¡¾×ªÌûLINUX¡¿netfilterÖеÄconntrackÄÚºËÔĶÁ±Ê¼Ç(5)
2008-07-07 22:09
6£¬TCP filterµÄÔÀí£º
µ±filterÊÕµ½Ä³¸öÁ¬½ÓµÄµÚÒ»¸ö±¨ÎÄʱ£¬»áΪ¸ÃÁ¬½ÓÔÚÈ«¾ÖÁ¬½Ó±íÖд´½¨Ò»¸ö±íÏ²¢Óñ¨ÎÄÖÐЯ´øµÄÔ´¡¢Ä¿µÄIPºÍ¶Ë¿ÚÕâ¸öËÄÔª×é´´½¨original tupleºÍreply tuple£¬ÕâÁ½¸ötuple·Ö±ð´Ó²»Í¬·½ÏòÀ´±êʶÕâ¸öÁ¬½Ó¡£ºóÐøµÄ±¨ÎÄ»á¸ù¾ÝÆäЯ´øµÄËÄÔª×éÕÒµ½ÏàÓ¦µÄÁ¬½Ó±íÏȻºó¸ù¾Ý±íÏîËù¼Ç¼µÄÀúʷ״̬£¬¼ì²é±¨ÎÄËùЯ´øµÄack¡¢Êý¾ÝÊÇ·ñÓÐЧ¡£
filterͨ¹ý·ÖÎö¸ÃÁ¬½ÓËùÓеÄÀúÊ·±¨ÎÄ£¬¼ÆËã³öackºÍÊý¾ÝÏàÓ¦µÄ×î´ó×îС·§Öµ£¬À´¼ì²éе½´ï±¨ÎÄackºÍÊý¾ÝµÄÓÐЧÐÔ¡£¸ÃÁ¬½ÓÏà¹ØµÄ×î´ó×îС·§ÖµÊǶ¯Ì¬±ä»¯µÄ£¬µ±Ð±¨ÎÄͨ¹ýÓÐЧÐÔ¼ì²éºó£¬·§Öµ½«Ê¹ÓÃб¨ÎÄËùЯ´øµÄÄÚÈÝÖØÐ¼ÆËã¡£ÔÚÌÖÂÛÈçºÎÈ·Á¢·§ÖµÖ®Ç°£¬ÏÈÀ´¿´¼¸ÌõÔ¼¶¨¡£¼ÙÉèAºÍBÖ®¼äµÄ±¨Îͼ¾¹ýfilter£¬ÄÇô£º
l filter¿ÉÒÔ¿´µ½A¡¢BÖ®¼äµÄËùÓб¨ÎÄÊý¾Ý£»
l filter¿ÉÒÔ¿´µ½Ã¿¸ö±¨ÎÄÖÐËùÉùÃ÷µÄ´°¿Ú´óС£»
l Èç¹ûB·¢Ë͵ı¨ÎĵÄACK±ê־λÖÃ룬ÇÒACK = n£¬ÄÇôfilter¿ÉÒÔÈÏΪBÒѽÓÊÕµ½µÄAÊý¾Ý£¬Æä³¤¶ÈÖÁÉÙΪn¡£
1£©£¬Á¬½ÓÏîÖе±Ç°ÓÐЧÊý¾Ý±ß½çµÄÈ·Á¢£º
¼ÙÉèAÏòB·¢Ë͵ı¨ÎÄÖУ¬Ëùº¬Êý¾Ý¶ÎΪ[seq,seq + len)£¬¼´±¨ÎÄËùº¬Êý¾ÝÆðʼSEQΪseq£¬Êý¾Ý³¤¶ÈΪlen¡£ÓÉÓÚAËù·¢Ë͵ı¨Îij¤¶È²»Äܳ¬¹ýBµ±Ç°´°¿ÚËùÄÜÈÝÄɵĴóС£¬Òò´ËÓÐЧÊý¾ÝµÄÉÏÏÞΪ£º
A :seq + len <= B : max { ack + max{win£¬1}} (I)
AËù·¢³ö±¨ÎÄÊý¾ÝµÄ×î´óÐòºÅ£¬Òª²»´óÓÚ´ÓB½ÓÊÕµ½µÄACK + max{win,1}µÄ×î´óÖµ¡£Ö®ËùÒÔÈ¡×î´óÖµ¶ø²»Ê¹ÓÃ×î½ü½ÓÊÕµ½µÄ±¨ÎĵÄÖµ£¬ÊÇÒòΪ±¨Îĵĵ½´ïÊÇÎÞÐòµÄ£¬½ÏСµÄ±¨ÎÄÓпÉÄÜÒòΪÆäËûÔÒò½ÏÍíµ½´ï¡£ÁíÍ⣬ÓÉÓÚ±¨ÎÄͨ¸æµÄ´°¿Ú´óСÓпÉÄÜΪ0£¬ÕâÖÖÇé¿öÏ£¬TCPµÄ¼á³Ö¶¨Ê±Æ÷ÔÊÐíA¼ä¸ôµØ·¢Ëͳ¤¶ÈΪ1µÄ´°¿Ú̽²â±¨ÎÄ£¬Òò´ÎÓÐЧÊý¾ÝµÄÉÏÏÞÐè²ÉÓÃmax{ win, 1}¡£ÉÏÏÞµÄÉèÖ㬿ÉÒÔ·ÀÖ¹BÊÕµ½³¬¹ýÆä´°¿Ú´óСµÄ±¨ÎÄ£¬filter¿ÉÒÔ½«Õⲿ·Ö±¨ÎÄÖ±½Ó¶ªÆú¶ø²»ÔÙת·¢µ½B¡£
ÓÐЧÊý¾ÝµÄÏÂÏÞ£º
A : seq >= A : max{ seq + len} – B : max{ max{ win, 1}} (II)
¼ÙÉèBµÄ×î´ó´°¿Ú´óСΪn£¬ÄÇôB¶Ë×î¶à¿ÉÒÔ»º´æn¸öAµÄ±¨ÎÄ£¬ÒòΪA¶ËËù·¢Ë͵ı¨ÎÄ×î¶àÓÐn¸öÉÐδȷÈÏ£¬¶ÔÓÚÒѾȷÈϵı¨ÎÄÔÙ´ÎÖØ·¢ÊÇûÓÐÒâÒåµÄ¡£
2£©£¬Á¬½ÓÏîÖе±Ç°ÓÐЧACK±ß½çµÄÈ·Á¢£º
ÒòΪA²»¿ÉÄÜΪÆäδÊÕµ½µÄÊý¾Ý½øÐÐÈ·ÈÏ£¬ËùÒÔ±¨Î
Ïà¹ØÎĵµ£º
ÊÇÒªÓм¸¸ö½×¶ÎµÄ¡£ ¿ªÊ¼¿´ulk,
ulk×îºÃµÄµØ·½¾ÍÊÇËûËù³«µ¼µÄѧϰ·½·¨ÌرðºÃ¡£µ±ÄãÏëѧϰij·½ÃæÊ±£¬ÏÈ¿´Í·Îļþ£¬ÔÚû°Ñÿ¸öÊý¾Ý½á¹¹ÖеÄÿ¸öÊý¾ÝÔªËØÅªÇå³þ֮ǰ²»Òª¿´ÊµÏÖ´úÂë¡£
¶ÁÍêÍ·Îļþ£¬Òâζ×ÅÆäÖеÄ×éÖ¯¹ØÏµ¸ú±ðµÄµØ·½µÄÁªÏµ¾ÍÇå³þÁË£¬ÕâʱºòÄãÈ¥¿´ÊµÏֵĴúÂëÄã»á·¢ÏÖËûÒѾ×öµÄÕýÊÇÄãËùÏëµÄ¡£
¸ú×Åulk°ÑÕâЩ»ù±¾µ ......
6. Devices
A device driver hides the hardware device’s communication
protocols from the operating system and allows the system to interact with the
device through a standardized interface.
Processes can communicate with a device driver via
file-like objects.
6.1 Device Types
A c ......
apacheµÄÔ´Âë°²×°
½«Ñ¹Ëõ°ü½âѹ֮ºó½øÈëÏàÓ¦µÄĿ¼
./configure \ #--------------------Ô¤±àÒëÃüÁî
"--prefix=/usr/local/apache" \ #--------------------°²×°Â·¾¶Îª“/usr/local/apache”
"--with-included-apr" \
"--enable-so" \ #--------------------¿ªÆôÏàÓ¦µÄÀ©Õ¹Ä£¿é ......
2008-07-07 22:05
³õʼ»¯
1£¬ip_conntrack_standalone_initÊÇcontrackÄ£¿éµÄ³õʼ»¯º¯Êý¡£ËüÖ÷ÒªÍê³ÉÒÔÏÂÄÚÈÝ£º
/*1, ³õʼ»¯conntrackÏà¹ØµÄÊý¾Ý½á¹¹£¬Èçhash±í£¬ip_conntrack_protocolÒÔ¼°ÄÚ´æ¹ÜÀíµÈ*/
ret = ip_conntrack_init();
if (ret < 0)
return ret;
#ifdef CON ......