Ï¡·¹¶¥¿Í×ÛºÏÉçÇøÏ¡·¹¶¥¿Í×ÛºÏÉçÇø

Ê×Ò³ | ×îÈȰæ¿é | »îÔ¾»áÔ± | ±¾ÖÜÈȵ㠷µ»ØUnix


·¢ÌùÈË:Nashira
·¢±íʱ¼ä:Fri Sep 14 12:41:23 2007
ËäÈ»FreeBSDÍø¹ØÅÜÆðÀ´ÁË£¬µ«»¹ÓÐºÜ¶àµØ·½²»ÍêÉÆ£¬ÎÒÃÇÐèÒª½øÒ»²½ÍêÉÆ:)

1.ÍêÉÆ·À»ðǽ
#ee /etc/ipfw.conf

cmd="ipfw -q add "
#Ð£Ô°Íø½Ó¿Ú
exif="xl0"
#¾ÖÓòÍø½Ó¿Ú
inif="fxp0"
#adslÐéÄâËíµÀÉ豸
adsl="tun0"

#Á½¸öºê
skip="skipto 50000"
ks="keep-state"

#Çå³ý·À»ðǽ¹æÔò
ipfw -q -f flush

#´ò¿ª¾ÖÓòÍø£¬»Ø»·É豸£¨127.0.0.1£©ºÍÁ¬½ÓadslµÄÍøÂç½Ó¿Ú
$cmd 10 allow all from any to any via $inif
$cmd 20 allow all from any to any via lo0
#$cmd 30 allow all from any to any via rl0

#nat½øÈëÐ£Ô°ÍøµÄip
$cmd 100 divert natd all from any to any in via $exif
#$cmd 110 check-state

#·ÅÐдÓÄÚ²¿ÏòÍâÍøµÄÁ¬½Ó£¬Ò²¿ÉÒÔʹÓøü¼ÓÑϸñµÄ²ßÂÔ£¬ÎÒ×Ô¼ºÓþÍËãÁË£¬ºÇºÇ~
$cmd 10000 $skip udp from any to any out via $exif $ks
$cmd 10010 $skip tcp from any to any out via $exif setup $ks
$cmd 10020 $skip icmp from any to any out via $exif $ks

$cmd 10100 allow udp from any to any out via $adsl $ks
$cmd 10110 allow tcp from any to any out via $adsl setup $ks
$cmd 10120 allow icmp from any to any out via $adsl $ks

#´ò¿ª±¾»ú¶ÔÍâÍøµÄftpºÍssh¶Ë¿Ú£¬ºÍicmpÊÔ̽
$cmd 20000 allow udp from any to me 20,21 via $exif $ks
$cmd 20010 allow icmp from any to me via $exif $ks
$cmd 20020 allow tcp from any to me 20,21,22 via $exif setup $ks

#×èÖ¹ÆäËüµÄÊý¾Ý¶Ô½øÈë±¾»ú
#ps£º×òÌìÀ¹½Øµ½ÁË1.8GBµÄÊý¾Ý£¬ºÇºÇ£¬²¡¶¾º¦ËÀÈ˰¢~
$cmd 40000 deny all from any to any

#natÁ÷ÏòÍâÍøµÄÊý¾Ý
$cmd 50000 divert natd all from any to any out via $exif

·À»ðǽÕâÑùÉèÖÃÖ®ºóÄÚ²¿¿ÉÒÔÎÞÏÞÖÆµÄ·ÃÎÊÍâÍø£¬¶øÍâÍøÖ®Äܹ»Á¬½Óµ½±¾»ú¿ª·ÅµÄftpºÍs
sh·þÎñ£¬Ò»Ð©¹¥»÷±»×èµ²ÁË~


2.ÔÚÄÚÍøÌṩdhcp·þÎñ

ÐèÒª°²×°isc-dhcp3-serverÈí¼þ
¿ÉÔÙ´Óports°²×°£¬ÔÚ£º/usr/ports/net/isc-dhcp3-server/
Ò²¿ÉÒÔpackage°²×°£¬¿´¸öÈËϲºÃÁË£¬ºÇºÇ~
#cd /usr/ports/net/isc-dhcp3-server/
#make install clean
#rehash

È»ºóÐÞ¸ÄÅäÖÃÎļþ
#ee /usr/local/etc/dhcpd.conf
ÄÚÈÝÈçÏ£º
option domain-name "jlu.edu.cn";
#DNS·þÎñÆ÷£¬ÍøÍ¨ºÍÐ£Ô°Íø¶¼ÓÐ
option domain-name-servers 202.98.0.68,202.198.16.3,202.98.5.68,202.198.16.5;

#option domain-name-servers 202.198.16.3,202.198.16.5;
#×ÓÍøÑÚÂë
option subnet-mask 255.255.255.0;
#·Ö·¢µÄipʱ¼ä
default-lease-time 86400;
max-lease-time 86400;
#ÍüÁËÊǸÉɶµÄÁË£¬ºÇºÇ£¬²»¹ýÐèÒªÏóÏÂÃæÕâÑù:)
ddns-update-style none;
#¾ÖÓòÍøÉϵÄipµØÖ··¶Î§£¬¸ù¾ÝÄã×Ô¼ºµÄÉ趨~
subnet 192.168.18.0 netmask 255.255.255.0 {
range 192.168.18.1 192.168.18.8;
#±¾»úµÄÄÚÍø½Ó¿Ú
option routers 192.168.18.254;
}

ÐÞ¸Ä/etc/rc.conf
Ìí¼ÓÏÂÁÐÈýÐУº
#dhcp server
dhcpd_enable="YES"
dhcpd_ifaces="fxp0" #fxp0ΪÄÚÍø½Ó¿Ú

×îºó
#reboot
»òÕß
#/usr/local/etc/rc.d/isc-dhcpd start
¾Í¿ÉÒÔÁË

3.×Ô¶¯¿ª¹Ø»ú

±¾¿ÆÉúËÞÉáÒ»°ã¶¼ÊÇҪͣµçµÄ£¬ËùÒÔÿÌìÒª¿ª¹Ø»úÒ²ÊǺÜÂé·³µÄ£¬ÎÒÃÇÈÃËû×Ô¶¯½øÐУ¬ºÙ
ºÙ~

¿ª»ú£º
Õâ¸öÓõÄÊÇÎÒ»úÆ÷µÄÒ»¸öbug£¬ÎҵĻúÆ÷acpiÓÐÎÊÌ⣬²»»á×Ô¶¯¹Ø±ÕµçÔ´£¬ËùÒÔÿ´Î¶¼ÊÇ¡°
·Ç·¨¹Ø»ú¡±£¬ºÇºÇ~
ÔÚBIOSÖÐÉèÖãºAfter power down : on
ÿ¸ö»úÆ÷¶¼²»´óÒ»Ñù£¬ºÃºÃÕÒÕÒ£¬´ó¸ÅÒâ˼¾ÍÊǵ±»úÆ÷ͻȻ¶Ïµçºó£¬ÔÙÀ´µçµÄʱºò»úÆ÷ÊÇ
·ñ×Ô¶¯¿ª»ú£¬ÎÒÃÇ¿ÉÒÔÑ¡Ôñ¿ª»ú£¬ÕâÑùµ±µÚ¶þÌìÀ´µçµÄʱºò»úÆ÷¾Í×Ô¶¯Æô¶¯ÁË~

¹Ø»ú£º
ÎÒÃÇÓÃcronÀ´Ê¹»úÆ÷ÔÚ¿ìϨµÆÊ±×Ô¶¯¹Ø±Õ
#ee /etc/crontab
Ìí¼ÓÈçÏÂÁ½ÐÐ
0 23 * * 0-4 root /sbin/shutdown -p 23:28
0 23 * * 5-6 root /sbin/shutdown -p 23:58
ÕâÑùÿÌì23£º00ʱ¶¼»áÖ´ÐÐshutdown -p£¬²¢Ìáʾ½«Òª¹Ø»ú£¬²¢ÔÚϨµÆÇ°Á½·ÖÖӹػú¡£

PS£ºÇëÈ·±£»úÆ÷µÄʱÖÓÕýÈ·£¬·ñÔò¡­¡­

µ÷Õûʱ¼ä¿ÉÒÔÓà dataÃüÁî~

4.ÅäÖÃsshd

#ee /etc/ssh/sshd_config
ÉèÖÃÏÂÃæ¼¸Ïî
#ÔÊÐírootÓû§µÇ¼
PermitRootLogin yes
#ÔÊÐíÃÜÂëÈÏÖ¤
PasswordAuthentication yes
#½ûÓÃDNS£¬DNSÅäÖôíÎóʱ¿ª»ú»áºÜÂý
UseDNS no

PermitRootLogin ºÍ PasswordAuthentication ¶¼ÊDz»°²È«µÄ×ö·¨£¬µ«ÊÇÎÒ×Ô¼ºÓ㬷½±ã
¾ÍºÃ£¬ºÇºÇ~

×îºóÐÞ¸Ä/etc/rc.conf
Ìí¼ÓÏÂÁÐÁ½ÐУº
#ssh server
sshd_enable="YES"


¾­¹ýÉÏÃæµÄÉèÖã¬ÄãµÄFreeBSDÍø¹Ø¾Í¿ÉÒÔ×Ô¼ºÄ¬Ä¬µØÔÚij¸ö½ÇÂäÀ﹤×÷ÁË£¬°Ñ¼üÅÌ£¬ÏÔʾ
Æ÷°Îµô¿ÉÒԺܶàÌì²»ÓùÜËü£¬Ëü¿ÉÒÔ×Ô¼º¹¤×÷µÄºÜºÃ~

--
¢ÙδÂú18ÖÜËêÈËÊ¿ÇëÔÚ¸¸Ä¸Ö¸µ¼ÏÂÓë±¾ÈËÁÄÌì¡£
¢Ú±¾ÈË·ÇרҵÁÄÌìÈËÊ¿£¬¡£²»³Ðµ£Ö÷¶¯´òÕкô¡¢Ö÷¶¯ÕÒ»°ÌâµÄÒåÎñ¡£
¢Ûл¾ø"ÈýÎÊÒ»´ðÖÆ"£¬Ð»¾øÔÚÁÄÌìµÄʱºòʹÓÃ"Ŷ"£¬ÔÚ±¾È˲»»Ø¸´µÄÇé¿öÏÂÇë×Ô¾õÍ£Ö¹Ò»ÇÐÐÅÏ¢¡£
¡¾×¢¡¿£º±¾ÈËÓµÓÐ×îÖÕ½âÊÍȨ£¡£¡£¡

¡ù À´Ô´:£®¼ªÁÖ´óѧĵµ¤Ô°Õ¾ bbs.jlu.edu.cn [FROM: 219.217.63.*]

¡ù ÐÞ¸Ä:£®Nashira ì¶ Sep 14 12:51:01 2007 Ð޸ı¾ÎÄ£®[FROM: 219.217.63.*]




Ïà¹ØÖ÷Ìâ:
×îÐÂÈÈÌù