°ÝÃD»¡±o«Ü²M·¡¡M±ÀÂ_¤]«Ü©ú´·¡C¦n¡T
ªO¤Wnµo°ÝÃDªºªB¤ÍÀ³¸Ó¦h¦V³o¦ì¤jô¾Ç²ß¾Ç²ß¡C
elf <elf.bbs@bbs.ntu.edu.tw>
wrote in message
news:3cYidk$85x@bbs.ntu.edu.tw...
> ©êºpÁÙ¬O¨Ó´£°ÝÃD¤F,¦]¬°§ä¤F¤@¨Ç¯¸ªººëµØ°ÏÁÙ¬O§ä¤£¨ì¸Ñµª,·Ð½Ð
> ¦U¦ì¥ý¶i¯à¤£§[«ü±Ð.
>
> ±¡§Î¬OÂæ¤lªº,§Úµo²{¦bNAT©³¤Uªº¤º³¡ºô°ì(¨Ï¥ÎµêÀÀIP)ªº¥D¾÷¦b³s
> ¨ì¥~³¡ªºFTP¯¸¥x®É,Y¨ä±±¨î³s±µµ{§ÇªºPort¬°well-knownªº21,«h
> ³s½u¤W¬O¨S¦³°ÝÃDªº,¦ý¬OYFTP¯¸¥xªº±±¨î³s±µµ{§ÇªºPort¤£¬O¥¿±`
> ªº21¦Ó¬O¨ä¥¦Port¸¹®É(¦p199µ¥),«h³s½u·|¦³°ÝÃD,ª¬ªp¬O¥i¥Hµn¤J,
> ¦ý¸ê®Æ«o¶Ç¤£¦^¨Ó,§Úª¾¹DFTPªº³s±µ¥²¶·³z¹L¨âºØµ{§Ç,¤]´N¬O»¡,¦b
> ±±¨î³s±µµ{§Çªº³s½uOK¥~,¸ê®Æ¶Ç¿éµ{§Ç¤]±o¥¿½T¤~¦æ,³Â·Ð´N³Â·Ð¦b
> ³o,¥Ñ©ó¥»¨ªºFTP¯¸¬O¬[¦b¤º³¡ºô°ìùØ,¦Ó¥B±±¨î³s±µµ{§ÇPort¤]¤£
> ¬O¥Î¥¿±`ªº21,¦Ó¬O¦Û¦æ³]©w¤F¨ä¥LªºPort,©Ò¥H¦bLinux¤§NAT¥D¾÷¤W
> ´N³]¤F¥H¤UªºÀô¹Ò¡G
>
> ipmasqadm portfw -a -P tcp -L xxx.xxx.xxx.xxx(My¯u¹êIP) 20 -R 192.1.
> 168.xxx 20
> ipmasqadm portfw -a -P tcp -L xxx.xxx.xxx.xxx(My¯u¹êIP) 206(ftp port)
192.1.
> 168.xxx 206(ftp port)
>
> µ²ªG¬OÂæ¤l¡G
>
> port localaddr rediraddr
lport rport
pcnt pref
> TCP ¥»¾÷¦WºÙ 192.1.168.xxx ftp-data
ftp-data 10 10
> TCP ¥»¾÷¦WºÙ 192.1.168.xxx 199
199 10 10
>
> §Ú·Q,¤£ª¾¬O¤£¬O¦]¬°§â¸ê®Æ¶Ç¿éµ{§Ç¥ÎªºPort¸¹20¤]Âà¶i¨ì¤º³¡¥D¾÷¤W¤~¨Ï±o
> ³s±µ¯S®í¥~³¡FTP(¦p¨ä³s±µPort¬°199)®Éµo¥Í°ÝÃD,©ó¬O§â¥¦¨ú®ø,Åܦ¨Âæ¤l¡G
>
> port localaddr rediraddr
lport rport
pcnt pref
> TCP ¥»¾÷¦WºÙ 192.1.168.xxx 199
199 10 10
¤£ª¾¹D±z©Ò«üªº FTP ¬O«ü±q¸Ì¨ì¥~§ì¡MÁÙ¬OÅý¥~¶i¸Ì§ì©O¡S
¦pªG¬O¨ì¥~±§ì¡M³o¸Ìªº³]©w¨S¤°»ò¼vÅT¡MFTP ©M FTP-DATA
³o¨âÓ port ³£¬Oµ¹
server ºÝ¥Îªº¡C¦Ó client ºÝ«h¦p±z¤U±©Ò«ü¥Xªº¡M¬O¤@Ó¤j©ó
1024 ÀH¾÷²£¥Íªº
port ¡C
>
> ¦ý¬O¤´µM¤£¦æ,§Ú³Ì°g´bªº¦a¤è¬O,¦]¬°¦bFTPªºClientºÝªº±±¨î³s±µµ{§ÇPort³£
> ¬OÀH¾÷ªº,©Ò¥H¦bLinuxªºNAT¥D¾÷¤W®Ú¥»µLªk¹w¥ý³]©w¦nnÂà¤JªºPort,¦ý¬O¬°
> ¤°»ò¥¿±`ªºFTP¥D¾÷(§Y±±¨î³s±µµ{§ÇPort¬°21)«o¥i¥H¥¿±`³s½u,¦³¨S¦³¿ìªkÅý
> NAT©³¤U¤º³¡ºô°ìªº¥D¾÷¦b³s±µ±±¨î³s±µµ{§ÇPort¤£¬O21ªºFTP¯¸¥x®É¤]¯à¥¿±`
> ³s½u©O?
>
> °ÝÃD¦³ÂI¤¾ªø,Y¦³°ÝÃD»¡©ú¤£©P¤§³B,ÁٽЦU¦ì¥ý¶i¤£§[µ¹¤©«ü¥¿,·PÁ¦U¦ì¥ý
> ¶i@¤ß¦a¬Ý§¹,Y¯à±o¨ì±zªºÀ°§U,·P¿E¤£ºÉ,ÁÂÁÂ.
·í±z¦b NAT «á±Åý«È¤áºÝ¨ì¥~±«Ø¥ß¼Ð·Çªº port 21 ªº FTP
ªA°È¡M¦pªG³æ¯Â¦b MASQ
¤§¤U¦Ó¤£¸ü¤J ip_masq_fp.o
¼Ò²Õªº¸Ü¡M¼Æ¾Ú³q¹D¬OµLªk«Ø¥ßªº¡C¦Ó¦Ü©ó¬°¤°»ò«D¼Ð·Ç
port ªº FTP
¤£¯à¦¨¥\¡M§Ú¤]¤£¬O«Ü²M·¡¡M¥i¯à¬O¼Ò²Õ¤£¯à¿ë§OªºÃö«Y¡C©Î³\±z¥i¥H§ï
¥Î passive mode ¨Ó¸Õ¸Õ¡C¦]¬°³s½u½Ð¨D³£¨Ó¦Û«È¤áºÝ¡MMASQ
À³¸Ó·|¦³¨C¤@Ó³s½uªº
°°¸Ë°O¿ý¡MµM«á¶¶§Q§¹¦¨ DE-MASQ ªº°Ê§@¡C
Ãö©ó FTP client ¦b NAT
«á±ªº¤u§@¡M§Ì¦b¦p¤Uºô¶Â²³æ»¡¹L¡M¥i¥H°Ñ¦Ò¤@¤Uªº¡R
http://ccns.ncku.edu.tw/study-area/linux/linux_nat.htm