IP Masquerade ¬O Linux µo®i¤¤ªº¤@ºØºô¸ô¥\¯à¡D¦pªG¤@¥x Linux ¥D¾÷¨Ï¥Î IP Masquerade ¥\¯à³s½u¨ìºô»Úºô¸ô¤W¡A¨º»ò±µ¤W¥¦ªº¹q¸£¡]¤£½×¬O¦b¦P¤@Ӱϰìºô¸ô¤W©ÎÂǥѼƾھ÷³s½u¡^¤]¥i¥H±µÄ²ºô»Úºô¸ô¡A§Y¨Ï¥¦Ì¨S¦³Àò±o¥¿¦¡«ü©wªº IP ¦ì§}¡D
³o¨Ï±o¤@¨Ç¹q¸£¥i¥HÁôÂæb¹h¹D(gateway) ¨t²Î«á±¦s¨úºô»Úºô¸ô¦Ó¤£³Qµo²{¡A¬Ý°_¨Ó´N¹³¥u¦³³oÓ¨t²Î¦b¨Ï¥Îºô»Úºô¸ô¡D¬ð¯}³]©w¨}¦nªº°°¸Ë(masquerade)¨t²Î¤§¦w¥þ¨¾Å@À³¸Ó·|¤ñ¬ð¯}¨}¦nªº«Ê¥]¹LÂo¦¡¨¾¤õÀð(packet filter firewall)¨Ó±o§ó¥[§xÃø¡]°²³]¨âªÌ¤§¤¤³£¨S¦³¿ù»~¡^¡D
IP Masquerade ¤´µM¦b¹êÅç¶¥¬q¡DµL½×¦p¦ó¡A®Ö¤ß±q 1.3.x ¶}©l¤w¸g¤º«Ø³o¶µ¤ä´©¡D³\¦hÓ¤H¬Æ¦Ü¤½¥q¥¿¦b¨Ï¥Î¥¦¡A¦Ó¦³º¡·Nªºµ²ªG¡D
ÂsÄýºô¶¥H¤Î»·ºÝñ¤J(telnet)¤w¸g¦³¦^³øªí¥Ü¥i¥H¦b IP Masquerade ¤W¹B§@¡DÀÉ®×¶Ç¿é(FTP)¡Aºô¸ô¥æ½Í(IRC) ¥H¤Î²âÅ¥ Real Audio ²{¦b¥i¥H¸ü¤J¬Y¨Ç¼Ò²Õ°t¦X¡D¨ä¥¦ªººô¸ô¸ê®Æ¬yµ°T (streaming audio) ¹³¬O True Speech ¥H¤Î Internet Wave ¤]¯à¹B§@¡D¤@¨Ç¶l»¼¦Cªí¤¤ªº¨Ï¥Î¹Ù¦ñ¬Æ¦ÜÁÙ¹Á¸Õ¹Lµø°T·|ij³nÅé¡D Ping
²{¦b°t¦X·sªñ¥i¥H¨ú±oªººô»Úºô¸ô±±¨î°T®§¨ó©w(ICMP)׸ÉÀɤ]¯à¹B§@¡D
§ó§¹¾ãªº¤ä´©³nÅé¦Cªí½Ð°Ñ¦Ò 4.3 ¸`¡D
IP Masquerade ¦b¼ÆºØ¤£¦Pªº§@·~¨t²Î¤Î¥»O¤W»P '«È¤áºÝ¾÷¾¹' °t¦X¨}¦n¡D¦¨¥\ªº®×¨Ò¦³¨Ï¥Î Unix, Windows95, Windows NT, Windows for Workgroup (with TCP/IP package), OS/2, Macintosh System's OS with Mac TCP, Mac Open Transport, DOS with NCSA Telnet package, VAX, Alpha with Linux, ¬Æ¦Ü Amiga with AmiTCP ©Î AS225-stack ªº¨t²Î¡D
¸`¦Û Ken eves ªº IP Masquerade FAQ:
³o¬O¤j³¡¤À²³æªº³]©w¯ó¹Ï: SLIP/PPP +------------+ +-------------+ to provider | Linux | SLIP/PPP | Anybox | <---------- modem1| |modem2 ----------- modem | | 111.222.333.444 | | 192.168.1.100 | | +------------+ +-------------+ ¤W±ªº¯ó¹Ï¤¤¤@¥x¦w¸Ë¨Ã°õ¦æ ip_masquerading ªº Linux ¾÷¾¹¨Ï¥Î modem1 ¸g¥Ñ SLIP/or/PPP ³s±µºô»Úºô¸ô¡D¥¦¦³¤@Ó «ü©wªº IP ¦ì§} 111.222.333.444¡D¥¦³]©w modem2 ¤¹³\¼·±µªÌ ñ¤J¨Ã°_©l SLIP/or/PPP ³sµ²¡D ²Ä¤GÓ¨t²Î¡]¤£¥²¬O°õ¦æ Linux ªº¨t²Î¡^¼·±µ¶i¤J Linux ¾÷¾¹¨Ã°_©l SLIP/or/PPP ³sµ²¡D¥¦¦bºô»Úºô¸ô¤W¨Ã¨S¦³«ü©wªº IP ¦ì§}©Ò¥H¥¦¨Ï¥Î 192.168.1.100¡D¡]°Ñ¾\¤Uz¡^ °t¦X ip_masquerade ¤Î¾A·í»¼°e°t¸m(routing configured) Anybox ³o¥x¾÷¾¹¥i¥H¸òºô»Úºô¸ô¥æ¬y´N¦p¦P¥¦¯uªº³s¦b¤W±¯ë ¡]°£¤F¤Ö¼Æ¨Ò¥~¡^¡D ¸`¿ý Pauline Middelink: §O§Ñ°O´£¨ì ANYBOX À³¸Ó§â Linux ¾÷¾¹·í§@¥¦ªº¹h¹D¡]µL½×¬O ¹w³]»¼°e¸ô®|©Î¥u¬OÓ¤lºô¸ô³£¨SÃö«Y¡^¡D¦pªG ANYBOX ¤£¯à°÷ ³o¼Ë³]¡A Linux ¾÷¾¹À³¸Ó¬°©Ò¦³n»¼°eªº¦ì§}°µ¥N²z¦ì§}¸ÑªR ªR¨ó©w(proxy arp) ªA°È¡A¦ý¥N²z¦ì§}¸ÑªRªº³]©w¶W¹L³o¥÷¤å¥ó ªº½d³ò¡D ¤U±¸`¿ý¦Û comp.os.linux.networking ªº¤@½g¥¬§i¨Ã¥Bµy¥[½s¿è¥H ²Å¦X¤Wz½d¨Òªº¥Îµü: ¡C§Ú§i¶D ANYBOX ³o¥x¾÷¾¹¶] slip ªº linux ¾÷¾¹¬O¥¦ªº¹h¹D¡D ¡C·í¤@Ó«Ê¥]±q ANYBOX ¶i¤J linux ¾÷¾¹®É¡A¥¦·|«ü©w·sªº¨Ó·½°ð ¸¹(source port number)¡A§â¥¦¦Û¤vªº ip ¦ì§}¶ë¤J«Ê¥]ªº¼ÐÀY¨Ã Àx¦sì¨Óªº¡DµM«á¥¦±N·|ÂÇ¥Ñ SLIP/or/PPP ¬É±§â×§ï¹Lªº«Ê¥] °e¤Wºô»Úºô¸ô¡D ¡C·í¤@Ó«Ê¥]±qºô»Úºô¸ô¨Ó¨ì linux ¾÷¾¹®É¡A¦pªG°ð¸¹¬O¤W±«ü©w ªº¨ä¤¤¤@Ó¡A¥¦±N·|¨ú¥Xì¨Óªº°ð¸¹¥H¤Î ip ¦ì§}¡A§â¥¦Ì©ñ¦^«Ê ¥]ªº¼ÐÀY¡A¨Ã¥B§â«Ê¥]°e©¹ ANYBOX ¡D ¡C°e¥X«Ê¥]ªº¥D¾÷±N¥Ã»·¤£ª¾¹D¨ä¤¤ªº®t§O¡D
¤@Ó IP Masquerading ªº¨Ò¤l:
¤U±ªº¹Ï¥Ü¬O¨å«¬ªº¨Ò¤l:-
+----------+ | | Ethernet | abox |:::::: | |2 :192.168.1.x +----------+ : : +----------+ PPP +----------+ : 1| Linux | link | | ::::| masq-gate|:::::::::// Internet | bbox |:::::: | | | |3 : +----------+ +----------+ : : +----------+ : | | : | cbox |:::::: | |4 +----------+ <-Internal Network->¦b³oÓ¨Ò¤l¤¤§Ú̦Ҽ{¥|¥x¹q¸£¨t²Î¡]·Q¥²»»»·ªº¥k¤èÁÙ¦³¨ÇªF¦èÅý§A¨ìºô»Úºô¸ôªº IP ³s½u¯à°÷³s±µ¡A¥H¤Î¤@¨Ç¡]»·¶W¹L³o¤@¶¡^¦bºô»Úºô¸ô¤W§A¦³¿³½ì¥æ´«¸ê°TªºªF¦è¡^¡D ³oÓ Linux ¨t²Î
masq-gate
¬O abox
, bbox
, cbox
¤º³¡ºô¸ô¾÷¾¹³s±µºô»Úºô¸ôªº°°¸Ë¹h¹D¡D
¤º³¡ºô¸ô¨Ï¥Î«ü©wªº¨p¥Î(private) ºô¸ô¦ì§}¡A¦b³oӮרҤ¤¬O class C ºô¸ô 192.168.1.0, Linux ¾÷¾¹¾Ö¦³¦ì§} 192.168.1.1 ¦Ó¨ä¥¦¨t²Î¤]¾Ö¦³¦¹ºô¸ô¤Wªº¦ì§}¡D
³o¤T¥x¾÷¾¹ abox
, bbox
¥H¤Î cbox
(¥¦Ì¥i¥H°õ¦æ¥ô¦ó§@·~¨t²Î ¡Ð ¹³¬O Windows 95, Macintosh MacTCP ©Î¬Æ¦Ü¬O¥t¤@¥x Linux ¾÷¾¹¡A¥un¥¦Ì¯à¤F¸Ñ IP)¥i¥H³s½u¨ìºô»Úºô¸ô¤Wªº¨ä¥¦¾÷¾¹¥h¡AµM¦Ó³oÓ°°¸Ë¨t²Î¹h¹D masq-gate
Âà´«¥¦Ì©Ò¦³ªº³s½u©Ò¥H³o¨Ç³s½u¬Ý°_¨Ó¹³¬O쥻§Y±q°°¸Ë¹h¹D masq-gate
¥»¨µo¥Xªº¡A¦Ó¥BÁÙ¦w±Æ°°¸Ë³s½u¶Ç¦^ªº¸ê®ÆÂà¦^ì¥ýªº¨t²Î ¡Ð ©Ò¥H¦b¤º³¡ºô¸ô¤Wªº¨t²Î¬Ý¨ìªº¬Oª½±µ³q©¹ºô»Úºô¸ôªº»¼°e¸ô®|¦Ó¥B¤£ª¾¹D¥L̪º¸ê®Æ³Q°°¸Ë¹L¡D
** ½Ð°Ñ¦Ò IP Masquerade Resource ¥HÀò±o³Ì·s¸ê°T¡A¦]¬°¸g±`§ó·s³o¥÷ HOWTO ¬Oº¡§xÃøªº¡D **