ë·Î µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù. À̰ÍÀº ¼º°øÇÏÁö ¸øÇßÁö¸¸ "³×¹øÂ°" ´Ü°è´Â ¼º°øÇß´Ù¸é, ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡ DNS ¼¹ö°ü·Ã ¼³Á¤À» Á¦´ë·Î Çß´ÂÁö È®ÀÎÇÑ´Ù.
- ¿©´ü¹øÂ°: ¸¶Áö¸· ½ÃÇèÀ¸·Î½á, ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡¼ À¥ ºê¶ó¿ìÁ®¸¦ ÅëÇØ¼ 'INTERNET'»óÀÇ WWW »çÀÌÆ®¸¦ ¿¾îº¸°í ºê¶ó¿ìÁ®¿¡ Ç¥½Ã°¡ µÇ´ÂÁö È®ÀÎÇÑ´Ù. ¿¹¸¦ µé¾î¼,
Linux Documentation Project site¸¦ Á¢¼ÓÇØ º»´Ù. À̰ÍÀÌ ¼º°øÇϸé, ¸ðµç °ÍÀÌ ÈǸ¢ÇÏ°Ô µ¿ÀÛÇϰí ÀÖ´Â °ÍÀÌ´Ù!
¸®´ª½º ¹®¼ ÇÁ·ÎÁ§Æ®ÀÇ È¨ÆäÀÌÁö¸¦ º¼ ¼ö ÀÖ´Ù¸é, ÃàÇÏÇÑ´Ù! ¼º°øÇß´Ù!
ÀÌ À¥ »çÀÌÆ®¸¦ Á¦´ë·Î º¼ ¼ö ÀÖ´Ù¸é, PING, TELNET, SSHµîÀÇ Ç¥ÁØ ³×Æ®¿÷ Åë½Åµé°ú, °ü·ÃµÈ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» ÀûÀçÇϸé FTP, Real Audio, IRC DCCs, Quake I/II/III, CuSeeme, VDOLiveµîµµ Á¦´ë·Î µ¿ÀÛÇÒ °ÍÀÌ´Ù! FTP, IRC, RealAudio, Quake I/II/IIIµîÀÌ Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê°Å³ª ºÎ½ÇÇÏ°Ô µ¿ÀÛÇÑ´Ù¸é, "lsmod"¸í·ÉÀ¸·Î °ü·ÃµÈ ¸¶½ºÄ¿·¹À̵ù ¸ðµâµéÀÌ Á¦´ë·Î ÀûÀçµÇ¾î ÀÖ´ÂÁö È®ÀÎÇϰųª ºÎÀûÀýÇÑ ¼¹ö Æ÷Æ®·Î ÀûÀçµÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ÇÊ¿äÇÑ ¸ðµâÀÌ ÀûÀçµÇ¾î ÀÖÁö ¾Ê´Ù¸é, /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®°¡ ±× ¸ðµâµéÀ» ÀûÀçÇϵµ·Ï µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. (¿¹¸¦ µé¸é ÇØ´ç IP ¸¶½ºÄ¿·¹À̵ù ¸ðµâÀÌ ÀÖ´Â ºÎºÐÀÌ "#" ¹®ÀÚ¸¦ Á¦°Å)
6.1 IP ¸¶½ºÄ¿·¹À̵åÀÇ ¹®Á¦Á¡
¾î¶² TCP/IP ÀÀ¿ë ÇÁ·Î±×·¥µéÀÇ ÇÁ·ÎÅäÄÝÀº, Æ÷Æ® ¹øÈ£¿¡ ´ëÇÑ °ÍµéÀ» Àڱ⠳ª¸§´ë·Î °¡Á¤Çϰųª ±×µé µ¥ÀÌÅÍÀÇ TCP/IP ÁÖ¼Ò³ª Æ÷Æ® ¹øÈ£¸¦ ¾ÏÈ£ÈÇϱ⠶§¹®¿¡, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼´Â Á¦´ë·Î µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. ¾ÏÈ£È ¶§¹®¿¡ ¹®Á¦°¡ µÇ´Â ÇÁ·ÎÅäÄÝÀ» »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µéÀº, ƯÁ¤ÇÑ ÇÁ·Ï½Ã ¼¹ö¶óµç°¡, ¸¶½ºÄ¿·¹À̵ù ÄÚµå ³»¿¡ ƯÁ¤ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» Ãß°¡ÇØ¾ß ÀÛµ¿ÇÑ´Ù.
6.2 ¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼ºñ½º
±âº»ÀûÀ¸·Î, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀº ¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼ºñ½ºµéÀ» ÀüÇô ó¸®ÇÏÁö ¸øÇÑ´Ù. ÇÏÁö¸¸, À̰ÍÀ» ó¸®ÇÒ ¼ö ÀÖ´Â ¸î°¡Áö ¹æ¹ýÀÌ ÀÖ´Ù.
¸¸¾à ³ôÀº ¼öÁØÀÇ º¸¾ÈÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù¸é, °£´ÜÈ÷ ¿äûÀÌ µé¾î¿À´Â IP Æ÷Æ®¸¦ Æ÷¿öµùÇØ ÁÖ¸é µÈ´Ù. À̸¦ ¼öÇàÇÏ´Â ¹æ¹ýÀº ¿©·¯°¡Áö°¡ ÀÖÁö¸¸, °¡Àå ¾ÈÁ¤ÀûÀÎ ¹æ¹ýÀº IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â
Forwarders
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼ºñ½ºµé¿¡ ´ëÇØ¼ ¾î´ÀÁ¤µµÀÇ ÀÎÁõÀýÂ÷¸¦ °®°Ô ÇÏ·Á¸é, TCP-wrappers³ª Xinetd µîÀ» »ç¿ëÇØ¼ ƯÁ¤ÇÑ IP ÁÖ¼Ò¸¸ Åë°ú½Ãų ¼ö ÀÖ´Ù. ±× µµ±¸³ª Á¤º¸¸¦ ¾ò±â À§Çؼ´Â TIS Firewall ToolkitÀ» »ìÆìº¸¸é ÁÁÀ» °ÍÀÌ´Ù.
¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â ¼ºñ½ºÀÇ º¸¾È¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº
TrinityOS ¹®¼¿Í
IP Masquerade Resource¿¡¼ ãÀ» ¼ö ÀÖÀ» °ÍÀÌ´Ù.
6.3 Áö¿øµÇ´Â Ŭ¶óÀÌ¾ðÆ® ¼ÒÇÁÆ®¿þ¾î¿Í ±×¿Ü ¼³Á¤¿¡ ´ëÇØ ¾Ë¾ÆµÑ Á¡
**
Linux Masquerade Application list¿¡¼ ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ùÀ» ÅëÇØ¼ µ¿ÀÛÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µé¿¡ °üÇÑ ´Ù·®ÀÇ ¿ì¼öÇÑ Á¤º¸µéÀ» ¾òÀ» ¼ö ÀÖ´Ù. ÀÌ »çÀÌÆ®´Â ÇöÀç Steve Grevemeyer°¡ °ü¸®Çϰí ÀÖÀ¸¸ç, ±×´Â dzºÎÇÑ µ¥ÀÌŸº£À̽º¸¦ ±¸ÃàÇØ ³õ¾Ò´Ù. ¾ÆÁÖ ÈǸ¢ÇÑ Á¤º¸ÀÚ¿øÀÌ´Ù!
ÀϹÝÀûÀ¸·Î, Ç¥ÁØ TCP¿Í UDP¸¦ »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µéÀº Àß ÀÛµ¿ÇÒ °ÍÀÌ´Ù. ¸¸¾à ¾î¶°ÇÑ Á¦¾ÈÀ̳ª ÈùÆ®µîÀÌ ÀÖ´Ù¸é
IP Masquerade Resource¸¦ È®ÀÎÇØ¼ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇϱ⠹ٶõ´Ù.
IP ¸¶½ºÄ¿·¹À̵å¿Í ÇÔ²² -µ¿ÀÛÇÏ´Â- ³×Æ®¿÷ Ŭ¶óÀÌ¾ðÆ®µé
ÀϹÝÀûÀΠŬ¶óÀÌ¾ðÆ®µé:
- Archie
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, ÈÀÏ °Ë»ö Ŭ¶óÀÌ¾ðÆ® (¸ðµç archie Ŭ¶óÀÌ¾ðÆ®°¡ Áö¿øµÇÁö´Â ¾Ê´Â´Ù).
- FTP
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, active FTP Á¢¼ÓÀ» À§Çؼ ip_masq_ftp.o Ä¿³Î ¸ðµâ »ç¿ë.
- Gopher client
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû.
- HTTP
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, À¥ ¼ÇÎ.
- IRC
Áö¿øµÇ´Â ¿©·¯°¡Áö Ç÷§Æû¿¡¼ µ¿ÀÛÇÏ´Â ¸ðÀº IRC Ŭ¶óÀ̾ðÆ®, DCC´Â ip_masq_irc.o ¸ðµâÀ» ÅëÇØ¼ Áö¿ø.
- NNTP (USENET)
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, USENET ´º½º Ŭ¶óÀ̾ðÆ®.
- PING
¸ðµç Ç÷§Æû, ICMP ¸¶½ºÄ¿·¹À̵ù Ä¿³Î ¿É¼Ç »ç¿ë
- POP3
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, À̸ÞÀÏ Å¬¶óÀ̾ðÆ®.
- SSH
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, º¸¾È»ó ¾ÈÀüÇÑ TELNET/FTP Ŭ¶óÀ̾ðÆ®.
- SMTP
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, Sendmail, Qmail, PostFixµîÀÇ À̸ÞÀÏ ¼¹ö.
- TELNET
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, ¿ø°Ý Á¢¼Ó.
- TRACEROUTE
UNIX¿Í Windows ±â¹Ý Ç÷§Æû, ¸î°¡Áö º¯Á¾µéÀº µ¿ÀÛÇÏÁö ¾ÊÀ» ¼ö ÀÖ´Ù.
- VRML
Windows(Áö¿øµÇ´Â ¸ðµç Ç÷§Æû¿¡¼µµ ¾î¼¸é °¡´É), °¡»ó Çö½Ç.
- WAIS client
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû.
¸ÖƼ¹Ìµð¾î¿Í Åë½Å Ŭ¶óÀ̾ðÆ®:
- Alpha Worlds
Windows, Ŭ¶óÀ̾ðÆ®-¼¹ö ¹æ½ÄÀÇ 3D äÆÃ ÇÁ·Î±×·¥.
- CU-SeeMe
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû, ip_masq_cuseeme ¸ðµâ »ç¿ë, ÀÚ¼¼ÇÑ »çÇ×Àº
CuSeeme
¼½¼Ç ÂüÁ¶.
- ICQ
Áö¿øµÇ´Â ¸ðµç Ç÷§Æû. ¸®´ª½º Ä¿³ÎÀÌ IPPORTFW¸¦ Áö¿øÇϵµ·Ï ÄÄÆÄÀϵǾî¾ß Çϸç, ICQ°¡ NON-SOCKS ÇÁ·Ï½Ã µÚÂÊ¿¡¼ µ¿ÀÛÇϵµ·Ï ¼³Á¤µÇ¾î¾ß ÇÑ´Ù. ÀÌ ¼³Á¤¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ¼³¸íÀº
ICQ
¼½¼Ç¿¡¼ È®ÀÎÇÒ ¼ö ÀÖ´Ù.
- Internet Phone 3.2
Windows, Peer-to-peer ¹æ½ÄÀÇ À½¼º Åë½Å, ´ç½ÅÀÌ Åëȸ¦ ¿äûÇÏ´Â °æ¿ì¿¡´Â Åë½ÅÀÌ °¡´ÉÇÏÁö¸¸, ´Ù¸¥ »ç¶÷µéÀÌ ´ç½Å¿¡°Ô Åëȸ¦ ¿äûÇÒ ¼ö ÀÖ°Ô ÇÏ·Á¸é ƯÁ¤ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
- Internet Wave Player
Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio).
- Powwow
Windows, Peer-to-peer ¹æ½ÄÀÇ ÅØ½ºÆ®, À½¼º, ÂÊÁö Åë½Å, ´ç½ÅÀÌ Åëȸ¦ ¿äûÇÏ´Â °æ¿ì¿¡´Â Åë½ÅÀÌ °¡´ÉÇÏÁö¸¸, ´Ù¸¥ »ç¶÷µéÀÌ ´ç½Å¿¡°Ô Åëȸ¦ ¿äûÇÒ ¼ö ÀÖ°Ô ÇÏ·Á¸é ƯÁ¤ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
- Real Audio Player
Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio), ip_masq_raudio UDP ¸ðµâÀ» »ç¿ëÇÏ¸é ´õ ÁÁÀº À½ÁúÀ» ¾òÀ» ¼ö ÀÖ´Ù.
- True Speech Player 1.1b
Windows, ³×Æ®¿÷ ½ºÆ®¸®¹Ö ¿Àµð¿À(network streaming audio)
- VDOLive
Windows, ip_masq_vdolive ÆÐÄ¡ Àû¿ë.
- Worlds Chat 0.9a
Windows, Ŭ¶óÀ̾ðÆ®-¼¹ö ¹æ½ÄÀÇ 3D äÆÃ ÇÁ·Î±×·¥.
°ÔÀÓ - LooseUDP ÆÐÄ¡¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº
LooseUDP
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Battle.net
µ¿ÀÛÀº ÇÏÁö¸¸, TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù. FSGS¿Í Bnetd ¼¹ö´Â NAT¿Í Àß µ¿ÀÛÇϵµ·Ï ¸¸µé¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®¿¡ IPPORTFW¸¦ ÇÊ¿ä·Î ÇÑ´Ù.
- BattleZone 1.4
LooseUDP ÆÐÄ¡¸¦ ÇÏ°í »õ·Î¿î NAT¿Í Àß µ¿ÀÛÇÏ´Â
.DLLs from Activision¸¦ »ç¿ëÇÏ¸é µ¿ÀÛÇÑ´Ù.
- Dark Reign 1.4
LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Diablo
LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. DiabloÀÇ »õ·Î¿î ¹öÁ¯Àº TCP Æ÷Æ® 6112¿Í UDP Æ÷Æ® 6112¸¸À» »ç¿ëÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Heavy Gear 2
LooseUDP ÆÐÄ¡¸¦ Çϰųª TCP Æ÷Æ® 116°ú 118°ú UDP Æ÷Æ® 6112¸¦ °ÔÀÓÀ» ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ·Î IP Æ÷¿öµù(IPPORTFW)ÇØÁà¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Quake I/II/III
¹Ù·Î ÀÛµ¿ÇÏÁö¸¸, ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö µÚÂÊ¿¡ Quake I/II/III Ç÷¹À̾ µÎ ¸í ÀÌ»ó ÀÖÀ» ¶§¿¡´Â ip_masq_quake ¸ðµâÀÌ ÇÊ¿äÇÏ´Ù. ¶Ç,, ÀÌ ¸ðµâÀº ±âº»ÀûÀ¸·Î´Â Quake I°ú QuakeWorld¸¸ Áö¿øÇÑ´Ù. Quake II¸¦ Áö¿øÇÏ°Ô Çϰųª ¼¹ö¿¡ ±âº»À¸·Î Á¤ÇØÁø ÀÌ¿ÜÀÇ Æ÷Æ®·Î Á¢¼ÓÇϰíÀÚ ÇÒ ¶§¿¡´Â,
rc.firewall-2.0.x
¿Í
rc.firewall-2.2.x
ÀÇ ¸ðµâ ¼³Ä¡ ¼½¼ÇÀ» ÂüÁ¶Ç϶ó.
- StarCraft
LooseUDP ÆÐÄ¡¸¦ Çϰí TCP¿Í UDPÀÇ 6112¹ø Æ÷Æ®¸¦ ¸¶½ºÄ¿·¹À̵ù ³»ºÎÀÇ °ÔÀÓÀ» ½ÇÇàÇÏ·Á´Â ÄÄÇ»ÅÍ·Î Æ÷¿öµù(IPPORTFW)ÇØÁÖ¾î¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- WorldCraft
LooseUDP ÆÐÄ¡¸¦ ÇÏ¸é µ¿ÀÛÇÑ´Ù.
±×¿ÜÀÇ Å¬¶óÀÌ¾ðÆ®µé:
- Linux net-acct package
Linux, ³×Æ®¿÷ °ü¸®-¾îÄ«¿îÆÃ °ü·Ã ÆÐŰÁö
- NCSA Telnet 2.3.08
DOS, TELNET, FTP, PINGµîÀÌ Æ÷ÇÔµÈ ÆÐŰÁö
- PC-anywhere for Windows
MS-Windows, TCP/IP¸¦ ÅëÇØ¼ ¿ø°ÝÀ¸·Î PC¸¦ Á¦¾îÇÑ´Ù. ƯÁ¤ÇÑ Æ÷Æ®¸¦ Æ÷¿öµùÇϵµ·Ï ¼³Á¤ÇÏÁö ¾ÊÀ¸¸é, Ŭ¶óÀÌ¾ðÆ®·Î´Â µ¿ÀÛÇÏÁö¸¸ È£½ºÆ®(¼¹ö)·Î´Â µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Socket Watch
NTP »ç¿ë - ³×Æ®¿÷ ½Ã°£Á¶Àý ÇÁ·ÎÅäÄÝ
µ¿ÀÛÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®:
- All H.323 programs
- MS Netmeeting, Intel Internet Phone Beta 2 - ¿¬°áÀº µÇÁö¸¸ ¸ñ¼Ò¸®´Â ÇÑÂÊÀ¸·Î¸¸(³ª°¡´Â ÂÊ) Àü´ÞµÈ´Ù. À̸¦ ÇØ°á °¡´ÉÇÑ ¹æ¹ýÀ¸·Î½á,
Equivalence's PhonePatch H.323 gateway¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.
- Intel Streaming Media Viewer Beta 1
¼¹ö¿¡ ¿¬°áÇÒ ¼ö ¾ø´Ù.
- Netscape CoolTalk
»ó´ëÆí¿¡ ¿¬°áÇÒ ¼ö ¾ø´Ù.
- WebPhone
ÇöÀç´Â µ¿ÀÛÇÏÁö ¾Ê´Â´Ù. (ÀÌ ÀÀ¿ëÇÁ·Î±×·¥Àº IP ÁÖ¼Ò¿¡ ´ëÇÑ À߸øµÈ °¡Á¤À» ÇÑ´Ù.)
6.4 º¸¾È °µµ°¡ º¸´Ù ³ôÀº IP ¹æÈº®(IPFWADM) Á¤Ã¥
ÀÌ ¼½¼Ç¿¡´Â Ä¿³Î 2.0.x¿¡¼ »ç¿ëµÇ´Â ¹æÈº® µµ±¸ÀÎ IPFWADM¿¡ ´ëÇÑ ´õ ½Éµµ ÀÖ´Â ¾È³»°¡ ½Ç·Á ÀÖ´Ù. IPCHAINS(2.2.x ¿ë)ÀÇ Á¤Ã¥µé¿¡ ´ëÇØ¼´Â ´ÙÀ½ ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
ÀÌ ¿¹´Â ¹æÈº®/¸¶½ºÄ¿·¹ÀÌµå ½Ã½ºÅÛÀ» °íÁ¤ ÁÖ¼Ò¸¦ °¡Áø PPP Á¢¼ÓÀ» ÅëÇØ¼ ±¸ÃàÇÏ´Â °ÍÀÌ´Ù.(µ¿Àû PPP¿¡ °üÇÑ °Íµµ Æ÷ÇԵǾî ÀÖÁö¸¸ ÄÚ¸àÆ® 󸮵Ǿî ÀÖ´Ù.) »ç¿ëµÈ ÀÎÅÍÆäÀ̽º´Â 192.168.0.1À̰í, PPP ÀÎÅÍÆäÀ̽ºÀÇ IP ÁÖ¼Ò´Â À߸øµÈ »ç¿ëÀ» ¿ì·ÁÇØ¼ ½ÇÁ¦¿Í ´Ù¸¥ ÁÖ¼Ò·Î ´ëüµÇ¾ú´Ù :) IP ½ºÇªÇÎ(¼ÓÀÓ)°ú ºÎÁ¤ÀûÀÎ ¶ó¿ìÆÃÀ̳ª ¸¶½ºÄ¿·¹À̵ùÀ» °ËÃâÇϱâ À§Çؼ µé¾î¿À°í ³ª°¡´Â ÀÎÅÍÆäÀ̽º¸¦ µû·Î µû·Î Àû¾ú´Ù. ¸í½ÃÀûÀ¸·Î Çã¿ëµÇÁö ¾ÊÀº °ÍÀº ±ÝÁöµÇ¾î ÀÖ´Ù (½ÇÁ¦ÀûÀ¸·Î´Â °ÅºÎµÈ´Ù). ¿©±â¿¡ ³ª¿Â rc.firewall ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ°í ³ª¼ IP ¸¶½ºÄ¿·¹ÀÌµå ¹Ú½º°¡ Á״´ٸé, ¿©·¯ºÐÀÇ »óȲ¿¡ ¸Âµµ·Ï ÆíÁýÀ» Çß´ÂÁö¸¦ È®ÀÎÇϰí, /var/log/messages³ª /var/adm/messagesÀÇ ½Ã½ºÅÛ ·Î±×ÈÀÏÀ» °ËÅäÇÑ´Ù.
PPP, ÄÉÀ̺í¸ðµ© µî¿¡ ´ëÇØ¼ Á»´õ ÀÌÇØÇϱ⠽¬¿î, "°µµ ³ôÀº IP ¸¶½ºÄ¿·¹À̵ùÀÇ IPFWADM Á¤Ã¥"¿¡ ´ëÇØ¼´Â,
TrinityOS - Section 10¿Í
GreatCircle's Firewall WWW page¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.
ÁÖÀÇ: ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ© µî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Ò´Ù¸é ºÎÆÃ½Ã¿¡ ÀÌ "°µµ ³ôÀº" Á¤Ã¥À» ·ÎµåÇÒ ¼ö ¾ø´Ù. µ¿ÀûÀ¸·Î IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÀ» ¶§¸¶´Ù ¹æÈº® Á¤Ã¥ÈÀÏÀ» ´Ù½Ã ·ÎµåÇϰųª, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. PPP À¯ÀúÀÇ °æ¿ì¿¡´Â, "Dynamic PPP IP fetch" ºÎºÐÀ» ÁÖÀÇ ±í°Ô ´Ù½Ã ÀÐ¾î º¸°í¼ ÀûÀýÇÑ ºÎºÐÀÇ ÄÚ¸ÇÆ®¸¦ ÇØÁ¦ÇØ ÁØ´Ù. °µµ ³ôÀº ¹æÈº® Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ´õ ÀÚ¼¼ÇÑ »çÇ×Àº
TrinityOS - Section 10 ¹®¼¸¦ ÂüÁ¶ÇÑ´Ù.
¶ÇÇÑ ¸î°¡ÁöÀÇ GUI ¹æ½ÄÀÇ ¹æÈº® ¼³Á¤ µµ±¸°¡ ÀÖ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
FAQ
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
¸¶Áö¸·À¸·Î, °íÁ¤ PPP IP ÁÖ¼Ò¸¦ »ç¿ëÇϰí ÀÖ´Ù¸é, "ppp_ip = "your.static.PPP.address"" ¶ó°í µÇ¾î ÀÖ´Â ÁÙÀ» ¿©·¯ºÐÀÇ IP ÁÖ¼Ò¿¡ ¸Â°Ô ¹Ù²Û´Ù.
----------------------------------------------------------------
#!/bin/sh
#
# /etc/rc.d/rc.firewall: An example of a semi-STRONG IPFWADM firewall ruleset
#
PATH=/sbin:/bin:/usr/sbin:/usr/bin
# testing, wait a bit then clear all firewall rules.
# uncomment following lines if you want the firewall to automatically
# disable after 10 minutes.
# (sleep 600; \
# ipfwadm -I -f; \
# ipfwadm -I -p accept; \
# ipfwadm -O -f; \
# ipfwadm -O -p accept; \
# ipfwadm -F -f; \
# ipfwadm -F -p accept; \
# ) &
# Load all required IP MASQ modules
#
# NOTE: Only load the IP MASQ modules you need. All current IP MASQ modules
# are shown below but are commented from loading.
# Needed to initially load modules
#
/sbin/depmod -a
# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp
# Supports the masquerading of RealAudio over UDP. Without this module,
# RealAudio WILL function but in TCP mode. This can cause a reduction
# in sound quality
#
#/sbin/modprobe ip_masq_raudio
# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc
# Supports the masquerading of Quake and QuakeWorld by default. This modules is
# for for multiple users behind the Linux MASQ server. If you are going to play
# Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960
# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme
#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive
#CRITICAL: Enable IP forwarding since it is disabled by default since
#
# Redhat Users: you may try changing the options in /etc/sysconfig/network from:
#
# FORWARD_IPV4=false
# to
# FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward
# Dynamic IP users:
#
# If you get your IP address dynamically from SLIP, PPP, or DHCP, enable this following
# option. This enables dynamic-ip address hacking in IP MASQ, making the life
# with Diald and similar programs much easier.
#
#echo "1" > /proc/sys/net/ipv4/ip_dynaddr
# Specify your Static IP address here.
#
# If you have a DYNAMIC IP address, you need to make this ruleset understand your
# IP address everytime you get a new IP. To do this, enable the following one-line
# script. (Please note that the different single and double quote characters MATTER).
#
# You will also need to either create the following link or have your existing
# /etc/ppp/ip-up script run the /etc/rc.d/rc.firewall script.
#
# ln -s /etc/rc.d/rc.firewall /etc/ppp/ip-up
#
# If the /etc/ppp/ip-up file already exists, you should edit it and add a line
# containing "/etc/rc.d/rc.firewall" near the end of the file.
#
# If you aren't already aware, the /etc/ppp/ip-up script is always run when a PPP
# connection comes up. Because of this, we can make the ruleset go and get the
# new PPP IP address and update the strong firewall ruleset.
#
# PPP users: If your Internet connect is via a PPP connection, the following
one-line script will work fine.
#
# DHCP users: If you get your TCP/IP address via DHCP, you will need to replace
# the word "ppp0" with the name of your external Internet connection
# (eth0, eth1, etc). It should be also noted that DHCP can change
# IP addresses on you. To fix this, users should configure their
# DHCPc or DHCP client to re-run the firewall ruleset when their
# DHCP lease is renewed. For DHCPcd users, use the "-c" option.
#
#ppp_ip = "`/sbin/ifconfig ppp0 | grep 'inet addr' | awk '{print $2}' | sed -e 's/.*://'`"
#
ppp_ip = "your.static.PPP.address"
# MASQ timeouts
#
# 2 hrs timeout for TCP session timeouts
# 10 sec timeout for traffic after the TCP/IP "FIN" packet is received
# 60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself)
#
/sbin/ipfwadm -M -s 7200 10 60
#############################################################################
# Incoming, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -I -f
/sbin/ipfwadm -I -p reject
# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0
# remote interface, claiming to be local machines, IP spoofing, get lost
#
/sbin/ipfwadm -I -a reject -V $ppp_ip -S 192.168.0.0/24 -D 0.0.0.0/0 -o
# remote interface, any source, going to permanent PPP address is valid
#
/sbin/ipfwadm -I -a accept -V $ppp_ip -S 0.0.0.0/0 -D $ppp_ip/32
# loopback interface is valid.
#
/sbin/ipfwadm -I -a accept -V 127.0.0.1 -S 0.0.0.0/0 -D 0.0.0.0/0
# catch all rule, all other incoming is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -I -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o
#############################################################################
# Outgoing, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -O -f
/sbin/ipfwadm -O -p reject
# local interface, any source going to local net is valid
#
/sbin/ipfwadm -O -a accept -V 192.168.0.1 -S 0.0.0.0/0 -D 192.168.0.0/24
# outgoing to local net on remote interface, stuffed routing, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 0.0.0.0/0 -D 192.168.0.0/24 -o
# outgoing from local net on remote interface, stuffed masquerading, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 192.168.0.0/24 -D 0.0.0.0/0 -o
# outgoing from local net on remote interface, stuffed masquerading, deny
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S 0.0.0.0/0 -D 192.168.0.0/24 -o
# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip /32 -D 0.0.0.0/0
# loopback interface is valid.
#
/sbin/ipfwadm -O -a accept -V 127.0.0.1 -S 0.0.0.0/0 -D 0.0.0.0/0
# catch all rule, all other outgoing is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -O -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o
#############################################################################
# Forwarding, flush and set default policy of deny. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
/sbin/ipfwadm -F -f
/sbin/ipfwadm -F -p deny
# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0
#
# catch all rule, all other forwarding is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
/sbin/ipfwadm -F -a reject -S 0.0.0.0/0 -D 0.0.0.0/0 -o
IPFWADMÀ» »ç¿ëÇϸé, ¿©·¯ºÐÀº -I, -O, -F µîÀÇ ¿É¼ÇÀ» ÀÌ¿ëÇØ¼ ƯÁ¤ »çÀÌÆ®·ÎÀÇ Á¢±ÙÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. °¢ Á¤Ã¥ ¸í·ÉµéÀº À§¿¡¼ºÎÅÍ ¾Æ·¡·Î ÀÐÇôÁö°í, "-a" ´Â ±âÁ¸ÀÇ Á¤Ã¥¿¡ "µ¡ºÙÀδÙ"´Â °ÍÀ» À¯³äÇÑ´Ù. ±×·¯¹Ç·Î, ƯÁ¤ÇÑ Á¦ÇÑ »çÇ×Àº Àü¹ÝÀûÀÎ Á¤Ã¥º¸´Ù ¾Õ¿¡ ¿Í¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é:
-I ¸¦ »ç¿ëÇϸé, °¡Àå ºü¸£Áö¸¸ Á¦ÇÑ »çÇ×Àº ³»ºÎÀÇ ÄÄÇ»Å͵鿡°Ô¸¸ Àû¿ëµÈ´Ù. ¹æÈº® ÄÄÇ»ÅÍ ÀÚü´Â ¿©ÀüÈ÷ "±ÝÁöµÈ" »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù. ¹°·Ð ¿©·¯ºÐÀº À̰͵éÀ» Á¶ÇÕÇØ¼ »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.
/etc/rc.d/rc.firewall Á¤Ã¥ ÈÀÏ Áß¿¡¼:
... start of -I rules ...
# reject and log local interface, local machines going to 204.50.10.13
#
/sbin/ipfwadm -I -a reject -V 192.168.0.1 -S 192.168.0.0/24 -D 204.50.10.13/32 -o
# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0
... end of -I rules ...
-O ¸¦ »ç¿ëÇϸé, ÆÐŶµéÀÌ ¸¶½ºÄ¿·¹À̵ùÀ» ¸ÕÀú Åë°úÇϱ⠶§¹®¿¡ ¼Óµµ´Â °¡Àå ´À¸®Áö¸¸, ¹æÈº® ÄÄÇ»ÅÍ ÀÚüµµ ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ¾ø´Ù.
... start of -O rules ...
# reject and log outgoing to 204.50.10.13
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S $ppp_ip/32 -D 204.50.10.13/32 -o
# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip/32 -D 0.0.0.0/0
... end of -O rules ...
-F ¸¦ »ç¿ëÇϸé, -I ¸¦ »ç¿ëÇÑ °Íº¸´Ù´Â Á¶±Ý ´õ ´À¸®°í ¿ª½Ã ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â (³»ºÎÀÇ) ÄÄÇ»Å͵鸸 Á¦ÇÑÇÏ°í ¹æÈº® ÄÄÇ»ÅÍ ÀÚü´Â ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù.
... start of -F rules ...
# Reject and log from local net on PPP interface to 204.50.10.13.
#
/sbin/ipfwadm -F -a reject -W ppp0 -S 192.168.0.0/24 -D 204.50.10.13/32 -o
# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0
... end of -F rules ...
192.168.0.0/24°¡ 204.50.11.0·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇϱâ À§ÇØ Æ¯º°ÇÑ Á¤Ã¥ÀÌ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. Àü¹ÝÀûÀÎ Á¤Ã¥¿¡ Æ÷ÇԵǾî Àֱ⠶§¹®ÀÌ´Ù.
À§ÀÇ Á¤Ã¥ÈÀÏ¿¡¼ ÀÎÅÍÆäÀ̽º¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀº ¿©·¯°¡Áö°¡ ÀÖÀ» ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î¼, "-V 192.168.255.1" ´ë½Å¿¡ "-W eth0"¶ó°í ÀûÀ» ¼ö ÀÖ°í, "-V $ppp_ip" ´ë½Å¿¡ "-W ppp0"¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù. "-V" ¸¦ »ç¿ëÇÏ´Â °ÍÀº IPCHAINS¿ÍÀÇ È£È¯À» À§Çؼ »ç¿ëµÈ °ÍÀ̰í, IPFWADM¸¸À» »ç¿ëÇÑ´Ù¸é ÀüÀûÀ¸·Î »ç¿ëÀÚÀÇ ¼±ÅÃÀÌ´Ù.
6.5 º¸¾È °µµ°¡ º¸´Ù ³ôÀº IP ¹æÈº®(IPCHAINS) Á¤Ã¥
ÀÌ ¼½¼Ç¿¡´Â Ä¿³Î 2.2.x¿¡¼ »ç¿ëµÇ´Â ¹æÈº® µµ±¸ÀÎ IPCHAINS¿¡ ´ëÇÑ ´õ ½Éµµ ÀÖ´Â ¾È³»°¡ ½Ç·Á ÀÖ´Ù. IPFWADM(2.0.x ¿ë)ÀÇ Á¤Ã¥µé¿¡ ´ëÇØ¼´Â ÀÌÀü ¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
ÀÌ ¿¹´Â ¹æÈº®/¸¶½ºÄ¿·¹ÀÌµå ½Ã½ºÅÛÀ» °íÁ¤ ÁÖ¼Ò¸¦ °¡Áø PPP Á¢¼ÓÀ» ÅëÇØ¼ ±¸ÃàÇÏ´Â °ÍÀÌ´Ù.(µ¿Àû PPP¿¡ °üÇÑ °Íµµ Æ÷ÇԵǾî ÀÖÁö¸¸ ÄÚ¸àÆ® 󸮵Ǿî ÀÖ´Ù.) »ç¿ëµÈ ÀÎ>ÅÍÆäÀ̽º´Â 192.168.0.1À̰í, PPP ÀÎÅÍÆäÀ̽ºÀÇ IP ÁÖ¼Ò´Â À߸øµÈ »ç¿ëÀ» ¿ì·ÁÇØ¼ ½ÇÁ¦¿Í ´Ù¸¥ ÁÖ¼Ò·Î ´ëüµÇ¾ú´Ù :) IP ½ºÇªÇÎ(¼ÓÀÓ)°ú ºÎÁ¤ÀûÀÎ ¶ó¿ìÆÃÀ̳ª ¸¶½ºÄ¿·¹À̵ùÀ» °ËÃâÇϱâ À§Çؼ µé¾î¿À°í ³ª°¡´Â ÀÎÅÍÆäÀ̽º¸¦ µû·Î µû·Î Àû¾ú´Ù. ¸í½ÃÀûÀ¸·Î Çã¿ëµÇÁö ¾ÊÀº °ÍÀº ±ÝÁöµÇ¾î ÀÖ´Ù (½ÇÁ¦ÀûÀ¸·Î´Â °ÅºÎµÈ´Ù). ¿©±â¿¡ ³ª¿Â rc.firewall ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ°í ³ª¼ IP ¸¶½ºÄ¿·¹ÀÌµå ¹Ú½º°¡ Á״´ٸé, ¿©·¯ºÐÀÇ >»óȲ¿¡ ¸Âµµ·Ï ÆíÁýÀ» Çß´ÂÁö¸¦ È®ÀÎÇϰí, /var/log/messages³ª /var/adm/messagesÀÇ ½Ã½ºÅÛ ·Î±×ÈÀÏÀ» °ËÅäÇÑ´Ù.
PPP, ÄÉÀ̺í¸ðµ© µî¿¡ ´ëÇØ¼ Á»´õ ÀÌÇØÇϱ⠽¬¿î, "°µµ ³ôÀº IP ¸¶½ºÄ¿·¹À̵ùÀÇ IPFWADM Á¤Ã¥"¿¡ ´ëÇØ¼´Â,
TrinityOS - Section 10¿Í
GreatCircle's Firewall WWW page¸¦ ÂüÁ¶Çϱ⠹ٶõ´Ù.
ÁÖÀÇ #1: 2.2.11º¸´Ù ¹öÁ¯ÀÌ ³·Àº ¸®´ª½º 2.2.x Ä¿³ÎÀº
IPCHAINS fragmentation bug¸¦ °¡Áö°í ÀÖ´Ù. ÀÌ ¶§¹®¿¡, °µµ ³ôÀº IPCHAINS Á¤Ã¥À» »ç¿ëÇÏ¸é °ø°Ý¿¡ ³ëÃâµÇ°Ô µÈ´Ù. ¹ö±×°¡ ¼öÁ¤µÈ Ä¿³Î·Î ¾÷±×·¹À̵åÇϱ⠹ٶõ´Ù.
ÁÖÀÇ #2: ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ© µî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Ò´Ù¸é ºÎÆÃ½Ã¿¡ ÀÌ "°µµ ³ôÀº" Á¤Ã¥À» ·ÎµåÇÒ ¼ö ¾ø´Ù. µ¿ÀûÀ¸·Î IP ÁÖ¼Ò¸¦ ÇÒ´ç¹ÞÀ» ¶§¸¶´Ù ¹æÈº® Á¤Ã¥ÈÀÏÀ» ´Ù½Ã ·ÎµåÇϰųª, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. PPP À¯ÀúÀÇ °æ¿ì¿¡´Â, "Dynamic PPP IP fetch" >ºÎºÐÀ» ÁÖÀÇ ±í°Ô ´Ù½Ã ÀÐ¾î º¸°í¼ ÀûÀýÇÑ ºÎºÐÀÇ ÄÚ¸ÇÆ®¸¦ ÇØÁ¦ÇØ ÁØ´Ù. °µµ ³ôÀº ¹æÈº® Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ´õ ÀÚ¼¼ÇÑ »çÇ×Àº
TrinityOS - Section 10 >¹®¼¸¦ ÂüÁ¶ÇÑ´Ù.
¶ÇÇÑ ¸î°¡ÁöÀÇ GUI ¹æ½ÄÀÇ ¹æÈº® ¼³Á¤ µµ±¸°¡ ÀÖ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
FAQ
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
¸¶Áö¸·À¸·Î, °íÁ¤ PPP IP ÁÖ¼Ò¸¦ »ç¿ëÇϰí ÀÖ´Ù¸é, "ppp_ip = "your.static.PPP.address"" ¶ó°í µÇ¾î ÀÖ´Â ÁÙÀ» ¿©·¯ºÐÀÇ IP ÁÖ¼Ò¿¡ ¸Â°Ô ¹Ù²Û´Ù.
----------------------------------------------------------------
#!/bin/sh
#
# /etc/rc.d/rc.firewall: An example of a Semi-Strong IPCHAINS firewall ruleset.
#
PATH=/sbin:/bin:/usr/sbin:/usr/bin
# Load all required IP MASQ modules
#
# NOTE: Only load the IP MASQ modules you need. All current IP MASQ modules
# are shown below but are commented from loading.
# Needed to initially load modules
#
/sbin/depmod -a
# Supports the proper masquerading of FTP file transfers using the PORT method
#
/sbin/modprobe ip_masq_ftp
# Supports the masquerading of RealAudio over UDP. Without this module,
# RealAudio WILL function but in TCP mode. This can cause a reduction
# in sound quality
#
/sbin/modprobe ip_masq_raudio
# Supports the masquerading of IRC DCC file transfers
#
#/sbin/modprobe ip_masq_irc
# Supports the masquerading of Quake and QuakeWorld by default. This modules is
# for for multiple users behind the Linux MASQ server. If you are going to play
# Quake I, II, and III, use the second example.
#
#Quake I / QuakeWorld (ports 26000 and 27000)
#/sbin/modprobe ip_masq_quake
#
#Quake I/II/III / QuakeWorld (ports 26000, 27000, 27910, 27960)
#/sbin/modprobe ip_masq_quake ports=26000,27000,27910,27960
# Supports the masquerading of the CuSeeme video conferencing software
#
#/sbin/modprobe ip_masq_cuseeme
#Supports the masquerading of the VDO-live video conferencing software
#
#/sbin/modprobe ip_masq_vdolive
#CRITICAL: Enable IP forwarding since it is disabled by default since
#
# Redhat Users: you may try changing the options in /etc/sysconfig/network from:
#
# FORWARD_IPV4=false
# to
# FORWARD_IPV4=true
#
echo "1" > /proc/sys/net/ipv4/ip_forward
# Get the dynamic IP address assigned via DHCP
#
extip="`/sbin/ifconfig eth1 | grep 'inet addr' | awk '{print $2}' | sed -e 's/.*://'`"
extint="eth1"
# Assign the internal IP
intint="eth0"
intnet="192.168.1.0/24"
# MASQ timeouts
#
# 2 hrs timeout for TCP session timeouts
# 10 sec timeout for traffic after the TCP/IP "FIN" packet is received
# 60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself)
#
ipchains -M -S 7200 10 60
#############################################################################
# Incoming, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F input
ipchains -P input REJECT
# local interface, local machines, going anywhere is valid
#
ipchains -A input -i $intint -s $intnet -d 0.0.0.0/0 -j ACCEPT
# remote interface, claiming to be local machines, IP spoofing, get lost
#
ipchains -A input -i $extint -s $intnet -d 0.0.0.0/0 -l -j REJECT
# remote interface, any source, going to permanent PPP address is valid
#
ipchains -A input -i $extint -s 0.0.0.0/0 -d $extip/32 -j ACCEPT
# loopback interface is valid.
#
ipchains -A input -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT
# catch all rule, all other incoming is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A input -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT
#############################################################################
# Outgoing, flush and set default policy of reject. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F output
ipchains -P output REJECT
# local interface, any source going to local net is valid
#
ipchains -A output -i $intint -s 0.0.0.0/0 -d $intnet -j ACCEPT
# outgoing to local net on remote interface, stuffed routing, deny
#
ipchains -A output -i $extint -s 0.0.0.0/0 -d $intnet -l -j REJECT
# outgoing from local net on remote interface, stuffed masquerading, deny
#
ipchains -A output -i $extint -s $intnet -d 0.0.0.0/0 -l -j REJECT
# anything else outgoing on remote interface is valid
#
ipchains -A output -i $extint -s $extip/32 -d 0.0.0.0/0 -j ACCEPT
# loopback interface is valid.
#
ipchains -A output -i lo -s 0.0.0.0/0 -d 0.0.0.0/0 -j ACCEPT
# catch all rule, all other outgoing is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A output -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT
#############################################################################
# Forwarding, flush and set default policy of deny. Actually the default policy
# is irrelevant because there is a catch all rule with deny and log.
#
ipchains -F forward
ipchains -P forward DENY
# Masquerade from local net on local interface to anywhere.
#
ipchains -A forward -i $extint -s $intnet -d 0.0.0.0/0 -j MASQ
#
# catch all rule, all other forwarding is denied and logged. pity there is no
# log option on the policy but this does the job instead.
#
ipchains -A forward -s 0.0.0.0/0 -d 0.0.0.0/0 -l -j REJECT
IPCHAINS¸¦ »ç¿ëÇϸé, ¿©·¯ºÐÀº "input", "output", "forward" ±ÔÄ¢À» ÅëÇØ¼ ƯÁ¤ »çÀÌÆ®¿ÍÀÇ Åë½ÅÀ» Á¦ÇÑÇÒ ¼ö ÀÖ´Ù. °¢ Á¤Ã¥ ¸í·ÉµéÀº À§¿¡¼ºÎÅÍ ¾Æ·¡·Î ÀÐÇôÁö°í, "-A" ´Â ±âÁ¸ÀÇ Á¤Ã¥¿¡ "µ¡ºÙÀδÙ"´Â °ÍÀ» À¯³äÇÑ´Ù. ±×·¯¹Ç·Î, ƯÁ¤ÇÑ Á¦ÇÑ »çÇ×Àº Àü¹ÝÀûÀÎ Á¤Ã¥º¸´Ù ¾Õ¿¡ ¿Í¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é:
"input" ±ÔÄ¢: °¡Àå ºü¸£Áö¸¸ Á¦ÇÑÀº ³»ºÎÀÇ ÄÄÇ»Å͵鿡°Ô¸¸ Àû¿ëµÈ´Ù. ¹æÈº® ÄÄÇ»ÅÍ ÀÚü´Â ¿©ÀüÈ÷ "±ÝÁöµÈ" »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù. ¹°·Ð ¿©·¯ºÐÀº À̰͵éÀ» Á¶ÇÕÇØ¼ »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.
/etc/rc.d/rc.firewall Á¤Ã¥ ÈÀÏ Áß¿¡¼:
... start of "input" rules ...
# reject and log local interface, local machines going to 204.50.10.13
#
/sbin/ipfwadm -I -a reject -V 192.168.0.1 -S 192.168.0.0/24 -D 204.50.10.13/32 -o
# local interface, local machines, going anywhere is valid
#
/sbin/ipfwadm -I -a accept -V 192.168.0.1 -S 192.168.0.0/24 -D 0.0.0.0/0
... end of "input" rules ...
"output"À» »ç¿ëÇϸé, ÆÐŶµéÀÌ ¸¶½ºÄ¿·¹À̵ùÀ» ¸ÕÀú Åë°úÇϱ⠶§¹®¿¡ ¼Óµµ´Â °¡Àå ´À¸®Áö¸¸, ¹æÈº® ÄÄÇ»ÅÍ ÀÚüµµ ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ¾ø´Ù.
... start of "output" rules ...
# reject and log outgoing to 204.50.10.13
#
/sbin/ipfwadm -O -a reject -V $ppp_ip -S $ppp_ip/32 -D 204.50.10.13/32 -o
# anything else outgoing on remote interface is valid
#
/sbin/ipfwadm -O -a accept -V $ppp_ip -S $ppp_ip/32 -D 0.0.0.0/0
... end of "output" rules ...
"forward"¸¦ »ç¿ëÇϸé, "input"À» »ç¿ëÇÑ °Íº¸´Ù´Â Á¶±Ý ´õ ´À¸®°í ¿ª½Ã ¸¶½ºÄ¿·¹ÀÌµå µÇ´Â (³»ºÎÀÇ) ÄÄÇ»Å͵鸸 Á¦ÇÑÇÏ°í ¹æÈº® ÄÄÇ»ÅÍ ÀÚü´Â ±ÝÁöµÈ »çÀÌÆ®¿¡ Á¢¼ÓÇÒ ¼ö ÀÖ´Ù.
... start of "forward" rules ...
# Reject and log from local net on PPP interface to 204.50.10.13.
#
/sbin/ipfwadm -F -a reject -W ppp0 -S 192.168.0.0/24 -D 204.50.10.13/32 -o
# Masquerade from local net on local interface to anywhere.
#
/sbin/ipfwadm -F -a masquerade -W ppp0 -S 192.168.0.0/24 -D 0.0.0.0/0
... end of "forward" rules ...
192.168.0.0/24°¡ 204.50.11.0·Î Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇϱâ À§ÇØ Æ¯º°ÇÑ Á¤Ã¥ÀÌ ÇÊ¿äÇÏÁö´Â ¾Ê´Ù. Àü¹ÝÀûÀÎ Á¤Ã¥¿¡ Æ÷ÇԵǾî Àֱ⠶§¹®ÀÌ´Ù.
IPFWADM¿Í´Â ´Ù¸£°Ô, À§ÀÇ Á¤Ã¥ÈÀÏ¿¡¼ ÀÎÅÍÆäÀ̽º¸¦ ±¸¼ºÇÏ´Â ¹æ¹ýÀº ¿ÀÁ÷ ÇѰ¡Áö »ÓÀÌ´Ù. IPCHAINS´Â "-i eth0" ¿É¼ÇÀ» »ç¿ëÇÑ´Ù. "-V"´Â IPFWADMÀÇ ¹æ¹ýÀ¸·Î IPCHAINS¿ÍÀÇ È£È¯À» À§Çؼ »ç¿ëµÈ °ÍÀ̰í, IPFWADM¸¸À» »ç¿ëÇÑ´Ù¸é ÀüÀûÀ¸·Î »ç¿ëÀÚÀÇ ¼±ÅÃÀÌ´Ù.
6.6 ¿©·¯°³ÀÇ ³»ºÎ ³×Æ®¿÷À» IP ¸¶½ºÄ¿·¹À̵ùÇÏ´Â ¹ý
¿©·¯°³ÀÇ ³»ºÎ ³×Æ®¿÷À» ¸¶½ºÄ¿·¹À̵ùÇÏ´Â °ÍÀÌ ¸Å¿ì °£´ÜÇÏ´Ù. ¿ì¼± ³»ºÎ¿Í ¿ÜºÎÀÇ ¸ðµç ³×Æ®¿÷ÀÌ Á¦´ë·Î µ¿ÀÛÇÏ´ÂÁö È®ÀÎÇØ¾ß ÇÑ´Ù. ±×·± ÈÄ¿¡ ³×Æ®¿÷ Æ®·¡ÇÈÀÌ ³»ºÎÀÇ ´Ù¸¥ ÄÄÇ»Å͵鿡°Ôµµ Àü´ÞµÇ°í ÀÎÅͳÝÀ¸·Î ¸¶½ºÄ¿·¹À̵ùµÇµµ·Ï ¸¸µé¾î¾ß ÇÑ´Ù.
´ÙÀ½À¸·Î, ³»ºÎÀÇ ÀÎÅÍÆäÀ̽º¿¡ ¸¶½ºÄ¿·¹À̵ùÀ» »ç¿ë°¡´ÉÇϵµ·Ï ÇØÁà¾ß ÇÑ´Ù. ÀÌ ¿¹´Â eth1 (192.168.0.1)¿Í eth2 (192.168.1.1)ÀÇ µÎ°³ÀÇ ³»ºÎ ÀÎÅÍÆäÀ̽º°¡ ¿ÜºÎ·Î ÇâÇÏ´Â eth0 ÀÎÅÍÆäÀ̽º·Î ¸¶½ºÄ¿·¹À̵ùµÇµµ·Ï ¼³Á¤ÇÏ´Â °ÍÀÌ´Ù. rc.firewall Á¤Ã¥ÈÀÏ¿¡ ´ÙÀ½ ³»¿ëÀ» Ãß°¡ÇÑ´Ù:
- IPFWADMÀ» »ç¿ëÇÏ´Â 2.0.x Ä¿³Î¿ë
#Enable internal interfaces to communication between each other
/sbin/ipfwadm -F -a accept -V 192.168.0.1 -D 192.168.1.0/24
/sbin/ipfwadm -F -a accept -V 192.168.1.1 -D 192.168.0.0/24
#Enable internal interfaces to MASQ out to the Internet
/sbin/ipfwadm -F -a masq -W eth0 -S 192.168.0.0/24 -D 0.0.0.0/0
/sbin/ipfwadm -F -a masq -W eth0 -S 192.168.1.0/24 -D 0.0.0.0/0
- IPCHAINS¸¦ »ç¿ëÇÏ´Â 2.2.x Ä¿³Î¿ë
#Enable internal interfaces to communication between each other
/sbin/ipchains -A forward -i eth1 -d 192.168.1.0/24
/sbin/ipchains -A forward -i eth2 -d 192.168.0.0/24
#Enable internal interfaces to MASQ out to the Internet
/sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.0.0/24 -d 0.0.0.0/0
/sbin/ipchains -A forward -j MASQ -i eth0 -s 192.168.1.0/24 -d 0.0.0.0/0
6.7 IP ¸¶½ºÄ¿·¹À̵å¿Í ÀüÈ Á¢¼Ó
- ÀÎÅͳݿ¡ ¿¬°áÇϱâ À§Çؼ ÀÚµ¿À¸·Î ÀüÈ Á¢¼ÓÀ» Çϵµ·Ï ¼³Á¤ÇϰíÀÚ ÇÑ´Ù¸é, Diald¸¦ »ç¿ëÇÑ ÀüȰɱ⳪ PPPdÀÇ »õ ¹öÁ¯À» »ç¿ëÇÏ´Â °ÍÀÌ ÁÁÀ» °ÍÀÌ´Ù. ±¸¼ºÀÌ ´õ ³ªÀº Diald¸¦ »ç¿ëÇÏ´Â °ÍÀ» ±ÇÀåÇÑ´Ù.
- Diald¸¦ ¼³Á¤Çϱâ À§Çؼ´Â,
Setting Up Diald for Linux Page³ª
TrinityOS - Section 23¸¦ »ìÆìº¸±â ¹Ù¶õ´Ù.
- ÀÏ´Ü Diald¿Í IP ¸¶½ºÄ¿·¹À̵ùÀÌ Á¦´ë·Î ¼³Á¤µÇ°í ³ª¸é, ¸¶½ºÄ¿·¹À̵åµÇ´Â Ŭ¶óÀÌ¾ðÆ®µéÀÌ À¥À̳ª telnet, ftpµîÀÇ Á¢¼ÓÀ» ÇÏ·Á°í ÇÏ¸é ¸®´ª½º box°¡ ÀÚµ¿À¸·Î ÀÎÅÍ³Ý ¿¬°áÀ» ÇÒ °ÍÀÌ´Ù.
- óÀ½ Á¢¼Ó ¶§´Â ½Ã°£ Ãʰú°¡ ÀÖÀ» ¼öµµ Àִµ¥, ¾Æ³¯·Î±× ¸ðµ©À» »ç¿ëÇÑ´Ù¸é ¾î¿ ¼ö ¾ø´Ù. ¸ðµ© ÀÚüÀÇ Á¢¼Ó°ú PPP Á¢¼ÓÀ» À§ÇÑ ½Ã°£ ¶§¹®¿¡, Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥µé(À¥ ºê¶ó¿ìÀú µî)ÀÌ ½Ã°£ Ãʰú¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ÇÏÁö¸¸ ´Ã ±×·± °ÍÀº ¾Æ´Ï´Ù. ¸¸¾à ÀÌ·± Çö»óÀÌ ÀϾ¸é, ´ÜÁö Àç½Ãµµ(À̸¦Å׸é, À¥ ÆäÀÌÁö¸¦ ´Ù½Ã º¸±â)¸¦ ÇÏ¸é ±× ´ÙÀ½ºÎÅÍ´Â Àß µ¿ÀÛÇÒ °ÍÀÌ´Ù. ¶Ç´Â, echo "1" > /proc/sys/net/ipv4/ip_dynaddr¶ó°í Ä¿³Î¿¡ ¿É¼ÇÀ» ÁÖ¾î¼ ÀÌ·¯ÇÑ Ãʱ⠼³Á¤¿¡ °üÇÑ °ÍÀ» ÇØ°áÇÒ ¼öµµ ÀÖ´Ù.
6.8 IPPORTFW, IPMASQADM, IPAUTOFW, REDIR, UDPRED µî°ú ±âŸÀÇ Æ÷Æ® Æ÷¿öµù µµ±¸µé
IPPORTFW, IPAUTOFW, REDIR, UDPRED µî°ú ±âŸ ´Ù¸¥ ÇÁ·Î±×·¥µéÀº ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵带 À§ÇÑ ÀϹÝÀûÀº TCP¶Ç´Â UDP Æ÷Æ® Æ÷¿öµù µµ±¸µéÀÌ´Ù. ÀÌ·¯ÇÑ µµ±¸µéÀº ÀϹÝÀûÀ¸·Î, ÇöÀçÀÇ FTP, Quake µîÀ» À§ÇÑ Æ¯Á¤ÇÑ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâµé°ú ÇÔ²² »ç¿ëµÇ°Å³ª ´ëÃ¼ÇØ¼ »ç¿ëµÈ´Ù. Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇϸé, ÀÎÅͳÝÀ¸·ÎºÎÅÍ ¿À´Â Á¢¼ÓµéÀ», IP ¸¶½ºÄ¿·¹À̵ù µÚ¿¡¼ ³»ºÎ ÁÖ¼Ò¸¸ °¡Áö°í ÀÖ´Â ÄÄÇ»ÅÍ·Î Àü´ÞÇØ ÁÙ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ Æ÷¿öµù ±â´ÉÀº TELNET, WWW, SMTP, FTP (Ưº°ÇÑ ÆÐÄ¡¸¦ ÇÊ¿ä·Î ÇÑ´Ù - ¾Æ·¡¸¦ º¼ °Í), ICQ ¿Í ´Ù¸¥ ¸¹Àº ³×Æ®¿÷ ÇÁ·ÎÅäÄݵéÀ» ó¸®ÇÒ ¼ö ÀÖ´Ù.
ÁÖÀÇ: ¸¸¾à IP ¸¶½ºÄ¿·¹À̵ù ¾øÀÌ ´ÜÁö Æ÷Æ® Æ÷¿öµù¸¸À» ÇÏ±æ ¿øÇÑ´Ù ÇØµµ, ¿©ÀüÈ÷ Ä¿³Î°ú IPFWADM³ª IPCHAINS Á¤Ã¥ ³»¿¡ IP ¸¶½ºÄ¿·¹À̵ù ±â´ÉÀ» Ãß°¡ÇÏ°í¼ ¸®´ª½ºÀÇ Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇØ¾ß ÇÑ´Ù.
±×·¯¸é À̰͵éÀÇ Â÷ÀÌ´Â ¹«¾ùÀΰ¡? IPAUTOFW, REDIR¿Í UDPRED(¸ðµç URLµéÀº
2.0.x-Requirements
¼½¼Ç¿¡ ÀÖ´Ù)µîÀº IP ¸¶½ºÄ¿·¹ÀÌµå »ç¿ëÀÚ°¡ ÀÌ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ ÇÊ¿äÇÑ ÃʱâÀÇ µµ±¸µéÀ̾ú´Ù. ½Ã°£ÀÌ È帣°í, ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵尡 ¹ßÀüÇϸé¼, ÀÌ µµ±¸µéÀº ´õ Áö´ÉÀûÀÎ ÇØ°áÃ¥ÀÎ IPPORTFW·Î ´ëüµÇ¾ú´Ù. »õ·Î¿î µµ±¸µéÀ» »ç¿ë°¡´ÉÇÏ°Ô µÇ¾ú±â ¶§¹®¿¡, IPQUTOFW¿Í REDIR¿Í °°Àº ¿¹ÀüÀÇ µµ±¸µéÀ» »ç¿ëÇÏ´Â °ÍÀº *¸Å¿ì ¹Ù¶÷Á÷ÇÏÁö ¾Ê´Ù*. À̵éÀº Ä¿³Î°ú ÇÔ²² Á¦´ë·Î µ¿ÀÛÇÏÁö ¸øÇϰųª ½ÉÁö¾î ¿©·¯ºÐÀÇ ¸®´ª½º ¼¹ö¸¦ ÆÄ±«ÇÒ ¼öµµ ÀÖ´Ù.
2.0.x ¹öÁ¯ÀÇ IPPORTFW³ª 2.2.x ¹öÁ¯ÀÇ IPMASQADMÀ» IPPORTFW¿Í ÇÔ²² »ç¿ëÇϱâ Àü¿¡, ´Ù¸¥ Æ÷Æ® Æ÷¿öµù µµ±¸µéÀ» »ç¿ëÇÏ¸é ³×Æ®¿÷ º¸¾È ¹®Á¦¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. ±× ÀÌÀ¯´Â ÀÌ·¯ÇÑ µµ±¸µéÀº TCP/UDP Æ÷Æ®¸¦ Æ÷¿öµùÇϱâ À§Çؼ ±âº»ÀûÀ¸·Î ÆÐŶ ¹æÈº®¿¡ ±¸¸ÛÀ» ¸¸µé±â ¶§¹®ÀÌ´Ù. À̰ÍÀÌ ¸®´ª½º ¸Ó½Å¿¡ À§ÇùÀ» ÁÖÁö´Â ¾ÊÁö¸¸, ÆÐŶÀÌ Æ÷¿öµùµÇ´Â ³»ºÎÀÇ ÄÄÇ»ÅÍ¿¡°Ô´Â ¹®Á¦°¡ µÉ ¼öµµ ÀÖ´Ù. Å« ¹®Á¦´Â ¾Æ´ÏÁö¸¸, IPPORTFWÀÇ Á¦ÀÛÀÚÀÎ Steven ClarkeÀº ´ÙÀ½°ú °°ÀÌ ¸»ÇÑ´Ù:
"ÇØ´çÇÏ´Â IPFWADM/IPCHAINS Á¤Ã¥¿¡ µé¾î¸Âµµ·Ï, Æ÷Æ® Æ÷¿öµùÀº
¸¶½ºÄ¿·¹À̵ù ÇÔ¼ö¿¡¼¸¸ ºÒ·ÁÁø´Ù. ¸¶½ºÄ¿·¹À̵ùÀº IP Æ÷¿öµùÀ¸·Î
È®ÀåµÈ´Ù. ±×·¡¼, ipportfw´Â ÀԷ°ú ipfwadm Á¤Ã¥ ¸ðµÎ¿¡ µé¾î¸Â´Â
ÆÐŶ¸¸À» º¼ ¼ö ÀÖ´Ù."
ÀÌ·¯ÇÑ ÀÌÀ¯·Î, °·ÂÇÑ ¹æÈº® Á¤Ã¥À» »ç¿ëÇÏ´Â °ÍÀÌ Áß¿äÇÏ´Ù. °·ÂÇÑ ¹æÈº® Á¤Ã¥¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ °ÍÀº
Strong-IPFWADM-Rulesets
°ú
Strong-IPCHAINS-Rulesets
¼½¼ÇÀ» ÂüÁ¶Çϱ⠹ٶõ´Ù.
ÀÌÁ¦, IPPORTFW Æ÷¿öµùÀ» 2.0.x³ª 2.2.x Ä¿³Î¿¡ »ç¿ëÇϱâ À§Çؼ´Â, ¸®´ª½º Ä¿³ÎÀÌ IPPORTFW¸¦ Áö¿øÇϵµ·Ï ÀçÄÄÆÄÀÏÇØ¾ß ÇÑ´Ù.
- 2.0.x Ä¿³Î »ç¿ëÀÚµéÀº ¾Æ·¡¿Í °°Àº °£´ÜÇÑ Ä¿³Î ¿É¼Ç ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù.
- 2.2.x Ä¿³Î »ç¿ëÀÚµéÀº IPMASQADMÀ» ÅëÇØ¼ ÀÌ¹Ì IPPORTFW Ä¿³Î ¿É¼ÇÀ» »ç¿ëÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù.
2.0.x Ä¿³Î¿¡¼ IPPORTFW »ç¿ë
¿ì¼±, /usr/src/linux µð·ºÅ丮¿¡ °¡Àå ÃÖ½ÅÀÇ 2.0.x Ä¿³ÎÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇÑ´Ù. ¸¸¾à ¾ø´Ù¸é,
Kernel-Compile
¼½¼Ç¿¡¼ ÀÚ¼¼ÇÑ »çÇ×À» ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À¸·Î,
2.0.x-Requirements
¼½¼Ç¿¡¼ "ipportfw.c" ÇÁ·Î±×·¥°ú "subs-patch-x.gz" Ä¿³Î ÆÐÄ¡¸¦ ´Ù¿î·ÎµåÇØ¼ /usr/src/ µð·ºÅ丮¿¡ ¾ÐÃàÀ» Ǭ´Ù.
ÁÖÀÇ: "subs-patch-x.gz"ÀÇ ÈÀÏ¸í¿¡¼ "x"´Â ±× »çÀÌÆ®¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â °¡Àå ÃÖ½ÅÀÇ ¹öÁ¯À¸·Î ´ëÄ¡ÇÑ´Ù.
ÀÌÁ¦, IPPORTFW ÆÐÄ¡(subs-patch-x.gz)¸¦ ¸®´ª½º µð·ºÅ丮·Î º¹»çÇÑ´Ù.
cp /usr/src/subs-patch-1.37.gz /usr/src/linux
´ÙÀ½¿¡, IPPORTFW Ä¿³Î ¿É¼ÇÀ» »ý¼ºÇϱâ À§Çؼ Ä¿³Î ÆÐÄ¡¸¦ ÇÑ´Ù:
cd /usr/src/linux
zcat subs-patch-1.3x.gz | patch -p1
´ÙÀ½À¸·Î, FTP Á¢¼ÓÀ» ³»ºÎÀÇ ¼¹ö·Î Æ÷Æ® Æ÷¿öµùÇϰíÀÚ ÇÑ´Ù¸é,
2.0.x-Requirements
¼½¼Ç¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â »õ·Î¿î IP_MASQ_FTP ¸ðµâ ÆÐÄ¡¸¦ ÇØ¾ß ÇÑ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº ÀÌ ¼½¼ÇÀÇ ³ªÁß ºÎºÐ¿¡ ³ª¿Í ÀÖ´Ù.
ÀÚ,
Kernel-Compile
¼½¼Ç¿¡ ÀÖ´Â °Íó·³ Ä¿³ÎÀ» ÄÄÆÄÀÏÇÒ Â÷·ÊÀÌ´Ù. Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼ IPPORTFW ¿É¼Ç¿¡ YES¶ó°í Çϵµ·Ï ÇÑ´Ù. ÀÏ´Ü ÄÄÆÄÀÏÀÌ ³¡³ª°í »õ·Î¿î Ä¿³Î·Î ¸®ºÎÆ®ÇÏ°í ³ª¸é, ´Ù½Ã ÀÌ ¼½¼ÇÀ¸·Î µ¹¾Æ¿Â´Ù.
ÀÌÁ¦ »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇØ¼, ½ÇÁ¦ÀÇ "IPPORTFW" ÇÁ·Î±×·¥À» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇÑ´Ù.
cd /usr/src
gcc ipportfw.c -o ipportfw
mv ipportfw /usr/local/sbin
ÀÌÁ¦, ¿¹¸¦ µé¾î¼ ¸ðµç À¥ Á¢¼Ó(Æ÷Æ® 80)À» ¸¶½ºÄ¿·¹À̵åµÇ´Â ³»ºÎÀÇ ¸Ó½Å Áß¿¡¼ 192.168.0.10À» ÁÖ¼Ò·Î °°Àº ¸Ó½ÅÀ¸·Î Æ÷¿öµåÇÏ·Á ÇÑ´Ù°í ÇÏÀÚ.
ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 80À» Æ÷Æ® Æ÷¿öµùÇϸé, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö´Â ±× Æ÷Æ®¸¦ ´õÀÌ»ó »ç¿ëÇÏÁö ¸øÇÑ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¿©·¯ºÐÀÌ ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ ÀÌ¹Ì À¥ ¼¹ö¸¦ ¿î¿µÇϰí ÀÖ°í Æ÷Æ® 80À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍ·Î Æ÷Æ® Æ÷¿öµùÇÑ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡¼ º¸³»´Â ÆäÀÌÁö°¡ ¾Æ´Ñ -³»ºÎÀÇ- À¥ ¼¹ö¿¡¼ º¸³»´Â ÆäÀÌÁö¸¦ º¼ °ÍÀÌ´Ù. À̸¦ ÇØ°áÇϱâ À§ÇÑ À¯ÀÏÇÑ ¹æ¹ýÀº ¿¹¸¦ µé¾î 8080°ú °°Àº ´Ù¸¥ Æ÷Æ®¸¦ ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÏ´Â °ÍÀÌ´Ù. ÀÌ·¸°Ô ÇÏ¸é µÇ±ä ÇÏÁö¸¸, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â À¥ ¼¹ö¿¡ Á¢¼ÓÇϱâ À§Çؼ URL¿¡ :8080À» µ¡ºÙ¿©¾ß ÇÑ´Ù.
¾î·µç, Æ÷Æ® Æ÷¿öµùÀ» »ç¿ëÇϱâ À§Çؼ´Â, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ÆíÁýÇÑ´Ù. ´ÙÀ½¿¡ ÀÖ´Â ³»¿ëÀ» Ãß°¡ÇϵÇ, "$extip"´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.
ÁÖÀÇ: ¸¸¾à ¿©·¯ºÐÀÌ ISP ·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼ »ç¿ëÇÑ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ´õ Áö´ÉÀûÀ¸·Î ¸¸µé¾î¾ß ÇÒ °ÍÀÌ´Ù. °·ÂÇÑ Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº
TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù.
/etc/rc.d/rc.firewall
--
#echo "Enabling IPPORTFW Redirection on the external LAN.."
#
/usr/local/sbin/ipportfw -C
/usr/local/sbin/ipportfw -A -t$extip/80 -R 192.168.0.10/80
--
ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!
¸¸¾à¿¡ "ipfwadm: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù.
FTP ¼¹öÀÇ Æ÷Æ® Æ÷¿öµù:
FTP¸¦ ³»ºÎÀÇ ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇϰíÀÚ ÇÑ´Ù¸é, ÀÏÀÌ Á» ´õ º¹ÀâÇØÁø´Ù. ±× ÀÌÀ¯´Â Ç¥ÁØÀÇ IP_MASQ_FTP Ä¿³Î ¸ðµâÀÌ ÀÌ·¯ÇÑ ¸ñÀûÀ¸·Î ¸¸µé¾îÁ® ÀÖÁö ¾Ê±â ¶§¹®ÀÌ´Ù. ´ÙÇàÈ÷ Fred Viles°¡ ÀÌ·¯ÇÑ ¸ñÀûÀ¸·Î µ¿ÀÛÇϵµ·Ï ¼öÁ¤µÈ IP_MASQ_FTP ¸ðµâÀ» ÀÛ¼ºÇß´Ù. Á¤È®È÷ ¹«¾ùÀÌ ¹®Á¦ÀÎÁö ¾Ë°í ½Í´Ù¸é, Fred°¡ ¹®¼¸¦ ¸Å¿ì Àß ÀÛ¼ºÇØ ³õ¾ÒÀ¸´Ï ±×°ÍÀ» ´Ù¿î·ÎµåÇØ º¸±â ¹Ù¶õ´Ù. ÀÌ ÆÐÄ¡´Â ´Ù¼Ò ½ÇÇèÀûÀÎ ¸éÀÌ ÀÖ´Ù´Â °Íµµ ¾Ë¾ÆµÎ±â ¹Ù¶õ´Ù. ¶ÇÇÑ ÇöÀç ÀÌ ÆÐÄ¡´Â 2.0.x Ä¿³Î¿ë¿¡¼¸¸ »ç¿ëÇÒ ¼ö ÀÖ´Ù´Â °Íµµ ¾Ë¾ÆµÎ±â ¹Ù¶õ´Ù. 2.2.x Ä¿³Î·ÎÀÇ Æ÷ÆÃµµ ¾î´À Á¤µµ ÀÌ·ç¾îÁ® ÀÖÁö¸¸, ¿©±â¿¡ µµ¿òÀ» ÁÖ°í ½Í´Ù¸é
Fred Viles - fv@episupport.com·Î Á÷Á¢ À̸ÞÀÏÀ» º¸³»±â ¹Ù¶õ´Ù.
ÀÌÁ¦ ´ÙÀ½ °úÁ¤À» °ÅÃļ 2.0.x ÆÐÄ¡¸¦ ÇÑ´Ù:
- ¿ì¼± ÀÌ ¼½¼ÇÀÇ ¾Õ ºÎºÐ¿¡ ÀÖ´Â °Í°ú °°ÀÌ IPPORTFW Ä¿³Î ÆÐÄ¡¸¦ °¡ÇÑ´Ù.
-
2.0.x-Requirements
¼½¼Ç¿¡ ¼ö·ÏµÈ Fred VilesÀÇ FTP ¼¹ö¿¡¼ "msqsrv-patch-36"¸¦ ´Ù¿î·ÎµåÇϰí /usr/src/linux¿¡ ³Ö´Â´Ù.
- "cat msqsrv-patch-36 | patch -p1"¶ó°í ¸í·ÉÇØ¼ ÀÌ »õ·Î¿î ÄÚµå·Î Ä¿³ÎÀ» ÆÐÄ¡ÇÑ´Ù.
- ÀÌÁ¦, ¿ø·¡ÀÇ "ip_masq_ftp.c" Ä¿³Î ¸ðµâÀ» »õ·Î¿î °ÍÀ¸·Î ´ëüÇÑ´Ù.
- mv /usr/src/linux/net/ipv4/ip_masq_ftp.c /usr/src/linux/net/ipv4/ip_masq_ftp.c.orig
- mv /usr/src/linux/ip_masq_ftp.c /usr/src/linux/net/ipv4/ip_masq_ftp.c
- ¸¶Áö¸·À¸·Î »õ·Î¿î Äڵ尡 Àû¿ëµÈ Ä¿³ÎÀ» »ý¼ºÇؼ ÀνºÅçÇÑ´Ù.
´Ù µÆÀ¸¸é, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ÆíÁýÇØ¼ ´ÙÀ½ ³»¿ëÀ» Ãß°¡Ç쵂 "$extip"´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.
ÁÖÀÇ: ¸¸¾à ¿©·¯ºÐÀÌ ISP ·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼ »ç¿ëÇÑ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ´õ Áö´ÉÀûÀ¸·Î ¸¸µé¾î¾ß ÇÒ °ÍÀÌ´Ù. °·ÂÇÑ Á¤Ã¥µé°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ×Àº
TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù.
ÀÌ ¿¹´Â À§¿¡¼¿Í °°ÀÌ ¸ðµç FTP Á¢¼Ó(Æ÷Æ® 21)À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½Å Áß 192.168.0.10ÀÇ ÁÖ¼Ò¸¦ °®´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÒ °ÍÀÌ´Ù.
ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 21À» Æ÷Æ® Æ÷¿öµùÇϸé, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö´Â ±× Æ÷Æ®¸¦ ´õ ÀÌ»ó »ç¿ëÇÏÁö ¸øÇÒ °ÍÀÌ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ ÀÌ¹Ì FTP ¼¹ö¸¦ ¿î¿µÇϰí ÀÖ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚÀÇ FTP Á¢¼ÓÀº IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö°¡ ¾Æ´Ï¶ó -³»ºÎÀÇ- FTP ¼¹ö·Î °¥ °ÍÀÌ´Ù.
/etc/rc.d/rc.firewall
--
#echo "Enabling IPPORTFW Redirection on the external LAN.."
#
/usr/local/sbin/ipportfw -C
/usr/local/sbin/ipportfw -A -t$extip/21 -R 192.168.0.10/21
--
ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!
¸¸¾à¿¡ "ipchains: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù. »õ·Î¿î Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖ´Â °ÍÀÌ È®½ÇÇÏ´Ù¸é, "ls /proc/net"À̶ó°í ¸í·ÉÇØ¼ "ip_portfw" ÈÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é, Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼ ¹«¾ùÀΰ¡ ºüÆ®·ÈÀ» °ÍÀÌ´Ù. Ä¿³ÎÀ» ´Ù½Ã ¸¸µç´Ù.
2.2.x Ä¿³Î¿¡¼ IPPORTFW¿Í ÇÔ²² IPMASQADM »ç¿ë
¿ì¼±, /usr/src/linux µð·ºÅ丮¿¡ ÃÖ½ÅÀÇ 2.2.x Ä¿³ÎÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é,
Kernel-Compile
¼½¼Ç¿¡¼ ÀÚ¼¼ÇÑ »çÇ×À» ÂüÁ¶ÇÑ´Ù. ´ÙÀ½À¸·Î,
2.2.x-Requirements
¼½¼Ç¿¡¼ "ipmasqadm.c" ÇÁ·Î±×·¥À» ´Ù¿î·ÎµåÇØ¼ /usr/src/ µð·ºÅ丮¿¡ ³Ö´Â´Ù.
´ÙÀ½À¸·Î,
Kernel-Compile
¼½¼Ç¿¡ ÀÖ´Â °Í°ú °°ÀÌ 2.2.x Ä¿³ÎÀ» ÄÄÆÄÀÏÇØ¾ß ÇÑ´Ù. Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼ IPPORTFW ¿É¼Ç¿¡ YES ¶ó°í ÇÑ´Ù. ÀÏ´Ü Ä¿³ÎÀ» ÄÄÆÄÀÏÇØ¼ ¸®ºÎÆ®ÇÑ ÈÄ¿¡ ÀÌ ¼½¼ÇÀ¸·Î µ¹¾Æ¿Â´Ù.
ÀÌÁ¦, IPMASQADM µµ±¸¸¦ ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇÑ´Ù:
cd /usr/src
tar xzvf ipmasqadm-x.tgz
cd ipmasqadm-x
make
make install
ÀÌÁ¦, ¿¹¸¦ µé¾î¼ ¸ðµç À¥ Á¢¼Ó(Æ÷Æ® 80)À» ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½ÅÁß¿¡¼ 192.168.0.10À» ÁÖ¼Ò·Î °®´Â ¸Ó½ÅÀ¸·Î Æ÷Æ® Æ÷¿öµùÇÑ´Ù°í ÇÏÀÚ.
ÁÖÀÇ: FTP Á¢¼ÓÀ» Æ÷Æ® Æ÷¿öµùÇϱâ À§Çؼ ¼öÁ¤µÈ IP_MASQ_FTP ¸ðµâÀÌ ÇöÀç·Î´Â 2.2.x Ä¿³Î¿¡¼ µ¿ÀÛÇÏÁö ¾ÊÀ» Áöµµ ¸ð¸¥´Ù. ÇÏÁö¸¸ À̸¦ ½ÃÇèÇØ º¸°í ½Í´Ù¸é, ÀÌ ¸ðµâÀ» 2.2.x Ä¿³Î¿ëÀ¸·Î Æ÷ÆÃÇØ º¸¶ó. ±×¸®°í Ambrose ¿Í David¿¡°Ô ¿©·¯ºÐÀÇ °á°ú¹°À» ¸ÞÀÏ·Î º¸³» Áֱ⠹ٶõ´Ù.
ÁÖÀÇ: ÀÏ´Ü Æ÷Æ® 80À» Æ÷Æ® Æ÷¿öµùÇÏ°í ³ª¸é, ¸®´ª½º IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö´Â ±× Æ÷Æ®¸¦ »ç¿ëÇÏÁö ¸øÇÑ´Ù. ´õ ±¸Ã¼ÀûÀ¸·Î, ¸¸¾à ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ ÀÌ¹Ì À¥ ¼¹ö¸¦ ¿î¿µÇϰí ÀÖ´Ù¸é, ¸ðµç ÀÎÅÍ³Ý »ç¿ëÀÚµéÀº ¿©·¯ºÐÀÇ IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö°¡ ¾Æ´Ñ -³»ºÎÀÇ- À¥ ¼¹ö¿¡¼ À¥ ÆäÀÌÁö¸¦ ¹Þ¾Æ º¼ °ÍÀÌ´Ù.
¾î·µç, Æ÷Æ® Æ÷¿öµùÀ» Çϱâ À§Çؼ´Â /etc/rc.d/rc.firewall Á¤Ã¥ ÈÀÏÀ» ÆíÁýÇÑ´Ù. ´ÙÀ½ÀÇ ³»¿ëÀ» Ãß°¡ÇϵÇ, "$extip"¸¦ ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò·Î ´ëÄ¡ÇÑ´Ù.
ÁÖÀÇ: ¸¸¾à ISP·ÎºÎÅÍ(PPP, ADSL, ÄÉÀÌºí ¸ðµ©, ±âŸ µîµî) µ¿Àû TCP/IP ÁÖ¼Ò¸¦ ¹Þ¾Æ¼ »ç¿ëÇϰí ÀÖ´Ù¸é, /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» Á»´õ Áö´ÉÀûÀ¸·Î ¸¸µé Çʿ䰡 ÀÖ´Ù. °·ÂÇÑ ¹æÈº® Á¤Ã¥°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ ÀÚ¼¼ÇÑ »çÇ׿¡ ´ëÇØ¼´Â
TrinityOS - Section 10À» ÂüÁ¶Çϱ⠹ٶõ´Ù. ¿©±â¿¡ ÈùÆ®¸¦ ÇѰ¡Áö Á¦°øÇÑ´Ù: PPP »ç¿ëÀÚµéÀ» À§ÇÑ /etc/ppp/ip-up ÈÀÏ.
/etc/rc.d/rc.firewall
--
#echo "Enabling IPPORTFW Redirection on the external LAN.."
#
/usr/sbin/ipmasqadm portfw -f
/usr/sbin/ipmasqadm portfw -a -P tcp -L $extip 80 -R 192.168.0.10 80
--
ÀÚ ÀÌÁ¦ µÆ´Ù! /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏÀ» ´Ù½Ã ½ÇÇà½ÃŰ°í ½ÃÇèÇØ º¸ÀÚ!
¸¸¾à¿¡ "ipchains: setsockopt failed: Protocol not available" ¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸°Ô µÈ´Ù¸é, »õ·Î ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖÁö ¾Ê´Â °ÍÀÌ´Ù. »õ·Î¿î Ä¿³ÎÀ» Á¦´ë·Î µÈ À§Ä¡¿¡ ¿Å°Ü ³õ¾Ò´ÂÁö, LILO¸¦ Àç ½ÇÇàÇß´ÂÁö È®ÀÎÇÏ°í ´Ù½Ã Çѹø ¸®ºÎÆ®ÇÑ´Ù. »õ·Î¿î Ä¿³ÎÀ» »ç¿ëÇϰí ÀÖ´Â °ÍÀÌ È®½ÇÇÏ´Ù¸é, "ls /proc/net/ip_masq"¶ó°í ¸í·ÉÇØ¼ "portfw" ÈÀÏÀÌ ÀÖ´ÂÁö È®ÀÎÇÑ´Ù. ¾ø´Ù¸é, Ä¿³ÎÀ» ¼³Á¤ÇÏ´Â ´Ü°è¿¡¼ ¹«¾ùÀΰ¡ ºüÆ®·ÈÀ» °ÍÀÌ´Ù. Ä¿³ÎÀ» ´Ù½Ã ¸¸µç´Ù.
6.9 CU-SeeMe¿Í ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵å
¸®´ª½º IP ¸¶½ºÄ¿·¹À̵å´Â "ip_masq_cuseeme" Ä¿³Î ¸ðµâÀ» ÅëÇØ¼ CuSeeme¸¦ Áö¿øÇÑ´Ù. ÀÌ Ä¿³Î ¸ðµâÀº /etc/rc.d/rc.firewall ½ºÅ©¸³Æ®¿¡¼ ¸Þ¸ð¸®¿¡ ÀûÀçµÇ¾î¾ß ÇÑ´Ù. ÀÏ´Ü "ip_masq_cuseeme" ¸ðµâÀÏ ¼³Ä¡µÇ¸é, ¿ø°ÝÀÇ reflectorµéÀ̳ª »ç¿ëÀڵ鿡°Ô Á¢¼Ó ½ÅÈ£¸¦ º¸³»°Å³ª Á¢¼ÓÀ» ¹Þ¾ÆµéÀÏ ¼ö ÀÖ°Ô µÈ´Ù.
ÁÖÀÇ: CuSeeme¸¦ »ç¿ëÇϱâ À§Çؼ´Â ¿¹ÀüÀÇ IPAUTOFW µµ±¸ ´ë½Å¿¡ IPPORTFW µµ±¸¸¦ »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇÑ´Ù.
CuSeeme¸¦ ¼³Á¤ÇÏ´Â µ¥ ÀÖ¾î¼ ´õ È®½ÇÇÑ Á¤º¸°¡ ÇÊ¿äÇÏ´Ù¸é,
Michael Owings's CuSeeMe page¿¡¼ ¹Ì´Ï-ÇÏ¿ìÅõ¸¦ º¸°Å³ª
The IP Masquerade Resources¿¡¼ ¹Ì´Ï-ÇÏ¿ìÅõÀÇ ¹Ì·¯ ÆäÀÌÁö¸¦ º¼ ¼ö ÀÖÀ» °ÍÀÌ´Ù.
6.10 Mirabilis ICQ
¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹öÀÇ µÚ¿¡¼ ICQ¸¦ »ç¿ëÇÏ´Â ¹æ¹ýÀº µÎ°¡Áö°¡ ÀÖ´Ù. ÇѰ¡Áö ¹æ¹ýÀº »õ·Î¿î ICQ ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» »ç¿ëÇÏ´Â °ÍÀ̰í, ´Ù¸¥ ÇѰ¡Áö´Â IPPORTFW¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù.
ICQ ¸ðµâÀº ¸î°¡Áö À̵æ°ú ÇÔ²² Á¦Çѵµ ÀÖ´Ù. ÀÌ ¸ðµâÀº °£´ÜÇÑ ¼³Á¤À¸·Î ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö µÚ¿¡¼ ¿©·¯¸íÀÌ ICQ¸¦ »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ICQ Ŭ¶óÀÌ¾ðÆ®¿¡¼ Ưº°ÇÑ ¼³Á¤À» ÇÊ¿ä·Î ÇÏÁöµµ ¾Ê´Â´Ù. ±×·¯³ª, ÇöÀç´Â ÈÀÏ Àü¼Û°ú ½Ç½Ã°£ äÆÃÀÌ µÇÁö ¾Ê´Â´Ù.
IPPORTFW¸¦ ¼³Á¤Çؼ »ç¿ëÇϸé, ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿Í ICQ Ŭ¶óÀÌ¾ðÆ® ¸ðµÎ¿¡ ¸î°¡Áö ¼³Á¤À» º¯°æ½ÃÄÑÁà¾ß ÇÏÁö¸¸, ICQÀÇ ¸Þ½ÃÁö ±â´É, URL ±â´É, äÆÃ, ÈÀÏ Àü¼Û µî ¸ðµç °ÍÀÌ µ¿ÀÛÇÒ °ÍÀÌ´Ù.
Andrew DeryabinÀÇ
djsf@usa.net 2.2.x Ä¿³ÎÀ» À§ÇÑ ICQ IP ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâ¿¡ °ü½ÉÀÌ ÀÖ´Ù¸é,
2.2.x-Requirements
¼½¼Ç¿¡¼ ÀÚ¼¼ÇÑ »çÇ×À» È®ÀÎÇϱ⠹ٶõ´Ù.
¸¶½ºÄ¿·¹ÀÌµå ¼¹ö µÚ¿¡¼ ICQ¸¦ »ç¿ëÇϱâ À§ÇØ ´Ù¼Ò °íÀüÀûÀÎ ¹æ¹ýÀ» ¾²±æ ¿øÇÑ´Ù¸é ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù:
- ¿ì¼±, ¸®´ª½º Ä¿³Î¿¡ IPPORTFW ±â´ÉÀ» Æ÷ÇÔ½ÃŲ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº
Forwarders
¼½¼ÇÀ» ÂüÁ¶ÇÑ´Ù.
- ´ÙÀ½À¸·Î, ´ÙÀ½ÀÇ ³»¿ëÀ» /etc/rc.d/rc.firewall ÈÀÏ¿¡ Ãß°¡ÇÑ´Ù. ÀÌ ¿¹´Â ¿ÜºÎ·Î ÅëÇÏ´Â ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý IP ÁÖ¼Ò¸¦ 10.1.2.3À¸·Î, ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ICQ Ŭ¶óÀÌ¾ðÆ®¸¦ 192.168.0.10À¸·Î °¡Á¤Çß´Ù:
IPFWADMÀ» »ç¿ëÇÏ´Â 2.0.x Ä¿³ÎÀÇ ¿¹:
µÎ°¡Áö ¿¹¸¦ Æ÷ÇÔ½ÃÄ×´Ù: ¾î¶² °ÍÀ̵ç Àß µ¿ÀÛÇÒ °ÍÀÌ´Ù:
¿¹ #1
--
/usr/local/sbin/ipportfw -A -t10.1.2.3/2000 -R 192.168.0.10/2000
/usr/local/sbin/ipportfw -A -t10.1.2.3/2001 -R 192.168.0.10/2001
/usr/local/sbin/ipportfw -A -t10.1.2.3/2002 -R 192.168.0.10/2002
/usr/local/sbin/ipportfw -A -t10.1.2.3/2003 -R 192.168.0.10/2003
/usr/local/sbin/ipportfw -A -t10.1.2.3/2004 -R 192.168.0.10/2004
/usr/local/sbin/ipportfw -A -t10.1.2.3/2005 -R 192.168.0.10/2005
/usr/local/sbin/ipportfw -A -t10.1.2.3/2006 -R 192.168.0.10/2006
/usr/local/sbin/ipportfw -A -t10.1.2.3/2007 -R 192.168.0.10/2007
/usr/local/sbin/ipportfw -A -t10.1.2.3/2008 -R 192.168.0.10/2008
/usr/local/sbin/ipportfw -A -t10.1.2.3/2009 -R 192.168.0.10/2009
/usr/local/sbin/ipportfw -A -t10.1.2.3/2010 -R 192.168.0.10/2010
/usr/local/sbin/ipportfw -A -t10.1.2.3/2011 -R 192.168.0.10/2011
/usr/local/sbin/ipportfw -A -t10.1.2.3/2012 -R 192.168.0.10/2012
/usr/local/sbin/ipportfw -A -t10.1.2.3/2013 -R 192.168.0.10/2013
/usr/local/sbin/ipportfw -A -t10.1.2.3/2014 -R 192.168.0.10/2014
/usr/local/sbin/ipportfw -A -t10.1.2.3/2015 -R 192.168.0.10/2015
/usr/local/sbin/ipportfw -A -t10.1.2.3/2016 -R 192.168.0.10/2016
/usr/local/sbin/ipportfw -A -t10.1.2.3/2017 -R 192.168.0.10/2017
/usr/local/sbin/ipportfw -A -t10.1.2.3/2018 -R 192.168.0.10/2018
/usr/local/sbin/ipportfw -A -t10.1.2.3/2019 -R 192.168.0.10/2019
/usr/local/sbin/ipportfw -A -t10.1.2.3/2020 -R 192.168.0.10/2020
--
¿¹ #2
--
port=2000
while [ $port -lt 2020 ]
do
/usr/local/sbin/ipportfw -A t10.1.2.3/$port