|
News,
Internal,
Projects,
Home Software, Support, Documentation |
¾È³çÇϼ¼¿ä. ÃÖ±Ù¿¡ KLTP¿¡ "masq·Î ¿¬°áµÈ À©µµ¿ì¿¡¼ ¼Ò¸® ¹Ù´Ù »ç¿ëÇϱâ!!"¶õ ±ÛÀÌ ¿Ã¶ó¿Ô±â¿¡ °°Àº ¿ø¸®·Î ipfw+natd ³»ºÎ¿¡ ÀÖ´Â À©µµ¿ì¿¡¼µµ ¼Ò¸® ¹Ù´Ù¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ»°Å¶ó »ý°¢ÇÏ°í ½ÃµµÇØ º¸´Ï ÀߵǴõ±º¿ä. 1. ¼Ò¸® ¹Ù´ÙÀÇ ¼³Á¤ Options¿¡ º¸¸é °³ÀÎ ¼¹ö¿¡ [»ç¿ëÇÒ Æ÷Æ®]¶õÀÌ ÀÖ½À´Ï´Ù. ¿©±â¼ ·£´ý Æ÷Æ® ±â´ÉÀ» ²ô°í 9049-9052(*ȤÀº ¾î´À ƯÁ¤ Æ÷Æ®µµ °ü°è ¾øÀ½)À» ¼±ÅÃÇÕ´Ï´Ù. ±×¸®°í ±âŸÀÇ [¿Â¶óÀÎ »óÅ ÀÚµ¿ °¨Áö] ±â´ÉÀ» ²¨ÁÝ´Ï´Ù. ÀÌ°É Äѵθé natd µÞ´Ü¿¡ ÀÖ´Ù´Â °É °¨ÁöÇÏ´ÂÁö ¸ô¶óµµ [ã¾ÆÁà] ¹öưÀ» »ç¿ëÇÒ ¼ö ¾ø´õ±º¿ä. 2. natdÀÇ ¼³Á¤ ¿©±â¼´Â ÀÌ¹Ì ipfw+natd¸¦ ÀÌ¿ëÇØ FreeBSD¸¦ À©µµ¿ì¿Í ÇÔ²² »ç¿ëÇϰí ÀÖ´Ù°í °¡Á¤ÇϰڽÀ´Ï´Ù. ps aux | grep natd ÇϽøé ÇöÀç natd°¡ µ¹¾Æ°¡°í ÀÖÀ» °ÍÀÔ´Ï´Ù. /etc/natd.conf ¶ó´Â ÆÄÀÏÀ» ¸¸µé°í ´ÙÀ½°ú °°Àº ³»¿ëÀÌ µé¾î°©´Ï´Ù. --- cut here --- n ep0 redirect_port udp 192.168.1.2:9049-9052 9049-9052 --- cut here --- n ¿É¼ÇÀº »ç¿ëÇÒ device¸¦ Á¤ÇØÁÖ´Â °ÍÀ̹ǷΠ°¢ÀÚ ÀÚ±â nic Ä«µå¸¦ Àû¾î ÁÝ´Ï´Ù. (¿ÜºÎ¿¡ ¹°¸° device Ä«µåÀÓ) ±×¸®°í udp 9049-9052¸¦ 192.168.1.2·Î forwarding ÇØÁشٴ ¶æÀÔ´Ï´Ù. ¿©±â¼ ¸ÅĪµÇ´Â port´Â °°Àº port ¹øÈ£·Î forwarding ÇϹǷΠÀ§¿Í °°ÀÌ 192.168.1.2:9049-9052 9049-9052°¡ µË´Ï´Ù. ¹°·Ð 192.168.1.2´Â ¼Ò¸® ¹Ù´Ù¸¦ »ç¿ëÇÒ ³»ºÎ È£½ºÆ®ÀÔ´Ï´Ù. ¼³Á¤ÀÌ ³¡³µÀ¸¸é ÇöÀç natd prcoess¸¦ ã¾Æ³»¼ kill·Î Á×ÀÌ°í ´Ù½Ã natd ¸¦ ¶Ù¿ó´Ï´Ù. /sbin/natd -f /etc/natd.conf -f ¿É¼ÇÀº ¼³Á¤ ÆÄÀÏÀ» ÁöÁ¤ÇØ ÁÙ ¶§ »ç¿ëµË´Ï´Ù. ²Ç¼öÀ̱ä ÇÏÁö¸¸ ¼Ò¸®¹Ù´Ù¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸´Ï ÁÁ³×¿ä. ÆÁÀÌ µµ¿òµÇ¼Ì±æ ¹Ù¶ø´Ï´Ù. -- Kwangyul Seo <skyul@plus.or.kr> My GnuPG key is available at my homepage. Visit My Homepage, Security 101 at http://skyul.plus.or.kr
Attachment:
pgp00019.pgp
Description: PGP signature
|
Copyright © 1998-2005 Korea FreeBSD Users Group. All rights reserved. webmaster at kr.FreeBSD.org $Date: 2002/03/26 13:30:30 $ |
|