PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï
PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï   µù¥U ±`¨£°ÝÃD ¼Ð°O°Q½×°Ï¬°¤wŪ

¦^¨ì   PCDVD¼Æ¦ì¬ì§Þ°Q½×°Ï > ¨ä¥L¸s²Õ > ºÃÃøÂø¯g°Ï
±b¤á
±K½X
 

¦^À³
 
¥DÃD¤u¨ã
processors4
New Member
 

¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
Unhappy ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe­±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ¨Ó¬Ý¬Ý§a...

®¦...¦b¤U¬O¬Y¤j¾Ç±JªÙ²zªººô¸ôºÞ²z¤p²Õ¦¨­û ¡A¥Ñ©ó³Ìªñ¥þ­±§ï¥ÎDHCP¦Û°Ê¨ú±oIP¤è¦¡¡A¨Ï±oºÞ²z¤W¦³«Ü¤jªº¤£«K ¡A«ç»¡¡H´N¬O§Ú­Ì­n°O¿ý¨º­ÓIP¬O­þ¶¡¹ì«Çªº¨º­Ó¤H¦b¥Î¡A¥H«K¥¼¨Ó§@ºÊ±±»PºÞ¨î¡]¨Ò¦p¥L¤¤¬r©Î¦b·mÀW¼e ¡^¡A¦ý¥Ñ©ó¨Ï¥ÎDHCPªºÃö«Y¡A¨Ï±o¤£¥Î¦b±Jºô²Õµn°O¤]¥i¥H¤Wºô ¡A©Ò¥H·Q­n®Ä³Xseednetªº¤è¦¡¡CSeednetªº§@ªk¬O¡A¦pªG¨Sú¶O¡A©Î¬O±b¸¹¨S¶}³q¡A¤@¶}ÂsÄý¾¹¥u·|³s¤W¤@­Óºô­¶¡Aseednet±MÄݪººô­¶¡A¥Î¨Ó¶}³q»P±b¸¹§@·~¥Îªº.....§Ú­Ì¤]·Q­n°µ¨ì¨º¼Ë¡A¦b¥¼µn°O«e¥u¯à³s¤W§Ú­Ì¬[ªººô¯¸¡AµM«á¦bºô­¶¤Wµn°O«á¡A§Y«K¶}³q¥Lªº±Jºô¡A¦³¨S¦³¤Hª¾¹D«ç»ò¥h°µ¨ì¦p¦¹©O¡H ÁÂÁ¦U¦ìªºÀ°¦£!
     
      
ÂÂ 2004-05-15, 02:18 PM #1
¦^À³®É¤Þ¥Î¦¹¤å³¹
processors4Â÷½u¤¤  
jackal0601
Advance Member
 

¥[¤J¤é´Á: Dec 2002
¤å³¹: 381
ÀW¼eºÞ²z ­t¸ü ¾¹

°µºô¥dMAC³]©w

¨C¥x³]

¨S³]ªº¤£¯à¤W

³o¼ËÀ³¸Ó¥i

¥u¬O«Ü³Â·Ð¤@W¤@
 
ÂÂ 2004-05-15, 02:23 PM #2
¦^À³®É¤Þ¥Î¦¹¤å³¹
jackal0601Â÷½u¤¤  
processors4
New Member
 

¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
¤Þ¥Î:
Originally posted by jackal0601
ÀW¼eºÞ²z ­t¸ü ¾¹

°µºô¥dMAC³]©w

¨C¥x³]

¨S³]ªº¤£¯à¤W

³o¼ËÀ³¸Ó¥i

¥u¬O«Ü³Â·Ð¤@W¤@


±z¦n¡G
§Ú­Ì²{¦b¾Ç®Õ¸Ìªº¤èªk´N¬O³o¼Ë¡A¦ý¥Ñ©ó§Ú­Ì±Jºô²Õªº¤H¤O¤£¨¬¡A©Ò¥H·Q­n´«¤èªk...ÁÂÁ±zªº·N¨£
ÂÂ 2004-05-15, 05:08 PM #3
¦^À³®É¤Þ¥Î¦¹¤å³¹
processors4Â÷½u¤¤  
8:5
Major Member
 

¥[¤J¤é´Á: Dec 2002
±zªº¦í§}: Á¼
¤å³¹: 265
¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe­±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ¨Ó¬Ý¬Ý§a...

¤Þ¥Î:
Originally posted by processors4
®¦...¦b¤U¬O¬Y¤j¾Ç±JªÙ²zªººô¸ôºÞ²z¤p²Õ¦¨­û ¡A¥Ñ©ó³Ìªñ¥þ­±§ï¥ÎDHCP¦Û°Ê¨ú±oIP¤è¦¡¡A¨Ï±oºÞ²z¤W¦³«Ü¤jªº¤£«K ¡A«ç»¡¡H´N¬O§Ú­Ì­n°O¿ý¨º­ÓIP¬O­þ¶¡¹ì«Çªº¨º­Ó¤H¦b¥Î¡A¥H«K¥¼¨Ó§@ºÊ±±»PºÞ¨î¡]¨Ò¦p¥L¤¤¬r©Î¦b·mÀW¼e ¡^¡A¦ý¥Ñ©ó¨Ï¥ÎDHCPªºÃö«Y¡A¨Ï±o¤£¥Î¦b±Jºô²Õµn°O¤]¥i¥H¤Wºô ¡A©Ò¥H·Q­n®Ä³Xseednetªº¤è¦¡¡CSeednetªº§@ªk¬O¡A¦pªG¨Sú¶O¡A©Î¬O±b¸¹¨S¶}³q¡A¤@¶}ÂsÄý¾¹¥u·|³s¤W¤@­Óºô­¶¡Aseednet±MÄݪººô­¶¡A¥Î¨Ó¶}³q»P±b¸¹§@·~¥Îªº.....§Ú­Ì¤]·Q­n°µ¨ì¨º¼Ë¡A¦b¥¼µn°O«e¥u¯à³s¤W§Ú­Ì¬[ªººô¯¸¡AµM«á¦bºô­¶¤Wµn°O«á¡A§Y«K¶}³q¥Lªº±Jºô¡A¦³¨S¦³¤Hª¾¹D«ç»ò¥h°µ¨ì¦p¦¹©O¡H ÁÂÁ¦U¦ìªºÀ°¦£!

­n±j­¢ÂsÄý¥ô¦óºô­¶³£Âà¨ì¯S©wºô­¶, ¦³¨âºØ¤è¦¡:
1. ¥Î policy based routing (PBR):
¦b router ¤W, ¥u©ñ¦æµn¿ý¹Lªº (source) IP addresses.
©|¥¼µn¿ýªº±N (destination) port 80 Âà¨ìµn¿ýªººô¯¸, «D port 80 ªº¤@«ß deny. (domain, bootp, ... °£¥~)
ºô­¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router ±N¥Lªº (source) IP addr. ©ñ¦æ.
(¦]¬°»Ý­n¨Ì¾Ú source IP addr. ¨Ó°µ routing, ©Ò¥H»Ý­n±Ò°Ê PBR)

2. ¥Î DNS ¨Ó±±¨î.
¦b router ¤W, ±N (destination) port 53 Âà¨ì¤@¥x¯S©wªº DNS server.
©|¥¼µn¿ýªº IP addr. ¬d¥ô¦ó domain®É, ³£·|¸Ñ¦¨µn¿ýªººô¯¸ªº IP addr.,
ºô­¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router (¤Î DNS server)±N¥Lªº IP addr. ©ñ¦æ.
(router ¤W¤£»Ý±Ò°Ê PBR, ¥H DNS server ¨Ì¾Ú clientºÝªº¤£¦P¨Ó°µÃþ¦üªº¤u§@....)



¥~­±¦³¤½¥q¦b¼g³oºØ¨t²Î, ¥]§t±z´£¨ìªº«áÄòªº (§Y®É) ºÊ±±ºÞ¨îªº¦Û°Ê¤Æ.

¦pªG¥u¬O­nÅý¨Ï¥ÎªÌ¨C¦¸¤Wºô«e¤@©w­n¥ýµn¿ý.
­Ó¤H´¿¬[¹L linux router/bridge,
¥H iptables + apache + php + radtest(radius client) ¼g¹L...
µ{¦¡ÁÙº¡µuªº...
ÂÂ 2004-05-16, 02:58 AM #4
¦^À³®É¤Þ¥Î¦¹¤å³¹
8:5Â÷½u¤¤  
cmwang
Elite Member
 

¥[¤J¤é´Á: May 2002
±zªº¦í§}: ªO¾ô
¤å³¹: 5,112
¦^ÂÐ: ¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe­±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ¨Ó¬Ý¬Ý�

¤Þ¥Î:
Originally posted by 8:5
­n±j­¢ÂsÄý¥ô¦óºô­¶³£Âà¨ì¯S©wºô­¶, ¦³¨âºØ¤è¦¡:
1. ¥Î policy based routing (PBR):
¦b router ¤W, ¥u©ñ¦æµn¿ý¹Lªº (source) IP addresses.
©|¥¼µn¿ýªº±N (destination) port 80 Âà¨ìµn¿ýªººô¯¸, «D port 80 ªº¤@«ß deny. (domain, bootp, ... °£¥~)
ºô­¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router ±N¥Lªº (source) IP addr. ©ñ¦æ.
(¦]¬°»Ý­n¨Ì¾Ú source IP addr. ¨Ó°µ routing, ©Ò¥H»Ý­n±Ò°Ê PBR)


¤£¹Lrouter¦ü¥G¤£¾A¦X°µ³oÃþ­W¤u(¤@¯ëASIC¥u¯à³B²z³æ¯Âªºpacket forwarding,access list/policy routing±o¥ÑCPU³B²z,¦ý¤@¯ërouterªºCPU³£¤£¬O«Ü°ªÀÉ,¦A¥[¤W­n°ÊºAupdate¨äconfig,«áªG¦p¦ó­n¸Õ¤F¤~ª¾¹D),¦b¾Ç³Nºô¸ôµ¥traffic¤jªººô¸ô¤W®£©È¶]°_¨Ó·|«Ü¦Y¤O....

¤Þ¥Î:

2. ¥Î DNS ¨Ó±±¨î.
¦b router ¤W, ±N (destination) port 53 Âà¨ì¤@¥x¯S©wªº DNS server.
©|¥¼µn¿ýªº IP addr. ¬d¥ô¦ó domain®É, ³£·|¸Ñ¦¨µn¿ýªººô¯¸ªº IP addr.,
ºô­¶µ{¦¡¦b¨Ï¥ÎªÌµn¿ý«á, «h³s¨ì router (¤Î DNS server)±N¥Lªº IP addr. ©ñ¦æ.
(router ¤W¤£»Ý±Ò°Ê PBR, ¥H DNS server ¨Ì¾Ú clientºÝªº¤£¦P¨Ó°µÃþ¦üªº¤u§@....)


À³¸Ó¬O§âunknown clientªºDNS request redirect¨ì¥t¤@³¡¥u´£¨Ñfake answerªºDNS server§Y¥i(¥H¤£Åܰʤ@¯ëDNS serverªº¹ê§@¬°­ì«h,¤£¹Lrouter­n¦p¦ó¤À¿ëunknown client®£©ÈÁÙ¬O±o°Ê¨ìpolicy routing,°ÝÃDÁÙ¬O¸ò«e­±¤@¼Ë)....BTW,¹J¨ìuserª½±µ¥´ip address®£©È´N¯}¥\¤F(default±odrop unknown traffic)...

¤Þ¥Î:

¥~­±¦³¤½¥q¦b¼g³oºØ¨t²Î, ¥]§t±z´£¨ìªº«áÄòªº (§Y®É) ºÊ±±ºÞ¨îªº¦Û°Ê¤Æ.

¦pªG¥u¬O­nÅý¨Ï¥ÎªÌ¨C¦¸¤Wºô«e¤@©w­n¥ýµn¿ý.
­Ó¤H´¿¬[¹L linux router/bridge,
¥H iptables + apache + php + radtest(radius client) ¼g¹L...
µ{¦¡ÁÙº¡µuªº...


§Ì¦bpczone¤]¬O«ØÄ³­ìµo¤åªÌ¸Õ¸Õtransparent mode firewall°t¦XÃþ¦üTPªº¤è¦¡(¹ï¨ä²{¦³ºô¸ô¬[ºcªºimpact³Ì¤p)....BTW,³oÃþ¤è¦¡»¡¬ï¤F¥u¬O¥Hmac address(³»¦h¦A¥[¤Wip address)¨Ó§PÂ_©ñ¦æ»P§_,¦]¬°¥uª¾user¤Wºôªº®ÉÂI,¦Ó¤£ª¾¨ä¦ó®Éoffline¦n§âACCEPT rule®³±¼,¦A¥[¤W¦bLAN¤¤­n°°³yip/mac address¤]¤£¬OÃø¨Æ,¨Ã¤£¬O«Ü¥i¾a,¥t¥~Áö»¡¦bLAN¤W¤]¯à¶]PPPoE,¦ý³o¹ê¦b¤£¬O­Ó¦n¥D·N....
__________________
¤h¤j¤Ò¤§µL®¢,¬O¿×°ê®¢....
ÂÂ 2004-05-16, 10:50 AM #5
¦^À³®É¤Þ¥Î¦¹¤å³¹
cmwang²{¦b¦b½u¤W  
8:5
Major Member
 

¥[¤J¤é´Á: Dec 2002
±zªº¦í§}: Á¼
¤å³¹: 265
¦^ÂÐ: ¦^ÂÐ: ¦^ÂÐ: ¡i¨D§U¡j¦³½Öª¾¹D«ç»ò°µ¨ì¹³seednetªº¡y±b¸¹¥¼¶}³q®Éªº³s½uµe­±¡z¡H¬Ý¤£À´¶Ü....ª½±µªñ�

¤Þ¥Î:
Originally posted by cmwang
¤£¹Lrouter¦ü¥G¤£¾A¦X°µ³oÃþ­W¤u(¤@¯ëASIC¥u¯à³B²z³æ¯Âªºpacket forwarding,access list/policy routing±o¥ÑCPU³B²z,¦ý¤@¯ërouterªºCPU³£¤£¬O«Ü°ªÀÉ,¦A¥[¤W­n°ÊºAupdate¨äconfig,«áªG¦p¦ó­n¸Õ¤F¤~ª¾¹D),¦b¾Ç³Nºô¸ôµ¥traffic¤jªººô¸ô¤W®£©È¶]°_¨Ó·|«Ü¦Y¤O....

¬O«Ü¦Y¤O, ©Ò¥H¤~·|¦³¥Î DNS ¨ÓºÞ¨îªº·Qªk.
¤Þ¥Î:
À³¸Ó¬O§âunknown clientªºDNS request redirect¨ì¥t¤@³¡¥u´£¨Ñfake answerªºDNS server§Y¥i(¥H¤£Åܰʤ@¯ëDNS serverªº¹ê§@¬°­ì«h,¤£¹Lrouter­n¦p¦ó¤À¿ëunknown client®£©ÈÁÙ¬O±o°Ê¨ìpolicy routing,°ÝÃDÁÙ¬O¸ò«e­±¤@¼Ë)....BTW,¹J¨ìuserª½±µ¥´ip address®£©È´N¯}¥\¤F(default±odrop unknown traffic)...

¶â... ²Ó¸`´N¤£±Ô­z¤F, ¤£¹L¬O¥i¥H§Ë¨ì router ¤£»Ý­n±Ò°Ê PBR:
±q DHCP ±o¨ìªº DNS server ¬O¤@¥x¯S©wªº DNS, (¤£¤À¬O§_µn¿ý¹L»P§_)
¨º¥x DNS ·|¨Ì¾Ú client ip addr.¨Ó¨M©w¦æ¬° (¨Ò¦p: ¨Ï¥Î view)
°£¥¦¤§¥~, (dest) port 53 ¤@«ß deny, (Á×§K¨Ï¥ÎªÌ¦Û¤v³]©w¨ä¥Lªº DNS servers)
¨º´N¥i¥HÅý DNS ¨Ó±j¨î¨Ï¥ÎªÌµn¿ý¤F,
¦Ü©ó, ¨Ï¥ÎªÌª½±µ¥´ IP addr... ¯u­nºÞ¨î, ¤]¦³¿ìªkªº...
¤Þ¥Î:
§Ì¦bpczone¤]¬O«ØÄ³­ìµo¤åªÌ¸Õ¸Õtransparent mode firewall°t¦XÃþ¦üTPªº¤è¦¡(¹ï¨ä²{¦³ºô¸ô¬[ºcªºimpact³Ì¤p)....BTW,³oÃþ¤è¦¡»¡¬ï¤F¥u¬O¥Hmac address(³»¦h¦A¥[¤Wip address)¨Ó§PÂ_©ñ¦æ»P§_,¦]¬°¥uª¾user¤Wºôªº®ÉÂI,¦Ó¤£ª¾¨ä¦ó®Éoffline¦n§âACCEPT rule®³±¼,¦A¥[¤W¦bLAN¤¤­n°°³yip/mac address¤]¤£¬OÃø¨Æ,¨Ã¤£¬O«Ü¥i¾a,¥t¥~Áö»¡¦bLAN¤W¤]¯à¶]PPPoE,¦ý³o¹ê¦b¤£¬O­Ó¦n¥D·N....

°£¤FÅý¨Ï¥ÎªÌ¦Û¤vÂI logout ¥~, ¤]¥i¥H³]©w idle timeout,
¦pªG¬O bridge mode, ¥Î forwarding table ¨M©w¬O§_ idle ¹L¤[ (brctl showmacs)
¦pªG¬O router mode, ¥Î arp table ¨Ó¨M©w¬O§_ idle ¹L¤[ (arp -a)
°²³y ip/mac addr. ªº°ÝÃD, ı±o¥i¥H©¿²¤...
(·Q±q linux bridge/router ¨Ó³]©wÀ³¸Ó¬OµL¸Ñ, »Ý­n­ì¥»ªº L2 switches ªº¤ä´©)

¦³¤@¨Ç²Ó¸`­nª`·N, ¤£¹L´N¤£¦A°Q½×¤F...


¨S¦³¥´ºâ½Ð¥~­±ªº¤½¥q¼gªº¸Ü,
¨Ï¥Î linux bridge, ¥H iptables ¨Ó³]©wÀ³¸Ó¬O¤ñ¸û¥i¦æªº¤èªk....
¦]¬°¥u¥Î¨ì¤@¥x¾÷¾¹, ¤ñ¸û³æ¯Â. ¦Ó¥B¦]¬°¬O bridge mode, ¦³°ÝÃD´N©Þ±¼©Î bypass
¤£¹L, ¦pªG traffic ¤Ó¤jªº¸Ü, ®Ä¯à¥i¯à·|¤£¯à±µ¨ü...
ÂÂ 2004-05-16, 06:03 PM #6
¦^À³®É¤Þ¥Î¦¹¤å³¹
8:5Â÷½u¤¤  
processors4
New Member
 

¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
®¦...ÁÂÁ¤j®aªº¦^ÂÐ...´£¨Ñ¤F¬Û·í¦hªº¤èªk...
¤£¹L...§Ú¦ü¥G§Ñ¤F»¡¤@¥ó«Ü­«­nªº¨Æ±¡...
§Ú§Ñ¤F»¡¤@¤U§Ú­Ì²{¦³ªº³]³Æ...¨þ¨þ¡ã

§Ú­Ìªº±Jºô¬[ºc¬O³o¼Ëªº...
­º¥ý¡A¬O¥Ñ¦U¹ì«Çªººô¸ôRJ-45±µ¤Õ³s½u¨ì¦U¼Ó¼hªºswitch HUB¡AµM«á¦A¥Ñ¦USwitch HUB³s±µ¨ì¦U°Ï°ìªº¡yÀW¼eºÞ²z¾¹¡z(ÀW¼eºÞ²z¾¹ªº¸Ô²Ó¸ê®Æ) ¤W¡AµM«á¦UÀW¼eºÞ²z¾¹¦b¤À§O³s±µ¨ì¨â¥x¡yÀW¼e¾ã¦X¾¹¡z¤W¡A³z¹L6±øADSL¹ï¥~³s±µ¡I

°ò¥»¤W¬O·Q­n§Q¥Î²{¦³ªº³]³Æ¥h°µ§ïµ½©Î·sªº½Õ¾ã¡A¥u¬O¤£ª¾¹D¯à¤£¯à°µªº¨ì...

·íµM¡A¤]¥i¥H´£¥X·sªº¬[ºc¡A¦³¨S¦³¤H¥i¥H«ØÄ³­n²KÁÊ­þ¨Ç³]³Æ¡H¥H¹F¨ì³Ì¨ÎªººÞ²z®Ä¯à¡I¤@¤Á°÷¥Î´N¦n...¸g¶O¤è­±¡A¥ÑªÙºÊ§e³ø¨ì¾Ç®Õ¥Ó½Ð....

¦A¦¸·PÁ¦U¦ì¥ý¶iªºÀ°¦£...¤p§Ìµ{«×¹ê¦b¬O¤£¨¬...¤£°÷¸ê®æ¶i±Jºô²Õ...ºF·\

¦¹¤å³¹©ó 2004-05-17 03:28 AM ³Q processors4 ½s¿è.
ÂÂ 2004-05-17, 03:17 AM #7
¦^À³®É¤Þ¥Î¦¹¤å³¹
processors4Â÷½u¤¤  
processors4
New Member
 

¥[¤J¤é´Á: Apr 2004
¤å³¹: 6
¦Û¤v¦b±À¤@¤U...
ÂÂ 2004-05-17, 04:45 PM #8
¦^À³®É¤Þ¥Î¦¹¤å³¹
processors4Â÷½u¤¤  
cmwang
Elite Member
 

¥[¤J¤é´Á: May 2002
±zªº¦í§}: ªO¾ô
¤å³¹: 5,112
¤Þ¥Î:
Originally posted by processors4
¦Û¤v¦b±À¤@¤U...


³oÃþªFªF¦bvlab(see http://www.vlab.com.tw/)¥i¯à·|¤ñ¸û¦h¤H¦³¿³½ì,¤£§«¨ì¨ºùØpost¤@¤U§a....
ÂÂ 2004-05-17, 05:08 PM #9
¦^À³®É¤Þ¥Î¦¹¤å³¹
cmwang²{¦b¦b½u¤W  


¦^À³


POPIN
¥DÃD¤u¨ã

µoªí¤å³¹³W«h
±z¤£¥i¥Hµo°_·s¥DÃD
±z¤£¥i¥H¦^À³¥DÃD
±z¤£¥i¥H¤W¶Çªþ¥[ÀÉ®×
±z¤£¥i¥H½s¿è±zªº¤å³¹

vB ¥N½X¥´¶}
[IMG]¥N½X¥´¶}
HTML¥N½XÃö³¬



©Ò¦³ªº®É¶¡§¡¬°GMT +8¡C ²{¦bªº®É¶¡¬O06:51 PM.


vBulletin Version 3.0.1
powered_by_vbulletin 2026¡C