´ÙÀ½ÀÇ ÇÏÀ§ ºÎºÐµéÀº ƯÁ¤ ³×Æ®¿öÅ© ±â¼ú¿¡ ´ëÇØ ¸í½ÃÇÑ °ÍÀÌ´Ù. ÀÌ ºÎºÐ¿¡ Æ÷ ÇÔµÈ Á¤º¸´Â ´Ù¸¥ ŸÀÔÀÇ ³×Æ®¿öÅ© ±â¼ú¿¡ ¹Ýµå½Ã Àû¿ëµÇ´Â °ÍÀº ¾Æ´Ï´Ù.
ARCNET µð¹ÙÀ̽º´Â 'arc0s', 'arc1e', 'arc2e' µîÀ¸·Î À̸§ºÙ¿©Áø´Ù. Ä¿³Î¿¡ ÀÇ ÇØ Ã³À½À¸·Î ¹ß°ßµÇ´Â Ä«µå´Â 'eth0'¿¡ ÇÒ´çµÇ¸ç ³ª¸ÓÁö´Â ±×µéÀÌ ¹ß°ßµÇ´Â ¼ø ¼¿¡ µû¶ó Â÷·Ê´ë·Î ÇÒ´çµÈ´Ù. ¸¶Áö¸·ÀÇ ¹®ÀÚ´Â ÀÌ´õ³Ý ÀÎĸ½¶·¹ÀÌ¼Ç ÆÐŶÀ» ¼± ÅÃÇß´ÂÁö, RFC1051 ÆÐŶ Æ÷¸ËÀ» »ç¿ëÇß´ÂÁö¸¦ ¾Ë·ÁÁØ´Ù.
Ä¿³Î ÄÄÆÄÀÏ ¿É¼Ç:
Network device support ---> [*] Network device support <*> ARCnet support [ ] Enable arc0e (ARCnet "Ether-Encap" packet format) [ ] Enable arc0s (ARCnet RFC1051 packet format)
ÇѹøÀÌ¶óµµ ÀÌ´õ³Ý Ä«µåÀÇ Áö¿øÀ» À§ÇØ Ä¿³ÎÀ» ÀûÀýÈ÷ ¸¸µé¾î º»ÀûÀÌ ÀÖ´Ù¸é ÀÌ Ä«µåÀÇ ¼³Á¤Àº ½¬¿ï°ÍÀÌ´Ù.
ÀüÇüÀûÀ¸·Î ´ÙÀ½°ú °°Àº°ÍÀ» »ç¿ëÇÒ °ÍÀÌ´Ù:
# ifconfig arc0e 192.168.0.1 netmask 255.255.255.0 up # route add 192.168.0.0 netmask 255.255.255.0 arc0eÀÚ¼¼ÇÑ Á¤º¸´Â /usr/src/linx/Documentation/networking/arcnet-hardware.txt ÆÄÀÏÀ» Âü°íÇ϶ó.
ARCNet Áö¿øÀº Avery Pennarun, apenwarr@foxnet.net¿¡ ÀÇÇؼ °³¹ßµÇ¾ú´Ù.
Appletalk Áö¿øÀº Ưº°ÇÑ µð¹ÙÀ̽º¸¦ »ç¿ëÇÏÁö ¾Ê´Âµ¥, ÀÌ°ÍÀÌ ±âÁ¸ÀÇ ³×Æ®¿öÅ© µð¹ÙÀ̽º¸¦ »ç¿ëÇϱ⠶§¹®ÀÌ´Ù. ÀÌ°ÍÀÇ Áß¿äÇÑ »ç¿ëÀº ¸®´ª½º ¸Ó½Å°ú ¾ÖÇà ÄÄÇ» ÅÍ°¡ ÇÁ¸°Åͳª µð½ºÅ©µîÀÇ ÀÚ¿øÀ» °øÀ¯Çϱâ À§ÇؼÀÌ´Ù. Ãß°¡ÀÇ ¼ÒÇÁÆ®¿þ¾î°¡ ÇÊ¿äÇϸç ÀÌ°ÍÀº netatalk¶ó°í ºÒ¸°´Ù. Wesley Craig netatalk@umich.edu°¡ ¹Ì ½Ã°£ ´ëÇÐÀÇ 'Research Systems Unix Groups'À̶õ ÆÀÀ» ´ëÇ¥ÇßÀ¸¸ç ±×µéÀº neta talk ÆÐÅ°Áö¸¦ °³¹ßÇØ ³»¾ú´Âµ¥, ÀÌ°ÍÀº Appletalk ÇÁ·ÎÅäÄÝ ½ºÅðú À¯¿ëÇÑ À¯ Æ¿¸®Æ¼¸¦ Á¦°øÇÏ´Â ¼ÒÇÁÆ®¿þ¾î¸¦ Á¦°øÇÑ´Ù. netatalk ÆÐÅ°Áö´Â ¸®´ª½º ¹èÆ÷º»¿¡ ÀÇÇØ Á¦°øµÇ°Å³ª ¾Æ´Ï¸é ¹Ì½Ã°£ ´ëÇп¡ Àִ Ȩ»çÀÌÆ®¿¡¼ ftp Àü¼ÛÀ» ¹ÞÀ»¼öÀÖ ´Ù.
< terminator.rs.itd.umich.edu/unix/netatalk/>
ÀÌ ÆÐÅ°Áö¸¦ ¼³Ä¡Çϱâ À§Çؼ´Â ´ÙÀ½°ú °°ÀÌ Ç϶ó.
# cd /usr/src # tar xvfz .../netatalk-1.4b2.tar.Z - ¿©±â¼ 'Makefile'À» ¼öÁ¤ÇÏ°í ½ÍÀ»¼öµµ Àִµ¥, ƯÈ÷ ÆÄÀϵéÀÌ ¾îµð¿¡ ¼³Ä¡µÉ °ÍÀΰ¡¸¦ Á¤ÀÇÇØÁÖ´Â DESTDIR º¯¼ö¸¦ ¹Ù²Ù¾î ÁÖ±â À§ÇØ ±× ·² °ÍÀÌ´Ù. µðÆúÆ®´Â /usr/local/atalk·Î µÇ¾îÀִµ¥ ¸Å¿ì ¾ÈÀüÇÏ´Ù.
# make - as root: # make install
ÀÌ°ÍÀÌ µ¿ÀÛÇÏ°Ô ÇϱâÀ§ÇØ °¡Àå ¸ÕÀú ÇؾßÇÒÀÏÀº /etc/services ÆÄÀÏ¿¡ »õ·Î¿î ¿£Æ®¸®¸¦ Ãß°¡ÇÏ´Â °ÍÀÌ´Ù. Ãß°¡ÇÒ ¿£Æ®¸®´Â ´ÙÀ½°ú °°´Ù:
rtmp 1/ddp # Routing Table Maintenance Protocol nbp 2/ddp # Name Binding Protocol echo 4/ddp # AppleTalk Echo Protocol zip 6/ddp # Zone Information Protocol´ÙÀ½Àº /usr/local/atalk/etc µð·ºÅ丮¿¡(ȤÀº ÆÐÅ°Áö¸¦ ¼³Ä¡ÇÑ µð·ºÅ丮¿¡) ap pletalk ¼³Á¤ÆÄÀÏÀ» ¸¸µé¾î ÁÖ´Â °ÍÀÌ´Ù.
óÀ½À¸·Î ¸¸µé¾îÁà¾ß ÇÏ´Â ÆÄÀÏÀº /usr/local/atalk/etc/atalkd.conf ÆÄÀÏÀÌ´Ù. óÀ½¿¡´Â ÀÌ ÆÄÀÏÀº ¾ÖÇà ¸Ó½ÅÀÌ ÀÖ´Â ³×Æ®¿öÅ©¸¦ Áö¿øÇÏ´Â ³×Æ®¿öÅ© µð¹ÙÀ̽º ÀÇ À̸§À» ÁöÁ¤ÇÏ´Â ÇϳªÀÇ ¶óÀθ¸ÀÌ ÇÊ¿äÇÒ»ÓÀÌ´Ù.
eth0Appletalk µ¥¸óÀº ³ª¸ÓÁö ¼¼ºÎ»çÇ×µéÀ» ½ÇÇàµÚ¿¡ Ãß°¡ÇÒ°ÍÀÌ´Ù.
³×Æ®¿öÅ©»óÀÇ ¾ÖÇøӽÅÀÌ °øÀ¯Çϵµ·Ï ¸®´ª½º ÆÄÀϽýºÅÛÀ» ³×Æ®¿öÅ©·Î export ÇÒ¼öµµ ÀÖ´Ù.
ÀÌ°ÍÀ» À§Çؼ´Â /usr/local/atalk/etc/AppleVolumes.system ÆÄÀÏÀ» ¼³Á¤ÇØ¾ß ÇÑ´Ù. /usr/local/atalk/etc/AppleVolumes.default¶ó ºÒ¸®´Â ´Ù¸¥ ¼³Á¤ ÆÄÀϵµ Àִµ¥ ÀÌ°ÍÀº ¿ÏÀüÈ÷ °°Àº Æ÷¸ËÀ» °¡Áö°í ÀÖÀ¸¸ç, °Ô½ºÆ® ±ÇÇÑÀ» °¡Áö°í Á¢¼Ó ÇÑ »ç¿ëÀÚ°¡ ¾î¶² ÆÄÀÏ ½Ã½ºÅÛÀ» ¹ÞÀ» °ÍÀΰ¡¸¦ ±â¼úÇÑ´Ù.
ÀÌ ÆÄÀÏÀÇ ¼³Á¤¿¡ ´ëÇÑ ¸ðµç ¼¼ºÎ»çÇ×°ú ¾î¶² ´Ù¾çÇÑ ¿É¼ÇÀÌ Àִ°¡´Â afpd ¸Ç ÆäÀÌÁö¿¡¼ ãÀ»¼ö ÀÖ´Ù.
´ÙÀ½°ú °°Àº °£´ÜÇÑ ¿¹¸¦ º¼¼öÀÖ´Ù:
/tmp Scratch /home/ftp/pub "Public Area"ÀÌ°ÍÀº /tmp ÆÄÀϽýºÅÛÀ» AppleShare VolumeÀÇ 'Scratch'·Î, ftp public µð·º Å丮¸¦ AppleShare VolumeÀÇ 'Public Area'·Î export ÇÒ°ÍÀÌ´Ù. VolumeÀÇ À̸§ Àº °Á¦ÀûÀÎ °ÍÀÌ ¾Æ´Ï°í µ¥¸óÀÌ ¸î°¡Áö¸¦ ¼±ÅÃÇϸç, ¾î¶µç ±×µéÀ» ¸í½ÃÇÏÁö ¸»¾Æ¶ó.
¾ÆÁÖ °£´ÜÇÏ°Ô ¸®´ª½º ÇÁ¸°Å͸¦ ¾ÖÇà ¸Ó½Å°ú °øÀ¯ÇÒ¼ö ÀÖ´Ù. ¿©·¯ºÐÀº Apple Pr inter Access Protocol DaemonÀÎ papd¸¦ ½ÇÇàÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥À» ¿î ¿µÇϸé ÀÌ°ÍÀº ¾ÖÇà ¸Ó½ÅÀ¸·Î ºÎÅÍ ¿äûÀ» ¹Þ¾ÆµéÀÌ°í ·ÎÄà ¶óÀÎ ÇÁ¸°ÅÍ µ¥¸óÀ¸ ·Î ÇÁ¸°Æ® ÀâÀ» ½ºÇ®ÇÒ°ÍÀÌ´Ù.
ÀÌ µ¥¸óÀÇ ¼³Á¤À» À§Çؼ´Â /usr/local/atalk/etc/papd.conf ÆÄÀÏÀ» ¼öÁ¤ÇÒ ÇÊ ¿ä°¡ ÀÖ´Ù. Á¤ÀÇ¿¡ ³Ö¾îÁØ À̸§Àº Appletalk naming ÇÁ·ÎÅäÄÝ°ú ÇÔ²² µî·ÏµÉ°Í ÀÌ´Ù.
´ÙÀ½°ú °°Àº °£´ÜÇÑ ¿¹¸¦ º¼¼öÀÖ´Ù:
TricWriter:\ :pr=lp:op=cg:ÀÌ°ÍÀº Appletalk ³×Æ®¿öÅ©¿¡¼ °¡´ÉÇÑ 'TricWriter'¶õ À̸§ÀÇ ÇÁ¸°Å͸¦ ¸¸µé¸ç µé¾î¿À´Â jobÀº lpd¸¦ »ç¿ëÇÏ´Â 'lp'(/etc/printcap¿¡ Á¤ÀÇµÈ ¹Ù¿Í °°ÀÌ) ÇÁ¸° ÅÍ·Î ÇÁ¸°Æ® µÉ°ÍÀÌ´Ù. 'op=cg' ¿£Æ®¸®´Â ¸®´ª½º À¯Àú 'cg'°¡ ÇÁ¸°ÅÍÀÇ ¿ÀÆÛ·¹ ÀÌÅÍÀÓÀ» ¸»ÇØÁØ´Ù.
ok, ÀÌÁ¦ ¿©·¯ºÐÀº ±âº» ¼³Á¤À» Å×½ºÆ®ÇÒ Áغñ°¡ µÇ¾ú´Ù. netatalk ÆÐÅ°Áö¿Í ÇÔ ²² Á¦°øµÇ¸ç Àß µ¿ÀÛÇÏ´Â rc.atalk ÆÄÀÏÀÌ ÀÖ´Ù. ±×·¯¹Ç·Î ¿©·¯ºÐÀº ´ÙÀ½¸¸ ÇØ ÁÖ¸é µÈ´Ù.
# /usr/local/atalk/etc/rc.atalk¸ðµç ½ÃÀÛÇÏ°í Àß µ¹¾Æ°¥°ÍÀÌ´Ù. ¾Æ¹«·± ¿¡·¯¸Þ¼¼Áöµµ ³ªÁö ¾ÊÀ»°ÍÀÌ°í, °¢ ½º Å×ÀÌÁö°¡ ½ÃÀÛÇÒ¶§ ÀÌ ¼ÒÇÁÆ®¿þ¾î´Â ÄַܼΠ¸Þ¼¼Áö¸¦ º¸³¾°ÍÀÌ´Ù.
ÀÌ ¼ÒÇÁÆ®¿þ¾î°¡ ÀûÀýÇÏ°Ô µ¿ÀÛÇϴ°¡¸¦ Å×½ºÆ®Çϱâ À§Çؼ´Â ¾ÖÇøӽÅÀ¸·Î ´Þ ·Á°¡¼, Apple ¸Þ´º¸¦ Ç®´Ù¿îÇÏ°í, Chooser¸¦ ¼±ÅÃÇѵÚ, AppleShare¸¦ Ŭ¸¯ÇØ ¶ó. ±×·¯¸é ¸®´ª½º ¹Ú½º°¡ º¸ÀÏ°ÍÀÌ´Ù.
¸®´ª½º¿¡¼ Aplletalk¸¦ ¼³Á¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ´õ ÀÚ¼¼ÇÑ ±â¼úÀº thehamptons.c om < thehamptons.com/anders/netatalk/>ÀÇ Anders Brownworth Linux Net atalk-HOWTO ÆäÀÌÁö¸¦ Âü°íÇ϶ó.
¸®´ª½º¿¡ Asynchronous Transfer Mode¸¦ Áö¿øÇϱâ À§ÇÑ ÇÁ·ÎÁ§Æ®¸¦ Werner Alme sberger < werner.almesberger@lrc.di.epfl.ch>°¡ °ü¸®ÁßÀÌ´Ù. ÇÁ·ÎÁ§Æ®ÀÇ »óȲ ¿¡ ´ëÇÑ ÇöÀç Á¤º¸´Â ´ÙÀ½¿¡¼ ¾òÀ»¼ö ÀÖ´Ù.< www.epfl.ch/linux-atm>
AX.25 µð¹ÙÀ̽º´Â Ä¿³Î 2.0.*¿¡¼ 'sl0', 'sl1' µîÀÌ°í, Ä¿³Î 2.1.*¿¡¼ 'ax0', 'ax1' µîÀÌ´Ù.
Kernel Compile Options: Networking options ---> [*] Amateur Radio AX.25 Level 2
AX25, Netrom, Rose ÇÁ·ÎÅäŬÀº AX25-HOWTO ¿¡¼ ´Ù·ç¾î Áø´Ù. ÀÌ ÇÁ·ÎÅäÄÝÀº ÆÐŶ ¶óµð¿À ½ÇÇèÀÇ ¼¼°è ¾Æ¸¶Ãß¾î ¶óµð¿À ¿ÀÆÛ·¹ÀÌÅÍ¿¡ ÀÇÇØ »ç¿ëµÈ´Ù.
ÀÌ ÇÁ·ÎÅäÄÝÀÇ implementationÀÇ ´ëºÎºÐÀÇ ÀÛ¾÷Àº Jonathon Naylor, jsn@cs.not.ac.uk¿¡ ÀÇÇØ ÀÌ·ç¾îÁ³´Ù.
DECNetÀÇ Áö¿øÀº ÇöÀçµµ °è¼Ó ÀÛ¾÷ÁßÀÌ´Ù. ÀÌÈÄÀÇ 2.1.* Ä¿³Î¿¡¼´Â º¼¼öµµ ÀÖ °Ú´Ù.
EQL µð¹ÙÀ̽º À̸§Àº 'eql'ÀÌ´Ù. Ç¥ÁØÀÇ Ä¿³Î¼Ò½º·Î´Â ÇÑ ¸Ó½Å´ç ÇϳªÀÇ EQL µð ¹ÙÀ̽º¸¸À» °®´Â´Ù. EQLÀº tcp/ip¸¦ ¿î¼ÛÇÏ´Â ½Ì±Û ·ÎÁöÄà ¸µÅ©·Î¼ÀÇ PPP, sli p, plipµîÀÇ ´ÙÁß point to point È°¿ëÀÇ ¼ö´ÜÀ» Á¦°øÇÑ´Ù. ¿©·¯°³ÀÇ Àú¼Ó ¶óÀÎ À» ¾²´Â °ÍÀÌ Á¾Á¾ ÇÑ°³ÀÇ °í¼Ó ¶óÀÎÀ» ¾²´Â°Íº¸´Ù ´õ ½Î´Ù.
Kernel Compile Options: Networking options ---> [*] Amateur Radio AX.25 Level 2
ÀÌ ¸ÞÄ«´ÏÁòÀ» Áö¿øÇϱâ À§Çؼ´Â ¶óÀÎÀÇ ´Ù¸¥ ³¡¿¡ ÀÖ´Â ¸Ó½Åµµ EQLÀ» Áö¿øÇØ ¾ß ÇÑ´Ù. Linux, Livingstone, Portmaster ±×¸®°í »õ·Î¿î ´ÙÀ̾óÀÎ ¼¹ö°¡ ȣȯ ´É·ÂÀ» Á¦°øÇÑ´Ù.
EQLÀ» ¼³Á¤Çϱâ À§Çؼ´Â ´ÙÀ½¿¡¼ ±¸ÇÒ¼ö ÀÖ´Â eql ÅøÀÌ ÀÖ¾î¾ß ÇÑ´Ù. sunsite.unc.edu < sunsite.unc.edu/pub/linux/system/Serial/eql-1.2.tar.gz>
¼³Á¤Àº ´ë´ÜÈ÷ ¼ö¿ùÇÏ´Ù. eql ÀÎÅÍÆäÀ̽º¸¦ ¼³Á¤ÇÏ¸é¼ ½ÃÀÛÇÑ´Ù. eql ÀÎÅÍÆäÀÌ ½º´Â ´Ù¸¥ ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽º¿Í ºñ½ÁÇÏ´Ù. ´ÙÀ½°ú °°ÀÌ ifconfig À¯Æ¿¸®Æ¼¸¦ ÀÌ¿ëÇÏ¿© IP ¾îµå·¹½º¿Í myu¸¦ ¼³Á¤ÇÑ´Ù.
ifconfig eql 192.168.10.1 mtu 1006 route add default eql´ÙÀ½À¸·Î »ç¿ëÇÒ °¢ ¶óÀÎÀ» ¼öµ¿À¸·Î ÃʱâÈÇØÁÙ ÇÊ¿ä°¡ ÀÖ´Ù. ÀÌ°ÍÀº point to point µð¹ÙÀ̽ºÀÇ Á¶ÇÕÀ¸·Î ³ªÅ¸³´Ù. Ä¿³Ø¼ÇÀ» ¾î¶»°Ô ÃʱâÈÇÒ°ÍÀΰ¡ ÇÏ´Â°Í Àº ¶óÀÎÀÇ Á¾·ù¿¡ µû¶ó ´Þ¶óÁö¸ç, ´õ ÀÚ¼¼ÇÑ Á¤º¸´Â ÀûÀýÇÑ ºÎºÐÀ» Âü°íÇϱ⠹٠¶õ´Ù.
¸¶Áö¸·À¸·Î EQL µð¹ÙÀ̽º¿Í ½Ã¸®¾ó ¸µÅ©¸¦ ¿¬°áÇÒ ÇÊ¿ä°¡ ÀÖÀ¸¸ç, ÀÌ°ÍÀº 'ensl aving'À̶ó°í ºÒ¸®°í º¸ÀÌ´Â ¹Ù¿Í °°ÀÌ eql_enslave ¸í·ÉÀ¸·Î ÀÌ·ç¾îÁø´Ù.
eql_enslave eql sl0 28800 eql_enslave eql ppp0 14400¿©·¯ºÐÀÌ eql_enslave¿¡ Á¦°øÇÏ´Â 'estimated speed' ÆĶó¸ÞÅÍ´Â Á÷Á¢ÀûÀ¸·Î´Â ¾Æ¹«°Íµµ ÇÏÁö ¾ÊÀ» °ÍÀÌ´Ù. ÀÌ°ÍÀº EQL µå¶óÀ̹ö¿¡ ÀÇÇØ µð¹ÙÀ̽º°¡ ¾ó¸¸ÅÀÇ µ¥ÀÌÅͱ׷¥À» ¹ÞÀ»°ÍÀΰ¡¸¦ °áÁ¤Çϱâ À§ÇØ »ç¿ëµÈ´Ù. ±×·¯¹Ç·Î ¿©·¯ºÐÀº ÀÌ °ª À» »ç¿ëÇÔÀ¸·Î½á ±ÕÇüÀ» ÀûÀýÈ÷ Á¶ÀýÇÒ¼ö ÀÖ´Ù.
EQL µð¹ÙÀ̽º·Î ºÎÅÍ ¶óÀÎÀÇ ¿¬°áÀ» ²÷±â À§Çؼ´Â ´ÙÀ½°ú °°ÀÌ eql_emancipate ¸í·ÉÀ» »ç¿ëÇÑ´Ù.
eql_emancipate eql sl0¶ó¿ìÆ®°¡ ½ÇÁ¦ÀÇ ½Ã¸®¾ó µðºñÀ̽º ´ë½Å¿¡ eql µð¹ÙÀ̽º¸¦ ÂüÁ¶ÇÏ´Â °ÍÀ» Á¦¿ÜÇÏ ¸é ´Ù¸¥ point to point ¸µÅ©·Î ¶ó¿ìÆÃÀ» Ãß°¡ÇÒ¼öµµ ÀÖ´Ù. ÀüÇüÀûÀ¸·Î ´ÙÀ½°ú °°ÀÌ ÇÏ¿ëÇÏ°ÚÁö:
route add default eql0EQL µå¶óÀ̹ö´Â Simon Janes simon@ncm.com¿¡ ÀÇÇØ °³¹ßµÇ¾ú´Ù.
ÀÌ´õ³Ý µð¹ÙÀ̽ºÀÇ À̸§Àº 'eth0', 'eth1' ,'eth2' µîÀÌ´Ù. Ä¿³Î¿¡ ÀÇÇØ Ã¹¹ø° ·Î ¹ß°ßµÇ´Â Ä«µå´Â 'eth0'¿¡ ÇÒ´çµÇ¸ç ³ª¸ÓÁö´Â ¹ß°ßµÇ´Â ¹ß°ßµÇ´Â ¼ø¼´ë·Î ÇÒ´çµÈ´Ù.
¸®´ª½º »ó¿¡¼ ÀÌ´õ³Ý Ä«µåÀÇ µ¿ÀÛ¹ýÀ» ¾Ë°í½Í´Ù¸é Ethernet-HOWTO¸¦ Âü°íÇ϶ó.
ÀÌ´õ³Ý Ä«µå¸¦ Áö¿øÇϵµ·Ï Ä¿³ÎÀ» ¸¸µé¾î º¸¾Ò´Ù¸é ÀÌ ¼³Á¤Àº ½¬¿ï°ÍÀÌ´Ù.
´ëü·Î ´ÙÀ½°ú °°ÀÌ ³ªÅ¸³¯°ÍÀÌ´Ù.
# ifconfig eth0 192.168.0.1 netmask 255.255.255.0 up # route add 192.168.0.0 netmask 255.255.255.0 eth0´ëºÎºÐÀÇ ÀÌ´õ³Ý µå¶óÀ̹ö´Â Donald Becker, becker@CESDIS.gsfc.nasa.gov¿¡ ÀÇ ÇØ °³¹ßµÇ¾ú´Ù.
FDDIÀÇ µð¹ÙÀ̽º ³×ÀÓÀº 'fddi0', 'fddi1', 'fddi2' µîÀÌ´Ù. Ä¿³Î¿¡ ÀÇÇØ Ã³À½ À¸·Î ¹ß°ßµÇ´Â µð¹ÙÀ̽º´Â 'fddi0'¿¡ ÇÒ´çµÇ°í, ³ª¸ÓÁö´Â ¹ß°ßµÇ´Â ¼ø¼´ë·Î ÇÒ ´çµÈ´Ù.
Lawrence V. Stefani, stefani@lkg.dec.com´Â Digital Equipment Corporation FDDI EISA ±×¸®°í PCI Ä«µå¸¦ °³¹ßÇß´Ù.
Kernel Compile Options: Network device support ---> [*] FDDI driver support [*] Digital DEFEA and DEFPA adapter support
FDDI µå¶óÀ̹ö¸¦ Áö¿øÇÏ´Â Ä¿³ÎÀ» ¸¸µé°í ¼³Ä¡Çß´Ù¸é, FDDI ÀÎÅÍÆäÀ̽ºÀÇ ¼³Á¤ Àº ÀÌ´õ³Ý ÀÎÅÍÆäÀ̽ºÀÇ ¼³Á¤°ú °ÅÀÇ µ¿ÀÏÇÏ´Ù. ÀûÀýÇÑ FDDI ÀÎÅÍÆäÀ̽ºÀÇ À̸§ À» ifconfig°ú route ¸í·É¿¡ ¸í½ÃÇØ¾ß ÇÑ´Ù.
DLCI ÀÎĸ½¶·¹ÀÌ¼Ç µð¹ÙÀ̽º¸¦ À§ÇÑ ÇÁ·¹ÀÓ ¸±·¹ÀÌÀÇ µð¹ÙÀ̽º À̸§Àº 'dlci00' , 'dlci01' µîÀ̸ç, FRAD¸¦ À§ÇÑ °ÍÀº 'sdla0', 'sdla1'µîÀÌ´Ù.
ÇÁ·¹ÀÓ ¸±·¹ÀÌ´Â µ¹¹ßÀûÀÎ ¶Ç´Â °£ÇæÀûÀÎ µ¥ÀÌÄ¿ Ä¿¹Â´ÏÄÉÀÌ¼Ç Æ®·¡ÇÈ¿¡ Àû¿ëÇÏ ±â À§ÇØ ¼³°èµÈ »õ·Î¿î ³×Æ®¿öÅ· ±â¼úÀÌ´Ù. Frame Relay Access Device(FRAD)¸¦ »ç¿ëÇØ ÇÁ·¹ÀÓ ¸±·¹ÀÌ ³×Æ®¿öÅ©¿¡ Á¢¼ÓÇÒ¼ö ÀÖ´Ù. ¸®´ª½º ÇÁ·¹ÀÓ ¸±·¹ÀÌ´Â RFC- 1490¿¡ ±â¼úµÈ´ë·Î ÇÁ·¹ÀÓ ¸±·¹ÀÌ »ó¿¡¼ IP¸¦ Áö¿øÇÑ´Ù.
Kernel Compile Options: Network device support ---> <*> Frame relay DLCI support (EXPERIMENTAL) (24) Max open DLCI (8) Max DLCI per device <*> SDLA (Sangoma S502/S508) support
Mike McLagan, mike. mclagan@linux.org°¡ ÇÁ·¹ÀÓ ¸±·¹ÀÌÀÇ Áö¿ø°ú ¼³Á¤ÅøÀ» °³ ¹ßÇß´Ù.
ÇöÀç Áö¿øµÇ´Â À¯ÀÏÇÑ ÇÁ·¹ÀÓ ¸±·¹ÀÌ´Â Sangoam TechnologyÀÇ S502A, S502E, S5 08ÀÌ´Ù.
Ä¿³ÎÀÇ À缳ġÈÄ¿¡ FRAD¿Í DLCI¸¦ ¼³Á¤Çϱâ À§Çؼ´Â ftp.invlogic.com¿¡¼ ¾ò À»¼ö ÀÖ´Â ÇÁ·¹ÀÓ ¸±·¹ÀÌ ¼³Á¤ÅøÀÌ ÇÊ¿äÇÏ´Ù. <ftp://ftp.invlogic.com/pub/linux/fr/frad-0.15.tgz>. ÄÄÆÄÀÏ°ú ¼³Ä¡´Â ¸Å¿ì ¼ö¿ùÇϳª, top ·¹º§ÀÇ MakefileÀÌ ¾øÀ¸¹Ç·Î ¼öµ¿À¸·Î ÇØÁÖ¾î¾ß ÇÑ´Ù.
# cd /usr/src # tar xvfz .../frad-0.15.tgz # cd frad-0.15 # for i in common dlci frad; do cd $i; make clean; make; cd ..;done # mkdir /etc/frad # install -m 644 -o root -g bin/*.sfm /etc/frad # install -m 700 -o root -g root frad/fradcfg /sbin # install -m 700 -o root -g root dlci/dlcicfg /sbinÅøÀ» ¼³Ä¡Çѵڿ¡ /etc/frad/router.conf ÆÄÀÏÀ» ¸¸µé ÇÊ¿ä°¡ ÀÖ´Ù. ÀÌ ÅÛÇø´À» ÀÌ¿ëÇÒ¼öµµ ÀÖÀ¸¸ç, ÀÌ°ÍÀº ¿¹Á¦ ÆÄÀÏÀÇ ¼öÁ¤ ¹öÀüÀÌ´Ù.
# /etc/frad/router.conf # This is a template configuration for frame relay. # All tags are included. The default values are based on the code # supplied with the DOS drivers for the Sangoma S502A card. # # A '#' anywhere in a line constitutes a comment # Blanks are ignored (you can indent with tabs too) # Unknown [] entries and unknown keys are ignored # [Devices] Count=1 # number of devices to configure Dev_1=sdla0 # the name of a device #Dev_2=sdla1 # the name of a device # Specified here, these are applied to all devices, and can be overriden for # each individual board. # Access=CPE Clock=Internal KBaud=64 Flags=TX # # MTU=1500 # Maximum transmit IFrame length, default is 4096 # T391=10 # T391 value 5 - 30, default is 10 # T392=15 # T392 value 5 - 30, default is 15 # N391=6 # N391 value 1 - 255, default is 6 # N392=3 # N392 value 1 - 10, default is 3 # N393=4 # N393 value 1 - 10, default is 4 # Specified here, these set the defaults for all boards # CIRfwd=16 # CIR forward 1 - 64 # Bc_fwd=16 # Bc forward 1 - 512 # Be_fwd=0 # Be forward 0 - 511 # CIRbak=16 # CIR backward 1 - 64 # Bc_bak=16 # Bc backward 1 - 512 # Be_bak=0 # Be backward 0 - 511 # # # Device specific configuration # # # # The first device is a Sangoma S502E # [sdla0] Type=Sangoma # Type of the device to configure, currently only # SANGOMA is recognised # # These keys are specific to the 'Sangoma' type # # The type of Sangoma board - S502A, S502E, S508 Board=S502E # # The name of the test firmware for the Sangoma board # Testware=/usr/src/frad-0.10/bin/sdla_tst.502 # # The name of the FR firmware # Firmware=/usr/src/frad-0.10/bin/frm_rel.502 # Port=360 # Port for this particular card Mem=C8 # Address of memory window, A0-EE, depending on c ard IRQ=5 # IRQ number, do not supply for S502A DLCIs=1 # Number of DLCI's attached to this device DLCI_1=16 # DLCI #1's number, 16 - 991 # DLCI_2=17 # DLCI_3=18 # DLCI_4=19 # DLCI_5=20 # # Specified here, these apply to this device only, # and override defaults from above # # Access=CPE # CPE or NODE, default is CPE # Flags=TXIgnore,RXIgnore,BufferFrames,DropAborted,Stats,MCI,AutoDLCI # Clock=Internal # External or Internal, default is Internal # Baud=128 # Specified baud rate of attached CSU/DSU # MTU=2048 # Maximum transmit IFrame length, default is 4096 # T391=10 # T391 value 5 - 30, default is 10 # T392=15 # T392 value 5 - 30, default is 15 # N391=6 # N391 value 1 - 255, default is 6 # N392=3 # N392 value 1 - 10, default is 3 # N393=4 # N393 value 1 - 10, default is 4 # # The second device is some other card # # [sdla1] # Type=FancyCard # Type of the device to configure. # Board= # Type of Sangoma board # Key=Value # values specific to this type of device # # DLCI Default configuration parameters # These may be overridden in the DLCI specific configurations # CIRfwd=64 # CIR forward 1 - 64 # Bc_fwd=16 # Bc forward 1 - 512 # Be_fwd=0 # Be forward 0 - 511 # CIRbak=16 # CIR backward 1 - 64 # Bc_bak=16 # Bc backward 1 - 512 # Be_bak=0 # Be backward 0 - 511 # # DLCI Configuration # These are all optional. The naming convention is # [DLCI_D<devicenum>_<DLCI_Num>] # [DLCI_D1_16] # IP= # Net= # Mask= # Flags defined by Sangoma: TXIgnore,RXIgnore,BufferFrames # DLCIFlags=TXIgnore,RXIgnore,BufferFrames # CIRfwd=64 # Bc_fwd=512 # Be_fwd=0 # CIRbak=64 # Bc_bak=512 # Be_bak=0 [DLCI_D2_16] # IP= # Net= # Mask= # Flags defined by Sangoma: TXIgnore,RXIgnore,BufferFrames # DLCIFlags=TXIgnore,RXIgnore,BufferFrames # CIRfwd=16 # Bc_fwd=16 # Be_fwd=0 # CIRbak=16 # Bc_bak=16 # Be_bak=0/etc/frad/router.conf ÆÄÀÏÀ» ¸¸µé¾úÀ¸¸é, ½ÇÁ¦ µð¹ÙÀ̽º¸¦ ¼³Á¤ÇÏ´Â Àϸ¸ ³² ¾Ò´Ù. ÀÌ°ÍÀº º¸ÅëÀÇ ³×Æ®¿öÅ© µð¹ÙÀ̽º ¼³Á¤º¸´Ù Á¶±Ý º¹ÀâÇϸç, DLCI ÀÎĸ½¶ ·¹ÀÌ¼Ç µð¹ÙÀ̽º Àü¿¡ FRAD µð¹ÙÀ̽º¸¦ °¡Á®¿Í¾ß ÇÔÀ» ±â¾ïÇØ¾ß ÇÑ´Ù.
# Configure the frad hardware and the DLCI parameter /sbin/fradcfg /etc/frad/router.conf || exit 1 /sbin/dlcicfg file /etc/frad/router.conf # Bring up the FRAD device ifconfig sdla0 up # # Configure the DLCI encapsulation interface and routing ifconfig dlci00 192.168.10.1 pointopoint 192.168.10.2 up route add 192.168.10.0 netmask 255.255.255.0 dlci00 # ifconfig dlci01 192.168.11.1 pointopoint 192.168.11.2 up route add 192.168.11.0 netmask 255.255.255.0 dlci00 # route add default dev dlci00 #
¸®´ª½º Ä¿³ÎÀÇ IP ¾îÄ«¿îÆà feature´Â ¸î¸î ³×Æ®¿öÅ© »ç¿ë µ¥ÀÌÅ͸¦ ¼öÁýÇÏ°í ºÐ¼®ÇÒ¼ö ÀÖ°Ô ÇØÁØ´Ù. ¼öÁýµÈ µ¥ÀÌÅÍ´Â ±×°ÍÀÌ ¸¶Áö¸·À¸·Î ¸®¼ÂµÈ ÀÌÈÄ¿¡ ¸î°³ ÀÇ ÆÐŶ°ú ÃàÀûµÈ ¸î°³ÀÇ ¹ÙÀÌÆ®·Î ÀÌ·ç¾îÁø´Ù. ¿©·¯ºÐÀº ÀÚ½ÅÀÇ ¸ñÀû¿¡ ¸Â°Ô °¢ figure¸¦ ºÐ·ùÇÏ´Â ´Ù¾çÇÑ ·êÀ» ¸í½ÃÇÒ¼ö ÀÖ´Ù.
Kernel Compile Options: Networking options ---> [*] IP: accounting
Ä¿³ÎÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡Çѵڿ¡ IP ¾îÄ«¿îÆÃÀ» ¼³Á¤Çϱâ À§Çؼ´Â ipfwadm ¸í·É À» »ç¿ëÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. ¼±ÅÃÇÒ¼ö ÀÖ´Â IP ¾îÄ«¿îÆÃÀÇ ºÐ·ù¹æ¹ýÀº ¸¹ÀÌ ÀÖ´Ù. ³ª´Â »ç¿ëÇϱâ ÁÁÀº °£´ÜÇÑ ¿¹Á¦¸¦ Çϳª ¼±ÅÃÇßÀ¸¸ç, ´õ ÀÚ¼¼ÇÑ Á¤º¸¸¦ ¿øÇϸé ipfwadm ¸ÇÆäÀÌÁö¸¦ Àо±â ¹Ù¶õ´Ù.
½Ã³ª¸®¿À: PPP·Î ÀÎÅͳݿ¡ ¿¬°áµÈ ÀÌ´õ³Ý ³×Æ®¿öÅ©°¡ ÀÖ´Ù. ÀÌ´õ³Ý »ó¿¡´Â ¥y°¡ Áö ¼ºñ½º¸¦ Á¦°øÇÏ´Â ¸Ó½ÅÀÌ ÀÖ°í, telnet, rogin, ftp, www µî¿¡ ÀÇÇØ ¹ß»ýÇÏ ´Â Æ®·¡ÇÈÀ» ¾Ë°í½Í¾î ÇÑ´Ù.
¾Æ¸¶µµ ´ÙÀ½°ú °°ÀÌ º¸ÀÌ´Â ¸í·É¾î ¼ÂÀ» »ç¿ëÇÒ°ÍÀÌ´Ù.
# # Flush the accounting rules ipfwadm -A -f # # Add rules for local ethernet segment ipfwadm -A in -a -P tcp -D 44.136.8.96/29 20 ipfwadm -A out -a -P tcp -S 44.136.8.96/29 20 ipfwadm -A in -a -P tcp -D 44.136.8.96/29 23 ipfwadm -A out -a -P tcp -S 44.136.8.96/29 23 ipfwadm -A in -a -P tcp -D 44.136.8.96/29 80 ipfwadm -A out -a -P tcp -S 44.136.8.96/29 80 ipfwadm -A in -a -P tcp -D 44.136.8.96/29 513 ipfwadm -A out -a -P tcp -S 44.136.8.96/29 513 ipfwadm -A in -a -P tcp -D 44.136.8.96/29 ipfwadm -A out -a -P tcp -D 44.136.8.96/29 ipfwadm -A in -a -P udp -D 44.136.8.96/29 ipfwadm -A out -a -P udp -D 44.136.8.96/29 ipfwadm -A in -a -P icmp -D 44.136.8.96/29 ipfwadm -A out -a -P icmp -D 44.136.8.96/29 # # Rules for default ipfwadm -A in -a -P tcp -D 0/0 20 ipfwadm -A out -a -P tcp -S 0/0 20 ipfwadm -A in -a -P tcp -D 0/0 23 ipfwadm -A out -a -P tcp -S 0/0 23 ipfwadm -A in -a -P tcp -D 0/0 80 ipfwadm -A out -a -P tcp -S 0/0 80 ipfwadm -A in -a -P tcp -D 0/0 513 ipfwadm -A out -a -P tcp -S 0/0 513 ipfwadm -A in -a -P tcp -D 0/0 ipfwadm -A out -a -P tcp -D 0/0 ipfwadm -A in -a -P udp -D 0/0 ipfwadm -A out -a -P udp -D 0/0 ipfwadm -A in -a -P icmp -D 0/0 ipfwadm -A out -a -P icmp -D 0/0 # # List the rules ipfwadm -A -l -n #¸¶Áö¸·ÀÇ ¸í·ÉÀº °¢ ¾îÄ«¿îÆà ·êÀ» ¸®½ºÆÃÇÏ°í ¼öÁýµÈ Åä´Þ Á¤º¸¸¦ º¸¿©ÁØ´Ù.
IP ¾îÄ«¿îÆÃÀ» ºÐ¼®ÇÒ¶§ ÁÖÀÇÇØ¾ß ÇÒ Áß¿äÇÑ Á¡Àº ¸ÅÄ¡ÇÏ´Â ¸ðµç ·ê¿¡ ´ëÇÑ Åä Å»ÀÌ Áõ°¡µÉ°ÍÀ̶ó´Â Á¡Àε¥, ±×·¯¹Ç·Î ´Ù¸¥ figure¸¦ ¾ò±â À§Çؼ´Â ÀûÀýÇÑ ¼ö ÇÐÀû 󸮸¦ ÇؾßÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. ¿¹¸¦ µé¾î¼ ¾ó¸¶³ª ¸¹Àº µ¥ÀÌÅÍ°¡ ftp, teln et, rlogin, wwwÀÇ µ¥ÀÌÅÍ°¡ ¾Æ´Ñ °ÍÀÎÁö¸¦ ¾Ë°í ½Í´Ù¸é, ¸ðµç Æ÷Æ®¿¡ ¸ÅÄ¡µÇ´Â ·ê¿¡¼ °³º°ÀûÀÎ(ftp, telnet, rlogin, wwwÀÇ) ÅäÅ»À» »©°Ú´Ù.
# ipfwadm -A -l -n IP accounting rules pkts bytes dir prot source destination ports 0 0 in tcp 0.0.0.0/0 44.136.8.96/29 * -> 20 0 0 out tcp 44.136.8.96/29 0.0.0.0/0 20 -> * 0 0 in tcp 0.0.0.0/0 44.136.8.96/29 * -> 23 0 0 out tcp 44.136.8.96/29 0.0.0.0/0 23 -> * 10 1166 in tcp 0.0.0.0/0 44.136.8.96/29 * -> 80 10 572 out tcp 44.136.8.96/29 0.0.0.0/0 80 -> * 242 9777 in tcp 0.0.0.0/0 44.136.8.96/29 * -> 513 220 18198 out tcp 44.136.8.96/29 0.0.0.0/0 513 -> * 252 10943 in tcp 0.0.0.0/0 44.136.8.96/29 * -> * 231 18831 out tcp 0.0.0.0/0 44.136.8.96/29 * -> * 0 0 in udp 0.0.0.0/0 44.136.8.96/29 * -> * 0 0 out udp 0.0.0.0/0 44.136.8.96/29 * -> * 0 0 in icmp 0.0.0.0/0 44.136.8.96/29 * 0 0 out icmp 0.0.0.0/0 44.136.8.96/29 * 0 0 in tcp 0.0.0.0/0 0.0.0.0/0 * -> 20 0 0 out tcp 0.0.0.0/0 0.0.0.0/0 20 -> * 0 0 in tcp 0.0.0.0/0 0.0.0.0/0 * -> 23 0 0 out tcp 0.0.0.0/0 0.0.0.0/0 23 -> * 10 1166 in tcp 0.0.0.0/0 0.0.0.0/0 * -> 80 10 572 out tcp 0.0.0.0/0 0.0.0.0/0 80 -> * 243 9817 in tcp 0.0.0.0/0 0.0.0.0/0 * -> 513 221 18259 out tcp 0.0.0.0/0 0.0.0.0/0 513 -> * 253 10983 in tcp 0.0.0.0/0 0.0.0.0/0 * -> * 231 18831 out tcp 0.0.0.0/0 0.0.0.0/0 * -> * 0 0 in udp 0.0.0.0/0 0.0.0.0/0 * -> * 0 0 out udp 0.0.0.0/0 0.0.0.0/0 * -> * 0 0 in icmp 0.0.0.0/0 0.0.0.0/0 * 0 0 out icmp 0.0.0.0/0 0.0.0.0/0 * #
ÇϳªÀÇ ³×Æ®¿öÅ©¿¡ ¿©·¯°³ÀÇ IP ¾îµå·¹½º¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Â ¸î°¡Áö ÀÀ¿ë ÇÁ·Î±× ·¥ÀÌ Àִµ¥ ÀÌ°ÍÀº ²Ï ¾µ¸¸ÇÏ´Ù. ÀÎÅÍ³Ý ¼ºñ½º Á¦°øÀÚ´Â °í°´¿¡°Ô Á¦°øÇÏ´Â w wwÀ̳ª ftp¿¡ ÀÌ 'customized'¸¦ Á¦°øÇÑ´Ù.
Kernel Compile Options: Networking options ---> .... [*] Network aliasing .... <*> IP: aliasing support
IP ¾Ë¸®¾Æ½º ±â´ÉÀ» Æ÷ÇÔÇÏ¿© Ä¿³ÎÀ» ÄÄÆÄÀÏÇÏ°í ¼³Ä¡ÇÑ µÚÀÇ ¼³Á¤Àº ¸Å¿ì °£´Ü ÇÏ´Ù. ¾Ë¸®¾Æ½º´Â ½ÇÁ¦ ³×Æ®¿öÅ© µð¹ÙÀ̽º¿Í ¿¬°üµÈ °¡»ó ³×Æ®¿öÅ© µð¹ÙÀ̽º·Î Ãß°¡µÈ´Ù. °£°£ÇÑ À̸§Áþ±â ±Ô¾àÀº ÀÌ µð¹ÙÀ̽º¿¡ <devname>:<virtual dev num> , ¿¹¸¦µé¾î eth0:0, ppp0:10ÀÇ ÇüÅ·ΠÀû¿ëµÈ´Ù.
¿¹·Î½á, µÎ°³ÀÇ ¼·Î´Ù¸¥ IP ¼ºê³ÝÀ» µ¿½Ã¿¡ Áö¿øÇÏ´Â ÀÌ´õ³Ý ³×Æ®¿öÅ©¸¦ °¡Áö °í ÀÖ´Ù°í °¡Á¤ÇÏ°í µÎ°³ ¸ðµÎ·ÎÀÇ ´ÙÀÌ·ºÆ® ¾ï¼¼½º¸¦ ÇÒ¼öÀÖ´Ù¸é ´ÙÀ½°ú °°ÀÌ »ç¿ëÇÒ¼ö ÀÖ´Ù.
# # ifconfig eth0:0 192.168.1.1 netmask 255.255.255.0 up # route add -net 192.168.1.0 netmask 255.255.255.0 eth0:0 # # ifconfig eth0:1 192.168.10.1 netmask 255.255.255.0 up # route add -net 192.168.10.0 netmask 255.255.255.0 #¾Ë¸®¾Æ½º¸¦ Áö¿ì·Á¸é ±×°ÍÀÇ À̸§µÚ¿¡ °£´ÜÈ÷ '-'¸¦ Ãß°¡ÇÏ¸é µÈ´Ù.
# ifconfig eth0:0- 0ÀÌ ¾Ë¸®¾Æ½º¿¡ °ü·ÃµÈ ¸ðµç ¶ó¿ìÆ®°¡ ÀÚµ¿À¸·Î Áö¿öÁú°ÍÀÌ´Ù.
IP ÆÄÀ̾î¿ù°ú ÆÄÀ̾î¿ù °ü·Ã À̽´´Â firewall-howto¿¡¼ ±íÀÌ ´Ù·ç¾îÁø´Ù. IP ÆÄÀ̾î¿ù¸µÀº ÇÊÅ͸µ°ú ÁöÁ¤µÈ IP·ÎºÎÅÍÀÇ µ¥ÀÌÅͱ׷¥¸¸ Çã¿ëÇÏ´Â µîÀÇ ¹æ¹ýÀ¸ ·Î Çã°¡µÇÁö ¾ÊÀº ³×Æ®¿öÅ© ¾ï¼¼½º·ÎºÎÅÍ ¸Ó½ÅÀ» º¸È£ÇØÁØ´Ù. ¼¼°¡Áö Ŭ·¡½ºÀÇ ·êÀÌ Àִµ¥, incoming filtering, outgoing filtering, forwarding filtering µîÀÌ´Ù. Incoming ·êÀº ³×Æ®¿öÅ© µð¹ÙÀ̽º·ÎºÎÅÍ ¹Þ¾ÆµéÀÌ´Â µ¥ÀÌÅͱ׷¥¿¡ Àû¿ë µÈ´Ù. Outgoing ·êÀº ³×Æ®¿öÅ© µð¹ÙÀ̽º¿¡ ÀÇÇØ Àü¼ÛµÇ´Â µ¥ÀÌÅͱ׷¥¿¡ Àû¿ëµÈ ´Ù. Filterling ·êÀº ¿¹¸¦µé¾î ¶ó¿ìÆÃµÈ µ¥ÀÌÅͱ׷¥°ú °°ÀÌ ÀÌ ¸Ó½ÅÀ» ÇâÇÏÁö ¾ÊÁö¸¸ ¹Þ¾ÆµéÀÌ´Â µ¥ÀÌÅͱ׷¥¿¡ Àû¿ëµÈ´Ù.
Kernel Compile Options: Networking options ---> [*] Network firewalls .... [*] IP: forwarding/gatewaying .... [*] IP: firewalling [ ] IP: firewall packet logging
IP ÆÄÀ̾î¿ù ·êÀÇ ¼³Á¤Àº ipfwadm ¸í·ÉÀ» ÅëÇؼ ÀÌ·ç¾îÁø´Ù. ÀÌ¹Ì ¾ð±ÞÇߴٽà ÇÇ, º¸¾ÈÀº ³» Àü¹®ºÐ¾ß°¡ ¾Æ´Ï¸ç ³»°¡ ¿©·¯ºÐÀÌ »ç¿ëÇÒ¼ö ÀÖ´Â ¿¹Á¦¸¦ Á¦°øÇÑ ´Ù ÇÏ´õ¶óµµ, º¸¾ÈÀÌ Àڽſ¡°Å Áß¿äÇÏ´Ù¸é ¿©·¯ºÐ ½º½º·Î°¡ ¿¬±¸ÇÏ°í °³¹ßÇØ¾ß ÇÑ´Ù.
IP ÆÄÀ̾î¿ùÀ» »ç¿ëÇÏ´Â °¡Àå ÈçÇÑ °æ¿ì´Â Çã°¡µÇÁö ¾ÊÀº ³×Æ®¿öÅ© ¿ÜºÎ·ÎºÎÅÍ ÀÇ ¾ï¼¼½º¸¦ ¸·±âÀ§ÇÏ¿© ¸®´ª½º¸Ó½ÅÀ» ¶ó¿ìÅͳª ÆÄÀ̾î¿ù °ÔÀÌÆ®¿þÀÌ·Î ÀÌ¿ëÇÏ ´Â °æ¿ìÀÏ °ÍÀÌ´Ù.
´ÙÀ½ÀÇ ¼³Á¤Àº Arnt Gulbrandsen, < agulbra@troll.no>ÀÇ ±â°í¿¡ ±Ù°ÅÇÑ °ÍÀÌ´Ù.
¾Æ·¡ÀÇ ¿¹´Â ÀÌ ´ÙÀ̾î±×·¥¿¡ ±×·ÁÁø°Í°ú °°Àº ¸®´ª½º ÆÄÀ̾î¿ù/¶ó¿ìÅÍ ¸Ó½ÅÀÇ ÆÄÀ̾î¿ù ¼³Á¤À» ¼³¸íÇÏ°í ÀÖ´Ù.
- - \ | 172.16.37.0 \ | /255.255.255.0 \ --------- | | 172.16.174.30 | Linux | | NET =================| f/w |------| ..37.19 | PPP | router| | -------- / --------- |--| Mail | / | | /DNS | / | -------- - -´ÙÀ½ÀÇ ¸í·ÉÀº º¸Åë rc ÆÄÀÏ¿¡ µé¾îÀÖ¾î¼ ½Ã½ºÅÛÀÌ ºÎÆõɶ§¸¶´Ù ÀÚµ¿À¸·Î ½Ç ÇàµÉ°ÍÀÌ´Ù. ÃÖ´ëÇÑÀÇ º¸¾ÈÀ» À§Çؼ ÀÌ°ÍÀº ³×Æ®¿öÅ© ¼³Á¤ÀÌ ³¡³µÚ¿¡ ±×·¯³ª ³×Æ®¿öÅ©°¡ ¿ÏÀüÈ÷ ÁغñµÇ±â Àü¿¡, (ÆÄÀ̾î¿ùÀÌ ¸®ºÎÆÃÇÏ´Â µ¿¾È¿¡ ´©±º°¡°¡ ¾ï ¼¼½º ±ÇÇÑÀ» ¾ò´Â°ÍÀ» ¸·±âÀ§Çؼ´Â), ¼öÇàµÇ¾î¾ß ÇÑ´Ù.
#!/bin/sh # Flush the 'Forwarding' rules table # Change the default policy to 'accept' # /sbin/ipfwadm -F -f /sbin/ipfwadm -F -p accept # #.. and for 'Incoming' # /sbin/ipfwadm -I -f /sbin/ipfwadm -I -p accept # First off, seal off the PPP interface # I'd love to use '-a deny' instead of '-a reject -y' but then it # would be impossible to originate connections on that interface too. # The -o causes all rejected datagrams to be logged. This trades # disk space against knowledge of an attack of configuration error. # /sbin/ipfwadm -I -a reject -y -o -P tcp -S 0/0 -D 172.16.174.30 # Throw away certain kinds of obviously forged packet packets right away. # Nothing should come from multicast/anycast/broadcast addresses. # /sbin/ipfwadm -F -a deny -o -S 224.0/3 -D 172.16.37.0/24 # # and nothing coming from the loopback network should ever be # seen on a wire /sbin/ipfwadm -F -a deny -o -S 127.0/8 -D 172.16.37.0/24 # accept incoming SMTP and DNS connections, but only # to the Mail/Name Server # /sbin/ipfwadm -F -a accept -P tcp -S 0/0 -D 172.16.37.19 25 53 # # DNS uses UDP as well as TCP, so allow that too # for question to our name server # /sbin/ipfwadm -F -a accept -P udp -S 0/0 -D 172.16.37.19 53 # # but not "answers" coming to dangerous ports like NFS and # Larry McVoy's NFS extension. If you run squid, add its port here. # /sbin/ipfwadm -F -a deny -o -P udp -S 0/0 53 \ -D 172.16.37.0/24 2049 2050 # answers to other user port are okay # /sbin/ipfwadm-F -a accept -P udp -S 0/0 53 \ -D 172.16.37.0/24 53 1024:65535 # Reject incoming connections to identd # We use 'reject' here so that the connecting host is told # straight away not to bother continuing, otherwise we'd experience # delays while ident timed out. # /sbin/ipfwadm -F -a reject -o -P tcp -S 0/0 -D 172.16.37.0/24 113 # Accept some common service connections from the 192.168.64 and # 192.168.65 networks, they are friends that we trust. # /sbin/ipfwadm -F -a accept -P tcp -S 192.168.64.0/23 \ -D 172.16.37.0/24 20:23 # accept and pass thruough anything originating inside # /sbin/ipfwadm -F -a accept -P tcp -S 172.16.37.0/24 -D 0/0 # deny most other incoming TCP connections, and log them # (append 1:1023 if you have problems with ftp not working) # /sbin/ipfwadm -F -a deny -o -y - tcp -S 0/0 -D 172.16.37.0/24 # ... for UDP too # /sbin/ipfwadm -F -a deny -o -P udp -S 0/0 -D 172.16.37.0/24ÈǸ¢ÇÑ ÆÄÀ̾î¿ùÀ» ¼³Á¤ÇÏ´Â °ÍÀº Á¶±Ý º¹ÀâÇÏ´Ù. ÀÌ ¿¹´Â ¿©·¯ºÐ¿¡°Ô ÇÕ¸®ÀûÀÎ ½ÃÀÛÁ¡ÀÌ µÉ°ÍÀÌ´Ù. ipfwadmÀÇ ¸ÇÆäÀÌÁö´Â ÀÌ ÅøÀ» »ç¿ëÇÏ´Â ¹æ¹ý¿¡ ÀÖ¾î¼ µµ ¿òÀ» Á¦°øÇØ ÁÙ°ÍÀÌ´Ù. ¸¸¾à ÆÄÀ̾î¿ùÀ» ¼³Á¤ÇÏ°íÀÚ ÇÑ´Ù¸é, ¹ÏÀ»¸¸ ÇÏ´Ù°í »ý °¢ÇÏ´Â ¼Ò½º·Î ºÎÅÍ ¸¹Àº ¾îµå¹ÙÀ̽º¸¦ ¾ò°í ³×Æ®¿öÅ© ¿ÜºÎ¿¡¼ Å×½ºÅ©¸¦ Çغ¸ ±â ¹Ù¶õ´Ù.
IPX ÇÁ·ÎÅäÄÝÀº ´ë°³ ³ëº§ ³×Æ®¿þ¾îÀÇ ·ÎÄà ¿¡¸®¾î ³×Æ®¿öÅ© ȯ°æ¿¡¼ È°¿ëµÈ ´Ù. ¸®´ª½º´Â ÀÌ ÇÁ·ÎÅäÄÝÀÇ Áö¿øÀ» Æ÷ÇÔÇÏ°í ÀÖÀ¸¸ç, IPXÀÇ ³×Æ®¿öÅ© ¿£µåÆ÷ÀÎ Æ®(endpoint) ¶Ç´Â ¶ó¿ìÅÍ·Î ¼³Á¤µÉ°ÍÀÌ´Ù.
Kernel Compile Options: Networking options ---> [*] The IPX protocol [ ] Full internal IPX network
IPX ÇÁ·ÎÅäÄÝ°ú NCPFS´Â IPX-HOWTO¿¡¼ ±íÀÌ ´Ù·ç¾îÁø´Ù.
¿©·¯ºÐÀÌ ¸· IP ³×Æ®¿öÅ©¸¦ ÀÌÇØÇϱ⠽ÃÀÛÇß´Ù°í »ý°¢ÇÒ¶§ ·êÀº º¯°æµÈ´Ù! IPv6 ´Â ÀÎÅÍ³Ý ÇÁ·ÎÅäÄÝÀÇ ¹öÀü 6¿¡ ´ëÇÑ °£´ÜÇÑ ±â·ÏÀÌ´Ù. IPv6´Â ÀÎÅÍ³Ý »çȸÀÇ ÇÒ´çÇÒ ¾îµå·¹½º°¡ ºÎÁ·ÇÏ´Ù´Â ¿ì·Á¸¦ ±Øº¹Çϱâ À§Çؼ °³¹ßµÇ¾ú´Ù. IPv6 ¾îµå ·¹½º´Â 32byte(128bit)ÀÇ ±æÀÌÀÌ´Ù. IPv6´Â ´Ù¸¥ º¯°æ»çÇ×À» Æ÷ÇÔÇÏ°í Àִµ¥ ´ë°³´Â °£¼ÒÈ¿¡ °üÇÑ°ÍÀÌ°í ÀÌ°ÍÀÌ IPv4¿¡ ºñÇØ IPv6¸¦ ´Ù·ç±â ½±°Ô ¸¸µé¾î ÁØ ´Ù.
¸®´ª½º´Â 2.1.* Ä¿³Î¿¡ IPv6¸¦ Áö¿øÇÏ°í ÀÖÁö¸¸ ¿ÏÀüÇÑ°ÍÀº ¾Æ´Ï´Ù.
½Å¼¼´ëÀÇ ÀÎÅÍ³Ý ±â¼úÀ» ½ÇÇèÇÏ°í ½Í´Ù¸é, ¶Ç´Â ÀÌ°ÍÀÌ ÇÊ¿äÇÏ´Ù¸é, www.terra. net¿¡¼ ±¸ÇÒ¼öÀÖ´Â IPv6-FAQ¸¦ Àо±â ¹Ù¶õ´Ù. < www.terra.net/ipv6/>.
³ª¸ÓÁö´Â 7¿ù 23ÀÏ ±îÁö ¿Ã¸³´Ï´Ù. ÀÌ ¹®¼¿¡ ´ëÇÑ ¹ö±× ¸®Æ÷Æ®´Â sudoer@nownuri.netÀ¸·Î ÇØÁֽñ⠹ٶø´Ï´Ù.