DHCP +NAT+Transparent PROXY¬[³] ·ç¤uºôºÞªL·çÂ×89.10.21
PS.¥H¤U5ºØ²Õ¦X°£CASE 3,4¨âªÌ¤G¾Ü¤@¤£n«ÂÐ¥~,¨ä¥L¦UºØ¥\¯à¥i¨Ì»Ý¨D¿W¥ß©Î¤¬¬Ûµ²¦X·f°t¨Ï¥Î
- CASE1:¥u³]NAT:
¯SÂI:³]©w²³æ,¤£¹L¹q¸£±Ð«Ç¤º¦U¾Ç¥ÍPC»ÝÓ§O«ü©wµêÀÀip,dns,gate...,¤ñ¸û³Â·Ð
- CASE2:³]DHCP+NAT:(«ØÄ³¨Ï¥Î)
¯SÂI:µ²¦Xdhcp,¦U¾Ç¥ÍPC¤£¥Î³]©w¥iª½±µ°ÊºA¨ú±oµêÀÀip,dns...
- CASE3:³]DHCP+NAT+ redirect proxy:
¯SÂI:©ónat¾÷¾¹¤W¦A¬[proxy servcer ¨Ãµ²¦Xredirect(¾É¦V)ªº¥\¯à,¥i±j¨î¾Ç¥Íªºrequest ¦Û°Êredirect¦Üproxy server ,¥Ñproxy server¦V¤W¼h§ì¸ê®Æ,´«¨¥¤§¤]´N¬O·íNAT¥D¾÷¤W¦¬¨ìport80ªº request®É,·| redirect ¦Üport 3128,¦p¦¹¥i¬Ù¥h¦UpcªºÂsÄý¾¹n³]proxyªº³Â·Ð,¤£¹L©Mcase2¤ñ¸û,¦¹ªk¥D¾÷°t³Æn¸û¨Î§_«h¤U¸üºô¶ªº³t«×¤Ï¦Ó·|¤ñ¸ûºC
- CASE4:³]DHCP+NAT+ dedicate proxy
¯SÂI:¦P¤W,®t§O¦b©ó¾Ç®Õ¤º°²³]¤w¦³¨ä¥Lproxy server(¦p210.59.2.3),«h©ónat ¾÷¾¹¤W¤£¥Î¦A¬[proxy server,¥iª½±µ±N¾Ç¥Íªºrequest ª½±µredirect(¾É¦V)¦Ü¾Ç®Õªºproxy server,¦A¥Ñ¾Ç®Õproxy server¦V¤W¼h§ì¸ê®Æ,¤£¹L³oºØ¤èªk§ì¨ìªººô¶·|©Ç©Çªº,¦³¨Ç¹Ï¤ù·|¿ù»~,«ö«·s¾ã²z,¨C¦¸¿ù»~ªº³¡¤À³£¤£¤@¼Ë,¦h«ö´X¦¸¤~·|¥¿½T,¤£ª¾¦ó¬G
- CASE5:³]DHCP+NAT+NAT Router¤ºªº¹ï¥~ªA°È¦øªA¾¹
¯SÂI:°£case2ªº¥\¯à¥~,¥t°²³]¹q¸£±Ð«Ç¤º¾Ç¥Ípc¨Ï¥ÎµêÀÀip,¥i¬O¨ä¤¤¦³¤@³¡¹q¸£(192.168.1.2)n´£¨ÑwwwªºªA°È(¦p¹Ï®ÑÀ]¬d¸ß¨t²Î),¨Ñ¥~¬É¬d¸ß,«h¥i§Q¥Î³oÓ¤èªk,¦¹ªkÃþ¦ücase4 redirect proxyªº³]©w,©Ò¥H·í§Ṵ́õ¦æ http://210.59.2.161®É,nat¥D¾÷·|¦Û°Ê±Nrequest REDIRECT¦Ü192.169.1.2³o³¡¥D¾÷
- ¥D¾÷:PIII-500
- HD:4.3G SCSI (¤£¥Î«Ü¤j)
- MEM:256M(·U¤j·U¦n)
- §@·~¨t²Î:REDHAT 6.0 ©Î 6.1
- VGA¥d: sis6326 AGP
- ºô¸ô¥d:D-LINK DFE530TX Rev-A ¨â¤ù (Bª© RH6.1·|§ì¤£¨ì)
- hostname: lib-gate.jfvs.tpc.edu.tw
- dns: 210.59.2.1
- defaulut route:210.59.2.254
- ¤¶±1(eth0) : ip 210.59.1.161 (¦Xªk ip)
netmask:255.255.255.0
- ¤¶±2(eth1): ip 192.168.1.254 (µêÀÀ ip)
netmask:255.255.255.0t
- ¦w¸Ëwebmin0.80
- ¦w¸Ëdhcp-2.0b1p16-2.i386.rpm(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)
rpm -Uvh /mnt/cdrom/Redhat/RPMS/dhcp*
- ©ówebmin0.80¤¤¶i¤Jdhcp¿ï¶µ
- ¼W¥[¨âÓ¤lºô¸ô(210.59.2.0)¤Î(192.168.1.0)
- ÂI¿ï192.168.1.0ºô¸ô¨Ã³]©w¤U¦C¼Æ¾Ú
- ºô¸ô¦ì§}:192.168.1.0
- IP¦ì§}½d³ò:192.168.1.2~192.168.1.253
- ¤lºô¾B¸n:255.255.255.0
- Àx¦s,¦AÂI¿ï ½s¿è«È¤áºÝ¿ï¶µ ¨Ã³]©w¤U¦C¼Æ¾Ú
- dns¦øªA¾¹:½Ð³]¥»®Õdns server¦p210.59.2.1
- ¹w³]¸ô¥Ñ¾¹:½Ð³]¤¶±2 ¤§ip ¦p192.168.1.254
- Àx¦s
- Y¦Xªkipºô°ì¤º¤w¦³¨ä¥Ldhcp ¦øªA¾¹,«h210.59.2.0ºô¸ô¤¤ùرªº¿ï¶µ¥i¥H¤£¥Î³]
- ±Ò°Êdhcp
- Àˬd clientºÝ¬O§_¦Û°Ê¨ú±oip,(¥i°õ¦æwinipcfgÀˬd)Y¦³«hªí¥Ü¦¨¥\
1.×§ï /etc/sysconfig/network
±N forward_ipv4 ³]¬° yes ,¨Ã«·s¶}¾÷
2.¦w¸Ë ipchain(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)
#rpm -Uvh /mnt/cdrom/Redhat/RPMS/ipchain*
3.°õ¦æ
#ipchains -A forward -p all -s 192.168.1.0/24 -d 0.0.0.0/0 -j MASQ
#/sbin/modprobe ip_masq_ftp
4.´ú¸Õ¬Ý¬ÝclientºÝ¬O§_¥i¥H¥¿±`¤Wºô,§twww,ftp,e-mail,telnet...,¥i¥H«hªí¥Ü¦¨¥\
¬[ redirect PROXY(Äò5)
1.#ipchains -A input -p tcp -d 0.0.0.0/0 80 -j REDIRCT 3128
2.¦w¸Ëproxy server(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)
#rpm -Uvh /mnt/cdrom/Re*/RP*/squid*
3. ×§ï /etc/squid/squid.conf
a. §ä¨ì¤U¦C¦U¦æ,¨Ã×§ï(#°O±o®ø±¼)
http_accel_host virtual (¹w³]¬°http_accel_host hostname)
http_accel_port 80 (¹w³]¬°http_accel_port port)
http_accel_with_proxy on (¹w³]¬° off)
http_accel_uses_host_header on (¹w³]¬° off)
b. ¨ä¥L¨Ì¤@¯ë³]©w×§ï,¦p³]parent, cache¤j¤p....µ¥
4.±Ò°Ê squid
#squid -z
#/etc/rc.d/init.d/squid start
- Ãö³¬¾Ç¥Í¹q¸£ÂsÄý¾¹¤§proxy³]©w«á, ¤Wºô´ú¸Õ¨ÃÀˬd/var/log/squid/access.log ¤º®e,¬Ý¬O§_¦³¦s¨ú°O¿ý,Y¦³«hªí¥Ü¦¨¥\
#/usr/sbin/redir 192.168.1.2 8082 80 &
¡@