DHCP +NAT+Transparent PROXY¬[³]           ·ç¤uºôºÞªL·çÂ×89.10.21

  1. «e¨¥:¥»®Õ(·çªÚ°ª¤u)·íªì¦V±Ð¨|³¡¥Ó½Ð¤@²Õclass cªºip ,½d³ò210.59.2.0~255,¦ý¦]ip¤£¨¬,¬G§Q¥ÎREDHAT6.1ª©µ²¦Xdhcp¤Înat...µ¥¥\¯à±N¹q¸£±Ð«Ç¹j¶},¹q¸£±Ð«Ç¤º¨Ï¥ÎµêÀÀ¦ì§}(192.168.1.1~254),¹ï¥~«h¨Ï¥Î1­Ó¦Xªk¦ì§}(¦p210.59.2.161),¨Ã¨Ì°Ï¬q¯S©Ê,¥i§@¤U¦C¤£¦Pªºµ²¦X³]©w:

       PS.¥H¤U5ºØ²Õ¦X°£CASE 3,4¨âªÌ¤G¾Ü¤@¤£­n­«ÂÐ¥~,¨ä¥L¦UºØ¥\¯à¥i¨Ì»Ý¨D¿W¥ß©Î¤¬¬Ûµ²¦X·f°t¨Ï¥Î

¯SÂI:³]©w²³æ,¤£¹L¹q¸£±Ð«Ç¤º¦U¾Ç¥ÍPC»Ý­Ó§O«ü©wµêÀÀip,dns,gate...,¤ñ¸û³Â·Ð

¯SÂI:µ²¦Xdhcp,¦U¾Ç¥ÍPC¤£¥Î³]©w¥iª½±µ°ÊºA¨ú±oµêÀÀip,dns...

¯SÂI:©ónat¾÷¾¹¤W¦A¬[proxy servcer ¨Ãµ²¦Xredirect(¾É¦V)ªº¥\¯à,¥i±j¨î¾Ç¥Íªºrequest ¦Û°Êredirect¦Üproxy server ,¥Ñproxy server¦V¤W¼h§ì¸ê®Æ,´«¨¥¤§¤]´N¬O·íNAT¥D¾÷¤W¦¬¨ìport80ªº request®É,·| redirect ¦Üport 3128,¦p¦¹¥i¬Ù¥h¦UpcªºÂsÄý¾¹­n³]proxyªº³Â·Ð,¤£¹L©Mcase2¤ñ¸û,¦¹ªk¥D¾÷°t³Æ­n¸û¨Î§_«h¤U¸üºô­¶ªº³t«×¤Ï¦Ó·|¤ñ¸ûºC

¯SÂI:¦P¤W,®t§O¦b©ó¾Ç®Õ¤º°²³]¤w¦³¨ä¥Lproxy server(¦p210.59.2.3),«h©ónat ¾÷¾¹¤W¤£¥Î¦A¬[proxy server,¥iª½±µ±N¾Ç¥Íªºrequest ª½±µredirect(¾É¦V)¦Ü¾Ç®Õªºproxy server,¦A¥Ñ¾Ç®Õproxy server¦V¤W¼h§ì¸ê®Æ,¤£¹L³oºØ¤èªk§ì¨ìªººô­¶·|©Ç©Çªº,¦³¨Ç¹Ï¤ù·|¿ù»~,«ö­«·s¾ã²z,¨C¦¸¿ù»~ªº³¡¤À³£¤£¤@¼Ë,¦h«ö´X¦¸¤~·|¥¿½T,¤£ª¾¦ó¬G

¯SÂI:°£case2ªº¥\¯à¥~,¥t°²³]¹q¸£±Ð«Ç¤º¾Ç¥Ípc¨Ï¥ÎµêÀÀip,¥i¬O¨ä¤¤¦³¤@³¡¹q¸£(192.168.1.2)­n´£¨ÑwwwªºªA°È(¦p¹Ï®ÑÀ]¬d¸ß¨t²Î),¨Ñ¥~¬É¬d¸ß,«h¥i§Q¥Î³o­Ó¤èªk,¦¹ªkÃþ¦ücase4 redirect proxyªº³]©w,©Ò¥H·í§Ú­Ì°õ¦æ http://210.59.2.161®É,nat¥D¾÷·|¦Û°Ê±Nrequest REDIRECT¦Ü192.169.1.2³o³¡¥D¾÷

  1. ¥D¾÷³W®æ:
  1. ¥D¾÷³]©w­È:(¥i§Q¥Î linuxconf  ©Îwebmin0.8³nÅé³]©w)

                              netmask:255.255.255.0

                              netmask:255.255.255.0t

  1. ¬[ DHCP SERVER:(³Ì¦n§Q¥Îwebmin0.80³nÅé¤ñ¸û²³æ)
  1. ¦w¸Ëwebmin0.80

        °Ñ¦Ò¬ÛÃö¤å¥ó

        ¤U¸ü

  1. ¦w¸Ëdhcp-2.0b1p16-2.i386.rpm(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)

       rpm -Uvh /mnt/cdrom/Redhat/RPMS/dhcp*

  1. ©ówebmin0.80¤¤¶i¤Jdhcp¿ï¶µ
  2. ¼W¥[¨â­Ó¤lºô¸ô(210.59.2.0)¤Î(192.168.1.0)
  3. ÂI¿ï192.168.1.0ºô¸ô¨Ã³]©w¤U¦C¼Æ¾Ú
  1. Àx¦s,¦AÂI¿ï ½s¿è«È¤áºÝ¿ï¶µ ¨Ã³]©w¤U¦C¼Æ¾Ú
  1. Àx¦s
  2. ­Y¦Xªkipºô°ì¤º¤w¦³¨ä¥Ldhcp ¦øªA¾¹,«h210.59.2.0ºô¸ô¤¤ùØ­±ªº¿ï¶µ¥i¥H¤£¥Î³]
  3. ±Ò°Êdhcp
  4. Àˬd clientºÝ¬O§_¦Û°Ê¨ú±oip,(¥i°õ¦æwinipcfgÀˬd)­Y¦³«hªí¥Ü¦¨¥\
  1.   ¬[ NAT  SERVER

               1.­×§ï /etc/sysconfig/network

                    ±N forward_ipv4 ³]¬° yes ,¨Ã­«·s¶}¾÷

                2.¦w¸Ë ipchain(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)

                    #rpm -Uvh /mnt/cdrom/Redhat/RPMS/ipchain*

                 3.°õ¦æ

                     #ipchains -A forward -p all -s 192.168.1.0/24 -d  0.0.0.0/0 -j MASQ

                    #/sbin/modprobe ip_masq_ftp

                    4.´ú¸Õ¬Ý¬ÝclientºÝ¬O§_¥i¥H¥¿±`¤Wºô,§twww,ftp,e-mail,telnet...,¥i¥H«hªí¥Ü¦¨¥\

  1. ¬[ redirect PROXY(Äò5)

                 1.#ipchains -A input -p tcp -d 0.0.0.0/0 80 -j REDIRCT 3128

                 2.¦w¸Ëproxy server(¦¹µ{¦¡©ñ©óRH6.1¥úºÐ¤¤)

                    #rpm -Uvh /mnt/cdrom/Re*/RP*/squid*

                 3. ­×§ï /etc/squid/squid.conf 

                      a. §ä¨ì¤U¦C¦U¦æ,¨Ã­×§ï(#°O±o®ø±¼)

                         http_accel_host virtual  (¹w³]¬°http_accel_host hostname)

                         http_accel_port 80 (¹w³]¬°http_accel_port port)

                         http_accel_with_proxy on  (¹w³]¬° off)

                         http_accel_uses_host_header on (¹w³]¬° off)

                      b. ¨ä¥L¨Ì¤@¯ë³]©w­×§ï,¦p³]parent, cache¤j¤p....µ¥

                    4.±Ò°Ê squid

                        #squid -z

                        #/etc/rc.d/init.d/squid start

  1. Ãö³¬¾Ç¥Í¹q¸£ÂsÄý¾¹¤§proxy³]©w«á, ¤Wºô´ú¸Õ¨ÃÀˬd/var/log/squid/access.log ¤º®e,¬Ý¬O§_¦³¦s¨ú°O¿ý,­Y¦³«hªí¥Ü¦¨¥\
  1. ¬[ dedicate proxy--(®Õ¤ºproxy server ¤§ip: 210.59.2.3) (Äò5)
    1. ¤U¸ü transproxy-0.4-1.i386.rpm (¬ù1.6M)¦Ü¥»¦aºÝ tmp ¥Ø¿ý
    2. rpm -Uvh transproxy*
    3. #ipchains -A input -p tcp -d 0.0.0.0/0 80 -j REDIRECT 8081
      #/usr/sbin/in.tproxyd -s 8081 -r nobody 210.59.2.3 3128
    4. ´ú¸Õ¨ÃÀˬdproxy server ¬O§_¦³°O¿ý
    5. ³oºØ¤èªkºô­¶·|©Ç©Çªº,¤£ª¾¦ó¬G?
  2. ¬[NAT Router¤ºªº¹ï¥~ªA°È¦øªA¾¹ (Äò6 ©Î7)
    1. µêÀÀip¤º¦³¤@³¡¹q¸£(192.168.1.2)¥i¥Ñ¥H¤U³]©w´£¨ÑwwwªºªA°È
    2. ¤U¸ü redir-1.1.tar.gz (¬ù79K) ¦Ü¥»¦aºÝ tmp ¥Ø¿ý
    3. tar xzvf redir*
    4. make redir
    5. cd redir-1.1
    6. cp redir /usr/sbin
    7. #ipchains -A input -p tcp -d 210.59.2.161 80 -j REDIRECT 8082

      #/usr/sbin/redir 192.168.1.2 8082 80 &

    8. ´ú¸Õ:½Ð±q¦Xªk¦ì§}¤§¹q¸£¤Uhttp://210.59.2.161 ¬Ý¬O§_¥i¥H¬Ý¨ì192.168.1.2ªººô­¶
  3. ¤ß±o:
    1. ¥H¤W¬O°w¹ï¥»®Õ¹ê»Ú±¡ªp,©óªñ´Á¬[¯¸¤§¤ß±o,ºî¦X¦h½g¦h¥ó,´ú¸ÕµL»~,¬Ù¥h§{¶¡¤å¥ó,¦U®a¤º®e¤¾ªø,°õ¦æ¤@¤j°ï«ü¥Oªº§xÂZ
    2. ­Y´ú¸ÕµL»~¥i±N¤W­z«ü¥O¼g¤J /etc/rc.d/rc.local ¤¤,¥H«á¶}¾÷¥i¦Û°Ê°õ¦æ
    3. ¤¤¥¡¤j¾Ç  live cd¥i´£¨Ñ¬ÛÃö¤£¿ùªº¥\¯à,¦w¸Ë«Ü²³æ,¤£¹L¦]²{¤µªº¥úºÐ¾÷¤@¤U¤l´N·|¶i¤J¬Ù¹qª¬ºA,·|³y¦¨nat ¥D¾÷¤ÏÀ³«Ü¿ð¶w,¤Wºô¤£¶¶,¤£ª¾¦³¦ó¸Ñ¨M¤§¹D
    4. ¦]®É¶¡¦³­­,¥¼¦³¥ô¦ó¹Ï¤ù»¡©ú,¦b¦¹»¡©êºp,¤~²¨¾Ç²L,­Y¦³»~º|·Ð¤©§iª¾
  4. °Ñ¦Ò¤å¥ó
    1. ¤¤¥¡¤j¾Ç ¼B¼C«C live cd ¥úºÐ¤º¤§»¡©úÀÉ
    2. linucer 4´Á
    3. RUN-PCÂø»x6¤ë¸¹
    4. BBS¯¸ LINUX ª©
    5. LINUX ¤¤¤å»¡©ú¤å¥ó¤¤¦³ÃöNAT ,FIREWALL,IPMASQµ¥³¡¤À

¡@