À¯¿ëÇÑ FAQ°¡ ÀÖ´Ù¸é, ambrose@writeme.com°ú dranch@trinnet.netÀ¸·Î º¸³»Áֱ⠹ٶõ´Ù. Áú¹®À» ¸íÈ®ÇÏ°Ô Ç¥½ÃÇÏ°í ÀûÀýÇÑ ´äº¯À» ´Þ¾ÆÁֱ⠹ٶõ´Ù. ¹Ì¸® °¨»çµå¸°´Ù!
¿©·¯ºÐÀÇ ¸®´ª½º ¹èÆ÷º»ÀÌ IP ¸¶½ºÄ¿·¹À̵带 ¹Ù·Î »ç¿ëÇÒ ¼ö ¾ø´Ù Çصµ °ÆÁ¤ÇÏÁö ¸¶½Ê½Ã¿ä. ´ÜÁö ÀÌ ÇÏ¿ìÅõ¿¡ ³ª¿Â ´ë·Î Ä¿³ÎÀ» ÀçÄÄÆÄÀÏÇϱ⸸ ÇÏ¸é µË´Ï´Ù.
ÁÖÀÇ: ÀÌ Ç¥¸¦ ¿Ïº®È÷ ä¿ì´Âµ¥ µµ¿òÀ» ÁÖ°íÀÚ ÇÒ ¶§¿¡´Â ambrose@writeme.comÀ̳ª dranch@trinnet.netÀ¸·Î À̸ÞÀÏÀ» Áֽʽÿä.
16MB RAMÀ» °®´Â 486/66À¸·Îµµ 1.54Mb/s T1À» 100% ó¸®ÇÏ°íµµ ³²¾Ò¾ú´Ù! ¸¶½ºÄ¿·¹À̵å´Â 386SX-16s ¿¡¼ 8BM RAMÀ» °¡Áö°í¼µµ Àß µ¿ÀÛÇÑ´Ù°í ¾Ë·ÁÁ® ÀÖ´Ù. ±×·¯³ª, ¸¶½ºÄ¿·¹À̵å Ç׸ñÀÌ 500°³°¡ ³ÑÀ¸¸é ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵嵵 ¹ö¹÷À̱⠽ÃÀÛÇÑ´Ù´Â °Íµµ ¾Ë¾ÆµÎ¾î¾ß ÇÒ °ÍÀÌ´Ù.
¸®´ª½º IP ¸¶½ºÄ¿·¹À̵带 Àá½Ã³ª¸¶ ¸ØÃß°Ô ÇÒ ¼ö ÀÖ´Â À¯ÀÏÇÑ ÀÀ¿ëÇÁ·Î±×·¥À¸·Î´Â, ÇÊÀÚ°¡ ¾Æ´Â ÇÑ GameSpy»ÓÀÌ´Ù. ±× ÀÌÀ¯´Â ¸ñ·ÏÀ» °»½ÅÇÒ ¶§, ¸Å¿ì ªÀº ½Ã°£µ¿¾È 10,000°³ÀÇ ºü¸¥ Á¢¼ÓÀ» ÇÊ¿ä·Î Çϱ⠶§¹®ÀÌ´Ù. ÀÌ ÀÏÀÌ ³¡³¯ ¶§±îÁö´Â, ¸¶½ºÄ¿·¹À̵å Å×À̺íÀÌ "²Ë" Â÷°Ô µÈ´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº FAQÀÇ No-Free-Ports ¼½¼ÇÀ» »ìÆ캸±â ¹Ù¶õ´Ù.
¸»ÇÏ´Â ±è¿¡ ¸î°¡Áö ´õ:
TCP¿Í UDP¿¡´Â 4096°³ÀÇ µ¿½Ã Á¢¼Ó ÇÑ°è°¡ ÀÖ´Ù. ÀÌ ÇÑ°è´Â /usr/src/linux/net/ipv4/ip_masq.h¿¡¼ °ªÀ» °Çµå¸®¸é ¼öÁ¤µÉ ¼ö ÀÖ´Ù - À§ÂÊ ÇÑ°èÀÎ 32000 Á¤µµµµ ±¦Âú´Ù. ÇÑ°èÄ¡¸¦ ¼öÁ¤ÇÏ°í ½Í´Ù¸é - PORT_MASQ_BEGIN ¿Í PORT_MASQ_END °ªÀ» 32Kº¸´Ù ³ô°í 64Kº¸´Ù ³·Àº ¹üÀ§·Î ¼öÁ¤ÇÏ¸é µÈ´Ù.
¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ù ¸ÞÀϸµ ¸®½ºÆ®¿¡ Âü°¡ÇÏ´Â ¹æ¹ý¿¡´Â µÎ°¡Áö°¡ ÀÖ½À´Ï´Ù. ù¹ø° ¹æ¹ýÀº masq-request@indyramp.comÀ¸·Î ¸ÞÀÏÀ» º¸³»´Â °ÍÀÔ´Ï´Ù. ¸®´ª½º IP ¸¶½ºÄ¿·¹À̵ù °³¹ßÀÚ ¸ÞÀϸµ ¸®½ºÆ®¿¡ Âü°¡Çϱâ À§Çؼ´Â, masq-dev-request@indyramp.comÀ¸·Î ¸ÞÀÏÀ» º¸³»½Ê½Ã¿ä. ´õ ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ÀÇ ±â»ç¸¦ ÂüÁ¶ÇϽʽÿä.
ÀÏ´Ü ¼¹ö°¡ ¿©·¯ºÐÀÇ ¿äûÀ» ¹ÞÀ¸¸é, ¿©·¯ºÐÀÌ ¿äûÇÑ ¸®½ºÆ®¿¡ °¡ÀÔ½ÃÅ°°í ¿©·¯ºÐ¿¡°Ô Æнº¿öµå¸¦ º¸³¾ °Ì´Ï´Ù. ÀÌ Æнº¿öµå¸¦ ¾îµò°¡¿¡ ÀúÀåÇØ ³õÀ¸½Ê½Ã¿ä. ¿É¼ÇÀ» º¯°æÇϰųª ¸®½ºÆ®¿¡¼ Å»ÅðÇÒ ¶§ ÇÊ¿äÇÕ´Ï´Ù.
µÎ¹ø° ¹æ¹ýÀº À¥ ºê¶ó¿ìÁ®¸¦ ÀÌ¿ëÇؼ °¡ÀÔÇÏ´Â °Ì´Ï´Ù. ¸¶½ºÄ¿·¹À̵å ÁÖ ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é http://www.indyramp.com/masq-list/ÀÇ Çü½Ä¿¡ ¸ÂÃç¼ °¡ÀÔÇÏ°í, ¸¶½ºÄ¿·¹ÀÌµå °³¹ßÀÚ ¸®½ºÆ®¿¡ °¡ÀÔÇÏ·Á¸é http://www.indyramp.com/masq-dev-list/¸¦ ÀÌ¿ëÇϽʽÿä.
ÀÏ´Ü °¡ÀÔµÇ°í ³ª¸é, °¡ÀÔµÈ ¸®½ºÆ®¿¡¼ À̸ÞÀÏÀ» ¹ÞÀ» °Ì´Ï´Ù. ¶Ç ÇÑ°¡Áö ¾Ë·ÁµÑ °ÍÀº ¸®½ºÆ®¿¡ °¡ÀÔÇÏµç °¡ÀÔÇÏÁö ¾Êµç, µÎ ¸®½ºÆ®ÀÇ archive¸¦ º¼ ¼ö ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ ¹æ¹ýÀº À§¿¡ ÀÖ´Â µÎ °³ÀÇ À¥ URLÀ» ÂüÁ¶ÇϽʽÿä.
¸¶Áö¸·À¸·Î ¾Ë·ÁµÑ °ÍÀº, ¸¶½ºÄ¿·¹ÀÌµå ¸®½ºÆ®¿¡ ±ÛÀ» ¿Ã¸®±â À§Çؼ´Â óÀ½¿¡ °¡ÀÔÇß´ø °èÁ¤°ú ÁÖ¼Ò¸¦ ÀÌ¿ëÇØ¾ß ÇÑ´Ù´Â °Ì´Ï´Ù.
¸ÞÀϸµ ¸®½ºÆ®³ª ¸ÞÀϸµ ¸®½ºÆ® archive¿¡ °ü·ÃÇÑ ¹®Á¦°¡ ¹ß»ýÇϸé, Robert Novak¿¡°Ô ¿¬¶ôÇϽʽÿä.
Proxy: ÇÁ·Ï½Ã ¼¹ö´Â ´ÙÀ½ ȯ°æ¿¡¼ »ç¿ë°¡´É: Win95, NT, Linux, Solaris, ±âŸ. ÀåÁ¡: + ÇÑ°³ÀÇ IP ÁÖ¼Ò ; Àú·ÅÇÔ + ´õ ³ªÀº ¼º´É(À¥ µî)À» À§Çؼ ¼±ÅÃÀûÀ¸·Î ij½¬ »ç¿ë ´ÜÁ¡: - ÇÁ·Ï½Ã ¼¹ö µÚ¿¡ ÀÖ´Â ¸ðµç ÀÀ¿ëÇÁ·Î±×·¥µéÀÌ ÇÁ·Ï½Ã ¼ºñ½º(SOCKS)¸¦ Áö¿øÇØ¾ß ÇÏ°í ÇÁ·Ï½Ã ¼¹ö¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤µÇ¾î¾ß ÇÑ´Ù - À¥ Ä«¿îÅͳª À¥ Åë°è ÇÁ·Î±×·¥À» È¥¶õ½ÃŲ´Ù ÇÁ·Ï½Ã ¼¹ö´Â, IP ¸¶½ºÄ¿·¹À̵å¿Í °°ÀÌ, ´Ü ÇÑ°³ÀÇ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ »ç¿ëÇÏ°í, ³»ºÎ LAN¿¡ Àִ Ŭ¶óÀ̾ðÆ®µé(À¥ ºê¶ó¿ìÀú µîµî)¿¡°Ô ¹ø¿ªÀÚ ¿ªÇÒÀ» ÇÑ´Ù. ÀÌ ÇÁ·Ï½Ã ¼¹ö´Â ³»ºÎ ³×Æ®¿÷À¸·ÎºÎÅÍ ¿À´Â TELNET, FTP, À¥°ú °°Àº Á¢¼ÓÀ» ÇÑ °³ÀÇ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇؼ ¹Þ¾ÆµéÀδÙ. ±×¸®°í ³ª¼, ÇÁ·Ï½Ã ¼¹ö ÀÚü¿¡¼ Á¢¼ÓÀ» ¿äûÇÑ °Íó·³ ¹Ù²Ù¾î¼ ¿ÜºÎ·Î º¸³½´Ù. ÀÏ´Ü ¿ø°ÝÀÇ ÀÎÅÍ³Ý ¼¹ö°¡ ¿äûÇÑ Á¤º¸¸¦ º¸³»¿À¸é, ÇÁ·Ï½Ã ¼¹ö´Â TCP/IP ÁÖ¼Ò¸¦ ³»ºÎÀÇ Å¬¶óÀ̾ðÆ®ÀÇ ÁÖ¼Ò·Î ´Ù½Ã º¯°æÇÏ°í ³»ºÎ¿¡¼ ¿äûÇß´ø È£½ºÆ®·Î º¸³»ÁØ´Ù. ÀÌ·¯ÇÑ °ÍÀ» "ÇÁ·Ï½Ã(´ë¸®ÀÎ)" ¼¹ö¶ó°í ºÎ¸¥´Ù. ÁÖÀÇ : ³»ºÎÀÇ ¸Ó½Åµé¿¡¼ »ç¿ëÇÏ´Â ¸ðµç ÀÀ¿ëÇÁ·Î±×·¥Àº *¹Ýµå½Ã* ÇÁ·Ï½Ã ¼¹ö »ç¿ëÀ» Áö¿øÇØ¾ß ÇÑ´Ù. ¿¹¸¦ µé¸é, Netscape³ª ¸î¸î ÁÁÀº TELNETÀ̳ª FTP Ŭ¶óÀ̾ðÆ®µé. ÇÁ·Ï½Ã ¼¹ö¸¦ Áö¿øÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®µéÀº µ¿ÀÛÇÏÁö ¾ÊÀ» °ÍÀÌ´Ù. ÇÁ·Ï½Ã ¼¹öÀÇ ÁÁÀº Á¡ ¶Ç ÇÑ°¡Áö´Â ¾î¶² ¼¹öµéÀº ij½¬ ±â´Éµµ °®Ãß°í ÀÖ´Ù´Â °ÍÀÌ´Ù(WWW¿¡ »ç¿ëÇÏ´Â Squid). ±×·³, 50°³ÀÇ ÇÁ·Ï½ÃµÇ´Â È£½ºÆ®µéÀÌ ÀÖ°í, ¸ðµÎ ÇѲ¨¹ø¿¡ Netscape¸¦ ½ÇÇàÇÑ´Ù°í ÇÏÀÚ. ±×µéÀÌ µðÆúÆ®·Î µÇ¾î Àִ ȨÆäÀÌÁö URL·Î ¼³Á¤µÇ¾ú´Ù¸é, 50°³ÀÇ µ¿ÀÏÇÑ Netcape À¥ ÆäÀÌÁö¸¦ ¿ø°Ý¿¡¼ ¹Þ¾Æ¿Í¼ ÇØ´çÇÏ´Â ÄÄÇ»ÅÍ·Î º¸³»ÁÖ¾î¾ß ÇÑ´Ù. ij½¬ ±â´ÉÀÌ ÀÖ´Â ÇÁ·Ï½Ã ¼¹ö¶ó¸é, ÇÁ·Ï½Ã ¼¹ö°¡ ¿ø°ÝÀ¸·ÎºÎÅÍ Çѹø¸¸ ÆäÀÌÁö¸¦ ·ÎµåÇÏ°í, ÇÁ·Ï½Ã ³»ºÎÀÇ ÄÄÇ»Å͵éÀº ij½¬·ÎºÎÅÍ ±× ÆäÀÌÁö¸¦ ¹Þ¾Æº¼ °ÍÀÌ´Ù. ÀÌ·¸°Ô Çϸé, ¿ÜºÎ·ÎÀÇ ÀÎÅÍ³Ý Á¢¼Ó ´ë¿ªÆøÀ» Àý¾àÇÒ ¼ö ÀÖÀ» »Ó ¾Æ´Ï¶ó, ÇÁ·Ï½Ã ³»ºÎÀÇ ¸Ó½ÅµéÀº ÆäÀÌÁö¸¦ Àд °ÍÀÌ ¾ÆÁÖ¾ÆÁÖ ¸¹ÀÌ ºü¸£°Ô ´À²¸Áú °ÍÀÌ´Ù. MASQ: IP ¸¶½ºÄ¿·¹À̵å´Â ¸®´ª½º¿Í Zytel Prestige128, Cisco 770, NetGear ISDN ȤÀº ¶ó¿ìÅÍ µîÀÇ ¸î¸î ¶ó¿ìÅÍ¿¡¼ »ç¿ë °¡´ÉÇÏ´Ù. 1´ë´Ù NAT ÀåÁ¡: + ¿ÀÁ÷ ÇÑ°³ÀÇ IP ÁÖ¼Ò¸¸ ÇÊ¿äÇÏ´Ù (Àú·ÅÇÔ) + ÀÀ¿ëÇÁ·Î±×·¥ÀÌ Æ¯º°ÇÑ °ÍÀ» Áö¿øÇÒ ÇÊ¿ä°¡ ¾ø´Ù + ³×Æ®¿÷ º¸¾ÈÀ» °ÈÇϱâ À§Çؼ ¹æȺ® ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÑ´Ù. ´ÜÁ¡: - ¸®´ª½º È£½ºÆ®³ª Ưº°ÇÑ ISDN ¶ó¿ìÅ͸¦ ÇÊ¿ä·Î ÇÑ´Ù (´Ù¸¥ Á¦Ç°µéµµ ÀÌ ±â´ÉÀ» °¡Áú ¼ö Àִµ¥µµ.. ) - ¿ÜºÎ·ÎºÎÅÍ µé¾î¿À´Â Á¤º¸µéÀº, ³»ºÎ LANÀÇ ÄÄÇ»ÅÍ¿¡¼ ¿äûÇÑ °ÍÀÌ ¾Æ´Ï°Å³ª, ƯÁ¤ Æ÷Æ® Æ÷¿öµù ¼ÒÇÁÆ®¿þ¾î°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾ÊÀ¸¸é ³»ºÎ LAN¿¡ Á¢±ÙÇÒ ¼ö ¾ø´Ù. ¸¹Àº NAT ¼¹öµéÀÌ ÀÌ·¯ÇÑ ±â´ÉÀ» Á¦°øÇÏÁö ¾Ê´Â´Ù. - Ưº°ÇÑ ÇÁ·ÎÅäÄݵéÀº ¹æȺ® Àü´ÞÀÚ(redirector) µî¿¡ ÀÇÇØ °³º°ÀûÀ¸·Î 󸮵Ǿî¾ß ÇÑ´Ù. ¸®´ª½º´Â ÀÌ·¯ÇÑ ±â´É(FTP, IRC, ±âŸµîµî)À» ¿ÏÀüÈ÷ Áö¿øÇÏÁö¸¸ ¸¹Àº ¶ó¿ìÅ͵éÀÌ Áö¿øÇÏÁö ¾Ê´Â´Ù (NetGear´Â Áö¿øÇÑ´Ù). ¸¶½ºÄ¿·¹À̵峪 1´ë´Ù(Òý) NAT´Â, ¼¹ö°¡ IP ÁÖ¼Ò¸¦ ÀüȯÇؼ, ¸¶Ä¡ ³»ºÎ ¸Ó½ÅÀÌ ¾Æ´Ï¶ó ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö ÀÚü°¡ Á¢¼ÓÀ» ¿äûÇÑ °Íó·³(¿¹¸¦ µé¸é À¥ Á¢¼Ó µî) ¿ø°Ý ¼¹ö¸¦ ¼ÓÀδٴ Á¡¿¡¼´Â, ÇÁ·Ï½Ã ¼¹ö¿Í À¯»çÇÏ´Ù. ¸¶½ºÄ¿·¹À̵å¿Í ÇÁ·Ï½Ã ¼¹öÀÇ ÁÖµÈ Â÷ÀÌÁ¡Àº, ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö´Â Ŭ¶óÀ̾ðÆ® ¸Ó½Å(³»ºÎ ¸Ó½Å)¿¡°Ô ¾î¶°ÇÑ ¼³Á¤ÀÇ º¯°æµµ ¿ä±¸ÇÏÁö ¾Ê´Â´Ù´Â °ÍÀÌ´Ù. ´Ü½Ã ³»ºÎ ¸Ó½ÅµéÀÌ ¸®´ª½º È£½ºÆ®¸¦ ±×µéÀÇ ±âº» °ÔÀÌÆ®¿þÀÌ·Î »ç¿ëÇϵµ·Ï Çϱ⸸ ÇÏ¸é ¸ðµç °ÍÀÌ Àß µ¿ÀÛÇÒ °ÍÀÌ´Ù. (¸®¾ó¿Àµð¿À, FTP µîÀÌ µ¿ÀÛÇϱâ À§Çؼ´Â ƯÁ¤ ¸®´ª½º ¸ðµâÀ» ¼³Ä¡ÇØ¾ß ÇÑ´Ù!) ¶ÇÇÑ, ¸¹Àº »ç¶÷µéÀÌ IP ¸¶½ºÄ¿·¹À̵带 TELNET, FTP µî¿¡ »ç¿ëÇϸé¼, *µ¿½Ã¿¡* °°Àº ¸®´ª½º È£½ºÆ®¿¡ À¥ Á¢¼ÓÀ» À§ÇÑ Ä³½¬¿ë ÇÁ·Ï½Ã¸¦ ¼³Ä¡Çؼ Ãß°¡ÀûÀÎ ¼º´É Çâ»óÀ» ¾ò±âµµ ÇÑ´Ù. NAT: NAT ¼¹ö´Â Windows 95/NT, Linux, Solaris, ±×¸®°í ¸î¸î °í±ÞÀÇ ISDN ¶ó¿ìÅÍ(Ascend Á¦¿Ü)¿¡¼ »ç¿ëÇÒ ¼ö ÀÖ´Ù ÀåÁ¡: + ¼³Á¤Çϱ⠸ſì ÁÁ´Ù + Ưº°ÇÑ ÀÀ¿ë ¼ÒÇÁÆ®¿þ¾î¸¦ ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù ´ÜÁ¡: - ISP·ÎºÎÅÍ ¼ºê³ÝÀ» ÇÒ´ç¹Þ¾Æ¾ß ÇÑ´Ù (ºñ½Î´Ù) Network Address Translation(³×Æ®¿÷ ÁÖ¼Ò Àüȯ)Àº, ÀÎÅÍ³Ý ÀÎÅÍÆäÀ̽º¿¡, »ç¿ë °¡´ÉÇÑ IP ÁÖ¼Ò ¸ðÀ½À» °¡Áö°í Àִ ȣ½ºÆ®¸¦ ÁöĪÇÑ´Ù. ³»ºÎ ³×Æ®¿÷¿¡¼ ÀÎÅÍ³Ý Á¢¼ÓÀ» ÇÏ°íÀÚ ÇÒ ¶§, ±× È£½ºÆ®´Â Á¢¼ÓÀ» ¿äûÇÑ ÄÄÇ»ÅÍÀÇ ¿ø·¡ ³»ºÎ IP ÁÖ¼Ò¿¡, ÀÎÅÍ³Ý ÀÎÅÍÆäÀ̽ºÀÇ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´çÇÑ´Ù. ±× ÈÄ¿¡, ¸ðµç Á¤º¸ ±³È¯Àº NATÀÇ °ø½ÄÀûÀÎ IP ÁÖ¼Ò¿¡¼ NAT ¾ÈÂÊÀÇ ³»ºÎ ÁÖ¼Ò·Î ÀüȯÇؼ ÀÌ·ç¾îÁø´Ù. ÀÌ¹Ì ÇÒ´çµÈ °ø½ÄÀûÀÎ NATÀÇ ÁÖ¼Ò°¡ ¹Ì¸® Á¤ÇØÁø ¾ó¸¶°£ÀÇ ½Ã°£ µ¿¾È »ç¿ëµÇÁö ¾ÊÀ¸¸é, ±× °ø½ÄÀûÀÎ IP ÁÖ¼Ò´Â ´Ù½Ã »ç¿ë °¡´ÉÇÑ NAT ÁÖ¼Ò ¸ðÀ½À¸·Î µÇµ¹·Á Áø´Ù. NAT°¡ °®´Â ÁÖµÈ ¹®Á¦Á¡Àº, ¸ðµç °ø½Ä IP ÁÖ¼ÒµéÀÌ »ç¿ëµÇ¸é, ³»ºÎÀÇ »ç¿ëÀÚµéÀº »ç¿ë°¡´ÉÇÑ ÁÖ¼Ò°¡ »ý±æ ¶§±îÁö ÀÎÅͳݿ¡ Á¢¼ÓÀ» ÇÒ ¼ö ¾ø´Ù´Â °ÍÀÌ´Ù.
±×·¸½À´Ï´Ù! ±×µéÀº »ç¿ëÀÚ ÀÎÅÍÆäÀ̽º³ª º¹À⼺ µî¿¡ Â÷ÀÌ°¡ ÀÖ½À´Ï´Ù. ±×·¯³ª, Áö±Ý±îÁö´Â ´ëºÎºÐ IPFWADM¸¸ Áö¿øÇÏÁö¸¸ ²Ï ÈǸ¢ÇÕ´Ï´Ù. »ç¿ë ÇÒ ¼ö ÀÖ´Â µµ±¸µéÀ» ¾ËÆĺª ¼øÀ¸·Î °£´ÜÈ÷ ¸ñ·ÏÀ¸·Î ¸¸µé¾ú½À´Ï´Ù. ´Ù¸¥ µµ±¸µéÀ» ¾Ë°í Àְųª ¾î¶² °ÍÀÌ ÁÁ°í ³ª»Ú°í ±î´Ù·Î¿îÁö ÆòÇÏ°í ½Í´Ù¸é, Ambrose³ª David¿¡°Ô À̸ÞÀÏÀ» º¸³»Áֱ⠹ٶø´Ï´Ù.
¿¹, ISP·ÎºÎÅÍ PPP³ª DHCP/BOOTp ¼¹ö¸¦ ÅëÇؼ ÇÒ´ç¹ÞÀº µ¿Àû IP Áּҿ͵µ µ¿ÀÛÇÕ´Ï´Ù. °ø½ÄÀûÀÎ ÀÎÅÍ³Ý IP ÁÖ¼Ò°¡ Àֱ⸸ ÇÏ¸é ¹Ýµå½Ã µ¿ÀÛÇÒ °Ì´Ï´Ù. ¹°·Ð, Á¤Àû IPµµ µ¿ÀÛÇÕ´Ï´Ù. ÇÏÁö¸¸, ¿©·¯ºÐÀÌ °·ÂÇÑ IPFWADM/IPCHAINS Á¤Ã¥À» »ç¿ëÇÏ°íÀÚ ÇѴٰųª, Æ÷Æ® Æ÷¿ö´õ¸¦ »ç¿ëÇÏ°íÀÚ ÇÑ´Ù¸é, ¿©·¯ºÐÀÇ Á¤Ã¥Àº IP ÁÖ¼Ò°¡ ¹Ù²ð ¶§¸¶´Ù ´Ù½Ã ½ÇÇàµÇ¾î¾ß ÇÕ´Ï´Ù. °·ÂÇÑ ¹æȺ® Á¤Ã¥°ú µ¿Àû IP ÁÖ¼Ò¿¡ °üÇÑ Ãß°¡ÀûÀÎ µµ¿òÀº TrinityOS - Section 10ÀÇ ¾ÕºÎºÐ¿¡¼ ãÀ» ¼ö ÀÖ½À´Ï´Ù.
¿¹, ¸®´ª½º°¡ ±× ³×Æ®¿÷ ÀÎÅÍÆäÀ̽º¸¦ Áö¿øÇϱ⸸ Çϸé, ¹Ýµå½Ã µ¿ÀÛÇÒ °Ì´Ï´Ù. µ¿ÀûÀÎ IP ÁÖ¼Ò¸¦ ÇÒ´ç¹Þ¾Ò´Ù¸é, À§ÀÇ FAQÀÇ "IP ¸¶½ºÄ¿·¹À̵尡 µ¿ÀûÀ¸·Î ÇÒ´ç¹ÞÀº IP Áּҿ͵µ µ¿ÀÛÇմϱî?" Ç׸ñ ¾Æ·¡¿¡ ÀÖ´Â URLÀ» º¸½Ê½Ã¿ä.
¹°·Ð °¡´ÉÇÕ´Ï´Ù! IP ¸¶½ºÄ¿·¹À̵ùÀº Diald³ª PPP¿Í´Â ¿ÏÀüÈ÷ Åõ¸íÇÑ °ü°è¿¡ ÀÖ½À´Ï´Ù(¿ªÀÚÁÖ: ¼·ÎÀÇ ¼¼ºÎÀûÀÎ ³»¿ë¿¡ ¾ô¸ÅÀÌÁö ¾ÊÀ½). ¹®Á¦°¡ µÉ¸¸ÇÑ À¯ÀÏÇÑ °æ¿ì´Â, ¿©·¯ºÐÀÌ µ¿Àû IP ÁÖ¼Ò¿Í ÇÔ²² °·ÂÇÑ ¹æȺ® Á¤Ã¥À» »ç¿ëÇÒ ¶§ÀÔ´Ï´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº À§ÀÇ FAQÀÇ "IP ¸¶½ºÄ¿·¹À̵尡 µ¿ÀûÀ¸·Î ÇÒ´ç¹ÞÀº IP Áּҿ͵µ µ¿ÀÛÇմϱî?" Ç׸ñÀ» º¸½Ê½Ã¿ä.
"µ¿ÀÛÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥"ÀÇ ¸ñ·ÏÀ» °è¼Ó ¸¸µå´Â °ÍÀº ¸Å¿ì ¾î·Á¿î ÀÛ¾÷ÀÔ´Ï´Ù. ÇÏÁö¸¸, À¥ ºê¶ó¿ì¡(Netscape, MSIE µî), FTP(WS_FTP°°Àº °Íµé), TELNET, SSH, ¸®¾ó ¿Àµð¿À, POP3(¸ÞÀÏ ¹Þ±â - Pine, Eudora, Outlook µî), SMTP(¸ÞÀÏ º¸³»±â), ±âŸ µîµîÀÇ Åë»óÀûÀÎ ÀÎÅÍ³Ý ÀÀ¿ëÇÁ·Î±×·¥Àº ´ëºÎºÐ Áö¿øµË´Ï´Ù. ¸¶½ºÄ¿·¹À̵å¿Í ÇÔ²² µ¿ÀÛÇϴ Ŭ¶óÀ̾ðÆ®µéÀÇ Á» ´õ ¿ÏÀüÇÑ ¸ñ·ÏÀº ÀÌ ÇÏ¿ìÅõÀÇ Clients ¼½¼Ç¿¡¼ ãÀ» ¼ö ÀÖÀ» °Ì´Ï´Ù.
È»óȸÀÇ ¼ÒÇÁÆ®¿þ¾î¿Í °°ÀÌ, Á»´õ º¹ÀâÇÑ ÇÁ·ÎÅäÄÝÀ̳ª Ưº°ÇÑ Á¢¼Ó ¹æ½ÄÀ» »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥µéÀº Ưº°ÇÑ µµ±¸¸¦ °°ÀÌ »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
´õ ÀÚ¼¼ÇÑ »çÇ×Àº, Linux IP masquerading Applications ÆäÀÌÁö¸¦ º¸½Ê½Ã¿ä.
¿©·¯ºÐÀÌ ¾î¶°ÇÑ ¸®´ª½º ¹èÆ÷º»À» »ç¿ëÇÏ°í ÀÖµç, ÀÌ ÇÏ¿ìÅõ¿¡¼ ¼³¸íÇÑ IP ¸¶½ºÄ¿·¹ÀÌµå ¼³Á¤ ¹æ¹ýÀº ¿ª½Ã À¯È¿ÇÕ´Ï´Ù. ¾î¶² ¹èÆ÷º»Àº ¼³Á¤À» ½±°Ô ÇØ ÁÖ´Â GUI³ª Ưº°ÇÑ ¼³Á¤ ÈÀÏÀ» °¡Áö°í ÀÖÀ» °Ì´Ï´Ù. ¿ì¸®´Â ÀÌ ÇÏ¿ìÅõ¸¦ °¡´ÉÇϸé ÀϹÝÀûÀÎ »óȲ¿¡ ¸ðµÎ Àû¿ë °¡´ÉÇϵµ·Ï ÀÛ¼ºÇϱâ À§Çؼ ÃÖ¼±À» ´ÙÇß½À´Ï´Ù.
IP ¸¶½ºÄ¿·¹À̵å´Â, ±âº»ÀûÀ¸·Î, TCP ¼¼¼Ç°ú TCP FIN, UDP Åë½ÅµîÀÇ Á¦Çѽð£À» 15ºÐÀ¸·Î ¸ÂÃß¾î ³õ½À´Ï´Ù. ´ÙÀ½ÀÇ ¼³Á¤À»(ÀÌ ÇÏ¿ìÅõÀÇ /etc/rc.d/rc.firewall Á¤Ã¥ ÈÀÏ¿¡ ÀÌ¹Ì ³ª¿Í ÀÖÀ½) °¡´ÉÇÏ¸é ¸ðµç »ç¿ëÀڵ鿡 ´ëÇØ »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇÕ´Ï´Ù:
IPFWADMÀ» »ç¿ëÇÏ´Â ¸®´ª½º 2.0.x:
# MASQ timeouts # # 2 hrs timeout for TCP session timeouts # 10 sec timeout for traffic after the TCP/IP "FIN" packet is received # 60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself) # /sbin/ipfwadm -M -s 7200 10 60
IPCHAINS¸¦ »ç¿ëÇÏ´Â ¸®´ª½º 2.2.x:
# MASQ timeouts # # 2 hrs timeout for TCP session timeouts # 10 sec timeout for traffic after the TCP/IP "FIN" packet is received # 60 sec timeout for UDP traffic (MASQ'ed ICQ users must enable a 30sec firewall timeout in ICQ itself) # /ipchains -M -S 7200 10 60
±× ÀÌÀ¯´Â ¿©·¯ºÐÀÌ µ¿ÀûÀÎ IP ÁÖ¼Ò¸¦ °¡Áö°í ÀÖ°í, ÀÎÅÍ³Ý ¿¬°áÀÌ Ã³À½À¸·Î ÀÌ·ç¾îÁú ¶§´Â, IP ¸¶½ºÄ¿·¹À̵尡 IP ÁÖ¼Ò¸¦ ¾Ë ¼ö ¾ø±â ¶§¹®¿¡ ±×·¸½À´Ï´Ù. À̸¦ À§ÇÑ ÇØ°áÃ¥ÀÌ ÀÖ½À´Ï´Ù. ¿©·¯ºÐÀÇ /etc/rc.d/rc.firewall Á¤Ã¥ÈÀÏ¿¡, ´ÙÀ½ ³»¿ëÀ» Ãß°¡ÇϽʽÿä:
# Dynamic IP users: # # If you get your IP address dynamically from SLIP, PPP, or DHCP, enable this following # option. This enables dynamic-ip address hacking in IP MASQ, making the life # with Diald and similar programs much easier. # echo "1" > /proc/sys/net/ipv4/ip_dynaddr
ÀÌ¿¡´Â, µÎ°¡Áö ÀÌÀ¯¸¦ »ý°¢ÇØ º¼ ¼ö ÀÖ½À´Ï´Ù. ù¹ø°´Â ¸Å¿ì ÀÚÁÖ ÀϾ´Â °ÍÀÌ°í, µÎ¹ø°´Â ¸Å¿ì µå¹® °æ¿ìÀÔ´Ï´Ù.
ÇÏÁö¸¸ °ÆÁ¤ÇÒ °ÍÀº ¾ø½À´Ï´Ù. ¸Å¿ì ÈǸ¢ÇÑ º¸¿ÏÃ¥Àº ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý Á¢¼ÓÀÇ MTU¸¦ 1500À¸·Î º¯°æÇÏ´Â °ÍÀÔ´Ï´Ù. ±×·¸°Ô µÇ¸é ¾î¶² »ç¿ëÀÚµéÀº ºÒÆòÇÏ°Ô µÉ °ÍÀε¥, ±×°Ç TELNETÀ̳ª °ÔÀÓµî ¸î¸î ÀáÀç´É·Â¿¡ ¹Î°¨ÇÑ ÇÁ·Î±×·¥µéÀÌ ¹®Á¦¸¦ ÀÏÀ¸Å°±â ¶§¹®ÀÔ´Ï´Ù. ÇÏÁö¸¸, ÇÇÇØ´Â ´ÜÁö Á¶±ÝÀÏ »ÓÀÔ´Ï´Ù. HTTP¿Í FTP ¼Óµµ´Â ´õ ÁÁ¾ÆÁú °ÍÀÔ´Ï´Ù!
ÀÌ ¹®Á¦¸¦ °íÄ¡±â À§Çؼ´Â, ¿ì¼± ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý ¿¬°áÀÇ MTU°¡ ¾ó¸¶ÀÎÁö ÇöÀç ¾ó¸¶ÀÎÁö ¾Ë¾Æ¾ß ÇÕ´Ï´Ù. È®ÀÎÇÏ´Â ¹æ¹ýÀº, "/bin/ifconfig"¶ó°í ¸í·ÉÇÏ´Â °ÍÀÔ´Ï´Ù. ÀÌÁ¦ ¿©·¯ºÐÀÇ ÀÎÅÍ³Ý ¿¬°á¿¡ ÇØ´çÇÏ´Â ¶óÀεéÀ» »ìÆ캸°í MTU°¡ ¾ó¸¶ÀÎÁö È®ÀÎÇÕ´Ï´Ù. ÀÌ °ªÀº 1500À̾î¾ß ÇÕ´Ï´Ù. º¸Åë Ethernet(ÀÌ´õ³Ý) ¿¬°áÀº ±âº»ÀûÀ¸·Î ÀÌ °ªÀ¸·Î µÇ¾î ÀÖÀ» °ÍÀÌ°í, PPP´Â ±âº»ÀûÀ¸·Î 576À¸·Î µÇ¾î ÀÖÀ» °Ì´Ï´Ù.
ÀÌ°Í¿¡´Â ¸î°¡Áö ÀÌÀ¯°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù:
¿©·¯ºÐÀÌ º¸Åë º¸°Ô µÉ ¸Þ½ÃÁö´Â ¾Æ¸¶µµ ´ÙÀ½ µÎ°¡ÁöÀÏ °Ì´Ï´Ù:
TrinityOS - Section 10 ¹®¼¿¡¼:
¾Æ·¡ÀÇ Á¤Ã¥¿¡¼, ¾î¶² Æ®·¡ÇÈÀ» °ÅÀý ¶Ç´Â °ÅºÎÇÏ´Â ¶óÀεéÀº "-o" ¿É¼ÇÀ» °¡Áö°í ÀÖ¾î¼ ¹æȺ®¿¡ÀÇ Á¢±Ù ±â·ÏÀ» ´ÙÀ½ÀÇ À§Ä¡¿¡ ÀÖ´Â SYSLOG ¸Þ½ÃÁö ÈÀÏ¿¡ ³²±é´Ï´Ù: Redhat: /var/log Slackware: /var/adm ÀÌ ¹æȺ® ·Î±×µéÀ» »ìÆ캸¸é, ´ÙÀ½ÀÇ °Íµé°ú °°Àº °ÍÀ» º¸°Ô µÉ °Ì´Ï´Ù: --------------------------------------------------------------------- IPFWADM: Feb 23 07:37:01 Roadrunner kernel: IP fw-in rej eth0 TCP 12.75.147.174:1633 100.200.0.212:23 L=44 S=0x00 I=54054 F=0x0040 T=254 IPCHAINS: Packet log: input DENY eth0 PROTO=17 12.75.147.174:1633 100.200.0.212:23 L=44 S=0x00 I=54054 F=0x0040 T=254 --------------------------------------------------------------------- ÀÌ ´Ü ÇÑ ÁÙ¿¡´Â ¾ÆÁÖ ¸¹Àº Á¤º¸°¡ ÀÖ½À´Ï´Ù. ÀÌ ¿¹¸¦ ºÐ¼®ÇØ º¸¸é¼ ¿©·¯ºÐÀÌ º¸°ÔµÇ´Â ¹æȺ® Á¢±Ù ±â·ÏÀ» È®ÀÎÇØ º¾½Ã´Ù. ÀÌ ¿¹´Â IPFWADMÀ» ¼³¸íÇÏ°í ÀÖÁö¸¸ IPCHAINS »ç¿ëÀڵ鵵 ¹Ù·Î ¹«¾ðÁö ¾Ë ¼ö ÀÖÀ» °Ì´Ï´Ù. -------------- - ÀÌ ¹æȺ® "Á¢±Ù"Àº "Feb 23 07:37:01"¿¡ ¹ß»ýÇß½À´Ï´Ù. - ÀÌ Á¢±ÙÀº "RoadRunner"¶ó´Â ÄÄÇ»ÅÍ¿¡ ´ëÇÑ °ÍÀÔ´Ï´Ù. - ÀÌ Á¢±ÙÀº "IP" ȤÀº TCP/IP ÇÁ·ÎÅäÄÝÀ» ÅëÇÑ °ÍÀÔ´Ï´Ù. - ÀÌ Á¢±ÙÀº ¹æȺ®À¸·Î "µé¾î¿À´Â"("fw-in") °ÍÀÔ´Ï´Ù. * ´Ù¸¥ ·Î±×µéÀº "³ª°¡´Â" °Í¿¡ ´ëÇؼ "fw-out" ȤÀº FORWARDÇÏ´Â °Í¿¡ ´ëÇؼ´Â "fw-fwd"¶ó°í ÇÒ °ÍÀÔ´Ï´Ù. - ÀÌ Á¢±ÙÀº "°ÅºÎµÇ¾ú½À´Ï´Ù(rejECTED)". * ´Ù¸¥ ·Î±×µéÀº "deny" ȤÀº "accept"¶ó°í ÇÒ ¼öµµ ÀÖ½À´Ï´Ù. - ÀÌ ¹æȺ® Á¢±Ù "eth0" ÀÎÅÍÆäÀ̽º(ÀÎÅÍ³Ý ¿¬°á)¿¡¼ ÀϾ½À´Ï´Ù. - ÀÌ Á¢±ÙÀº "TCP" ÆÐŶÀ̾ú½À´Ï´Ù. - ÀÌ Á¢±ÙÀº "12.75.147.174"fksms IP ÁּҷκÎÅÍ ¿Â °ÍÀÌ°í "1633"¹ø Æ÷Æ®·Î µ¹·ÁÁ³½À´Ï´Ù. - ÀÌ Á¢±ÙÀº "100.200.0.212"¶ó´Â ÁÖ¼Ò¿¡ "23"¹ø Æ÷Æ® ȤÀº TELNETÀ¸·Î ¿¬°áÇϱâ À§ÇÑ °ÍÀ̾ú½À´Ï´Ù. * 23¹ø Æ÷Æ®°¡ TELNETÀ» À§ÇÑ °ÍÀÎÁö Àß ¸ð¸£°Ú´Ù¸é, /etc/services ÈÀÏ¿¡¼ Æ÷Æ®¸¦ È®ÀÎÇϽʽÿä. - ÀÌ ÆÐŶÀº Å©±â°¡ "44" ¹ÙÀÌÆ®¿´½À´Ï´Ù. - ÀÌ ÆÐŶÀº "Type of Service(¼ºñ½º Á¾·ù)"°¡ ¼³Á¤µÅ ÀÖÁö ¾Ê¾Ò½À´Ï´Ù. --ÀÌ ¸»À» ÀÌÇØÇÏÁö ¸øÇÏ´õ¶ó°í °ÆÁ¤ÇÏÁö ¸¶½Ê½Ã¿ä.. ¾Ë ÇÊ¿ä ¾ø½À´Ï´Ù. * ipchains »ç¿ëÀÚÀÇ °æ¿ì ÀÌ °ªÀ» 4·Î ³ª´©¸é ¼ºñ½º Á¾·ù°¡ µË´Ï´Ù. - ÀÌ ÆÐŶÀº "IP ID" ¹øÈ£°¡ "18" À̾ú½À´Ï´Ù. --ÀÌ ¸»À» ÀÌÇØÇÏÁö ¸øÇÏ´õ¶ó°í °ÆÁ¤ÇÏÁö ¸¶½Ê½Ã¿ä.. ¾Ë ÇÊ¿ä ¾ø½À´Ï´Ù. - ÀÌ ÆÐŶÀº 16ºñÆ®ÀÇ Á¶°¢ À§Ä¡¸¦ °¡Áö°í ÀÖ°í TCP/IP ÆÐŶ Ç÷¡±×´Â "0x0000"À̾ú½À´Ï´Ù. --ÀÌ ¸»À» ÀÌÇØÇÏÁö ¸øÇÏ´õ¶ó°í °ÆÁ¤ÇÏÁö ¸¶½Ê½Ã¿ä.. ¾Ë ÇÊ¿ä ¾ø½À´Ï´Ù. * "0x2..."³ª "0x3..."·Î ½ÃÀÛÇÏ´Â °ªÀº "´õ ¸¹Àº Á¶°¢" ºñÆ®°¡ µÇ¾î¼ ´õ¸¹Àº Á¶°¢³ ÆÐŶµéÀÌ µµÂøÇؾßÁö ÀÌ "Å«" ÆÐŶÀÌ ¿Ï¼ºµÉ °ÍÀ̶ó´Â °ÍÀ» ÀǹÌÇÕ´Ï´Ù. * "0x4..."³ª "0x5..."·Î ½ÃÀÛÇÏ´Â °ªÀº "Á¶°¢³»±â ±ÝÁö" ºñÆ®°¡ ¼³Á¤µÇ¾î ÀÖ´Ù´Â °ÍÀ» ÀǹÌÇÕ´Ï´Ù. * ´Ù¸¥ °ªµéÀº Á¶°¢ À§Ä¡ (8·Î ³ª¿ì¾úÀ» ¶§) °ªµéÀÌ°í ³ªÁß¿¡ ¿ø·¡ÀÇ Å« ÆÐŶÀ¸·Î Á¶ÇÕÇÒ ¶§ »ç¿ëµË´Ï´Ù. - ÀÌ ÆÐŶÀº Áö¼Ó½Ã°£(TimeToLive) (TTL)ÀÌ 20À̾ú½À´Ï´Ù. * ÀÎÅͳݻ󿡼ÀÇ ¸Å µµ¾à ¶§ ¸¶´Ù ÀÌ °ªÀº 1¾¿ °¨¼ÒÇÕ´Ï´Ù. º¸Åë, ÆÐŶµéÀº Ãâ¹ßÇÒ ¶§ 255ÀÇ °ªÀ» °®°í ¸¸¾à ÀÌ ¼ýÀÚ°¡ °á±¹ 0ÀÌ µÇ¸é, ÆÐŶÀº ¾ø¾îÁø °ÍÀ̶ó¼ Áö¿öÁö°Ô µÉ °Ì´Ï´Ù.
¿¹! IPPORTFW¸¦ »ç¿ëÇϸé, ¸ðµç, ȤÀº ¼±ÅÃµÈ ¸î¸î ÀÎÅÍ³Ý È£½ºÆ®µéÀÌ ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»Å͵鿡 Á¢¼ÓÇÒ ¼ö ÀÖµµ·Ï ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÁÖÁ¦¿¡ ´ëÇؼ´Â Forwarders ¼½¼Ç¿¡¼ »ó¼¼È÷ ´Ù·ç°í ÀÖ½À´Ï´Ù.
³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½Å Áß Çϳª°¡ ÀÎÅͳÝÀ¸·Î ³ª°¡´Â ÆÐŶÀ» ºñÁ¤»óÀûÀ¸·Î ¸¹ÀÌ ¸¸µé°í Àֱ⠶§¹®ÀÔ´Ï´Ù. IP ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö´Â ¸¶½ºÄ¿·¹À̵å Å×À̺íÀ» ¸¸µé°í ÀÌ ÆÐŶµéÀ» ÀÎÅͳÝÀ¸·Î ³»º¸³»´Âµ¥, ÀÌ Å×À̺íÀÌ ³Ê¹« »¡¸® ä¿öÁö´Â °Ì´Ï´Ù. ÀÏ´Ü Å×À̺íÀÌ ²Ë Â÷°Ô µÇ¸é, ÀÌ¿Í °°Àº ¿¡·¯¸¦ ³»°Ô µË´Ï´Ù.
ÀÌ·¯ÇÑ »óȲÀ» ¸¸µé¾î ³»´Â ÀÀ¿ëÇÁ·Î±×·¥À¸·Î¼ Á¦°¡ ¾Ë°í ÀÖ´Â À¯ÀÏÇÑ °ÍÀº "GameSpy"¶ó´Â °ÔÀÓ ÇÁ·Î±×·¥ÀÔ´Ï´Ù. ÀÌÀ¯´Â, Gamespy¶ó´Â °ÔÀÓÀº ¼¹öÀÇ ¸®½ºÆ®¸¦ ¸¸µé°í, ±× ¸®½ºÆ®¿¡ ÀÖ´Â ¼öõ°³ÀÇ ¸ðµç °ÔÀÓ ¼¹ö¿¡ pingÀ» Çϱ⠶§¹®ÀÔ´Ï´Ù. ÀÌ·¸°Ô pingÀ» ÇÔÀ¸·Î½á, ¸Å¿ì ªÀº ½Ã°£µ¿¾È ¼ö¸¸°³ÀÇ ºü¸¥ Á¢¼ÓÀ» ¿ä±¸ÇÕ´Ï´Ù. À̵éÀÌ IP ¸¶½ºÄ¿·¹À̵åÀÇ ½Ã°£Á¦ÇÑ¿¡ °É·Á¼ ³¡³¯ ¶§±îÁö, ¸¶½ºÄ¿·¹À̵å Å×À̺íÀ» "²Ë" Â÷°Ô µË´Ï´Ù.
±×·³ ¾î¶»°Ô Çϳª¿ä? ÀÌ»óÀûÀ¸·Î ¸»ÇÑ´Ù¸é, ±×·± ÇÁ·Î±×·¥Àº ¾²Áö ¸¶½Ê½Ã¿ä. ·Î±× ÈÀÏ¿¡ ±×·± ¿¡·¯µéÀÌ ½×Àδٸé, ¾î¶² ÇÁ·Î±×·¥ÀÎÁö ã¾Æ³»¼ »ç¿ëÀ» ÁßÁöÇϽʽÿä. ÇÏÁö¸¸, ¿©·¯ºÐÀÌ GameSpy°°Àº °ÔÀÓÀ» Á¤¸»·Î ÁÁ¾ÆÇÑ´Ù¸é, ¼¹ö ¸ñ·ÏÀ» °»½ÅÇÏ´Â °ÍÀ» ¸¹ÀÌ ÇÏÁö ¸¶½Ê½Ã¿ä. ¾î·µç, ±×·± ÇÁ·Î±×·¥µéÀ» »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é, ¸¶½ºÄ¿·¹À̵尡 ³»º¸³»´ø ±× ¿¡·¯µéÀº ´õ ÀÌ»ó ³ªÅ¸³ªÁö ¾ÊÀ» °Ì´Ï´Ù.
"ipfwadm: setsockopt failed: Protocol not available"¶ó´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ ¸¸³´Ù¸é, »õ·Ó°Ô ÄÄÆÄÀÏÇÑ Ä¿³ÎÀ» »ç¿ëÇÏ°í ÀÖÁö ¾ÊÀº °ÍÀÔ´Ï´Ù. »õ Ä¿³ÎÀ» Á¦ À§Ä¡¿¡ ¿Å±â°í, LILO¸¦ ´Ù½Ã ½ÇÇàÇÏ°í, ´Ù½Ã ÀçºÎÆÃÇØ º¸½Ê½Ã¿ä.
ÀÚ¼¼ÇÑ »çÇ×Àº Forwarders ¼½¼ÇÀÇ ¸¶Áö¸· ºÎºÐÀ» º¸½Ê½Ã¿ä.
MicrosoftÀÇ SMB ÇÁ·ÎÅäÄÝÀ» Á¦´ë·Î Áö¿øÇϱâ À§Çؼ´Â ±×¸¦ À§ÇÑ ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀÌ ÀÖ¾î¾ß ÇÏÁö¸¸, ÇöÀç·Î¼´Â ¼¼°¡ÁöÀÇ ¿ìȸÀûÀÎ ¹æ¹ýÀÌ ÀÖ½À´Ï´Ù. ÀÚ¼¼ÇÑ »çÇ×Àº, this Microsoft KnowledgeBase articleÀ» º¸½Ê½Ã¿ä.
ù¹ø° ¿ìȸ¹æ¹ýÀº, IPPORTFW¸¦ Forwarders ¼½¼Ç¿¡ ³ª¿Â ´ë·Î ¼³Á¤ÇÏ°í, TCP Æ÷Æ® 137, 138, 139¸¦ ³»ºÎÀÇ À©µµ¿ìÁî ¸Ó½ÅÀÇ IP ÁÖ¼Ò·Î Æ÷¿öµåÇÏ´Â °ÍÀÔ´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é µ¿ÀÛÇϱä ÇÏÁö¸¸, ¿ÀÁ÷ ÇÑ °³ÀÇ ³»ºÎ ¸Ó½Å¿¡ ´ëÇؼ¸¸ µ¿ÀÛÇÒ °ÍÀÔ´Ï´Ù.
µÎ¹øÀç ¹æ¹ýÀº, ¸®´ª½º ¸¶½ºÄ¿·¹ÀÌµå ¼¹ö¿¡ Samba¸¦ ¼³Ä¡ÇÏ´Â °ÍÀÔ´Ï´Ù. Samba°¡ ½ÇÇàÇϸé, ³»ºÎÀÇ À©µµ¿ìÁîÀÇ ÈÀÏ ÇÁ¸°Æ® °øÀ¯¸¦ Samba ¼¹ö¿¡¼ º¸ÀÌ°Ô ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¸é, ¿ÜºÎÀÇ ¸ðµç Ŭ¶óÀ̾ðÆ®¿¡¼ ÀÌ °øÀ¯µé¿¡ Á¢±ÙÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù. Samba¸¦ ¼³Á¤ÇÏ´Â ¹æ¹ýÀº ¸®´ª½º ¹®¼ ÇÁ·ÎÁ§Æ®ÀÇ HOWTO¿¡¼ ãÀ» ¼ö ÀÖ°í, TrinityOS ¹®¼¿¡¼µµ ¿ª½Ã ãÀ» ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
¼¼¹ø° ¹æ¹ýÀº, µÎ ¿Þµµ¿ìÁî ¸Ó½Å »çÀÌ¿¡, ȤÀº µÎ ³×Æ®¿÷ »çÀÌ¿¡ VPN(°¡»ó °³ÀÎ ³×Æ®¿÷)À» ¼³Á¤ÇÏ´Â °ÍÀÔ´Ï´Ù. ÀÌ°ÍÀº PPTP³ª IPSEC VPN ¼Ö·ç¼ÇÀ» »ç¿ëÇؼ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¸®´ª½º¿ëÀÇ PPTP ÆÐÄ¡µµ ÀÖ°í, 2.0.x¿Í 2.2.x Ä¿³Î¿¡¼ »ç¿ëÇÒ ¼ö ÀÖ´Â ¿ÏÀüÇÑ IPSECµµ ±¸ÇöµÇ¾î ÀÖ½À´Ï´Ù. ÀÌ ¹æ¹ýÀº ¼¼°¡Áö ¹æ¹ý Áß¿¡¼ °¡Àå ¾ÈÁ¤ÀûÀÌ°í ¾ÈÀüÇÑ ¹æ¹ýÀÔ´Ï´Ù.
ÀÌ ¹æ¹ýµéÀº ÀÌ HOWTO¿¡¼ ´Ù·çÁö´Â ¾Ê½À´Ï´Ù. IPSEC¿¡ ´ëÇؼ´Â TrinityOS ¹®¼¿¡¼ µµ¿òÀ» ¹ÞÀ» ¼ö ÀÖÀ» °ÍÀÌ°í, ±× ÀÌ»óÀÇ Á¤º¸´Â JJohn HardinÀÇ PPTP ÆäÀÌÁö¸¦ º¼ °ÍÀ» ±ÇÀåÇÕ´Ï´Ù.
¶ÇÇÑ ¾Ë¾Æ µÑ °ÍÀº, MicrosoftÀÇ SMB ÇÁ·ÎÅäÄÝÀº º¸¾È¿¡ ¸Å¿ì Ãë¾àÇÏ´Ù´Â °ÍÀÔ´Ï´Ù. ÀÌ ¶§¹®¿¡, ÀÎÅͳÝÀ» ÅëÇؼ ¾ÏÈ£È ¾øÀÌ Microsoft ÈÀÏ ÇÁ¸°Æ® °øÀ¯³ª ¿Þµµ¿ìÁî µµ¸ÞÀÎ ·Î±äÀ» »ç¿ëÇÏ´Â °ÍÀº ¸Å¿ì ÁÁÁö ¾Ê½À´Ï´Ù.
ÁÖµÈ ¿øÀÎÀ¸·Î »ý°¢ÇÒ ¼ö ÀÖ´Â °ÍÀº, ´ëºÎºÐÀÇ ¸®´ª½º ¹èÆ÷º»µéÀÇ IDENT³ª "ÀÎÁõ" ¼¹ö´Â IP ¸¶½ºÄ¿·¹À̵åµÇ´Â ¿¬°áÀ» ó¸®ÇÏÁö ¸ø ÇÑ´Ù´Â °Ì´Ï´Ù. ÇÏÁö¸¸ °ÆÁ¤ÇÒ °ÍÀº ¾ø½À´Ï´Ù. Á¦´ë·Î µ¿ÀÛÇÏ´Â IDENTµéÀÌ ÀÖÀ¸´Ï±î¿ä.
ÀÌ ¼ÒÇÁÆ®¿þ¾î¸¦ ¼³Ä¡ÇÏ´Â °ÍÀº ÀÌ HOWTOÀÇ ³»¿ëÀ» ¹þ¾î³ª´Â °ÍÀÔ´Ï´Ù. °¢°¢ÀÇ µµ±¸µéÀº °¢°¢ ¹®¼µéÀ» °¡Áö°í ÀÖ½À´Ï´Ù. ¿©±â¿¡ ¸î°³ÀÇ URLµéÀ» Àû½À´Ï´Ù:
¾î¶² ÀÎÅÍ³Ý IRC ¼¹öµéÀº ¿©ÀüÈ÷ °°Àº È£½ºÆ®¿¡¼ ¿©·¯°³ÀÇ Á¢¼ÓÀ» ÇÏ´Â °ÍÀ» Çã¿ëÇÏÁö ¾Ê°í ÀÖ½À´Ï´Ù. ÀÎÁõ Á¤º¸¸¦ ÅëÇؼ »ç¿ëÀÚµéÀÌ ¼·Î ´Ù¸£´Ù´Â °ÍÀ» ¾Ë ¼ö ÀÖ´õ¶óµµ ¸»ÀÔ´Ï´Ù. ±× ¶§´Â ±× ¼¹öÀÇ °ü¸®ÀÚ¿¡°Ô Ç×ÀÇÇϽʽÿä. :)
ÀÌ°ÍÀº mIRCÀÇ ¼³Á¤ ¹®Á¦ÀÔ´Ï´Ù. °íÄ¡±â À§Çؼ´Â, ¿ì¼± mIRC¸¦ IRC ¼¹ö·ÎºÎÅÍ Á¢¼ÓÀ» ²÷½À´Ï´Ù. ±×¸®°í, mIRC¿¡¼ ÈÀÏ --> ¼³Á¤À¸·Î °¡¼ "IRC servers tab"À» Ŭ¸¯ÇÕ´Ï´Ù. Æ÷Æ®°¡ 6667·Î ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÕ´Ï´Ù. ´Ù¸¥ Æ÷Æ®¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù¸é, ÀÌ ¾Æ·¡¿¡ ÀÖ´Â ³»¿ëÀ» º¸½Ê½Ã¿ä. ´ÙÀ½À¸·Î, ÈÀÏ --> ¼³Á¤ --> Áö¿ª Á¤º¸·Î °¡¼ Áö¿ª È£½ºÆ®(ÀÚ½ÅÀÇ È£½ºÆ®)¿¡ ÇØ´çÇÏ´Â ºÎºÐ°ú IP ÁÖ¼Ò¸¦ Áö¿ó´Ï´Ù. "LOCAL HOST"¿Í "IP address"(IP address´Â üũµÇ¾úÁö¸¸ »ç¿ëºÒ°¡·Î µÉ ¼ö ÀÖ½À´Ï´Ù)ÀÇ Ã¼Å©¹Ú½º¸¦ ¼±ÅÃÇÕ´Ï´Ù. ´ÙÀ½À¸·Î, "Lookup Method(°Ë»ö¹æ¹ý)"À» "normal(º¸Åë)"À¸·Î ¼³Á¤ÇÕ´Ï´Ù. ¸¸¾à¿¡ "servers"°¡ ¼±ÅõǾî ÀÖÀ¸¸é µ¿ÀÛÇÏÁö ¾ÊÀ» °Ì´Ï´Ù. ÀÚ ³¡³µ½À´Ï´Ù. IRC ¼¹ö¿¡ ´Ù½Ã Á¢¼ÓÇØ º¸½Ê½Ã¿ä.
IRC ¼¹öÀÇ Æ÷Æ®¸¦ 6667ÀÌ ¾Æ´Ñ °ÍÀ» »ç¿ëÇØ¾ß ÇÑ´Ù¸é, (¿¹¸¦ µé¾î 6969) IRC ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» ·ÎµåÇÏ´Â /etc/rc.c/rc.firewall ÈÀÏÀ» ÆíÁýÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÈÀÏ¿¡¼ "modprobe ip_masq_irc"¶ó´Â ÁÙÀÌ ÀÖ´Â °÷À» ÆíÁýÇؼ "ports=6667,6969"¸¦ ±¸°¡ÇÕ´Ï´Ù. ´Ù¸¥ Æ÷Æ®µéµµ ÄÞ¸¶·Î ±¸ºÐÇؼ Ãß°¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.
¸¶Áö¸·À¸·Î, ¸¶½ºÄ¿·¹À̵åµÇ´Â ¸Ó½ÅµéÀÇ IRC Ŭ¶óÀ̾ðÆ®µéÀ» Á¾·áÇÏ°í IRC ¸¶½ºÄ¿·¹ÀÌµå ¸ðµâÀ» ´Ù½Ã ·ÎµåÇÕ´Ï´Ù:
/sbin/rmmod ip_masq_irc /etc/rc.d/rc.firewall
±×·¸±âµµ ÇÏ°í ¾Æ´Ï±âµµ ÇÕ´Ï´Ù. "IP Alias"¶ó´Â Ä¿³ÎÀÇ ±â´ÉÀ» ÅëÇؼ, »ç¿ëÀÚ´Â eth0:1, eth0:2 µî°ú °°ÀÌ ¿©·¯°³ÀÇ ÀÎÅÍÆäÀ̽º¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÇÏÁö¸¸, IP ¸¶½ºÄ¿·¹À̵忡 aliasµÈ ÀÎÅÍÆäÀ̽º¸¦ »ç¿ëÇÏ´Â °ÍÀº ÃßõÇÏÁö ¾Ê½À´Ï´Ù. ¿Ö³Ä±¸¿ä? ÇÑ °³ÀÇ ³×Æ®¿÷ Ä«µå¸¦ ÅëÇؼ´Â ¾ÈÀüÇÑ ¹æȺ®À» ±¸¼ºÇÏ´Â °ÍÀÌ ´ë´ÜÈ÷ ¾î·Æ½À´Ï´Ù. ¶ÇÇÑ, ÆÐŶµéÀÌ µé¾î¿À¸é ¶Ç µ¿½Ã¿¡ ³»º¸³»Áö±â ¶§¹®¿¡ »ó´ç·®ÀÇ ¿¡·¯µéÀÌ ³¯ °ÍÀÔ´Ï´Ù. ÀÌ·± ÀÌÀ¯µµ ÀÖ°í ¶Ç ¿äÁòÀº ³×Æ®¿÷ Ä«µå°¡ Àú·ÅÇϱ⠶§¹®¿¡, Àú´Â ¿©·¯ºÐ¿¡°Ô ³×Æ®¿÷ Ä«µå¸¦ ´õ ±¸ÀÔÇÒ °ÍÀ» °·ÂÈ÷ ±ÇÀåÇÕ´Ï´Ù.
¿©·¯ºÐÀÌ ¶Ç ¾Ë¾ÆµÖ¾ß ÇÒ °ÍÀº, IP ¸¶½ºÄ¿·¹À̵ùÀº eth0, eth1 µî°ú °°Àº ¹°¸®ÀûÀÎ ÀÎÅÍÆäÀ̽º¿¡¼¸¸ Á¦´ë·Î µ¿ÀÛÇÑ´Ù´Â °Ì´Ï´Ù. "eth0:1, eth1:1 µî°ú °°ÀÌ" alias µÈ ÀÎÅÍÆäÀ̽º¿¡¼ ¸¶½ºÄ¿·¹À̵ùÀº Á¦´ë·Î µ¿ÀÛÇÏÁö ¾ÊÀ» °Ì´Ï´Ù. ¸»ÇÏÀÚ¸é, ´ÙÀ½°ú °°Àº °æ¿ì´Â µ¿ÀÛÇÏÁö ¾ÊÀ» °Ì´Ï´Ù:
ÇÏÁö¸¸ ¿©ÀüÈ÷ alias µÈ ÀÎÅÍÆäÀ̽º¸¦ »ç¿ëÇÏ°í ½Í´Ù¸é, Ä¿³Î¿¡¼ "IP Alias" ±â´ÉÀ» ÄÑ¾ß ÇÕ´Ï´Ù. ±×¸®°í Ä¿³ÎÀ» ´Ù½Ã ÄÄÆÄÀÏÇÏ°í ÀçºÎÆÃÇØ¾ß ÇÕ´Ï´Ù. »õ·Î¿î Ä¿³Î·Î ºÎÆÃÇÏ°í ³ª¸é, ¸®´ª½º°¡ »õ·Î¿î ÀÎÅÍÆäÀ̽º(¿¹¸¦ µé¸é /dev/eth0:1 µî)¸¦ »ç¿ëÇϵµ·Ï ¼³Á¤ÇØ Áà¾ß ÇÕ´Ï´Ù. ±×¸®°í ³ª¸é, ¾Õ¼ ¸»ÇÑ °Í°ú °°Àº Á¦¾àÀº ÀÖÁö¸¸ ±×°ÍµéÀ» º¸ÅëÀÇ ÀÌ´õ³Ý ÀÎÅÍÆäÀ̽ºÃ³·³ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
"netstat" ÇÁ·Î±×·¥¿¡´Â ¹®Á¦°¡ ÀÖ½À´Ï´Ù. ¸®´ª½º ºÎÆ®µÈ Á÷ÈÄ¿¡, "netstat -M"¶ó°í ¸í·ÉÇϸé Àß µ¿ÀÛÇÏÁö¸¸, ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍ°¡ pingÀ̳ª traceroute °°Àº ICMP Åë½ÅÀ» ¼öÇàÇÏ°í ³ª¼´Â ´ÙÀ½°ú °°Àº °ÍÀ» º¸°Ô µÉ °Ì´Ï´Ù:
masq_info.c: Internal Error `ip_masquerade unknown type'.
À̸¦ À§ÇÑ ´Ù¸¥ ¹æ¹ýÀº "/sbin/ipfwadm -M -l"¶ó´Â ¸í·ÉÀ» »ç¿ëÇÏ´Â °Ì´Ï´Ù. ¶ÇÇÑ ¿°ÅµÈ ICMP ¸¶½ºÄ¿·¹À̵å Ç׸ñµéÀÌ ³¡³ª°í ³ª¸é, "netstat"°¡ ´Ù½Ã Àß µ¿ÀÛÇÏ´Â °É º¸°Ô µÉ °Ì´Ï´Ù.
°¡´ÉÇÕ´Ï´Ù. ÇÏÁö¸¸ ÀÌ ¹®¼ÀÇ ¹üÁÖ¸¦ ¹þ¾î³ª´Â °ÍÀ̹ǷÎ, ÀÚ¼¼ÇÑ Á¤º¸´Â John HardinÀÇ PPTP Masq¸¦ º¸½Ã±â ¹Ù¶ø´Ï´Ù.
¿ì¼±, Steve Grevemeyer's MASQ Applications page¸¦ »ìÆ캸½Ê½Ã¿ä. °Å±â¿¡ ÇØ°áÃ¥ÀÌ ¾ø´Ù¸é, À§ÀÇ LooseUDP ¼½¼Ç¿¡ ÀÖ´Â Glenn LambÀÇ LooseUDP ÆÐÄ¡·Î ¸®´ª½º Ä¿³ÎÀ» ÆÐÄ¡ÇØ º¸½Ê½Ã¿ä. ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â Dan KegelÀÇ NAT Page¸¦ »ìÆ캸½Ê½Ã¿ä.
¿©·¯ºÐÀÌ ±â¼úÀûÀÎ ´É·ÂÀÌ ÀÖ´Ù¸é, "tcpdump" ÇÁ·Î±×·¥À» »ç¿ëÇؼ ¿©·¯ºÐÀÇ ³×Æ®¿÷À» sniff ÇØ º¸½Ê½Ã¿ä. ±× XYZ °ÔÀÓÀÌ »ç¿ëÇÏ°í ÀÖ´Â ÇÁ·ÎÅäÄÝ°ú Æ÷Æ® ¹øÈ£¸¦ ¾Ë¾Æ³»´Â °Ì´Ï´Ù. ÀÌ Á¤º¸µéÀ» ¾Ë¾Æ³»¸é, IP Masq email list¿¡ °¡ÀÔÇÏ°í ¿©·¯ºÐÀÇ °á°ú¸¦ ÀÌ ¸ÞÀÏ·Î º¸³»°í µµ¿òÀ» ¿äûÇϽʽÿä.
Á¦°¡ »ý°¢Çϱ⿡ ¿©·¯ºÐÀº IPAUTOFWÀ» »ç¿ëÇÏ°í Àְųª Ä¿³Î¿¡ Æ÷ÇÔ½ÃÄ×À» °Ì´Ï´Ù. ¸Â³ª¿ä?? ÀÌ°Ç IPAUTOFWÀÇ Àß ¾Ë·ÁÁø ¹®Á¦Á¡ÀÔ´Ï´Ù. ¸®´ª½º Ä¿³Î¿¡ IPAUTOFW ±â´ÉÀ» Æ÷ÇÔ½ÃÅ°Áö ¸»°í, ´ë½Å IPPORTFW ¿É¼ÇÀ» »ç¿ëÇϽʽÿä. ÀÌ ¹®Á¦µéÀº Forwarders ¼½¼Ç¿¡¼ ÀÚ¼¼È÷ ´Ù·ç°í ÀÖ½À´Ï´Ù.
ÀÌ°ÍÀÌ ¸¶½ºÄ¿·¹À̵ù¿¡ °ü·ÃµÈ »çÇ×Àº ¾ÆÁö¸¸, ¸¹Àº »ç¶÷µé¿¡ °ü°èµÈ °ÍÀ̱⠶§¹®¿¡ ¿©±â¿¡ ¾ð±ÞÇÕ´Ï´Ù.
SMTP: ¿©·¯ºÐÀº ¾Æ¸¶µµ ¸®´ª½º ¹Ú½º¸¦ SMTP Áß°è±â(relay)·Î »ç¿ëÇÏ·Á°í ÇÏ°í ´ÙÀ½°ú °°Àº ¿¡·¯°¡ ³¯ °Ì´Ï´Ù:
"error from mail server: we do not relay"
SendmailÀÇ »õ ¹öÁ¯À̳ª ´Ù¸¥ ¸ÞÀÏ Àü¼Û ÇÁ·Î±×·¥(MTA)µéÀº ±âº»ÀûÀ¸·Î Á߰踦 ÇÏÁö ¾Ê½À´Ï´Ù(ÀÌ°ÍÀÌ ¹Ù¶÷Á÷ÇÑ °Ì´Ï´Ù). ÀÌ ¹®Á¦¸¦ °íÄ¡·Á¸é ´ÙÀ½°ú °°ÀÌ ÇÕ´Ï´Ù:
POP-3: ¾î¶² »ç¿ëÀÚµéÀº ³»ºÎÀÇ ¸¶½ºÄ¿·¹À̵åµÇ´Â ÄÄÇ»ÅÍÀÇ POP-3 Ŭ¶óÀ̾ðÆ®µéÀÌ ¿ÜºÎÀÇ SMTP ¼¹ö¿¡ Á¢¼ÓÇϵµ·Ï ¼³Á¤ÇÕ´Ï´Ù. ÀÌ°Ç ±¦ÂúÁö¸¸, ¸¹Àº SMTP ¼¹öµéÀº Æ÷Æ® 113À¸·Î ¿©·¯ºÐÀÇ ¿¬°áÀ» ÀÎÁõ(IDENT)ÇÏ°íÀÚ ÇÒ °ÍÀÔ´Ï´Ù. ¹®Á¦°¡ ¹ß»ýÇÏ´Â °ÍÀº, ´ëºÎºÐ ¿©·¯ºÐÀÇ ±âº» ¸¶½ºÄ¿·¹À̵å Á¤Ã¥ÀÌ DENYÀÎ °Í°ú °ü·ÃµÅ ÀÖ½À´Ï´Ù. ÀÌ°Ç ¹Ù¶÷Á÷ÇÏÁö ¾Ê½À´Ï´Ù. ÀÌ°ÍÀ» REJECT·Î ¼³Á¤ÇÏ°í rc.firewall Á¤Ã¥À» ´Ù½Ã ½ÇÇàÇϽʽÿä.
¿©·¯ºÐÀÌ ´ÙÀ½°ú °°Àº ¹®Á¦¸¦ °¡Áö°í ÀÖ´Ù°í ÇսôÙ:
³»ºÎ LAN -----> °ø½Ä IP 192.168.1.x --> 123.123.123.11 192.168.2.x --> 123.123.123.12
¿©·¯ºÐÀº ¿ì¼±, IPFWADM°ú IPCHAINS´Â ¶ó¿ìÆà ½Ã½ºÅÛÀÌ ÆÐŶÀ» ¾îµð·Î º¸³¾ °ÍÀΰ¡¸¦ °áÁ¤ÇÑ *ÈÄ¿¡* ½ÇÇàµÈ´Ù´Â »ç½ÇÀ» ÀÌÇØÇØ¾ß ÇÕ´Ï´Ù. ÀÌ »ç½ÇÀº ¸ðµç IPFWADM/IPCHAINS/IPMASQ ¹®¼¿¡ Ä¿´Ù¸¥ ºÓÀº ±Û¾¾·Î µµÀåÀ» Âï¾î³ö¾ß ¸¶¶¥ÇÕ´Ï´Ù. ¿ì¼± ¶ó¿ìÆÃÀÌ Á¦´ë·Î µÇµµ·Ï ÇÏ°í ³ª¼ IPFWADM/IPCHAINS³ª ¸¶½ºÄ¿·¹À̵ùÀ» Ãß°¡ÇØ¾ß ÇÏ´Â °Ì´Ï´Ù.
À§ÀÇ °æ¿ì¿¡¼´Â, ¿ì¼± ¶ó¿ìÆà ½Ã½ºÅÛÀÌ 192.168.1.x·ÎºÎÅÍÀÇ ÆÐŶÀ» 123.123.123.11·Î, 192.168.2.x·ÎºÎÅÍÀÇ ÆÐŶÀ» 123.123.123.12·Î º¸³»µµ·Ï ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÀÛ¾÷ÀÌ ¾î·Á¿î ÀÛ¾÷ÀÌ°í, ±× À§¿¡ ¸¶½ºÄ¿·¹À̵带 ¼³Á¤ÇÏ´Â °ÍÀº ½±½À´Ï´Ù.
ÀÌ ÀÛ¾÷À» À§Çؼ IPROUTE2¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
Primary FTP site is:
Mirrors are:
ftp://linux.wauug.org/pub/net ftp://ftp.nc.ras.ru/pub/mirrors/ftp.inr.ac.ru/ip-routing/ ftp://ftp.gts.cz/MIRRORS/ftp.inr.ac.ru/ ftp://ftp.funet.fi/pub/mirrors/ftp.inr.ac.ru/ip-routing/ (STM1 to USA) ftp://sunsite.icm.edu.pl/pub/Linux/iproute/ ftp://ftp.sunet.se/pub/Linux/ip-routing/ ftp://ftp.nvg.ntnu.no/pub/linux/ip-routing/ ftp://ftp.crc.ca/pub/systems/linux/ip-routing/ ftp://ftp.paname.org (France) ftp://donlug.ua/pub/mirrors/ip-route/ ftp://omni.rk.tusur.ru/mirrors/ftp.inr.ac.ru/ip-routing/
RPMs are available at ftp://omni.rk.tusur.ru/Tango/ and at ftp://ftp4.dgtu.donetsk.ua/pub/RedHat/Contrib-Donbass/KAD/
NOTE: The following instructions are given below ONLY because currently there is very little documentation to the IPROUTE2 tool available. Check out http://www.compendium.com.ar/policy-routing.txt for the beginnings of a IPROUTE2 howto.
The "iprule" and "iproute" commands are the same as "ip rule" and "ip route" commands (I prefer the former since it is easier to search for.) All the commands below are completely untested, if they do not work, please contact the author of IPROUTE2.. not David Ranch, Ambrose Au, or anyone on the Masq email list as it has NOTHING to do with IP Masquerading.
The first few commands only need to be done once at boot, say in /etc/rc.d/rc.local file.
# Allow internal LANs to route to each other, no masq.
/sbin/iprule add from 192.168.0.0/16 to 192.168.0.0/16 table main pref 100
# All other traffic from 192.168.1.x is external, handle by table 101
/sbin/iprule add from 192.168.1.0/24 to 0/0 table 101 pref 102
# All other traffic from 192.168.2.x is external, handle by table 102
/sbin/iprule add from 192.168.2.0/24 to 0/0 table 102 pref 102
These commands need to be issued when eth0 is configured, perhaps in
/etc/sysconfig/network-scripts/ifup-post (for Redhat systems). Be sure to
do them by hand first to make sure they work.
# Table 101 forces all assigned packets out via 123.123.123.11
/sbin/iproute add table 101 via 62123.123.123.11
# Table 102 forces all assigned packets out via 123.123.123.12
/sbin/iproute add table 102 via 62123.123.123.12
At this stage, you should find that packets from 192.168.1.x to the
outside world are being routed via 123.123.123.11, packets from
192.168.2.x are routed via 123.123.123.12.
Once routing is correct, now you can add any IPFWADM or IPCHAINS rules.
The following examples are for IPCHAINS:
/sbin/ipchains -A forward -i ppp+ -j MASQ
If everything hangs together, the masq code will see packets being
routed out on 123.123.123.11 and 123.123.123.12 and will use those addresses
as the masq source address.
IPCHAINS supports the following features that IPFWADM doesn't:
There are several things you should check assuming your Linux IP Masq box already have proper connection to the Internet and your LAN:
/usr/src/linux/Documentation/Changes
and make sure you have the minimal requirement for the network tools installed.
There are several things you should check assuming your Linux IP Masq box already have proper connection to the Internet and your LAN:
/usr/src/linux/Documentation/Changes
and make sure you have the minimal requirement for the network tools installed.
EQL has nothing to do with IP Masq though they are commonly teamed up on Linux boxes. Because of this, I recommend to check out the NEW version of Robert Novak's EQL HOWTO for all your EQL needs.
Giving up a free, reliable, high performance solution that works on minimal hardware and pay a fortune for something that needs more hardware, lower performance and less reliable? (IMHO. And yes, I have real life experience with these ;-)
Okay, it's your call. If you want a Windows NAT and/or proxy solution, here is a decent listing. I have no preference of these tools since I haven't used them before.
Lastly, do a web search on "MS Proxy Server", "Wingate", "WinProxy", or goto www.winfiles.com. And definitely DON'T tell anyone that we sent you.
Join the Linux IP Masquerading DEVELOPERS list and ask the developers there what you can help with. For more details on joining the lists, check out the Masq-List FAQ section.
Please DON'T ask NON-IP-Masquerade development related questions there!!!!
You can find more information on IP Masquerade at the Linux IP Masquerade Resource that both David Ranch and Ambrose Au maintain.
You can also find more information at Dranch's Linux page where the TrinityOS and other Linux documents are kept.
You may also find more information at The Semi-Original Linux IP Masquerading Web Site maintained by Indyramp Consulting, who also provides the IP Masq mailing lists.
Lastly, you can look for specific questions in the IP MASQ and IP MASQ DEV email archives or ask a specific question on these lists. Check out the Masq-List FAQ item for more details.
Make sure the language you want to translate to is not already covered by someone else. But, most of the translated HOWTOs are now OLD and need to be updated. A list of available HOWTO translations are available at the Linux IP Masquerade Resource.
If a copy of a current IP MASQ HOWTO isn't in your proposed language, please download the newest copy of the IP-MASQ HOWTO SGML code from the Linux IP Masquerade Resource. From there, begin your work while maintaining good SGML coding. For more help on SGML, check out www.sgmltools.org
Yes, this HOWTO is still being maintained. In the past, we've been guilty of being too busy working on two jobs and don't have much time to work on this, my apology. As of v1.50, David Ranch has begun to revamp the document and get it current again.
If you think of a topic that could be included in the HOWTO, please send email to ambrose@writeme.com and dranch@trinnet.net. It will be even better if you can provide that information. We will then include the information into the HOWTO once it is both found appropriate and tested. Many thanks for your contributions!
We have a lot of new ideas and plans for improving the HOWTO, such as case studies that will cover different network setup involving IP Masquerade, more on security via strong IPFWADM/IPCHAINS firewall rulesets, IPCHAINS usage, more FAQ entries, etc. If you think you can help, please do! Thanks.