Korea FreeBSD Users Group News, Internal, Projects, Home
Software, Support, Documentation

[tip] freebsd¿¡¼­ ¼Ò¸®¹Ù´Ù »ç¿ëÇϱâ



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

[ÀÌÀü ±Û] [´ÙÀ½ ±Û] [ÀÌÀü ´ñ±Û] [´ÙÀ½ ´ñ±Û]


¾È³çÇϼ¼¿ä. 

ÃÖ±Ù¿¡ KLTP¿¡ "masq·Î ¿¬°áµÈ À©µµ¿ì¿¡¼­ ¼Ò¸® ¹Ù´Ù »ç¿ëÇϱâ!!"¶õ ±ÛÀÌ
¿Ã¶ó¿Ô±â¿¡ °°Àº ¿ø¸®·Î ipfw+natd ³»ºÎ¿¡ ÀÖ´Â À©µµ¿ì¿¡¼­µµ ¼Ò¸® ¹Ù´Ù¸¦
»ç¿ëÇÒ ¼ö ÀÖÀ»°Å¶ó »ý°¢ÇÏ°í ½ÃµµÇØ º¸´Ï ÀߵǴõ±º¿ä.

1. ¼Ò¸® ¹Ù´ÙÀÇ ¼³Á¤

Options¿¡ º¸¸é °³ÀÎ ¼­¹ö¿¡ [»ç¿ëÇÒ Æ÷Æ®]¶õÀÌ ÀÖ½À´Ï´Ù. ¿©±â¼­ ·£´ý Æ÷Æ®
±â´ÉÀ» ²ô°í 9049-9052(*ȤÀº ¾î´À ƯÁ¤ Æ÷Æ®µµ °ü°è ¾øÀ½)À» ¼±ÅÃÇÕ´Ï´Ù.
±×¸®°í ±âŸÀÇ [¿Â¶óÀÎ »óÅ ÀÚµ¿ °¨Áö] ±â´ÉÀ» ²¨ÁÝ´Ï´Ù. ÀÌ°É Äѵθé 
natd µÞ´Ü¿¡ ÀÖ´Ù´Â °É °¨ÁöÇÏ´ÂÁö ¸ô¶óµµ [ã¾ÆÁà] ¹öưÀ» »ç¿ëÇÒ ¼ö 
¾ø´õ±º¿ä.

2. natdÀÇ ¼³Á¤

¿©±â¼­´Â ÀÌ¹Ì ipfw+natd¸¦ ÀÌ¿ëÇØ FreeBSD¸¦ À©µµ¿ì¿Í ÇÔ²² »ç¿ëÇϰí ÀÖ´Ù°í
°¡Á¤ÇϰڽÀ´Ï´Ù. 

ps aux | grep natd ÇϽøé ÇöÀç natd°¡ µ¹¾Æ°¡°í ÀÖÀ» °ÍÀÔ´Ï´Ù.

/etc/natd.conf ¶ó´Â ÆÄÀÏÀ» ¸¸µé°í ´ÙÀ½°ú °°Àº ³»¿ëÀÌ µé¾î°©´Ï´Ù.

--- cut here ---

n ep0
redirect_port udp 192.168.1.2:9049-9052 9049-9052

--- cut here ---

n ¿É¼ÇÀº »ç¿ëÇÒ device¸¦ Á¤ÇØÁÖ´Â °ÍÀ̹ǷΠ°¢ÀÚ ÀÚ±â nic Ä«µå¸¦ Àû¾î
ÁÝ´Ï´Ù. (¿ÜºÎ¿¡ ¹°¸° device Ä«µåÀÓ)

±×¸®°í udp 9049-9052¸¦ 192.168.1.2·Î forwarding ÇØÁشٴ ¶æÀÔ´Ï´Ù.
¿©±â¼­ ¸ÅĪµÇ´Â port´Â °°Àº port ¹øÈ£·Î forwarding ÇϹǷΠÀ§¿Í °°ÀÌ
192.168.1.2:9049-9052 9049-9052°¡ µË´Ï´Ù. ¹°·Ð 192.168.1.2´Â ¼Ò¸®
¹Ù´Ù¸¦ »ç¿ëÇÒ ³»ºÎ È£½ºÆ®ÀÔ´Ï´Ù.

¼³Á¤ÀÌ ³¡³µÀ¸¸é ÇöÀç natd prcoess¸¦ ã¾Æ³»¼­ kill·Î Á×ÀÌ°í ´Ù½Ã natd
¸¦ ¶Ù¿ó´Ï´Ù.

/sbin/natd -f /etc/natd.conf

-f ¿É¼ÇÀº ¼³Á¤ ÆÄÀÏÀ» ÁöÁ¤ÇØ ÁÙ ¶§ »ç¿ëµË´Ï´Ù.

²Ç¼öÀ̱ä ÇÏÁö¸¸ ¼Ò¸®¹Ù´Ù¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸´Ï ÁÁ³×¿ä. ÆÁÀÌ µµ¿òµÇ¼Ì±æ
¹Ù¶ø´Ï´Ù.


-- 
Kwangyul Seo <skyul@plus.or.kr>
My GnuPG key is available at my homepage.
Visit My Homepage, Security 101 at http://skyul.plus.or.kr

Attachment: pgp00019.pgp
Description: PGP signature


[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

Copyright © 1998-2005 Korea FreeBSD Users Group.
All rights reserved. webmaster at kr.FreeBSD.org
$Date: 2002/03/26 13:30:30 $
Powered by FreeBSD