![]() |
||
|
|||||||
|
|
|
¥DÃD¤u¨ã |
|
New Member
¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
|
®¦...¦b¤U¬O¬Y¤j¾Ç±JªÙ²zªººô¸ôºÞ²z¤p²Õ¦¨û
¡A¥Ñ©ó³Ìªñ¥þ±§ï¥ÎDHCP¦Û°Ê¨ú±oIP¤è¦¡¡A¨Ï±oºÞ²z¤W¦³«Ü¤jªº¤£«K ¡A«ç»¡¡H´N¬O§ÚÌn°O¿ý¨ºÓIP¬Oþ¶¡¹ì«Çªº¨ºÓ¤H¦b¥Î¡A¥H«K¥¼¨Ó§@ºÊ±±»PºÞ¨î¡]¨Ò¦p¥L¤¤¬r©Î¦b·mÀW¼e ¡^¡A¦ý¥Ñ©ó¨Ï¥ÎDHCPªºÃö«Y¡A¨Ï±o¤£¥Î¦b±Jºô²Õµn°O¤]¥i¥H¤Wºô ¡A©Ò¥H·Qn®Ä³Xseednetªº¤è¦¡¡CSeednetªº§@ªk¬O¡A¦pªG¨Sú¶O¡A©Î¬O±b¸¹¨S¶}³q¡A¤@¶}ÂsÄý¾¹¥u·|³s¤W¤@Óºô¶¡Aseednet±MÄݪººô¶¡A¥Î¨Ó¶}³q»P±b¸¹§@·~¥Îªº.....§Ṳ́]·Qn°µ¨ì¨º¼Ë¡A¦b¥¼µn°O«e¥u¯à³s¤W§Ú̬[ªººô¯¸¡AµM«á¦bºô¶¤Wµn°O«á¡A§Y«K¶}³q¥Lªº±Jºô¡A¦³¨S¦³¤Hª¾¹D«ç»ò¥h°µ¨ì¦p¦¹©O¡H ÁÂÁ¦U¦ìªºÀ°¦£!![]() |
|||||||
|
|
|
Advance Member
![]() ![]() ¥[¤J¤é´Á: Dec 2002
¤å³¹: 381
|
ÀW¼eºÞ²z t¸ü ¾¹
°µºô¥dMAC³]©w ¨C¥x³] ¨S³]ªº¤£¯à¤W ³o¼ËÀ³¸Ó¥i ¥u¬O«Ü³Â·Ð¤@W¤@ |
||
|
|
|
New Member
¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
|
¤Þ¥Î:
±z¦n¡G §Ú̲{¦b¾Ç®Õ¸Ìªº¤èªk´N¬O³o¼Ë¡A¦ý¥Ñ©ó§Ú̱Jºô²Õªº¤H¤O¤£¨¬¡A©Ò¥H·Qn´«¤èªk...ÁÂÁ±zªº·N¨£ |
|
|
|
|
Major Member
![]() ¥[¤J¤é´Á: Dec 2002 ±zªº¦í§}: Á¼
¤å³¹: 265
|
¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ¨Ó¬Ý¬Ý§a...
¤Þ¥Î:
n±j¢ÂsÄý¥ô¦óºô¶³£Âà¨ì¯S©wºô¶, ¦³¨âºØ¤è¦¡: 1. ¥Î policy based routing (PBR): ¦b router ¤W, ¥u©ñ¦æµn¿ý¹Lªº (source) IP addresses. ©|¥¼µn¿ýªº±N (destination) port 80 Âà¨ìµn¿ýªººô¯¸, «D port 80 ªº¤@«ß deny. (domain, bootp, ... °£¥~) ºô¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router ±N¥Lªº (source) IP addr. ©ñ¦æ. (¦]¬°»Ýn¨Ì¾Ú source IP addr. ¨Ó°µ routing, ©Ò¥H»Ýn±Ò°Ê PBR) 2. ¥Î DNS ¨Ó±±¨î. ¦b router ¤W, ±N (destination) port 53 Âà¨ì¤@¥x¯S©wªº DNS server. ©|¥¼µn¿ýªº IP addr. ¬d¥ô¦ó domain®É, ³£·|¸Ñ¦¨µn¿ýªººô¯¸ªº IP addr., ºô¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router (¤Î DNS server)±N¥Lªº IP addr. ©ñ¦æ. (router ¤W¤£»Ý±Ò°Ê PBR, ¥H DNS server ¨Ì¾Ú clientºÝªº¤£¦P¨Ó°µÃþ¦üªº¤u§@....) ¥~±¦³¤½¥q¦b¼g³oºØ¨t²Î, ¥]§t±z´£¨ìªº«áÄòªº (§Y®É) ºÊ±±ºÞ¨îªº¦Û°Ê¤Æ. ¦pªG¥u¬OnÅý¨Ï¥ÎªÌ¨C¦¸¤Wºô«e¤@©wn¥ýµn¿ý. Ó¤H´¿¬[¹L linux router/bridge, ¥H iptables + apache + php + radtest(radius client) ¼g¹L... µ{¦¡ÁÙº¡µuªº... |
|
|
|
|
Elite Member
![]() ![]() ![]() ![]() ![]() ¥[¤J¤é´Á: May 2002 ±zªº¦í§}: ªO¾ô
¤å³¹: 5,112
|
¦^ÂÐ: ¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ¨Ó¬Ý¬Ý�
¤Þ¥Î:
¤£¹Lrouter¦ü¥G¤£¾A¦X°µ³oÃþW¤u(¤@¯ëASIC¥u¯à³B²z³æ¯Âªºpacket forwarding,access list/policy routing±o¥ÑCPU³B²z,¦ý¤@¯ërouterªºCPU³£¤£¬O«Ü°ªÀÉ,¦A¥[¤Wn°ÊºAupdate¨äconfig,«áªG¦p¦ón¸Õ¤F¤~ª¾¹D ),¦b¾Ç³Nºô¸ôµ¥traffic¤jªººô¸ô¤W®£©È¶]°_¨Ó·|«Ü¦Y¤O ....¤Þ¥Î:
À³¸Ó¬O§âunknown clientªºDNS request redirect¨ì¥t¤@³¡¥u´£¨Ñfake answerªºDNS server§Y¥i(¥H¤£Åܰʤ@¯ëDNS serverªº¹ê§@¬°ì«h,¤£¹Lroutern¦p¦ó¤À¿ëunknown client®£©ÈÁÙ¬O±o°Ê¨ìpolicy routing,°ÝÃDÁÙ¬O¸ò«e±¤@¼Ë )....BTW,¹J¨ìuserª½±µ¥´ip address®£©È´N¯}¥\¤F(default±odrop unknown traffic )...¤Þ¥Î:
§Ì¦bpczone¤]¬O«ØÄ³ìµo¤åªÌ¸Õ¸Õtransparent mode firewall°t¦XÃþ¦üTPªº¤è¦¡(¹ï¨ä²{¦³ºô¸ô¬[ºcªºimpact³Ì¤p )....BTW,³oÃþ¤è¦¡»¡¬ï¤F¥u¬O¥Hmac address(³»¦h¦A¥[¤Wip address)¨Ó§PÂ_©ñ¦æ»P§_,¦]¬°¥uª¾user¤Wºôªº®ÉÂI,¦Ó¤£ª¾¨ä¦ó®Éoffline¦n§âACCEPT rule®³±¼,¦A¥[¤W¦bLAN¤¤n°°³yip/mac address¤]¤£¬OÃø¨Æ,¨Ã¤£¬O«Ü¥i¾a,¥t¥~Áö»¡¦bLAN¤W¤]¯à¶]PPPoE,¦ý³o¹ê¦b¤£¬OÓ¦n¥D·N ....
__________________
¤h¤j¤Ò¤§µL®¢,¬O¿×°ê®¢ ![]() ....
|
|||
|
|
|
Major Member
![]() ¥[¤J¤é´Á: Dec 2002 ±zªº¦í§}: Á¼
¤å³¹: 265
|
¦^ÂÐ: ¦^ÂÐ: ¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ�
¤Þ¥Î:
¬O«Ü¦Y¤O, ©Ò¥H¤~·|¦³¥Î DNS ¨ÓºÞ¨îªº·Qªk. ¤Þ¥Î:
¶â... ²Ó¸`´N¤£±Ôz¤F, ¤£¹L¬O¥i¥H§Ë¨ì router ¤£»Ýn±Ò°Ê PBR: ±q DHCP ±o¨ìªº DNS server ¬O¤@¥x¯S©wªº DNS, (¤£¤À¬O§_µn¿ý¹L»P§_) ¨º¥x DNS ·|¨Ì¾Ú client ip addr.¨Ó¨M©w¦æ¬° (¨Ò¦p: ¨Ï¥Î view) °£¥¦¤§¥~, (dest) port 53 ¤@«ß deny, (Á×§K¨Ï¥ÎªÌ¦Û¤v³]©w¨ä¥Lªº DNS servers) ¨º´N¥i¥HÅý DNS ¨Ó±j¨î¨Ï¥ÎªÌµn¿ý¤F, ¦Ü©ó, ¨Ï¥ÎªÌª½±µ¥´ IP addr... ¯unºÞ¨î, ¤]¦³¿ìªkªº... ¤Þ¥Î:
°£¤FÅý¨Ï¥ÎªÌ¦Û¤vÂI logout ¥~, ¤]¥i¥H³]©w idle timeout, ¦pªG¬O bridge mode, ¥Î forwarding table ¨M©w¬O§_ idle ¹L¤[ (brctl showmacs) ¦pªG¬O router mode, ¥Î arp table ¨Ó¨M©w¬O§_ idle ¹L¤[ (arp -a) °²³y ip/mac addr. ªº°ÝÃD, ı±o¥i¥H©¿²¤... (·Q±q linux bridge/router ¨Ó³]©wÀ³¸Ó¬OµL¸Ñ, »Ýn쥻ªº L2 switches ªº¤ä´©) ¦³¤@¨Ç²Ó¸`nª`·N, ¤£¹L´N¤£¦A°Q½×¤F... ¨S¦³¥´ºâ½Ð¥~±ªº¤½¥q¼gªº¸Ü, ¨Ï¥Î linux bridge, ¥H iptables ¨Ó³]©wÀ³¸Ó¬O¤ñ¸û¥i¦æªº¤èªk.... ¦]¬°¥u¥Î¨ì¤@¥x¾÷¾¹, ¤ñ¸û³æ¯Â. ¦Ó¥B¦]¬°¬O bridge mode, ¦³°ÝÃD´N©Þ±¼©Î bypass ¤£¹L, ¦pªG traffic ¤Ó¤jªº¸Ü, ®Ä¯à¥i¯à·|¤£¯à±µ¨ü... |
|||
|
|
|
New Member
¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
|
®¦...ÁÂÁ¤j®aªº¦^ÂÐ...´£¨Ñ¤F¬Û·í¦hªº¤èªk...
¤£¹L...§Ú¦ü¥G§Ñ¤F»¡¤@¥ó«Ü«nªº¨Æ±¡... §Ú§Ñ¤F»¡¤@¤U§Ú̲{¦³ªº³]³Æ...¨þ¨þ¡ã §Ú̪º±Jºô¬[ºc¬O³o¼Ëªº... º¥ý¡A¬O¥Ñ¦U¹ì«Çªººô¸ôRJ-45±µ¤Õ³s½u¨ì¦U¼Ó¼hªºswitch HUB¡AµM«á¦A¥Ñ¦USwitch HUB³s±µ¨ì¦U°Ï°ìªº¡yÀW¼eºÞ²z¾¹¡z(ÀW¼eºÞ²z¾¹ªº¸Ô²Ó¸ê®Æ) ¤W¡AµM«á¦UÀW¼eºÞ²z¾¹¦b¤À§O³s±µ¨ì¨â¥x¡yÀW¼e¾ã¦X¾¹¡z¤W¡A³z¹L6±øADSL¹ï¥~³s±µ¡I °ò¥»¤W¬O·Qn§Q¥Î²{¦³ªº³]³Æ¥h°µ§ïµ½©Î·sªº½Õ¾ã¡A¥u¬O¤£ª¾¹D¯à¤£¯à°µªº¨ì... ·íµM¡A¤]¥i¥H´£¥X·sªº¬[ºc¡A¦³¨S¦³¤H¥i¥H«ØÄ³n²KÁÊþ¨Ç³]³Æ¡H¥H¹F¨ì³Ì¨ÎªººÞ²z®Ä¯à¡I¤@¤Á°÷¥Î´N¦n...¸g¶O¤è±¡A¥ÑªÙºÊ§e³ø¨ì¾Ç®Õ¥Ó½Ð.... ¦A¦¸·PÁ¦U¦ì¥ý¶iªºÀ°¦£...¤p§Ìµ{«×¹ê¦b¬O¤£¨¬...¤£°÷¸ê®æ¶i±Jºô²Õ...ºF·\ ![]() ¦¹¤å³¹©ó 2004-05-17 03:28 AM ³Q processors4 ½s¿è. |
|
|
|
New Member
¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
|
¦Û¤v¦b±À¤@¤U...
![]() |
|
|
|
Elite Member
![]() ![]() ![]() ![]() ![]() ¥[¤J¤é´Á: May 2002 ±zªº¦í§}: ªO¾ô
¤å³¹: 5,112
|
¤Þ¥Î:
³oÃþªFªF¦bvlab(see http://www.vlab.com.tw/)¥i¯à·|¤ñ¸û¦h¤H¦³¿³½ì,¤£§«¨ì¨ºùØpost¤@¤U§a ![]() .... |
|
|
|