×¢²á | µÇ¼ Íü¼ÇÃÜÂ룿 51ctoÊ×Ò³ | ²©¿Í | ÂÛ̳ | ÕÐÆ¸
ÈȵãÎÄÕ ¸ºÔؾùºâ¼¼ÊõɳÁúÎÊ´ð»ã¼¯
¡¡°ïÖú
2006-12-22 09:08:00
ǰÑÔ£ºÔÚÍøÂçÖУ¬µ±ÐÅÏ¢½øÐд«²¥µÄʱºò£¬¿ÉÒÔÀûÓù¤¾ß£¬½«ÍøÂç½Ó¿ÚÉèÖÃÔÚ¼àÌýµÄģʽ£¬±ã¿É½«ÍøÂçÖÐÕýÔÚ´«²¥µÄÐÅÏ¢½Ø»ñ»òÕß²¶»ñµ½£¬´Ó¶ø½øÐй¥»÷¡£ÍøÂç¼àÌýÔÚÍøÂçÖеÄÈκÎÒ»¸öλÖÃģʽ϶¼¿Éʵʩ½øÐС£¶øºÚ¿ÍÒ»°ã¶¼ÊÇÀûÓÃÍøÂç¼àÌýÀ´½ØÈ¡Óû§¿ÚÁî¡£±ÈÈçµ±ÓÐÈËÕ¼ÁìÁËһ̨Ö÷»úÖ®ºó£¬ÄÇôËûÒªÔÙÏ뽫ս¹ûÀ©´óµ½Õâ¸öÖ÷»úËùÔÚµÄÕû¸ö¾ÖÓòÍø»°£¬¼àÌýÍùÍùÊÇËûÃÇÑ¡ÔñµÄ½Ý¾¶¡£ºÜ¶àʱºòÎÒÔÚ¸÷ÀలȫÂÛ̳ÉÏ¿´µ½Ò»Ð©³õѧµÄ°®ºÃÕߣ¬ÔÚËûÃÇÈÏΪÈç¹ûÕ¼ÁìÁËijÖ÷»úÖ®ºóÄÇôÏë½øÈëËüµÄÄÚ²¿ÍøÓ¦¸ÃÊǺܼòµ¥µÄ¡£Æäʵ·ÇÒ²£¬½øÈëÁËijÖ÷»úÔÙÏëתÈëËüµÄÄÚ²¿ÍøÂçÀïµÄÆäËü»úÆ÷Ò²¶¼²»ÊÇÒ»¼þÈÝÒ×µÄÊÂÇé¡£ÒòΪÄã³ýÁËÒªÄõ½ËûÃǵĿÚÁîÖ®Í⻹ÓоÍÊÇËûÃǹ²ÏíµÄ¾ø¶Ô·¾¶£¬µ±È»ÁË£¬Õâ¸ö·¾¶µÄ¾¡Í·±ØÐëÊÇÓÐдµÄȨÏÞÁË¡£ÔÚÕâ¸öʱºò£¬ÔËÐÐÒѾ­±»¿ØÖƵÄÖ÷»úÉϵļàÌý³ÌÐò¾Í»áÓдóÊÕЧ¡£²»¹ýÈ´ÊÇÒ»¼þ·ÑÉñµÄÊÂÇ飬¶øÇÒ»¹ÐèÒªµ±ÊÂÕßÓÐ×ã¹»µÄÄÍÐĺÍÓ¦±äÄÜÁ¦¡£Ö÷Òª°üÀ¨£º
Êý¾ÝÖ¡µÄ½Ø»ñ 
¶ÔÊý¾ÝÖ¡µÄ·ÖÎö¹éÀà 
dos¹¥»÷µÄ¼ì²âºÍÔ¤·À 
IPðÓõļì²âºÍ¹¥»÷ 
ÔÚÍøÂç¼ì²âÉϵÄÓ¦Óà
¶ÔÀ¬»øÓʼþµÄ³õ²½¹ýÂË 
Ñо¿µÄÒâÒ壺
1£©ÎÒ¹úµÄÍøÂçÕýÔÚ¿ìËÙ·¢Õ¹ÖУ¬ÏàÓ¦µÄÎÊÌâÒ²¾ÍÏÔÏÖ³öÀ´£¬ÍøÂç¹ÜÀí¼°ÏàÓ¦Ó..



2006-12-22 09:03:00
ϵͳ׼±¸:Ò»¸öÔËתÕý³£µÄLinux(Õâ¸ö´ó¼Ò¶¼ÓÐ) 
¡¡¡¡Ó²¼þÒªÇó:ÖÁÉÙÒ»¿éÍø¿¨£¬¿í´øÉ豸ÒѾ­ÉêÇëÍê±Ï£¬Í¬Ê±ÒѾ­¿ªÍ¨
¡¡¡¡¹ãÖݵçÐŵÄADS(LAN)LʹÓõÄÊÇPPPOE²¦ºÅ·½Ê½£¬Òò´Ë£¬ÒªÔÚLinuxÏÂʹÓÃADSL£¬±ØÐë°²×°PPPOE¿Í»§¶ËÈí¼þ¡£
¡¡¡¡ÏÂÃæËµÃ÷ÈçºÎ½øÐа²×°:±¾ÈËÒÔRedHat Linux 7.3Ϊƽ̨£¬ÆäËüƽ̨LinuxµÄ°²×°°ì·¨¿ÉÒÔ²ÎÕÕÏÂÃæ°²×°µÄ²½Öè¡£
¡¡¡¡Ò»¡¢°²×°µÄǰÌáÌõ¼þ1.È·±£°²×°ÁËÍø¿¨²¢¹¤×÷Õý³£Ê¹ÓÃÃüÁî#ifconfig eth0²é¿´Íø¿¨×´Ì¬2.ÔÚϵͳÖв»ÒªÉèÖÃĬÈÏ·ÓÉ(Íø¹Ø)£¬ÈÃADSL²¦ºÅºó×Ô¶¯»ñµÃÈç¹ûÒѾ­ÉèÖÃÁËĬÈÏ·ÓÉ£¬Ê¹ÓÃÒÔÏ·½·¨É¾³ý:ÔÚÎļþ /etc/sysconfig/network ÖÐɾ³ý GATEWAY= ÕâÒ»ÐУ¬È»ºóÒÔrootÖ´ÐÐ:#/etc/rc.d/init.d/network restart 3.ÒѾ­°²×°ÁËpppdÈí¼þ°üÈç¹û´æÔÚÎļþ /usr/sbin/pppd£¬Ôò˵Ã÷ÒѾ­°²×°ÁËpppd;Èçδ°²×°£¬´ÓRedHatLinux °²×°¹âÅÌÉÏ×°ppp-2.3.11-4.i386.rpm(°æ±¾¿ÉÄܲ»Ò»Ñù)Õâ¸öÈí¼þ°ü¶þ¡¢°²×°PPPOE¿Í»§¶ËÈí¼þLinuxϵÄPPPOE¿Í»§¶ËÈí¼þ±È½Ï¶à£¬¶øÇÒ´ó¶àʹÓÃGNU License£¬ÍƼöʹÓÃrp-pppoeÕâ¸öÈí¼þ°ü£¬
¡¡¡¡´Ó
http://www.roaringpenguin.com/pppoe/Õâ¸öÍøÕ¾ÉÏ£¬²»½ö¿ÉÒÔÏ..



2006-12-22 09:01:00
Linux°æ»·¾³ÒªÇ󣬰²×°·½·¨£¬Æô¶¯·½·¨£¬ÔËÓª/¹ÜÀí·½·¨
1£©¹¤×÷»·¾³ÒªÇó
Linux °æ SoftEtherÔËÐУ¬ÐèÒªÈçÏ»·¾³

pthread ¿â
OpenSSL ¿â (<--- 
http://www.openssl.org ¿ÉÒÔÏÂÔØ×îаæ)

²¢ÇÒÐèÒª¿ÉÒÔʶ±ð *.a Îļþ¸ñʽ(ѹËõÐÎʽµÄ¾²Ì¬¿â)µÄLinker

ÔÚ RedHat 7.1¡¢RedHat 9.0¡¢Vine Linux 2.6 ÉÏÑé֤ȷÈÏ¡£ÆäËûµÄLinux ·¢Ðа汾£¬Ò²¶¼¸ÃÓÐpthread¿âºÍOpenSSL¿âµÄ¡£


2£©°²×°·½·¨
se_100_linux.zipÀïÃæÓÐÈçÏÂÈý¸öÎļþ

libse_hub.a
ca.crt
ca.key

Ëæ±ãÕ¹¿ªµ½Ê²Ã´µØ·½¾ÍÐУ¬ÎªÁ˱ãÓÚ˵Ã÷£¬¼ÙÉèÕ¹¿ªµ½ÁËÒ»¸öÃûΪse_hubµÄĿ¼

SoftEther Linux°æV-HUB³ÌÐò²¢²»ÊÇÒ»¸ö¿ÉÖ´ÐÐÐÎʽ£¬¶øÊÇÒÔ¾²Ì¬¿âÐÎʽ´æ·ÅÔÚlibse_hub.aÀïÃæ¡£Òò´Ë£¬ÐèÒª°Ñpthread¿âºÍOpenSSL¿âÎļþÁ´½Óµ½´Ë¾²Ì¬¿âÉÏÈ¥£¬²ÅÄÜÉú³É¿ÉÖ´ÐÐÎļþ

±ÈÈçÓÃgcc×÷ΪÁ´½ÓÆ÷µÄʱºò£¬Èç´ËÕâ°ã

gcc libse_hub.a -lpthread -lssl -lcrypt -o se_hub

Èç¹ûҪûÓÐÏÔʾ´íÎ󣬾ÍËãÁ´½Ó³É¹¦ÁË¡£ÔÚÕâ¸öĿ¼Àï»áÉú³ÉÃûΪ¡°se_hub¡±µÄÕâôһ¸öÎļþ


ÔËÐз½·¨ÕýÔÚ¼ÌÐø·­Ò룬ÉÙ°²ÎãÔê

3£©Æô¶¯·½·¨
..



2006-11-27 10:29:59
·À»ðǽ(Firewall)ÊÇÔÚÒ»¸ö¿ÉÐŵÄÍøÂçºÍ²»¿ÉÐŵÄÍøÂçÖ®¼ä½¨Á¢°²È«ÆÁÕϵÄÈí¼þ»òÓ²¼þ²úÆ·¡£Linux²Ù×÷ϵͳÄں˾ßÓаü¹ýÂËÄÜÁ¦£¬ÏµÍ³¹ÜÀíԱͨ¹ý¹ÜÀí¹¤¾ßÉèÖÃÒ»×鹿Ôò¼´¿É½¨Á¢Ò»¸ö»ùÓÚLinuxµÄ·À»ðǽ£¬ÓÃÕâ×鹿Ôò¹ýÂ˱»Ö÷»ú½ÓÊÕ¡¢·¢Ë͵İü»òÖ÷»ú´ÓÒ»¸öÍø¿¨×ª·¢µ½ÁíÒ»¸öÍø¿¨µÄ°ü£¬ÎÞÐ뻨·Ñ¶îÍâ×ʽð¹ºÂòרÃŵķÀ»ðǽ²úÆ·£¬±È½ÏÊÊÓÃÓÚijЩÖÐСÆóÒµ»ò²¿Ãż¶Óû§¡£
Ò»¡¢·À»ðǽµÄÀàÐͺÍÉè¼Æ²ßÂÔ
ÔÚ¹¹Ôì·À»ðǽʱ£¬³£²ÉÓÃ2ÖÖ·½Ê½£¬°ü¹ýÂ˺ÍÓ¦ÓôúÀí·þÎñ¡£°ü¹ýÂËÊÇÖ¸½¨Á¢°ü¹ýÂ˹æÔò£¬¸ù¾ÝÕâЩ¹æÔò¼°IP°üÍ·µÄÐÅÏ¢£¬ÔÚÍøÂç²ãÅж¨ÔÊÐí»ò¾Ü¾ø°üµÄͨ¹ý¡£ÈçÔÊÐí»ò½ûÖ¹FTPµÄʹÓ㬵«²»ÄܽûÖ¹FTPÌØ¶¨µÄ¹¦ÄÜ£¨ÀýÈçGetºÍPutµÄʹÓã©¡£Ó¦ÓôúÀí·þÎñÊÇÓÉλÓÚÄÚ²¿ÍøºÍÍâ²¿ÍøÖ®¼äµÄ´úÀí·þÎñÆ÷Íê³ÉµÄ£¬Ëü¹¤×÷ÔÚÓ¦Óò㣬´úÀíÓû§½ø¡¢³öÍøµÄ¸÷ÖÖ·þÎñÇëÇó£¬ÈçFTPºÍTelenetµÈ¡£
Ŀǰ£¬·À»ðǽһ°ã²ÉÓÃË«ËÞÖ÷»ú£¨Dual-homed Firewall£©¡¢ÆÁ±ÎÖ÷»ú(Screened Host Firewall)ºÍÆÁ±Î×ÓÍø(Screened Subnet Firewall)µÈ½á¹¹¡£Ë«ËÞÖ÷»ú½á¹¹ÊÇÖ¸³Ðµ£´úÀí·þÎñÈÎÎñµÄ¼ÆËã»úÖÁÉÙÓÐ2¸öÍøÂç½Ó¿ÚÁ¬½Óµ½ÄÚ²¿ÍøºÍÍâ²¿ÍøÖ®¼ä¡£ÆÁ±ÎÖ÷»ú½á¹¹ÊÇÖ¸³Ðµ£´úÀí·þÎñÈÎÎñµÄ¼ÆËã»ú½ö½öÓëÄÚ²¿ÍøµÄÖ÷»úÏàÁ¬¡£ÆÁ±Î×ÓÍø½á¹¹ÊǰѶîÍâµÄ°²È«²..



2006-11-27 08:47:00
·À»ðǽ(Firewall)ÊÇÔÚÒ»¸ö¿ÉÐŵÄÍøÂçºÍ²»¿ÉÐŵÄÍøÂçÖ®¼ä½¨Á¢°²È«ÆÁÕϵÄÈí¼þ»òÓ²¼þ²úÆ·¡£Linux²Ù×÷ϵͳÄں˾ßÓаü¹ýÂËÄÜÁ¦£¬ÏµÍ³¹ÜÀíԱͨ¹ý¹ÜÀí¹¤¾ßÉèÖÃÒ»×鹿Ôò¼´¿É½¨Á¢Ò»¸ö»ùÓÚLinuxµÄ·À»ðǽ£¬ÓÃÕâ×鹿Ôò¹ýÂ˱»Ö÷»ú½ÓÊÕ¡¢·¢Ë͵İü»òÖ÷»ú´ÓÒ»¸öÍø¿¨×ª·¢µ½ÁíÒ»¸öÍø¿¨µÄ°ü£¬ÎÞÐ뻨·Ñ¶îÍâ×ʽð¹ºÂòרÃŵķÀ»ðǽ²úÆ·£¬±È½ÏÊÊÓÃÓÚijЩÖÐСÆóÒµ»ò²¿Ãż¶Óû§¡£
Ò»¡¢·À»ðǽµÄÀàÐͺÍÉè¼Æ²ßÂÔ
ÔÚ¹¹Ôì·À»ðǽʱ£¬³£²ÉÓÃ2ÖÖ·½Ê½£¬°ü¹ýÂ˺ÍÓ¦ÓôúÀí·þÎñ¡£°ü¹ýÂËÊÇÖ¸½¨Á¢°ü¹ýÂ˹æÔò£¬¸ù¾ÝÕâЩ¹æÔò¼°IP°üÍ·µÄÐÅÏ¢£¬ÔÚÍøÂç²ãÅж¨ÔÊÐí»ò¾Ü¾ø°üµÄͨ¹ý¡£ÈçÔÊÐí»ò½ûÖ¹FTPµÄʹÓ㬵«²»ÄܽûÖ¹FTPÌØ¶¨µÄ¹¦ÄÜ£¨ÀýÈçGetºÍPutµÄʹÓã©¡£Ó¦ÓôúÀí·þÎñÊÇÓÉλÓÚÄÚ²¿ÍøºÍÍâ²¿ÍøÖ®¼äµÄ´úÀí·þÎñÆ÷Íê³ÉµÄ£¬Ëü¹¤×÷ÔÚÓ¦Óò㣬´úÀíÓû§½ø¡¢³öÍøµÄ¸÷ÖÖ·þÎñÇëÇó£¬ÈçFTPºÍTelenetµÈ¡£
Ŀǰ£¬·À»ðǽһ°ã²ÉÓÃË«ËÞÖ÷»ú£¨Dual-homed Firewall£©¡¢ÆÁ±ÎÖ÷»ú(Screened Host Firewall)ºÍÆÁ±Î×ÓÍø(Screened Subnet Firewall)µÈ½á¹¹¡£Ë«ËÞÖ÷»ú½á¹¹ÊÇÖ¸³Ðµ£´úÀí·þÎñÈÎÎñµÄ¼ÆËã»úÖÁÉÙÓÐ2¸öÍøÂç½Ó¿ÚÁ¬½Óµ½ÄÚ²¿ÍøºÍÍâ²¿ÍøÖ®¼ä¡£ÆÁ±ÎÖ÷»ú½á¹¹ÊÇÖ¸³Ðµ£´úÀí·þÎñÈÎÎñµÄ¼ÆËã»ú½ö½öÓëÄÚ²¿ÍøµÄÖ÷»úÏàÁ¬¡£ÆÁ±Î×ÓÍø½á¹¹ÊǰѶîÍâµÄ°²È«²..



2006-11-27 08:45:00
Á˽âÁËiptablesµÄ»ù±¾¸ÅÄîºÍÓ÷¨£¬ÏÂÃæÎÒÃǾͿªÊ¼ÕýʽʹÓÃiptablesÀ´´´½¨ÎÒÃǵķÀ»ðǽ¡£Æô¶¯ºÍÍ£Ö¹iptablesµÄ·½·¨È¡¾öÓÚËùʹÓõÄLinux·¢Ðа棬Äã¿ÉÒԲ鿴ËùʹÓÃLinux°æ±¾µÄÎĵµ¡£ÔÚRed HatÖУ¬Æô¶¯iptablesÓãº

#service iptables start

Ò»°ãÇé¿öÏ£¬iptablesÒѾ­°üº¬ÔÚÁËLinux·¢ÐаæÖУ¬¿ÉÒÔÔËÐÐiptables --versionÀ´²é¿´ÏµÍ³ÊÇ·ñ°²×°ÁËiptables¡£ÔÚÎÒʹÓõÄFedora Core 1ÖУ¬°²×°µÄ°æ±¾ÊÇiptables v1.2.8¡£Èç¹ûÄãµÄϵͳȷʵûÓа²×°iptables£¬ÄÇô¿ÉÒÔ´ÓÒÔϵØÖ·ÏÂÔØ£º

http://www.netfilter.org/

²é¿´¹æÔò¼¯

ËäÈ»ÉÏÎĶÔiptablesµÄÓ÷¨×÷Ò»¸ö¼òµ¥½éÉÜ£¬µ«ÏÖʵÖÐÎÒÃÇ¿ÉÄÜÐèÒªÖªµÀ¸üÍêÕûµÄÐÅÏ¢£¬ÕâʱÎÒÃÇ¿ÉÒÔÔËÐÐman iptablesÀ´²é¿´ËùÓÐÃüÁîºÍÑ¡ÏîµÄÍêÕû½éÉÜ£¬Ò²¿ÉÒÔÔËÐÐiptables helpÀ´²é¿´Ò»¸ö¿ìËÙ°ïÖú¡£Òª²é¿´ÏµÍ³ÖÐÏÖÓеÄiptables¹æ»®¼¯£¬¿ÉÒÔÔËÐÐÒÔÏÂÃüÁ

iptables list

ÏÂÃæÊÇûÓж¨Ò广»®Ê±iptablesµÄÑù×Ó£º

Chain INPUT (policy ACCEPT)

target¡¡ prot opt source¡¡ destination

Chain FORWARD (policy ACCEPT)

target¡¡ prot opt source¡¡ destination

Chain OUTPUT (policy ACCEPT)

target¡¡ prot opt source¡¡ destination

ÈçÉÏÃæµÄ..



2006-11-27 08:43:00
Linux ϵķÀ»ðǽ(firewall)´Óµ®Éúµ½ÏÖÔÚ£¬·À»ðǽÖ÷Òª¾­ÀúÁËËĸö·¢Õ¹½×¶Î£ºµÚÒ»½×¶Î£º»ùÓÚ·ÓÉÆ÷µÄ·À»ðǽ£»µÚ¶þ½×¶ÎÓû§»¯µÄ·À»ðǽ¹¤¾ßÌ×£»µÚÈý½×¶Î£º½¨Á¢ÔÚͨÓòÙ×÷ϵͳÉϵķÀ»ðǽ£»µÚËĽ׶Σº¾ßÓа²È«²Ù×÷ϵͳµÄ·À»ðǽ¡£Ä¿Ç°ÊÀ½çÉÏ´ó¶àÊý·À»ðǽ¹©Ó¦ÉÌÌṩµÄ¶¼ÊǾßÓа²È«²Ù×÷ϵͳµÄÈíÓ²¼þ½áºÏµÄ·À»ðǽ£¬ÏóÖøÃûµÄNETEYE¡¢NETSCREEN¡¢TALENTITµÈ¡£ÔÚLinux²Ù×÷ϵͳÉϵķÀ»ðǽÈí¼þÒ²ºÜ¶à£¬ÓÐЩÊÇÉÌÓð汾µÄ·À»ðǽ£¬ÓеÄÔòÊÇÍêÈ«Ãâ·ÑºÍ¹«¿ªÔ´´úÂëµÄ·À»ðǽ¡£´ó¶àÊýLinux½Ì³Ì¶¼Ìáµ½ÁËÈçºÎÔÚLinuxƽ̨ÖÐʹÓÃIPCHAINSÀ´¹¹Öþ·À»ðǽ¡£

ÉèÖú͹ÜÀíLinux²Ù×÷ϵͳÖеķÀ»ðǽÊÇÍøÂçϵͳ¹ÜÀíÔ±µÄÖØÒª¹¤×÷¡£Ò»°ãÇé¿öÏ£¬ÅäÖ÷À»ðǽȷʵÊÇÒ»¼þÐèÒªºÜ¸ß¼¼ÊõµÄ¹¤×÷¡£ÎÞÂÛÊÇÉÌÒµ°æ±¾µÄ·À»ðǽ»¹ÊÇÍêÈ«Ãâ·ÑµÄ·À»ðǽ¶¼ÐèÒªÔÚLinuxƽ̨ÖнøÐÐÈíÓ²¼þµÄÅäÖá£

ÓÐûÓÐÄÜËæÉíЯ´øµÄ£¬Ê¹Ó÷½±ãµÄLinux·À»ðÇ½ÄØ£¿´ð°¸ÊÇÓеģ¬ÏÖÔÚÎÒ¾ÍÏò´ó¼Ò½éÉÜÒ»ÖÖÄÜ×°ÔÚÆÕͨÈíÅÌÀïÃæµÄLinux·À»ðǽ¡£ÕâÌ×Ãû×Ö½ÐfloppyfwµÄLinux ·À»ðǽÄÜ´æ·ÅÔÚÒ»ÕÅÆÕͨµÄÈíÅÌÀ²¢¶ÀÁ¢µÄÔÚRAMÄÚ´æÖÐÔËÐС£Ê¹ÓÃËüÄÜÆô¶¯¼ÆËã»ú£¬ÀûÓÃipchains¹ýÂ˵ôÎÞÓõÄIP°ü£¬»¹¿ÉÒÔʹÓÃËüÀ´ÅäÖÃIPαװ£¨IP masquerade£©,¼àÊӶ˿ڣ¬Í¨¹ýËü¿ÉÒÔʹÓÃÖ÷»..



2006-11-27 08:41:00
·À»ðǽµäÐ͵ÄÉèÖÃÊÇÓÐÁ½¸öÍø¿¨£¬Ò»¸öÁ÷È룬һ¸öÁ÷³ö¡£iptables¶ÁÈ¡Á÷ÈëºÍÁ÷³öµÄÊý¾Ý°üµÄ±¨Í·£¬È»ºó½«ËüÃÇÓë¹æ»®¼¯(ruleset)Ïà±È½Ï£¬È»ºó½«¿É½ÓÊܵÄÊý¾Ý°ü´ÓÒ»¸öÍø¿¨×ª·¢ÖÁÁíÍâÒ»¸öÍø¿¨¡£¶ÔÓÚ±»¾Ü¾øµÄÊý¾Ý°ü£¬¿ÉÒÔ±»¶ªÆú»òÕß°´ÕÕÄãËù¶¨ÒåµÄ·½Ê½À´´¦Àí¡£

ͨ¹ýÏò·À»ðǽÌṩÓйضÔÀ´×Ôij¸öÔ´¡¢µ½Ä³¸öÄ¿µÄµØ»ò¾ßÓÐÌØ¶¨Ð­ÒéÀàÐ͵ÄÐÅÏ¢°üÒª×öЩʲôµÄÖ¸ÁîµÄ¹æÔò£¬¿ØÖÆÐÅÏ¢°üµÄ¹ýÂË¡£Í¨¹ýʹÓÃiptablesϵͳÌṩµÄÌØÊâÃüÁî iptables£¬½¨Á¢ÕâЩ¹æÔò£¬²¢½«ÆäÌí¼Óµ½Äں˿ռäµÄÌØ¶¨ÐÅÏ¢°ü¹ýÂ˱íÄÚµÄÁ´ÖС£¹ØÓÚÌí¼Ó¡¢³ýÈ¥¡¢±à¼­¹æÔòµÄÃüÁîµÄÒ»°ãÓï·¨ÈçÏ£º

iptables [-t table] command [match] [target]

ÏÖʵÖУ¬ÎªÁËÒ×¶Á£¬ÎÒÃÇÒ»°ã¶¼ÓÃÕâÖÖÓï·¨¡£´ó²¿·Ö¹æÔò¶¼Êǰ´ÕâÖÖÓ﷨дµÄ£¬Òò´Ë£¬Èç¹û¿´µ½±ðÈËдµÄ¹æÔò£¬ÄãºÜ¿ÉÄܻᷢÏÖÓõÄÒ²ÊÇÕâÖÖÓï·¨¡£

Èç¹û²»ÏëÓñê×¼µÄ±í£¬¾ÍÒªÔÚ[table]´¦Ö¸¶¨±íÃû¡£Ò»°ãÇé¿öÏÂûÓбØÒªÖ¸¶¨Ê¹ÓÃµÄ±í£¬ÒòΪiptables ĬÈÏʹÓÃfilter±íÀ´Ö´ÐÐËùÓеÄÃüÁҲûÓбØÒª·ÇµÃÔÚÕâÀïÖ¸¶¨±íÃû£¬Êµ¼ÊÉϼ¸ºõ¿ÉÔÚ¹æÔòµÄÈκεط½Ö¸¶¨±íÃû¡£µ±È»£¬°Ñ±íÃû·ÅÔÚ¿ªÊ¼´¦ÒѾ­ÊÇÔ¼¶¨Ë׳ɵıê×¼¡£¾¡¹ÜÃüÁî×ÜÊÇ·ÅÔÚ¿ªÍ·£¬»òÕßÊÇÖ±½Ó·ÅÔÚ±íÃûºóÃæ£¬ÎÒÃÇÒ²Òª¿¼Âǵ½µ×·ÅÔÚÄĶùÒ×¶Á¡£

¡..



2006-11-27 08:40:00
ÔÚ¹ýÈ¥¼¸ÄêÖУ¬linux×÷Ϊ·À»ðǽƽ̨µÄÓ¦ÓÃÏÔÖøÔö³¤¡£´ÓÔçÆÚ1.2°æÄں˵Äipfwadm¿ªÊ¼£¬LinuxµÄ·À»ðǽ´úÂëÒ²×ß¹ýÁ˺ܳ¤Ò»¶Î·³ÌÁË¡£ÔÚ2.4°æµÄLinuxÄÚºËÖУ¬Ê¹ÓÃÁËnetfilterÌåϵ¡£ÔÚ×îеÄ2.4°æÖУ¬Linux´ó´ó¼ÓÇ¿Á˰²È«ÐÔ£¬ÀýÈ磺¸üºÃµÄ¼ÓÃÜÖ§³ÖºÍ netfilterÌåϵµÄʹÓá£netfilter¾ßÓÐÍêÈ«µÄÏòºó¼æÈÝÐÔ¡£
±¾ÎĽ«¶ÔiptablesµÄÅäÖÃ×öÒ»¸ö×ÛÊö²¢ÇÒÖØµã½éÉÜһЩiptablesµÄÅäÖù¤¾ß¡£±¾ÎĵÄÌÖÂÛ½«×ÅÑÛÓÚlinuxÄں˵ÄIP·À»ðǽÒÔ¼°Æä¸÷ÖÖ½çÃæµÄÅäÖù¤¾ß£¬±ÈÈ磺GUI»òÕ߽ű¾(shell¡¢Perl»òÕßÌØ¶¨µÄÅäÖÃÓïÑÔ)¡£Ê¹ÓÃÕâЩ¹¤¾ßÄܹ»¼ò»¯iptablesµÄÅäÖüõÉÙÅäÖõĴíÎó¡£¹ØÓÚ iptablesµÄ֪ʶÇë²Î¿¼Rusty RussellдµÄLinux iptables HOWTO¡£
ʹÓÃÃüÁîÐÐÅäÖÃiptablesµÄÀ§ÄÑ
ʹÓÃiptablesµÄÃüÁîÐнӿÚÀ´ÅäÖÃiptables·À»ðǽ¶ÔÒ»¸öÈËÀ´ËµÊÇÒ»¸öÌôÕ½£¬Óû§ºÜÄÑÖ¸¶¨ËùÓÐIP±¨ÎĵÄÐÐΪ¡£Óû§ÐèÒª¶ÔTCP/IP ºÍÓ¦ÓòãЭÒéÓнÏÉîµÄÁ˽⡣ÏóÆäǰ±²ipchainsÒ»Ñù£¬iptables°ÑIP¹ýÂ˹æÔò¹é²¢µ½Á´ÖУ¬IP±¨ÎıéÀú¹æÔòÁ´½ÓÊÜ´¦Àí£¬»¹¿ÉÒÔË͵½ÁíÍâµÄÁ´½ÓÊÜ´¦Àí£¬»òÕß×îºóÓÉĬÈϲßÂÔ(ACCEPT¡¢DROP¡¢REJECT)´¦Àí¡£ÓÐÐ©ÍøÂçÓ¦ÓóÌÐò±ÈÆäËüһЩ³ÌÐò¸üÈÝÒ×´©¹ý·À»ðǽ£¬Òò´ËÐèÒªÀí½âÍøÂçÁ¬½ÓµÄ½¨Á¢ºÍ¶Ï¿ª¡£
ÎÒÃÇ¿´Ò»ÏÂP..