¡¾×ªÌûLINUX¡¿netfilterÖеÄconntrackÄÚºËÔĶÁ±Ê¼Ç(5)
2008-07-07 22:09
6£¬TCP filterµÄÔÀí£º
µ±filterÊÕµ½Ä³¸öÁ¬½ÓµÄµÚÒ»¸ö±¨ÎÄʱ£¬»áΪ¸ÃÁ¬½ÓÔÚÈ«¾ÖÁ¬½Ó±íÖд´½¨Ò»¸ö±íÏ²¢Óñ¨ÎÄÖÐЯ´øµÄÔ´¡¢Ä¿µÄIPºÍ¶Ë¿ÚÕâ¸öËÄÔª×é´´½¨original tupleºÍreply tuple£¬ÕâÁ½¸ötuple·Ö±ð´Ó²»Í¬·½ÏòÀ´±êʶÕâ¸öÁ¬½Ó¡£ºóÐøµÄ±¨ÎÄ»á¸ù¾ÝÆäЯ´øµÄËÄÔª×éÕÒµ½ÏàÓ¦µÄÁ¬½Ó±íÏȻºó¸ù¾Ý±íÏîËù¼Ç¼µÄÀúʷ״̬£¬¼ì²é±¨ÎÄËùЯ´øµÄack¡¢Êý¾ÝÊÇ·ñÓÐЧ¡£
filterͨ¹ý·ÖÎö¸ÃÁ¬½ÓËùÓеÄÀúÊ·±¨ÎÄ£¬¼ÆËã³öackºÍÊý¾ÝÏàÓ¦µÄ×î´ó×îС·§Öµ£¬À´¼ì²éе½´ï±¨ÎÄackºÍÊý¾ÝµÄÓÐЧÐÔ¡£¸ÃÁ¬½ÓÏà¹ØµÄ×î´ó×îС·§ÖµÊǶ¯Ì¬±ä»¯µÄ£¬µ±Ð±¨ÎÄͨ¹ýÓÐЧÐÔ¼ì²éºó£¬·§Öµ½«Ê¹ÓÃб¨ÎÄËùЯ´øµÄÄÚÈÝÖØÐ¼ÆËã¡£ÔÚÌÖÂÛÈçºÎÈ·Á¢·§ÖµÖ®Ç°£¬ÏÈÀ´¿´¼¸ÌõÔ¼¶¨¡£¼ÙÉèAºÍBÖ®¼äµÄ±¨Îͼ¾¹ýfilter£¬ÄÇô£º
l filter¿ÉÒÔ¿´µ½A¡¢BÖ®¼äµÄËùÓб¨ÎÄÊý¾Ý£»
l filter¿ÉÒÔ¿´µ½Ã¿¸ö±¨ÎÄÖÐËùÉùÃ÷µÄ´°¿Ú´óС£»
l Èç¹ûB·¢Ë͵ı¨ÎĵÄACK±ê־λÖÃ룬ÇÒACK = n£¬ÄÇôfilter¿ÉÒÔÈÏΪBÒѽÓÊÕµ½µÄAÊý¾Ý£¬Æä³¤¶ÈÖÁÉÙΪn¡£
1£©£¬Á¬½ÓÏîÖе±Ç°ÓÐЧÊý¾Ý±ß½çµÄÈ·Á¢£º
¼ÙÉèAÏòB·¢Ë͵ı¨ÎÄÖУ¬Ëùº¬Êý¾Ý¶ÎΪ[seq,seq + len)£¬¼´±¨ÎÄËùº¬Êý¾ÝÆðʼSEQΪseq£¬Êý¾Ý³¤¶ÈΪlen¡£ÓÉÓÚAËù·¢Ë͵ı¨Îij¤¶È²»Äܳ¬¹ýBµ±Ç°´°¿ÚËùÄÜÈÝÄɵĴóС£¬Òò´ËÓÐЧÊý¾ÝµÄÉÏÏÞΪ£º
A :seq + len <= B : max { ack + max{win£¬1}} (I)
AËù·¢³ö±¨ÎÄÊý¾ÝµÄ×î´óÐòºÅ£¬Òª²»´óÓÚ´ÓB½ÓÊÕµ½µÄACK + max{win,1}µÄ×î´óÖµ¡£Ö®ËùÒÔÈ¡×î´óÖµ¶ø²»Ê¹ÓÃ×î½ü½ÓÊÕµ½µÄ±¨ÎĵÄÖµ£¬ÊÇÒòΪ±¨Îĵĵ½´ïÊÇÎÞÐòµÄ£¬½ÏСµÄ±¨ÎÄÓпÉÄÜÒòΪÆäËûÔÒò½ÏÍíµ½´ï¡£ÁíÍ⣬ÓÉÓÚ±¨ÎÄͨ¸æµÄ´°¿Ú´óСÓпÉÄÜΪ0£¬ÕâÖÖÇé¿öÏ£¬TCPµÄ¼á³Ö¶¨Ê±Æ÷ÔÊÐíA¼ä¸ôµØ·¢Ëͳ¤¶ÈΪ1µÄ´°¿Ú̽²â±¨ÎÄ£¬Òò´ÎÓÐЧÊý¾ÝµÄÉÏÏÞÐè²ÉÓÃmax{ win, 1}¡£ÉÏÏÞµÄÉèÖ㬿ÉÒÔ·ÀÖ¹BÊÕµ½³¬¹ýÆä´°¿Ú´óСµÄ±¨ÎÄ£¬filter¿ÉÒÔ½«Õⲿ·Ö±¨ÎÄÖ±½Ó¶ªÆú¶ø²»ÔÙת·¢µ½B¡£
ÓÐЧÊý¾ÝµÄÏÂÏÞ£º
A : seq >= A : max{ seq + len} – B : max{ max{ win, 1}} (II)
¼ÙÉèBµÄ×î´ó´°¿Ú´óСΪn£¬ÄÇôB¶Ë×î¶à¿ÉÒÔ»º´æn¸öAµÄ±¨ÎÄ£¬ÒòΪA¶ËËù·¢Ë͵ı¨ÎÄ×î¶àÓÐn¸öÉÐδȷÈÏ£¬¶ÔÓÚÒѾȷÈϵı¨ÎÄÔÙ´ÎÖØ·¢ÊÇûÓÐÒâÒåµÄ¡£
2£©£¬Á¬½ÓÏîÖе±Ç°ÓÐЧACK±ß½çµÄÈ·Á¢£º
ÒòΪA²»¿ÉÄÜΪÆäδÊÕµ½µÄÊý¾Ý½øÐÐÈ·ÈÏ£¬ËùÒÔ±¨Î
Ïà¹ØÎĵµ£º
Ò»¸öСÀúÊ·½«ÓÐÖúÓÚ°ïÖúÄúÀí½â Security-Enhanced Linux£¨SELinux£©——¶øÇÒËü±¾ÉíÒ²ÊǶÎÓÐȤµÄÀúÊ·¡£
ÃÀ¹ú¹ú¼Ò°²È«¾Ö
£¨National
Security
Agency£¬NSA£©³¤Ê±¼äÒÔÀ´¾Í¹Ø×¢´ó²¿·Ö²Ù×÷ϵͳÖÐÊÜÏ޵ݲȫÄÜÁ¦¡£±Ï¾¹£¬ËûÃǵŤ×÷Ö®Ò»¾ÍÊÇҪȷ±£ÃÀ¹ú¹ú·À²¿Ê¹ÓõļÆËã»úÔÚà ......
½ñÌìÔÚGentooϰ²×°ÁËVirtualBoxÐéÄâÁËÒ»¸öXP£¬ÕâÑùÐèҪѸÀ×µÈһЩֻÓÐFor WindowsϵÄÈí¼þʱºò²»ÓñØÐëÖØÐÂÆô¶¯Çл»µ½WindowsÏÂÁË¡£
ÏÔÈ»Á½¸öOS֮ǰµÄÎļþ½»»»Ò²ºÜ¹Ø¼ü£¬½â¾ö·½°¸Ò²·Ç³£µÄ¼òµ¥¡£
1£©ÔÚGentooϰ²×°openssh
emerge openssh
2£©ÔÚwindows¿Í»§»úÉϰ²×°FileZilla
......
FreeBSDÊÇÒ»¸öÍêÕûµÄ²Ù×÷ϵͳ£¬°üº¬ÁË´Ó¿ª·¢¹¤¾ßµ½¸÷ÖÖ¸÷ÑùµÄÓ¦ÓóÌÐò¡£
ĿǰÈËÃÇÈÏΪFreeBSDÔÚÎȶ¨ÐÔºÍÍøÂçÔË×÷ÉϵÄÐÔÄÜÒªÓÅÓÚLinux¡£
ËüÓÉÒ»¸öÈí¼þ¿ª·¢µÄºËÐÄÍŶÓÀ´Î¬»¤£¬Õû¸öÔʼ³ÌÐò´úÂë»áÓÐ×éÖ¯µØ½øÐиüУ¬ËùÒÔ³ÌÐò´úÂë±È½ÏÓÐÒ»ÖÂÐÔ¡£
ÓÉÓÚÈËÃǶÔFreeBSDµÄÈÏʶ±È½ÏÉÙ£¬Ê¹Ó÷¶Î§Ò²±È½ÏС£¬µ¼ÖÂÁËËüÔÚ¶ÔһЩвúÆ· ......
UNIX/Linux ϵͳ´ÅÅÌ ¿Õ¼ä¼à¿Ø ×Ô¶¯»¯½Å±¾ ʾÀý
1. ·ÖÇø¼à¿Ø /root/disktab ÎļþʾÀý
2. checkdisk ½Å±¾³õʼ»¯²¿·Ö
3. checkdisk ½Å±¾·ÖÎö /root/disktab Îļþ²¿·Ö
4.ÖеĽű¾ÊµÏÖÁËʵʱ¼à¿Ø²¢¼ì²â·ÖÇø×´¿ö£¬Í¨¹ýÇ°Ãæ»ñµÃµÄÓû§¶¨ÒåµÄãÐÖµºÍ df ÃüÁîµÄÊä³ö½øÐбȽϣ¬Èç¹û df ÏÔʾµÄij¸ö·ÖÇøµÄ¿Õ¼äÕ¼Óó¬¹ýÁËÓû§¶¨ÒåµÄã ......
2008-07-07 22:06
PREROUTING£ºip_conntrack_defrag à ip_conntrack_in
1£¬ip_conntrack_defrag:
ͨ³£µ±IP±¨Îı»ËÍÖÁL4²ã´¦Àíʱ£¬Èç¹û¸Ã±¨ÎÄÊÇ·ÖÆ¬±¨ÎÄ£¬ÄÇô±¨ÎľͻáÏȱ»±£´æÆðÀ´£¬Ö±µ½ËùÓÐ·ÖÆ¬µ½´ïºóÖØ×é³ÉÒ»¸öÍêÕû±¨Îĺó£¬ÔÙ±»·Ö·¢µ½L4²ã¡£µ±Ã»ÓÐÆô¶¯conntrackʱ£¬netfilter¸÷HOOKµã¶Ô±¨ÎIJÙ×÷ʱ£¬²¢²»¼ì²é¸Ã± ......