[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[debian-users:25630] Re: routing with Debian



ä½é‡Žï¼ æµœæ¾ã§ã™ã€‚

In <200012031152.UAA05270@xxxxxxxxxxxx>,
  on "Sun, 3 Dec 2000 20:51:48 +0900',
   with "Re: routing with Debian",
 help <help@xxxxxxxxx> ã•ã‚“ wrote:

> ã€ç›®çš„】
>  Firewall を作る(ã§ãã‚Œã°ã‚«ã‚¿ã‚ã«)
> ãƒãƒªã‚·
> ・Intranet ã‹ã‚‰å¤–ã¸ã¯è‡ªç”±ã«å‡ºã‚‰ã‚Œã‚‹
> ・Internet å´ã‹ã‚‰ã¯ Firewall ã‚’å«ã‚ã¦ãã®å…ˆã¸
>  アクセスã§ããªã„よã†ã«ã™ã‚‹ã€‚

Firewall ã«ã¯ã‚¢ã‚¯ã‚»ã‚¹ã§ãã¦ã—ã¾ã†ã€ã¨ã„ã†ã‹ã€ã¾ã£ãŸãアクセス
ã§ããªã„状態ã§ã¯ Firewall ã¨ã—ã¦æ©Ÿèƒ½ã—ãªã„よã†ãªã€‚

> ã€å•é¡Œã€‘
> 下記ãƒãƒƒãƒˆãƒ¯ãƒ¼ã‚¯ã¨è¨­å®šã«ã¦ intranet å´ã‹ã‚‰å¤–ã¸
> routing ã•ã‚Œãªã„。
> ç¾åœ¨ã¯ ping ã«ã¦å®Ÿé¨“。

ping ã®å ´åˆã¯ã‚«ãƒ¼ãƒãƒ«ã®

IP: ICMP masquerading
CONFIG_IP_MASQUERADE_ICMP
  The basic masquerade code described for "IP: masquerading" above
  only handles TCP or UDP packets (and ICMP errors for existing
  connections). This option adds additional support for masquerading
  ICMP packets, such as ping or the probes used by the Windows 95
  tracert program.

  If you want this, say Y. 

ã“ã‚ŒãŒå¿…è¦ã«ãªã‚‹ã¨æ€ã„ã¾ã™ãŒã€å…¥ã£ã¦ã¾ã™ã‹ã­ ?

> â–  sanma ã®è¨­å®š 
> help@sanma:~$ cat /etc/network/interfaces
> # /etc/network/interfaces -- configuration file for ifup(8), ifdown(8)
> 
> # The loopback interface
> iface lo inet loopback
> 
> # The first network card - this entry was created during the Debian installation
> auto eth0
> iface eth0 inet static
>         address 192.168.1.11
>         network 192.168.1.0
>         netmask 255.255.255.0
>         boradcast 192.168.1.255
>         gateway 192.168.1.1
> auto eth1
> iface eth1 inet static
>         address 192.168.20.1
>         network 192.168.20.0
>         netmask 255.255.255.0
>         boradcast 192.168.20.255

ã“ã® /etc/network/interfaces ã« ipchains コマンドを設定ã™ã‚‹è©±ã€
以å‰ã“ã® debian-users ã§ã‚„ã£ã¦ã„ãŸã“ã¨ãŒã‚ã£ãŸã‚ˆã†ãªã€‚

 "ipchains" をキーワードã«ã“ã“一年ãらã„ã§æ¤œç´¢ã‹ã‘ã¦ã¿ã¦ã¯ ?

> â– ã“ã“ã§æ°—ãŒã¤ã„ãŸã“ã¨
> ・ping ã‚’ hotate ã‹ã‚‰æ‰“ã£ã¦ã„ã¾ã™ã€‚
>  デフォルトã®ã¾ã¾ãªã®ã§ç´„ 1 秒㫠1 回ã ã¨æ€ã„ã¾ã™ã€‚
> ・saba ãŠã‚ˆã³ nv1 ã® LED ãŒåŒã˜ã‚¿ã‚¤ãƒŸãƒ³ã‚°ã§ç‚¹æ»…ã—ã¦ã„ã¾ã™ã€‚
>  →hotate ã‹ã‚‰ã® ping ã¯æ¥ã¦ã„る?
>   →何らã‹ã®ç†ç”±ã§è¿”事ãŒè¿”らãªã„?
> ・ã»ã‹ã«ç´„ 1 秒㫠1 回ã®ãƒ‘ケット飛ã°ã—ã‚’ã—ã¦ã„るマシンã¯
>  ã‚ã‚Šã¾ã›ã‚“。
> ・hotate ã‹ã‚‰ã® ping ã‚’æ­¢ã‚る㨠saba ãŠã‚ˆã³ nv1 ã®
>   LED ã®ç‚¹æ»…ã¯ã¨ã¾ã‚Šã¾ã™ã€‚

> 実㯠man interfaces ã—ãŸã®ã§ã™ãŒ
> ãã®æ„味ã™ã‚‹ã¨ã“ã‚ã¨ã„ã†ã‹ç›®çš„ãŒç†è§£ã§ããªãã¦ã€‚
> ãªã‚“ã¨ãªãã“ã“ã® up 㨠down ㌠reboot ã—ãªã„ã§ã‚‚
> IP アドレスを変更ã§ãã‚‹(/etc/init.d/networking restart ãªã©)
> 秘密ãªã®ã‹ãªã¨æ€ã£ãŸã‚Šã€‚

preup, up, down, post-down 㯠ifup ã®å‹•ä½œã«åˆã‚ã›ã¦ä»»æ„ã®ã‚³ãƒžãƒ³ãƒ‰ã‚’
実行ã•ã›ã‚‹ãŸã‚ã®ä»•çµ„ã§ã™ã­ã€‚ipchains ã¨ã‹ã‚’指定ã™ã‚‹ãŸã‚ã«ä½¿ã‚ã‚ŒãŸã‚Š
ã™ã‚‹ã¨æ€ã„ã¾ã™ã€‚

-- 
     # (ã‚ãŸã—ã®ãŠã†ã¡ã¯æµœæ¾å¸‚ã€ã€Œå¤œã®ãŠè“å­ã€ã§æœ‰åã•ã€‚)
    <kgh12351@xxxxxxxxxxx> : Taketoshi Sano (ä½é‡Žã€€æ­¦ä¿Š)