+ + IP ¥Þ¥¹¥«¥ì¡¼¥É¤ÎÀßÄê + +


++ Contents ++

[5.1] /etc/network/option ¤ÎÊÔ½¸
[5.2] /etc/hosts ¤ÎÊÔ½¸
[5.3] /etc/network/interfaces ¤ÎÊÔ½¸
[5.4] ipchains ²òÀâ



[5.1] /etc/network/option ¤ÎÊÔ½¸


ip_forward=no

¤È¤Ê¤Ã¤Æ¤¤¤ëÉôʬ¤ò

ip_forward=yes

¤Ë½ñ¤­´¹¤¨¤ë¡£


[5.2] /etc/hosts ¤ÎÊÔ½¸

ÆâÉô¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¤ÎDNS¤Ï¡¢/etc/hosts ¥Õ¥¡¥¤¥ë¤ÎÀßÄê¤Ë ¤è¤Ã¤Æ·è¤á¤é¤ì¤Æ¤¤¤ë¡£

/etc/hosts ¥Õ¥¡¥¤¥ë¤Ë

192.168.10.1 Ž Ž postel.ep.sci.hokudai.ac.jp Ž Ž  postel

¤È½ñ¤­¹þ¤ß¡¢IP¥¢¥É¥ì¥¹¤È¥Û¥¹¥È̾¤ÎÂбþ¤ò½ñ¤¤¤Æ¤ª¤¯¡£

[5.3] /etc/network/interfaces ¤ÎÀßÄê

¤â¤È¤â¤È½ñ¤¤¤Æ¤¢¤ë¤â¤Î¤Î²¼¤Ë°Ê²¼¤Î¤â¤Î¤ò²Ã¤¨¤ë¡£

iface eth1 inet static
address 192.168.0.1 netmask 255.255.255.0
network 192.168.0.0
broadcast 192.168.0.255
geteway 133.87.45.1

up ipchains -P forward DENY
up ipchains -A forward -s 192.168.10.0/24 -j MASQ
up ipchains -M -S 21600 0 0
up /sbin/depmod -a
up /sbin/modprobe ip_masq_ftp

¡Ögateway 133.87.45.1 ¡× ¤Ë¤Ï¥ë¡¼¥¿¡Ê¤³¤Î¾ì¹ç¤Ï postel ¡Ë¤Î¥²¡¼¥È¥¦¥§¥¤¥¢¥É¥ì¥¹¤È¤ª¤Ê¤¸¤â¤Î¤ò ÀßÄꤹ¤ë¡£


[5.4] ipchains ²òÀâ

ipchains ¤Ï¡¢¥Õ¥¡¥¤¥ä¡¼¥¦¥©¡¼¥ë¤òºÙ¤«¤¯ÀßÄꤷ¤Æ¤¤¤¯¥³¥Þ¥ó¥É¤Ç¤¢¤ë¡£

[5.4.1] ÀßÄꥫ¥Æ¥´¥ê

¤Þ¤º¡¢ipchains ¤ÎÀßÄê¥Á¥§¥¤¥ó¤Ï¡¢°Ê²¼¤Î3¤Ä¤Ë¤ï¤±¤é¤ì¤ë¡¢

input¤Ï¤¤¤Ã¤Æ¤¯¤ë¥Ñ¥±¥Ã¥È¤ËÂФ¹¤ë¥Á¥§¥¤¥ó
output¤Ç¤Æ¤¤¤¯¥Ñ¥±¥Ã¥È¤ËÂФ¹¤ë¥Á¥§¥¤¥ó
forward¥ë¡¼¥Æ¥£¥ó¥°¤¹¤ë¥Ñ¥±¥Ã¥È¤ËÂФ¹¤ë¥Á¥§¥¤¥ó
³Æ¥Á¥§¥¤¥ó¤Î¥Ç¥Õ¥©¥ë¥È¤Ï¡¢ACCEPT(¤¹¤Ê¤ï¤Á¡¢¤¹¤Ù¤Æµö²Ä)¤È¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢¤³¤ì¤Ëµ¬À©¤ò¤«¤±¤Æ¥Õ¥¡¥¤¥ä¡¼¥¦¥©¡¼¥ë¤ò¹½ÃÛ¤·¤Æ¤¤¤¯¡£º£²ó¡¢postel ¤Ï¥ë¡¼¥¿¡¼¤Ç¤¢¤ë¤¿¤á¡¢¥Õ¥¡¥¤¥ä¡¼¥Õ¥©¡¼¥ë¤ÎÀßÄê¤Ï¡¢ forward ¤Î¤ß¹Ô¤¦¡£

[5.4.2] ¥¿¡¼¥²¥Ã¥È

ipchains ¤Ç¤Î¥¿¡¼¥²¥Ã¥È¤Ï°Ê²¼¤ÎÄ̤ê¤Ç¤¢¤ë¡£
ACCEPTÄÌ¿®¤òµö²Ä
DENYÄÌ¿®¤òÉÔµö²Ä(Á÷¿®¸µ¤ØÉÔµö²Ä¤òÅÁ¤¨¤Ê¤¤)
REJECTÄÌ¿®¤òÉÔµö²Ä(Á÷¿®¸µ¤ØÉÔµö²Ä¤òÅÁ¤¨¤ë)
MASQ¤¢¤¿¤«¤â¤½¤ÎPC¤«¤éȯ¿®¤µ¤ì¤¿¤«¤Î¤è¤¦¤Ë¥Þ¥¹¥«¡¼¥ì¡¼¥É¤µ¤ì¤ë¡£¼õ¿®»þ¤â¼«Æ°Åª¤Ë¥Þ¥¹¥«¡¼¥ì¡¼¥É¤ò³°¤µ¤ì¤ë¡£(input¡¢output¤Ç¤Ï»ÈÍÑÉÔ²Ä)
REDIRET¥ê¥â¡¼¥È¥Û¥¹¥È°¸¤ØÁ÷¿®¤µ¤ì¤¿¥Ñ¥±¥Ã¥È¤â¥í¡¼¥«¥ë¤Î¥½¥±¥Ã¥È¤Ø¸þ¤±¤ë¡£(output¡¢forward¤Ç¤Ï»ÈÍÑÉÔ²Ä)

[5.4.3] ½ñ¼°

ipchains ¤Ç¤Î½ñ¼°¤Ï¼¡¤Î¤è¤¦¤Ë¤Ê¤ë
ipchains -A(--append) chain rule [option]
¡¡¥Á¥§¥¤¥ó¤ÎºÇ¸åÈø¤Ë¥ë¡¼¥ë¤òÄɲ乤ë
ipchains -D(--delete) chain rule(ruleNo.) [option]
¡¡¥ë¡¼¥ë¤òºï½ü¤¹¤ë
ipchains -R(--replace) chain ruleNo. rule [option]
¡¡¥ë¡¼¥ë¤òÃÖ¤­´¹¤¨¤ë
ipchains -I(--insert) chain ruleNo. rule [option]
¡¡¥ë¡¼¥ëÈÖ¹æ¤ò»ØÄꤷ¤Æ¥ë¡¼¥ë¤òÄɲ乤ë
ipchains -L(--list) chain [option]
¡¡¥ë¡¼¥ë°ìÍ÷¤òɽ¼¨¤¹¤ë
ipchains -F(--flush) chain [option]
¡¡¥ë¡¼¥ë¤ò¤¹¤Ù¤Æ¾Ãµî¤¹¤ë
ipchains -Z(--zero) chain [opition]
¡¡¥Ñ¥±¥Ã¥È¥«¥¦¥ó¥¿¡¢¥Ð¥¤¥È¥«¥¦¥ó¥¿¤ò0¤Ë½é´ü²½¤¹¤ë
ipchains -N(--new-chain) chain [option]
¡¡¿·¤¿¤Ë¥Á¥§¥¤¥ó¤òÄêµÁ¤¹¤ë
ipchains -x(--delete-chain) chain [option]
¡¡¥æ¡¼¥¶¡¼¤¬ÄêµÁ¥Á¥§¥¤¥ó¤ó¤òºï½ü¤¹¤ë¡£
ipchains -P(--policy) target
¡¡¥Ý¥ê¥·¡¼¤ò»ØÄꤷ¤¿¥¿¡¼¥²¥Ã¥È¤ËÀßÄꤹ¤ë
ipchains -M(--masquerading) -L [option]
¡¡¥Þ¥¹¥«¥ì¡¼¥É¤µ¤ì¤Æ¤¤¤ëÀܳ¤òɽ¼¨¤¹¤ë
ipchains -M(--masquerading) -S(--set tcp tcpfin udp) [option]
¡¡¥Þ¥¹¥«¥ì¡¼¥É¤Ç¤Î¥¿¥¤¥à¥¢¥¦¥È»þ´Ö(ÉÃ)¤òÀßÄꤹ¤ë¡£O¤òÆþ¤ì¤ë¤ÈÊѹ¹¤·¤Ê¤¤
ipchains -C(--check) chain rule [option]
¡¡Í¿¤¨¤é¤ì¤¿¥Ñ¥±¥Ã¥È¤ò¾È¹ç¤¹¤ë
ipchains -h(--help)
¡¡¥³¥Þ¥ó¥É½ñ¼°¤ÎÀâÌÀ¤òɽ¼¨¤¹¤ë
ipchains -V(--version)
¡¡ipchains ¤Î¥Ð¡¼¥¸¥ç¥óÈÖ¹æ¤òɽ¼¨¤¹¤ë

[5.4.4] ¥ë¡¼¥ë

ÄÌ¿®¤Î¥ë¡¼¥ë¤Ï¼¡¤Î¤è¤¦¤ËÄê¤á¤ë¡£

-s "ȯ¿®¸µ" -d "ȯ¿®Àè" -j target

ȯ¿®¸µ¡¢È¯¿®Àè¤Ï¡¢°Ê²¼¤Î¤è¤¦¤Ë»ØÄꤹ¤ë

IPaddress[/mask] [port[:port]] (ex.192.168.0.1/24 80:80)

¤¿¤À¤·¡¢³Æ¥Ñ¥é¥á¡¼¥¿¡¼¤ÎÁ°¤Ë"!"¤ò¤Ä¤±¤ë¤È¤½¤ì°Ê³°¤Î¤â¤Î¤ò»ØÄꤷ¤¿¤³¤È¤Ë¤Ê¤ë¡£¤Þ¤¿¡¢¤¹¤Ù¤Æ¤ÎIP ¥¢¥É¥ì¥¹¤ä¥Ý¡¼¥È¤ò»ØÄꤹ¤ë¾ì¹ç¤Ï¡¢¤½¤Î¥Ñ¥é¥á¡¼¥¿¡¼¤ò¾Êά¤·¤ÆÎɤ¤¡£


[5.4.5] º£²ó¤ÎÀßÄê¤Ï?

¤È¤¤¤¦¤³¤È¤Ç¡¢¤ä¤Ã¤Èº£²ó¤ÎÀßÄê¡£ÀßÄê»þ¤Ë½ñ¤¤¤¿¤Î¤Ï°Ê²¼¤Î»°¹Ô

up ipchains -P forward DENY
up ipchains -A forward -s 192.168.10.0/24 -j MASQ
up ipchains -M -S 21600 0 0

¤Þ¤º¡¢°ì¹ÔÌÜ¡£

up ipchains -P forward DENY

¤³¤ì¤Ï¡¢-P forward ¤Ç¥ë¡¼¥Æ¥£¥ó¥°¤¹¤ë¤È¤­¤Î¥Ý¥ê¥·¡¼¤ò·è¤á¤Æ¤¤¤ë¡£´ðËÜŪ¤Ëipchains¤òÍѤ¤¤Æ¥Õ¥¡¥¤¥ä¡¼¥¦¥©¡¼¥ë¤ÎºÙ¤«¤¤ÀßÄê¤ò¹Ô¤¦¾ì¹ç¤Ï¡¢¥Ý¥ê¥·¡¼¤Ï DENY(ÄÌ¿®¤òÉÔµö²Ä) ¤Ç¤¢¤ë¡£

¥Ç¥Õ¥©¥ë¥È¤ÎÀßÄê¤Ç¤Ï¤¹¤Ù¤Æ ACCEPT ¤È¤Ê¤Ã¤Æ¤¤¤ë¤¬¡¢¤½¤Î¾õÂÖ¤«¤é»È¤ï¤Ê¤¤ÄÌ¿®¤òÉÔµö²Ä¤Ë¤·¤Æ¤¤¤¯ºî¶È¤Ï¥ß¥¹¤òͶ¤¤¤ä¤¹¤¤¡£ºÇ½é¤ËDENY¤ÇÊɤòºî¤ê¡¢¤½¤³¤Ëµö²Ä¤·¤Æ¤¤¤¤ÄÌ¿®¤Î¤ß¤Î·ê¤ò¤¢¤±¤ë¤Î¤Ç¤¢¤ë¡£


¼¡¤Ë¡¢Æó¹ÔÌÜ¡£

up ipchains -A forward -s 192.168.10.0/24 -j MASQ

¤³¤ì¤Ï¡¢-A forward ¤Ç¡¢¥ë¡¼¥Æ¥£¥ó¥°¤òµö²Ä¤¹¤ëÄÌ¿®¤òµ­½Ò¤·¤Æ¤¢¤ë¡£

¤É¤Î¤è¤¦¤ÊÄÌ¿®¤òµö²Ä¤·¤Æ¤¤¤ë¤Î¤«¤È¤¤¤¦¤È¡¢-s 192.168.10.0/24 -j MASQ ¤è¤ê¡¢"192.168.10.0/24 ¤È¤¤¤¦IP¥¢¥É¥ì¥¹¤«¤é¡¢¤¹¤Ù¤Æ¤ÎIP¥¢¥É¥ì¥¹¤Ø¤ÎÄÌ¿®¤ò¥Þ¥¹¥«¥ì¡¼¥É¤¹¤ë"¤³¤È¤Ç¤¢¤ë¡£

¤Þ¤¿¡¢¥Ý¡¼¥ÈÈÖ¹æ¤Ï¾Êά¤µ¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢¤¹¤Ù¤Æ¤Î¥Ý¡¼¥È¤ÎÄÌ¿®¤òµö²Ä¤·¤Æ¤¤¤ë¤³¤È¤Ë¤Ê¤ë¡£


ºÇ¸å¤Ë¡¢»°¹ÔÌÜ¡£

up ipchains -M -S 21600 0 0

¤³¤ì¤Ï¡¢-M -S ¤Ç¡¢ºÇ¸å¤ËÄÌ¿®¤·¤Æ¤«¤é²¿Éøå¤ËÄÌ¿®¤òÀܳ¤¹¤ë¤«¤¬µ­¤·¤Æ¤¢¤ë¡£

¤³¤ì¤é¤Î¿ô»ú¤ÏÁ°¤«¤é¡¢TCPÀܳ, ½ªÎ»ÄÌÃÎ(FIN¥Ñ¥±¥Ã¥È)¤ò¼õ¤±¤¿TCPÀܳ, UDPÀܳ ¤Ç¡¢¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï15ʬ, 2ʬ, 5ʬ¤È¤Ê¤Ã¤Æ¤¤¤ë¡£TCPÀܳ¤Î15ʬ¤Ç¤Ïû¤¤¤Î¤Ç¡¢¤³¤³¤Ç¤Ï£¶»þ´Ö¤Ë¤Î¤Ð¤·¤Æ¤¤¤ë¡£


<< Cap.4 || UP || Cap.6 >>
last up : 2002/05/27 (C.Mitsuda)