亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb

首頁 > 系統 > FreeBSD > 正文

FreeBSD6.1Release下利用route和ipfilter架設路由的方法

2020-10-28 18:52:14
字體:
來源:轉載
供稿:網友
架設此服務器,使內網用戶通過本服務器與外界通訊;基本原理為內網用戶通過FreeBSD內自帶的網關路由功能(route)與外網進行通訊,服務器的安全性及病毒的防護控制通過FreeBSD的ipfilter來完成。初步架設過程如下:

網卡接口說明:
vr0:外網網卡接口
vr1:內網網卡接口

1、    最小化安裝FreeBSD6.1Release
從ftp://ftp.FreeBSD.org/pub/FreeBSD/下載FreeBSD6.1Release鏡像文件,然后刻成光盤,將服務器設置成從光驅啟動,開始安裝,安裝時我選擇最小化安裝,開通ftp及ssh。其它的默認安裝就可以。具體可參考這篇文章。安裝完后重啟機器。

2、    安裝內核
將安裝光盤放入光驅,然后:
# /usr/sbin/sysinstall
然后選擇Configure --> Distributions -> src -> sys,點install,安裝完成后重啟機器。

3、    基本的配置
配置/etc/rc.conf
# cd /etc
# ee rc.conf
內容如下:
hostname="gatewall.wxic.edu.cn"
defaultrouter="172.16.252.17"
ifconfig_vr0="inet 172.16.252.x netmask 255.255.255.252"
ifconfig_vr1="inet 58.193.11x.25x netmask 255.255.248.0"
inetd_enable="YES"
linux_enable="YES"
sshd_enable="YES"
usbd_enable="YES"
sendmail_enable="NONE"

配置/etc/resolv.conf
# ee /etc/rc.conf
內容如下:
nameserver 58.193.112.1

4
、    配置內核,加入對ipfilter的支持
# cd /usr/src/sys/i386/conf
# cp GENERIC funpower
# ee funpower
然后開始編輯內核文件,機器和應用方面的不同會有不同的內核文件,因為需要用到ipfilter,我們加入對ipfilter的支持。在內核中加入如下內容:
options   IPFILTER
options   IPFILTER_LOG
options   IPFILTER_DEFAULT_BLOCK
其它選項可以參考這篇文章,然后自己定制。編輯完后保存退出。然后進行如下操作:
# /usr/sbin/config funpower
# cd ../compile/funpower
# make cleandepend
# make depend
# make
# make install
編譯完后重啟服務器(因為ipfilter默認是阻止所有通訊,所以確保你是在服務器前操作)。

5、    在/etc/rc.conf中加入路由選項
# cd /etc
# ee rc.conf
在最后加入如下幾行:
gateway_enable="YES"
static_routes="static1"
route_static1="-net 58.193.11x.0/21 172.16.252.x/30" //
說明第一個IP為內網IP范圍;第二個IP為外網網卡的網關地址

6、    配置ipfilter
在/etc/rc.conf中加入:

ipfilter_enable="YES"
ipfilter_rules="/etc/ipf.conf"
然后編輯/etc/ipf.conf文件
# cd /etc/
# ee ipf.conf
內容如下:
#環路網卡lo0 
#out in 全部通過

pass in quick on lo0 all
pass out quick on lo0 all

#
外網網卡vr0
#out 只讓開通的IP通訊

block out quick on vr0 from any to 192.168.0.0/16
block out quick on vr0 from any to 0.0.0.0/8
block out quick on vr0 from any to 169.254.0.0/8
block out quick on vr0 from any to 10.0.0.0/8
block out quick on vr0 from any to 127.16.0.0/12
block out quick on vr0 from any to 127.0.0.0/8
block out quick on vr0 from any to 192.0.2.0/24
block out quick on vr0 from any to 204.152.64.0/23
block out quick on vr0 from any to 224.0.0.0/3

#
開通58.193.112.1
pass out quick on vr0 proto tcp/udp from 58.193.112.1/32 to any keep state
pass out quick on vr0 proto icmp from 58.193.112.1/32 to any keep state

#開通
58.193.112.3
pass out quick on vr0 proto tcp/udp from 58.193.112.3/32 to any keep state
pass out quick on vr0 proto icmp from 58.193.112.3/32 to any keep state

#開通
58.193.113.1
pass out quick on vr0 proto tcp/udp from 58.193.113.1/32 to any keep state
pass out quick on vr0 proto icmp from 58.193.113.1/32 to any keep state

#開通
58.193.113.2
pass out quick on vr0 proto tcp/udp from 58.193.113.2/32 to any keep state
pass out quick on vr0 proto icmp from 58.193.113.2/32 to any keep state

block out on vr0 all

#in 阻止一些IP(比如私有IP)和一些病毒攻擊端口(如138139445等
)
block in quick on vr0 from 192.168.0.0/16 to any
block in quick on vr0 from 172.16.0.0/12 to any
block in quick on vr0 from 10.0.0.0/8 to any
block in quick on vr0 from 127.0.0.0/8 to any
block in quick on vr0 from 0.0.0.0/8 to any
block in quick on vr0 from 169.254.0.0/16 to any
block in quick on vr0 from 192.0.2.0/24 to any
block in quick on vr0 from 204.152.64.0/23 to any
block in quick on vr0 from 224.0.0.0/3 to any
block in quick on vr0 from 58.193.112.0/21 to any

block in quick on vr0 proto udp from any to any port = 69
block in quick on vr0 proto tcp/udp from any to any port = 135
block in quick on vr0 proto udp from any to any port = 137
block in quick on vr0 proto udp from any to any port = 138
block in quick on vr0 proto tcp/udp from any to any port = 139
block in quick on vr0 proto tcp/udp from any to any port = 445
block in quick on vr0 proto tcp/udp from any to any port = 593
block in quick on vr0 proto tcp from any to any port = 1022
block in quick on vr0 proto tcp from any to any port = 1023
block in quick on vr0 proto tcp from any to any port = 1025
block in quick on vr0 proto tcp from any port = 1034 to any port = 80
block in quick on vr0 proto tcp from any to any port = 1068
block in quick on vr0 proto tcp from any to any port = 1433
block in quick on vr0 proto udp from any to any port = 1434
block in quick on vr0 proto tcp from any to any port = 1871
block in quick on vr0 proto tcp from any to any port = 2745
block in quick on vr0 proto tcp from any to any port = 3208
block in quick on vr0 proto tcp from any to any port = 3127
block in quick on vr0 proto tcp from any to any port = 4331
block in quick on vr0 proto tcp from any to any port = 4334
block in quick on vr0 proto tcp from any to any port = 4444
block in quick on vr0 proto tcp from any port = 4444 to any
block in quick on vr0 proto tcp from any to any port = 4510
block in quick on vr0 proto tcp from any to any port = 4557
block in quick on vr0 proto tcp from any to any port = 5554
block in quick on vr0 proto tcp from any to any port = 5800
block in quick on vr0 proto tcp from any to any port = 5900
block in quick on vr0 proto tcp from any to any port = 6129
block in quick on vr0 proto tcp from any to any port = 6667
block in quick on vr0 proto tcp from any to any port = 9995
block in quick on vr0 proto tcp from any to any port = 9996
block in quick on vr0 proto tcp from any to any port = 10080

block in quick on vr0 all with frags
block in quick on vr0 proto tcp all with short
block in quick on vr0 all with opt lsrr
block in quick on vr0 all with opt ssrr
block in log first quick on vr0 proto tcp from any to any flags FUP
block in quick on vr0 all with ipopts

pass in quick on vr0 proto tcp from any to any port = 80 flags S keep state
pass in quick on vr0 proto tcp from any to any port = 23 flags S keep state
pass in quick on vr0 proto tcp from any to any port = 22 flags S keep state
pass in quick on vr0 proto tcp from any to any port = ftp flags S/SA keep state
pass in quick on vr0 proto tcp from any to any port = ftp-data flags S/SA keep state
pass in quick on vr0 proto tcp from any to any port 30000 >< 50001 flags S/SA keep state

pass in quick on vr0 proto icmp from any to any icmp-type 0
pass in quick on vr0 proto icmp from any to any icmp-type 11
block in log quick on vr0 proto icmp from any to any

block in log on vr0 all


#內網網卡
vr1
#out 全部通過

pass out on vr1 all
#in
全部通過
pass in on vr1 all

配置完后重啟服務器。

找一臺客戶機測試,首先使用ipf.conf中開通的IP,然后ping edu.cn,可以ping通,說明可以連接外網了。
然后將IP設置為不是開通列表中的IP,如果ping不通,則說明ipf.conf的設置生效了。
發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
亚洲香蕉成人av网站在线观看_欧美精品成人91久久久久久久_久久久久久久久久久亚洲_热久久视久久精品18亚洲精品_国产精自产拍久久久久久_亚洲色图国产精品_91精品国产网站_中文字幕欧美日韩精品_国产精品久久久久久亚洲调教_国产精品久久一区_性夜试看影院91社区_97在线观看视频国产_68精品久久久久久欧美_欧美精品在线观看_国产精品一区二区久久精品_欧美老女人bb
亚洲二区中文字幕| 亚洲精品97久久| 538国产精品一区二区在线| 蜜臀久久99精品久久久久久宅男| 色综合久久天天综线观看| 国产精品热视频| 亚洲人成五月天| 亚洲国产成人精品久久| 国产国语刺激对白av不卡| 日韩av综合中文字幕| 啪一啪鲁一鲁2019在线视频| 国产精品欧美激情在线播放| 亚洲第一天堂无码专区| 国产精品十八以下禁看| 国产欧美日韩视频| 午夜精品久久久久久久99热| 欧美国产欧美亚洲国产日韩mv天天看完整| 国产精品久久久久久久av大片| 成人在线视频网站| 大胆人体色综合| 精品一区二区电影| 精品国产91久久久久久老师| 欧美成年人视频网站| 国内精品久久久久影院优| 国产在线98福利播放视频| 日韩精品中文字幕在线观看| 亚洲日韩欧美视频| 国产欧美精品久久久| 久久久久亚洲精品国产| 2021久久精品国产99国产精品| 亚洲欧美在线免费观看| 亚洲裸体xxxx| 亚洲精品第一国产综合精品| 亚洲日本成人网| 亚洲国产精品va| 成人激情在线观看| 精品一区二区电影| 欧美国产日韩精品| 中文字幕亚洲第一| 亚洲一级免费视频| 久久国产精品久久久久久| 一区二区三区国产在线观看| 久久国产精品首页| 国产精品丝袜久久久久久高清| 91高清免费在线观看| 亚洲欧美中文另类| 亚洲国产精品人久久电影| 黄色成人在线免费| 精品日本高清在线播放| 欧美午夜美女看片| 午夜精品一区二区三区视频免费看| 午夜精品久久久久久久久久久久久| 亚洲欧美色图片| 日韩电影在线观看永久视频免费网站| 最近2019年手机中文字幕| 久久综合网hezyo| 在线不卡国产精品| 亚洲人精选亚洲人成在线| 久久手机精品视频| 欧美午夜视频一区二区| 亚洲精品一区二三区不卡| 日本精品一区二区三区在线| 黑人巨大精品欧美一区二区免费| 精品国产一区二区三区久久久狼| 人九九综合九九宗合| 中文字幕亚洲无线码a| 成人国产精品av| 日韩欧美在线观看视频| 久久久久久国产| 国产精品久久激情| 欧美日韩亚洲一区二| 亚洲黄页视频免费观看| 中文字幕久久久| 久久在线观看视频| 琪琪第一精品导航| 国产97色在线|日韩| 欧美在线视频一区| 色一区av在线| 欧美精品日韩三级| 欧美成人精品在线视频| 国产亚洲欧美视频| 久久亚洲精品国产亚洲老地址| 九九热这里只有在线精品视| 亚洲精品视频在线播放| 亚洲男人av电影| 欧美在线视频免费| 国产精品无av码在线观看| 国产成人精品免费视频| 国产大片精品免费永久看nba| 国产精品嫩草影院一区二区| 亚洲自拍小视频| 精品国内亚洲在观看18黄| 日韩电影免费观看在线| 日韩国产高清污视频在线观看| 国产精品激情av电影在线观看| 日韩综合视频在线观看| 欧美日本高清视频| 日韩精品在线观看一区| 欧美xxxx14xxxxx性爽| 亚洲乱码一区av黑人高潮| 欧美一二三视频| 高潮白浆女日韩av免费看| 亚洲免费视频在线观看| 91麻豆国产精品| 久久久国产精品一区| 久久久女女女女999久久| 国产欧美一区二区三区视频| 中文字幕成人精品久久不卡| 亚洲精品在线观看www| 欧美大学生性色视频| 国产一区视频在线播放| 日韩av网站电影| 国产精品激情av在线播放| 国产精品第一视频| 奇米成人av国产一区二区三区| 九九热这里只有精品6| 亚洲精品97久久| 亚洲国产欧美一区二区丝袜黑人| 欧美www视频在线观看| 亚洲自拍在线观看| 亚洲欧洲激情在线| 亚洲男人第一av网站| 成人免费观看49www在线观看| 欧美一级成年大片在线观看| 欧美一级成年大片在线观看| 69久久夜色精品国产7777| 国产91成人在在线播放| 日本韩国欧美精品大片卡二| 久久精品91久久久久久再现| 亚洲成人网在线观看| 欧美性做爰毛片| 国产欧美精品日韩| 国产精品久久久久久av| 欧美午夜丰满在线18影院| 中文综合在线观看| 92看片淫黄大片欧美看国产片| 欧美极品少妇xxxxⅹ裸体艺术| 欧美黑人一级爽快片淫片高清| 欧美福利视频网站| 国产精品久久久av| 国产伦精品一区二区三区精品视频| 视频在线观看一区二区| 国产精品国产福利国产秒拍| 日韩在线观看免费网站| 国产v综合v亚洲欧美久久| 青草青草久热精品视频在线网站| 国产精品美女午夜av| 中文字幕在线国产精品| 最近中文字幕2019免费| 欧美亚洲免费电影| 亚洲欧美日韩第一区| 成人高清视频观看www| 亚洲加勒比久久88色综合| 欧美激情按摩在线| 日韩精品视频中文在线观看| 一本色道久久88亚洲综合88| 久久成人在线视频| 国产精品网红福利| 久久久久久久久久久av| 91精品免费视频| 国产97色在线|日韩| 亚洲第一天堂无码专区| 欧美高清激情视频| 6080yy精品一区二区三区|