² Firewall []
wA@As峹аѦB
̪sG2003/08/25
@
bͧF򥻪w[Aoӳ`DnNnwyzӶi椶ФFIثeDnOH Linux Kernel 2.4 iptables DA iptables iHϥΫOӤUFA]iHzLsg shell script ӶiOXCHߺDϥ scripts Ӷi iptables WOIF iptables ~AƹWA²檺٦ TCP Wrappers oӪNALhDnOwYǪAȨӶi޲zoIeDnNObгoӭnnFI
@
G
@@Gݭn
@@G𪺥DnO
@@G𪺤@uGuPקޥ
@@G𪺨ϥέ
Linux ʥ]LoG
@@GLinux ֤ߪP
@@Giptables Pʥ]iJy{
@@Giptables ykG MWh, wqF, W[PJWh, P^_Wh
@²檺]wG
@@GڪWh
@@GWh]w
TCP WrappersG
@@GO TCP Wrappers PL׾
@@GTCP Wrapperes Wh
LG
iGݦA[]
I^U
ѦҸ
ҫm

G
Linux ʥ]Lo
@²檺]wG
TCP_WrappersG
LաG
Moˤ@ӴNyLظmnFzFIOֳD쩳o˪ĪGpHҥHAzݭnOhɶӶiթOIժBJiHOG
  1. ѥDV~DʳsuլݬݡF
  2. AѨp줺 PC V~DʳsuլݬݡF
  3. ̫A Internet WDADʳsuz Linux DլݬݡF
@B@B@UӡAݬݰDXb̡AMhhhiB}II򥻤WAWثeܦhƥiHѱzѦҤFIo@g]wgO²Aj٦bжqӤwIƱjaUIڦbѦҸƷCXXӦΪAƱjaůunhhhݬݡI|ܦUI

iGݦA[]
ڭ̨ӦҼ{@Ӥ쪺DANOpPϥ|pAƹWADO[]bݪIbo˪pUAڭ̭nNӦ Internet ʥ]Ag firewall ໼ݪDWOHIڭ̥iHѦҤ@Uʥ]y{ApPWϤEA]Ӧ Internet ʥ]nᵹݪDAҥHbyѤeNݭn]wnഫzAFI]b nat table PREROUTING WӶiҿתy Destination NAT, DNAT zʧ@~աIzݭnb iptables WAb nat table WsW@Wh~IykpUG
@
iptables LѼƻG
@
-j <ʧ@>GF` ACCEPT P DROP ~A٦ǰʧ@H
@DNAT --to IP[:port]
@@@`ΦbݪDʥ]໼WI
@
dҡGNӦ Internet port 80 suʥ]໼ 192.168.10.10 oӥDW
[root@test root]# iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 80 \
> -j DNAT --to 192.168.10.10:80
@
WdҬO²檺@ӨҤlAb²ҤUOiH\zi WWW Ϊ̬O Mail AȪILApGΦb FTP WiNܳ·ФF] FTP FW 21 oөROqDf~A٦ƶǰeDʩʻPQʩʡI]wWܬOxZ㦳쪺ܡAiHѦҩUCXX iptables Io̤AFI

I^UG
ѦҸ
ҫmG
2002/08/20GĤ@I
2003/08/25Gs]peAg@ǫOСAPe@gy{Ѻwz@II