[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[debian-users:31996] Re: [Q] Which PPP file do I describe IP Masquerade setting?



水原@サンパウロã§ã™ã€‚
# ã‚ã¨æ•°æ—¥ã§å¸°å›½ã§ãる予定…。

At Fri, 8 Mar 2002 10:04:53 +0900,
ã‹ã‚ˆã“ wrote:
> è¡Œã„ãŸã„ã®ã¯ã€
> (1) PPP 接続後ã«ã€ppp0 をデフォルトゲートウェイã¨ã—ã€iptables ã«ã‚ˆã‚‹ppp0 ã«å¯¾
>  ã™ã‚‹ãƒžã‚¹ã‚«ãƒ¬ãƒ¼ãƒ‰è¨­å®šã‚’è¡Œã„ãŸã„。
> (2) PPP 切断後ã«ã€ppp 接続å‰ã®çŠ¶æ…‹ã«ãƒ«ãƒ¼ãƒ†ã‚£ãƒ³ã‚°ã¨ãƒžã‚¹ã‚«ãƒ¬ãƒ¼ãƒ‰ã®è¨­å®šã‚’戻ã—ãŸã„
> ã¨ã„ã†ï¼’点ã§ã™ã€‚
> 
> ã¡ãªã¿ã«ã€ç¾åœ¨ã® CATV-Modem (eth0 ) ã«å¯¾ã™ã‚‹iptables ã®è¨­å®šã¯ã€potato ã®è¨­å®šã
> ã®ã¾ã¾ã«ã€/etc/network/interfaces ã«pre-up, post-down ã§è¨˜è¿°ã—ã¦ã„ã¾ã™ã€‚
> # woody çš„ã«ã¯åˆ¥ã®å ´æ‰€ã«è¨˜è¿°ã™ã‚‹ã‚ˆã†ãªæ°—ãŒã—ã¦ã—ょã†ãŒãªã„ã®ã§ã™ãŒã€
> # 今ã®ã¨ã“ã‚手ã¤ã‹ãšã§ã™ã€‚
> 
> FAQ ã‹ã¨ã¯æ€ã†ã®ã§ã™ãŒã€/usr/share/doc/ppp/SETUP.gz ã‚„ã€åŒãƒ‡ã‚£ãƒ¬ã‚¯ãƒˆãƒªã®
> FAQ.gzを見ã¦ã‚‚よã分ã‹ã‚‰ãªã‹ã£ãŸã®ã§ã™ã€‚

ç§ã¯ã„ã¾ã ã« potato 環境ãªã®ã§å¤–ã—ã¦ã„ã‚‹ã‹ã‚‚知れã¾ã›ã‚“。
/etc/ppp/ip-up (シェルスクリプトã§ã™) を見るã¨ã€PPP コãƒã‚¯ã‚·ãƒ§ãƒ³ç¢ºç«‹ã®
éš›ã«ã“ã®ã‚¹ã‚¯ãƒªãƒ—トãŒå‘¼ã°ã‚Œã€ãã®ä¸­ã§ run-parts /etc/ppp/ip-up.d ãŒå®Ÿè¡Œ
ã•ã‚Œã‚‹ã“ã¨ãŒåˆ†ã‹ã‚Šã¾ã™ã€‚run-parts ã¯ã€ãã®ãƒ‡ã‚£ãƒ¬ã‚¯ãƒˆãƒªã®ä¸­ã«ã‚るスクリ
プトやプログラムを実行ã—ã¦ãれるコマンドã§ã™ã‹ã‚‰ã€ã“ã®ãƒ‡ã‚£ãƒ¬ã‚¯ãƒˆãƒªã«
PPP コãƒã‚¯ã‚·ãƒ§ãƒ³ç¢ºç«‹æ™‚ã«å®Ÿè¡Œã—ãŸã„スクリプトを書ã„ã¦ãŠã‘ã°è‰¯ã„ã‚ã‘ã§ã™ã€‚
ã¡ãªã¿ã«ãƒžãƒ‹ãƒ¥ã‚¢ãƒ«ã‚’読むã¨åˆ†ã‹ã‚Šã¾ã™ãŒã€å®Ÿè¡Œã•ã‚Œã‚‹ãƒ•ã‚¡ã‚¤ãƒ«åã¯è‹±æ•°å­—ã¨
ãƒã‚¤ãƒ•ãƒ³ãŠã‚ˆã³ã‚¢ãƒ³ãƒ€ãƒ¼ã‚¹ã‚³ã‚¢ã®ã¿ã‹ã‚‰ãªã£ã¦ã„ãªãã¦ã¯ãªã‚‰ãš (ã¤ã¾ã‚Šæ‹¡å¼µ
å­ãªã©ãŒã¤ã„ã¦ã„ã¦ã¯ã„ã‘ãªã„)ã€ã‚·ã‚§ãƒ«ã‚’自動的ã«å‘¼ã³å‡ºã—ã¦ãã‚Œãªã„ã®ã§ã€
最åˆã®è¡Œã«æ˜Žç¤ºçš„ã« #!/bin/sh ã¨ã‹æ›¸ã„ã¦ãŠãå¿…è¦ãŒã‚ã‚Šã¾ã™ (ç§ã¯æœ€åˆã€
ã“ã‚Œã§ã¯ã¾ã‚Šã¾ã—ãŸ)。

åŒæ§˜ã« /etc/ppp/ip-down.d ã«ã‚³ãƒžãƒ³ãƒ‰ã‚’書ã„ã¦ãŠã‘ã°ã€PPP コãƒã‚¯ã‚·ãƒ§ãƒ³åˆ‡
断時ã«å®Ÿè¡Œã—ã¦ãã‚Œã¾ã™ã€‚

ã‚㨠/etc/ppp/peers/provider ã«ã§ã‚‚ defaultroute ã¨æ›¸ã„ã¦ãŠã‘ã°ã€ãƒ‡ãƒ•ã‚©
ルトルートã®ä»˜ã‘外ã—㯠pppd ãŒã‚„ã£ã¦ãれるã¯ãšã§ã™ã€‚

ã¡ãªã¿ã«ç§ã¯ä»¥ä¸‹ã®ã‚ˆã†ãªãƒ•ã‚¡ã‚¤ãƒ«ã‚’ç½®ã„ã¦ã„ã¾ã™ã€‚良ã‘ã‚Œã°å‚考ã«ã—ã¦ãã 
ã•ã„。192.168.1.0/24 ãŒãƒ­ãƒ¼ã‚«ãƒ«ãƒ—ライベートアドレスã§ã™ã€‚

# ã¨ã“ã‚ã§ä¾¿ä¹—質å•ã§ã™ãŒã€ipchains -L -M ã¨åŒã˜ã“㨠(マスカレードã•ã‚Œ
# ã¦ã„るコãƒã‚¯ã‚·ãƒ§ãƒ³ã®ä¸€è¦§è¡¨ç¤º) 㯠iptables ã§ã¯ã§ããªã„ã®ã§ã—ょã†ã‹ï¼Ÿ

::::::::::::::
/etc/ppp/ip-up.d/iptables
::::::::::::::
#!/bin/sh

iptables -N ident-from-ppp
iptables -A ident-from-ppp -j LOG --log-prefix "IDENT from $PPP_IFACE: "
iptables -A ident-from-ppp -p tcp -j REJECT --reject-with tcp-reset

iptables -N imap-from-ppp
iptables -A imap-from-ppp -j LOG --log-prefix "IMAP from $PPP_IFACE: "
iptables -A imap-from-ppp -j ACCEPT

iptables -N ssh-from-ppp
iptables -A ssh-from-ppp -j LOG --log-prefix "SSH from $PPP_IFACE: "
iptables -A ssh-from-ppp -j ACCEPT

iptables -N uucp-from-ppp
iptables -A uucp-from-ppp -j LOG --log-prefix "UUCP from $PPP_IFACE: "
iptables -A uucp-from-ppp -s uucp.somewhere.net -j ACCEPT

iptables -N ppp-in

iptables -A ppp-in -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A ppp-in -m state --state NEW -p tcp --dport auth -j ident-from-ppp
iptables -A ppp-in -m state --state NEW -p tcp --dport imap2 -j imap-from-ppp
iptables -A ppp-in -m state --state NEW -p tcp --dport ssh -j ssh-from-ppp
iptables -A ppp-in -m state --state NEW -p tcp --dport uucp -j uucp-from-ppp
iptables -A ppp-in -j LOG --log-prefix "Bad packet from $PPP_IFACE: "
iptables -A ppp-in -j DROP

iptables -I INPUT -i $PPP_IFACE -j ppp-in
iptables -I FORWARD -i $PPP_IFACE -j ppp-in

iptables -t nat -N ppp-masq
iptables -t nat -A ppp-masq -j LOG --log-prefix "MASQUERADE to $PPP_IFACE: "
iptables -t nat -A ppp-masq -j MASQUERADE

iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -o $PPP_IFACE -j ppp-masq
::::::::::::::
/etc/ppp/ip-up.d/notify
::::::::::::::
#!/bin/sh

email=admin@xxxxxxxxxxxxx

sendmail $email <<EOF
To: $email
Subject: PPP connection re-established

The new IP address is $PPP_LOCAL
EOF
::::::::::::::
/etc/ppp/ip-down.d/iptables
::::::::::::::
#!/bin/sh

iptables -t nat -D POSTROUTING -o $PPP_IFACE -j ppp-masq

iptables -t nat -F ppp-masq
iptables -t nat -X ppp-masq

iptables -D INPUT -i $PPP_IFACE -j ppp-in
iptables -D FORWARD -i $PPP_IFACE -j ppp-in

iptables -F ppp-in
iptables -X ppp-in

iptables -F ident-from-ppp
iptables -X ident-from-ppp

iptables -F imap-from-ppp
iptables -X imap-from-ppp

iptables -F ssh-from-ppp
iptables -X ssh-from-ppp

iptables -F uucp-from-ppp
iptables -X uucp-from-ppp
-- 
水原 <mizuhara@xxxxxxx>