Next Previous Contents

3. ½ÇÇà µµÁß ¹ß»ýÇÏ´Â ¹®Á¦

3.1 NAT: X dropping untracked packet Y Z aaa.aaa.aaa.aaa -> 224.bbb.bbb.bbb

ÀÌ ¸Þ½ÃÁö´Â NAT Äڵ忡 ÀÇÇØ Ãâ·ÂµÇ´Âµ¥ ¸ÖƼij½ºÆ® ÆÐŶÀÌ NAT Å×À̺íÀ» °Çµé°í Àֱ⠶§¹®ÀÔ´Ï´Ù. ÇöÀç connection trackingÀº ¸ÖƼij½ºÆ® ÆÐŶÀ» Á¦´ë·Î ó¸®ÇÏ°í ÀÖÁö ¾Ê½À´Ï´Ù. ¸ÖƼij½ºÆ®°¡ ¹«¾ùÀÎÁö ¸ð¸£°Ú°Å³ª ±×°ÍÀÌ ÀüÇô ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ´ÙÀ½°ú °°ÀÌ Çϼ¼¿ä:

iptables -t mangle -I PREROUTING -j DROP -d 224.0.0.0/8

3.2 NAT: X dropping untracked packet Y Z aaa.aaa.aaa.aaa -> bbb.bbb.bbb.bbb

syslog¿Í Äֿܼ¡ ´ÙÀ½°ú°°Àº ¸Þ½ÃÁö°¡ Ãâ·ÂµË´Ï´Ù:

NAT: X dropping untracked packet Y Z aaa.aaa.aaa.aaa -> bbb.bbb.bbb.bbb

NAT Äڵ忡 ÀÇÇØ Ãâ·ÂµÇ´Â °ÍÀ¸·Î NAT°¡ À¯È¿ÇÑ connection tracking Á¤º¸¸¦ °®±âÀ§ÇØ ÆÐŶÀ» µå·ÓÇÏ´Â °ÍÀÔ´Ï´Ù. ÀÌ ¸Þ½ÃÁö´Â connection trackingÀÌ conntrack Á¤º¸¸¦ °áÁ¤ÇÒ ¼ö ¾ø´Â ¸ðµç ÆÐŶ¿¡ ´ëÇؼ­ Ãâ·ÂµË´Ï´Ù.

°¡´ÉÇÑ ÀÌÀ¯·Î´Â:

ÀÌ ÆÐŶ¿¡ ´ëÇÑ Á»´õ ±¸Ã¼ÀûÀÎ ·Î±×¸¦ ¾ò°í ½Í´Ù¸é (½ºÄ³´× ÆÐŶÀ̳ª ¿ÜºÎ¿¡¼­ÀÇ ¾î¶² °ø°Ý ½Ãµµ·Î ÀǽÉÀÌ µÇ¸é) ´ÙÀ½°ú °°Àº ·êÀ» »ç¿ëÇϽʼî:

iptables -t mangle -A PREROUTING -j LOG -m state --state INVALID

ÆÐŶÀÌ ÇÊÅÍ Å×ÀÌºí¿¡ µµÂøÇϱâ Àü¿¡ NAT Äڵ忡 ÀÇÇØ µå·ÓµÇ±â ¶§¹®¿¡ ÀÌ ·êÀº mangle Å×ÀÌºí¿¡ ³Ö¾î¾ß ÇÕ´Ï´Ù.

3.3 ¸®´ª½º ºê¸´Áö ÄÚµå¿Í netfilter¸¦ ÇÔ°Ô »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù.

¿Ïº®ÇÑ transparent ¹æÈ­º®À» ±¸ÃàÇÒ °èȹÀ̽Ű¡¿ä? ÁÁÀº »ý°¢ÀÔ´Ï´Ù. Ä¿³Î 2.4.16°ú ±×¸®°í ºÎ°¡ÀûÀÎ ÆÐÄ¡´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ ãÀ» ¼ö ÀÖ½À´Ï´Ù. http://bridge.sourceforge.net/.

3.4 IRC ¸ðµâÀÌ DCC RESUMEÀ» ó¸®ÇÒ ¼ö ¾ø½À´Ï´Ù.

±Û½ê¿ä. ÀÌ°ÍÀº Àý¹Ý¸¸ »ç½ÇÀÔ´Ï´Ù. ¿ÀÁ÷ NAT ¸ðµâ¸¸ÀÌ ±×µéÀ» ó¸®ÇÒ ¼ö ¾ø½À´Ï´Ù. NAT ¾øÀÌ ¹æÈ­º®À» ±¸ÇöÇÏ°í ÀÖ´Ù¸é ¹Ýµå½Ã Àß ÀÛµ¿ÇØ¾ß ÇÕ´Ï´Ù.

3.5 ¾î¶»°Ô ´ÙÁß ÁÖ¼Ò¿¡ ´ëÇÑ SNAT¸¦ ÀÛµ¿ÇÏ°Ô ÇÒ ¼ö ÀÖ½À´Ï±î?

netfilter´Â °¡´ÉÇÑÇÑ Àû°Ô ÆÐŶÀ» Á¶ÀÛÇÕ´Ï´Ù. ±×·¡¼­ ¸¸¾à freshly-rebooted°¡ °¡´ÉÇÑ ¸Ó½Å°ú ±×¸®°í ´©±º°¡ SNAT ¹Ú½º ¾ÈÂÊ¿¡¼­ ·ÎÄà Æ÷Æ® 1234¸¦ ¿­°í ÀÖ´Ù¸é netfilter ¹Ú½º´Â ¿ÀÁ÷ °°Àº »óÅ·Π¸Ó¹°·¯ ÀÖ´Â ip ÁÖ¼Ò¿Í Æ÷Æ®¸¸À» Á¶ÀÛÇÕ´Ï´Ù.

´©±º°¡ °°Àº source Æ÷Æ®·Î ¶Ç ´Ù¸¥ Á¢¼ÓÀ» ÇÏ¸é ±×°ÍÀÌ SNAT¿¡°Ô ÀÖ¾î ´ÜÀÏ IP¶ó¸é netfilter´Â IP¿Í Æ÷Æ®¸¦ Á¶ÀÛÇÒ °ÍÀÔ´Ï´Ù.

But if there are more than one available, it again only has to mangle the IP part. ÇÏÁö¸¸ 2°³ ÀÌ»óÀ̶ó¸é ip ºÎºÐÀ» ´Ù½Ã Á¶ÀÛÇØ¾ß ÇÕ´Ï´Ù.

3.6 ip_conntrack: maximum limit of XXX entries exceeded

syslog¿¡¼­ ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö¸¦ ºÃ´Ù¸é ÀÌ´Â conntrack µ¥ÀÌÅͺ£À̽º°¡ ¿©·¯ºÐÀÇ È¯°æ¿¡ ÃæºÐÇÏÁö ¾ÊÀº ¿£Æ®¸®¸¦ °¡Áø°ÍÀ» ÀǹÌÇÕ´Ï´Ù. µðÆúÆ®·Î connection tracking Àº Á¤ÇØÁø µ¿½Ã Á¢¼Ó ¼ö±îÁö¸¸ ó¸®ÇÕ´Ï´Ù. ÀÌ ¼ö´Â ¿©·¯ºÐÀÇ ÃÖ´ë ¸Þ¸ð¸® Å©±â¿¡ ÀÇÁ¸ÀûÀÔ´Ï´Ù(64MB: 4096, 128MB: 8192,...).

ÃÖ´ë°ªÀº ½±°Ô Áõ°¡½Ãų ¼ö ÀÖÁö¸¸ °¢°¢ÀÇ tracking µÇ´Â Á¢¼ÓÀº ¾à 350 ¹ÙÀÌÆ®ÀÇ non-swappable Ä¿³Î ¸Þ¸ð¸®¸¦ Á¡À¯ÇÔÀ» À¯ÀÇÇØ¾ß ÇÕ´Ï´Ù.

ÃÖ´ë°ªÀ» 8192·Î Áõ°¡Çϱ⠿¹Á¦

echo "8192" > /proc/sys/net/ipv4/ip_conntrack_max

3.7 2.2.x¿¡¼­ 'ipchains -L -M' ½ÄÀ¸·Î ÇÏ´ø ¸ðµç tracking/¸¶½ºÄ¿·¹À̵ùµÇ´Â Á¢¼ÓÀº ¾î¶»°Ô Ãâ·ÂÇմϱî?

proc È­ÀÏ ½Ã½ºÅÛ¿¡ º¸¸é /proc/net/ip_conntrack¶ó´Â È­ÀÏÀÌ ÀÖ½À´Ï´Ù. ÀÌ È­ÀÏÀ» ´ÙÀ½°ú °°ÀÌ Ãâ·ÂÇؼ­ º¸¸é µË´Ï´Ù.

cat /proc/net/ip_conntrack

3.8 ¸ðµç °¡´ÉÇÑ IP Å×À̺íÀ» ¾î¶»°Ô Ãâ·ÂÇմϱî?

¸ðµç »ç¿ë°¡´ÉÇÑ IP Å×À̺íÀº ´ÙÀ½°ú °°ÀÌ Ãâ·ÂÇÒ ¼ö ÀÖ½À´Ï´Ù.

cat /proc/net/ip_tables_names

3.9 iptable-1.2¿¡¼­ iptables-save / iptables-restore ¼¼±×¸àÅ×ÀÌ¼Ç ÆúÆ®°¡ ³³´Ï´Ù.

ÀÌ¹Ì ¾Ë·ÁÁø ¹ö±×·Î½á ÃֽŠcvs·Î ¾÷µ¥ÀÌÆ®¸¦ Çϰųª iptables >=1.2.1 À» »ç¿ëÇÏ¸é µË´Ï´Ù.

3.10 iptables -LÀÌ ·êÀ» Ãâ·ÂÇϴµ¥ ¸Å¿ì ¿À·£ ½Ã°£ÀÌ °É¸³´Ï´Ù.

ÀÌ°ÍÀº iptablesÀÌ °¢°¢ÀÇ ip ÁÖ¼Ò¿¡ ´ëÇÑ DNS lookupÀ» Çϱ⠶§¹®ÀÔ´Ï´Ù. °¢°¢ÀÇ ·êÀº 2°³ÀÇ ÁÖ¼Ò¸¦ °¡Áö°í ÀÖ°í ÃÖ¾ÇÀÇ °æ¿ì °¢°¢ÀÇ ·ê¸¶´Ù DNS lookupÀ» µÎ¹øÇÏ°Ô µÇ´Â °æ¿ì°¡ ÀÖ½À´Ï´Ù.

¹®Á¦´Â »ç¼³ ip ÁÖ¼Ò¸¦ »ç¿ëÇÏ´Â °æ¿ìÀε¥(10.x.x.x ȤÀº 192.168.x.x), DNS´Â È£½ºÆ®À̸§À» ãÀ» ¼ö ¾ø°í ŸÀÓ ¾Æ¿ôÀÌ °É¸®°Ô µË´Ï´Ù. ÀÌ Å¸ÀӾƿô ½Ã°£À» ¸ðµÎ ÇÕÇÏ¸é ¸Å¿ì ±ä ½Ã°£ÀÌ µÉ °ÍÀÔ´Ï´Ù.

ÀÌ·¸µí DNS lookup ÇÏ´Â °ÍÀ» ¹æÁöÇÏ·Á¸é -n (numeric) ¿É¼ÇÀ» »ç¿ëÇÏ½Ã¸é µË´Ï´Ù.

3.11 Äֿܼ¡ ·Î±×°¡ Ãâ·ÂµÇÁö ¾Ê°Ô ÇÏ·Á¸é ¾î¶»°Ô ÇØ¾ß Çմϱî?

syslogd¸¦ ÀûÀýÈ÷ ¼³Á¤ÇØ Áà¾ßÇÕ´Ï´Ù. LOG targetÀº ¿ì¼±¼øÀ§ warning(4)·Î½á ·Î±×¸¦ ³²±â´Â ÀåÄ¡ÀÔ´Ï´Ù. ÀÌ·± ÀåÄ¡¿Í ¿ì¼±¼øÀ§¿¡ ´ëÇؼ­ Á»´õ °øºÎÇÏ°í ½ÍÀ¸¸é syslogd.conf ¸Ç ÆäÀÌÁö¸¦ Âü°íÇϽñ⠹ٶø´Ï´Ù.

µðÆúÆ®·Î debug(7) ¿ì¼±¼øÀ§º¸´Ù ³ôÀº ¸ðµç Ä¿³Î ¸Þ½ÃÁö´Â Äֿܼ¡ º¸³»Áöµµ·Ï µÇ¾î ÀÖ½À´Ï´Ù. ÀÌ°ÍÀ» 7´ë½Å 4·Î Áõ°¡½ÃŲ´Ù¸é ´õÀÌ»ó LOG ¸Þ½ÃÁö°¡ ÄÜ¼Ö»ó¿¡ ³ªÅ¸³ªÁö ¾ÊÀ»°ÍÀÔ´Ï´Ù.

ÀÌ·¸°Ô Çϸé ÄÜ¼Ö»ó¿¡ ³ªÅ¸³ª¾ßÇÒ ´Ù¸¥ Áß¿äÇÑ ¸Þ½ÃÁöµµ ¶ÇÇÑ ³ªÅ¸³ªÁö ¾Ê´Â Á¡À» À¯ÀÇÇÏ¼Å¾ß ÇÕ´Ï´Ù.

3.12 squid¿Í iptables¸¦ »ç¿ëÇÏ¿© ¾î¶»°Ô transparent ÇÁ·Ï½Ã¸¦ ±¸¼ºÇմϱî?

¸ÕÀú ÀûÇÕÇÑ DNAT ȤÀº REDIRECT ·êÀÌ ÇÊ¿äÇÕ´Ï´Ù. ¸¸¾à squid°¡ NAT ¹Ú½º »ó¿¡¼­ µ¿ÀÛÇÑ´Ù¸é REDIRECT¸¦ »ç¿ëÇϼ¼¿ä. ¿¹¸¦µé¸é:

iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to 192.168.22.33:3128

±×¸®°í ³ª¼­ squid¸¦ ÀûÀýÇÏ°Ô ¼³Á¤ÇØ¾ß ÇÕ´Ï´Ù. ¿ì¸®´Â ¿©±â¿¡¼­ ªÀº ¿¹¸¸À» º¸¿©ÁÙ °ÍÀ̹ǷΠÁ»´õ ÀÚ¼¼ÇÑ »çÇ׿¡ ´ëÇؼ­´Â squid ¹®¼­¸¦ ÂüÁ¶ÇϽñ⠹ٶø´Ï´Ù.

squid 2.3¿ë squid.conf´Â ´ÙÀ½ÀÇ »çÇ×µéÀÌ ÇÊ¿äÇÒ °ÍÀÔ´Ï´Ù.

http_port 3128
httpd_accel_host virtual
httpd_accel_port 80
httpd_accel_with_proxy  on
httpd_accel_uses_host_header on
squid 2.4´Â ´ÙÀ½ÀÇ ºÎ°¡ÀûÀÎ ¶óÀÎÀÌ ÇÊ¿äÇÕ´Ï´Ù.
httpd_accel_single_host off

3.13 LOG targetÀº ¾î¶»°Ô »ç¿ëÇմϱî? / ¾î¶»°Ô LOG¿Í DROPÀ» µ¿½Ã¿¡ ÇÒ ¼ö ÀÖ½À´Ï±î?

LOG target´Â "non-terminating target"À» ¸»ÇÕ´Ï´Ù. Áï ÀÌ°ÍÀº ÆÐŶ ·ê Æ®·¡¹ö½º( traverse)¸¦ ³¡³»Áö ¾Ê½À´Ï´Ù. LOG targetÀ» »ç¿ëÇϸé ÆÐŶÀº ·Î±ëµÇ°í ·êÀÇ ¼øȸ´Â ´ÙÀ½·ê±îÁö °è¼ÓµË´Ï´Ù.

±×·³ ¾î¶»°Ô µ¿½Ã¿¡ ·Î±ë°ú µå·ÓÀÌ µÉ±î¿ä? °¡Àå ½¬¿î ¹æ¹ýÀ¸·Î ´ÙÀ½ 2°³ÀÇ ·êÀ» Æ÷ÇÔÇÏ´Â »ç¿ëÀÚ Ã¼ÀÎÀ» »ý¼ºÇÏ´Â °ÍÀÌ ÀÖ½À´Ï´Ù.

iptables -N logdrop
iptables -A logdrop -j LOG
iptables -A logdrop -j DROP

"-j logdrop". ÀÚ ÀÌÁ¦ ÆÐŶ¿¡ ´ëÇÑ ·Î±ë°ú µå·ÓÀ» ¿øÇÒ ¶§¸é ¾ðÁ¦µçÁö "-j logdrop"À» ÇÏ¸é µË´Ï´Ù.

3.14 Ä¿³Î ·Î±×: Out of window data xxx

patch-o-matic¿¡ ÀÖ´Â tcp-window-tracking ÆÐÄ¡¸¦ »ç¿ëÇß±º¿ä. ÀÌ ÄÚµå´Â ÆÐŶÀÇ seq/ack ¹øÈ£, ¼¼±×¸ÕÆ® Å©±â µîµîµî¿¡ ÀÇÇØ ¼ö¿ë°¡´ÉÇÑ TCP ÆÐŶÀ» ±â·ÏÇÏ°í ÀÖ½À´Ï´Ù. ÀÌ°ÍÀº ¼ö¿ë°¡´ÉÇÏÁö ¾ÊÀº ÆÐŶÀ» ŽÁöÇßÀ» ¶§(out of the window) ±× ÆÐŶÀ» INVALID·Î Ç¥½ÃÇÏ°í À§¿Í °°Àº ¸Þ½ÃÁö¸¦ Ãâ·ÂÇÏ°Ô µË´Ï´Ù.

»õ ¹öÀü¿¡¼­´Â ±× ÆÐŶ°ú Á¤È®È÷ ¾î¶² »óÅ¿¡¼­ failÀÌ ¹ß»ýÇß´ÂÁö ·Î±×¸¦ ³²±é´Ï´Ù.

sysctl ¶ÇÇÑ »õ¹öÀü¿¡¼­´Â sysctlÀ» ÅëÇؼ­ ·Î±×¸¦ öÀúÈ÷ °¨Ãâ¼öµµ ÀÖ½À´Ï´Ù.

echo 0 > /proc/sys/net/ipv4/netfilter/ip_ct_tcp_log_out_of_window


Next Previous Contents