Chapter 12 Networking

Biing Jong Lin
12.1. §ÚÀ³¸Ó¨ì­þÃä§ä¦³ÃöµLºÏºÐ¶}¾÷ ¡§diskless booting¡¨ ªº¸ê®Æ¡H
12.2. FreeBSD ªº¥D¾÷¥i¥H·í§@¬Y­Óºô¸ô¤Wªº¸ô¥Ñ¾¹(router)¶Ü¡H
12.3. §Ú¥i¥H³z¹L FreeBSD ±N§Úªº Win95 ¾÷¾¹³s¤W Internet ¶Ü¡H
12.4. FreeBSD ¤ä´© SLIP ©M PPP ¶Ü¡H
12.5. FreeBSD ¤ä´© NAT ©Î Masquerading ¶Ü¡H
12.6. §Ú¦p¦ó±N¨â¥x FreeBSD ¥D¾÷¥Î¥­¦æ°ð (parallel line) ³z¹L PLIP ³s½u¡H
12.7. §Ú¨S¦³¿ìªk«Ø¥ß /dev/ed0 ³o­Ó device¡A ¬°¤°»ò¡H
12.8. §Ú¦p¦ó«Ø¥ß Ethernet aliases¡H
12.9. §Ú¦p¦ó«ü©w§Úªº 3C503 ¨Ï¥Î¨ä¥L¤£¦Pªºªº network port¡H
12.10. ¬°¤°»ò§Ú¦b¨Ï¥Î FreeBSD ªº NFS ®É¥X²{°ÝÃD¡H
12.11. ¬°¤°»ò§Ú¤£¯à NFS-mount Linux ªº¾÷¾¹¡H
12.12. ¬°¤°»ò§Ú¤£¯à NFS-mount Sun ªº¾÷¾¹¡H
12.13. ¬°¤°»ò mountd ¤@ª½°­¥s»¡ ¡§can't change attributes¡¨ ¦Ó¥B§Ú¤@ª½¬Ý¨ì ¡§bad exports list¡¨ ³o­Ó°T®§¦b§Úªº FreeBSD NFS ¦øªA¾¹¤W¡H
12.14. ¬°¤°»ò§Ú¦b¨Ï¥Î PPP ³s½u¨ì NeXTStep ¾÷¾¹®É¦³°ÝÃD¡H
12.15. §Ú­n«ç¼Ë¤~¯à§â IP multicast support ¥´¶}¡H
12.16. ­þ¨Çºô¸ô¥d¬O¨Ï¥Î DEC PCI chipset¡H
12.17. ¬°¤°»ò­n¥Î FQDN ¤~¯à³s¨ì¨ä¥L¾÷¾¹¡H
12.18. ¬°¤°»ò§Ú¦b³s½u®É¤@ª½¥X²{ ¡§Permission denied¡¨ ªº¿ù»~°T®§¡H
12.19. IPFW ·|³y¦¨¦h¤jªººô¸ô©µ¿ð¡H
12.20. ¬°¤°»ò§Úªº ipfw ¡§fwd¡¨ redirect ³W«h±NªA°ÈÂà¦V¨ä¥L¾÷¾¹®ÉµLªk¥¿±`¹B§@¡H
12.21. ­n¦p¦ó§â¹ï¬Y¥x¾÷¾¹ªººô¸ôªA°È­n¨D(service request)Âà¦V¨ì¥t¤@¥x¡H
12.22. ¨º¸Ì¥i¥H§ä¨ìºÞ²zÀW¼eªº¤u¨ã¡H
12.23. «ç»ò·|¶]¥X ¡§/dev/bpf0: device not configured¡¨³o­Ó°T®§¡H
12.24. §Ú­n«ç¼Ë¤~¯à±N Windows ¾÷¾¹¤¤ªººÏºÐ±¾¤J¨t²Î, ´N¹³ Linux ´£¨Ñ ªº smbmount ¨º¼Ë¡H
12.25. §Ú¦b¨t²Î¤é»x¤¤µo²{¥H¤U°T®§¡G ¡§icmp-response bandwidth limit 300/200 pps¡¨¡A³o¬O ½¼¦Ì¸J¿|¡H
12.26. ³o­Ó¿ù»~°T®§ ¡§arp: unknown hardware address format¡¨ ¬O¤°»ò·N«ä¡H
12.27. §Ú­è­è¸Ë¦n CVSup ®M¥ó¡A¦ý¬O¦b¹Á¸Õ°õ¦æ®Éµo¥Í¤F¿ù»~¡A­n«ç»ò¿ì¡H

12.1. §ÚÀ³¸Ó¨ì­þÃä§ä¦³ÃöµLºÏºÐ¶}¾÷ ¡§diskless booting¡¨ ªº¸ê®Æ¡H

¡§Diskless booting¡¨ ´N¬OÅý FreeBSD ¥D¾÷±qºô¸ô ¤W¶}¾÷¡A¨Ã¥B±qºô¸ô¤Wªº server ¤WŪ¨ú¨ä¥L¥²­nªºÀɮסA¦Ó«D¥Ñ¥D¾÷ ªºµwºÐ¤W¨ú±o³o¨ÇÀɮסC¸Ô²Óªº¸ê®Æ¥i¥H°Ñ¦Ò FreeBSD ¤â¥UªºµLºÏºÐ¶}¾÷½g ¡C

12.2. FreeBSD ªº¥D¾÷¥i¥H·í§@¬Y­Óºô¸ô¤Wªº¸ô¥Ñ¾¹(router)¶Ü¡H

¬Oªº¡C½Ð°Ñ¦Ò FreeBSD ¤â¥Uªººô¸ô¶i¶¥½g advanced networking¡A¤×¨ä¬O¸ô¥Ñ»P¹h¹D¾¹ routing and gatewaysªº³¡¤À¡C

12.3. §Ú¥i¥H³z¹L FreeBSD ±N§Úªº Win95 ¾÷¾¹³s¤W Internet ¶Ü¡H

°ò¥»¤W¡A·|°Ý³oºØ°ÝÃDªº¤H¦b®a¸Ì¦Ü¤Ö¦³¨â¥x¹q¸£¡A¤@¥x¶] FreeBSD ¥t¥~¤@¥x¶] Win95¡F³o­Ó·Qªk¬O±N FreeBSD ¥D¾÷³s¤W Internet¡AµM«á³z ¹L³o¥x FreeBSD ¥D¾÷¡AÅý¶] Win95 ªº¹q¸£¯à°÷¤Wºô¡C³o­Ó°ÝÃDºâ¬O«e¤@ ­Ó°ÝÃDªº¤@­Ó¯S¨Ò

... µª®×¬O¡G¥i¥Hªº¡I¦b FreeBSD 3.x ª©¤¤¡A¨Ï¥ÎªÌ¼Ò¦¡(user-mode)ªº ppp(8) ¥]§t¤F -nat ¿ï¶µ¡C¦pªG§A¦b /etc/rc.conf ¨Ï¥Î-nat¿ï¶µ¨Ã ³]©w gateway_enable ¬° YES ¡A¥H³oºØ³]©w±Ò°Ê ppp(8) ¡A¨Ã¥B¥¿½Tªº³]©w§Aªº Windows ¥D¾÷ªº ¸Ü¡A³o­Ó°µªkÀ³¸Ó¬O¥i¥H¥¿±`¨Ï¥Îªº¡C

Ãö©ó¥»¥DÃD§ó¸Ô²Óªº¸ê®Æ¥i¥H°Ñ¦Ò Steve Sims ©Ò¼¶¼gªº Pedantic PPP Primer ¤@¤å¡C

¦pªG§A¨Ï¥Îªº¬O®Ö¤ß¼Ò¦¡ (kernel-mode) PPP¡A©ÎªÌ§A¦³°Ï°ì³s½u (Ethernet connection) ¥i³q¹F Internet ªº¸Ü¡A§A±N»Ý­n¨Ï¥Î natd(8)¡C½Ð¬d¾\ FAQ ¤¤Ãö©ó natd ªº³¡¤À¡C

12.4. FreeBSD ¤ä´© SLIP ©M PPP ¶Ü¡H

¬Oªº¡C§A¥i¥H¬d¬d man pages ¤¤Ãö©ó slattach(8)¡A sliplogin(8)¡Appp(8)¡A¥H¤Î pppd(8) ªº³¡¤À¡C ppp(8) ¤Î pppd(8) ´£¨Ñ¶i¥XÂù¦V³s½uªº¤ä´©¡A¥t¥~ sliplogin(8) ±Mªù´£¨Ñ¶i¤J³s½uªº¤ä´©¡A¦Ó slattach(8) ±Mªù´£¨Ñ¦V¥~³s½uªº¤ä´©¡C

¦pªG§A»Ý­n§ó¶i¤@¨Bªº¸ê®Æªº¸Ü,½Ð¬d¾\ FreeBSD ¤â¥U¤¤Ãö©ó PPP »P SLIP ªº»¡©ú¡C

¦pªG§A¥u¯à°÷¹L ¡§shell account¡¨ ³s½u¨ì Internet ªº¸Ü¡A§A¤]³\¥i¥H¸Õ¸Õ net/slirp ³o­Ó®M¥óµ{¦¡¡C³o­Ó®M¥óµ{¦¡¥i¥H´£¨Ñ§Aªº¹q¸£ª½±µ³s¤W¬Y¨Ç(­­©wªº)ªA°È ³s½u¡A¦p ftp ¤Î http µ¥µ¥¡C

12.5. FreeBSD ¤ä´© NAT ©Î Masquerading ¶Ü¡H

¦pªG§A¦³¤@­ÓªñºÝªº¤lºô¸ô(¦³¤@¥x¥H¤Wªº¾÷¾¹)¡A¦ý¬O§Aªº Internet provider «o¥u¤À°t¤@­Ó IP number µ¹§A(©ÎªÌ§A¥u¤À°t¨ì¤@­Ó °ÊºAªº IP number)¡A§A¥i¥H°Ñ¦Ò natd(8) ³o­Óµ{¦¡¡C natd(8) Åý§A¥i¥H³z¹L³o¤@­Ó IP number Åý¾ã­Ó¤lºô¸ôªº¹q¸£³£¯à³s¤W internet¡C

ppp(8) ³o­Óµ{¦¡¤]´£¨ÑÃþ¦üªº¥\¯à¡A¦pªG§A«ü©w -nat ¿ï¶µ¡Calias library (libalias(3)) ¦b³o¨â­Ó³B²z¤è¦¡¤¤³£·|³Q¨Ï¥Î¨ì¡C

12.6. §Ú¦p¦ó±N¨â¥x FreeBSD ¥D¾÷¥Î¥­¦æ°ð (parallel line) ³z¹L PLIP ³s½u¡H

½Ð°Ñ¦Ò¤â¥U¤¤Ãö©ó PLIP section ªº³¡¤À¡C

12.7. §Ú¨S¦³¿ìªk«Ø¥ß /dev/ed0 ³o­Ó device¡A ¬°¤°»ò¡H

¦]¬°¤£»Ý­n¡I¦b Berkeley ºô¸ô¬[ºc¤¤¡A¥u¦³ kernel µ{¦¡½X¥i¥Hª½ ±µ¦s¨úºô¸ô¬É­±¥d¡C½Ð°Ñ¦Ò /etc/rc.network ³o ­ÓÀɮשM manual pages ¨ú±o»P¨ä¥L¤£¦Pºô¸ôµ{¦¡¡C§ó¶i¤@¨Bªº¸ê°T¡G¦p ªG§Aı±o§A§¹¥þ·d²V¤Fªº¸Ü¡A±zÀ³¸Ó§ä¤@¥»»P¨ä¥L BSD ¬ÛÃö§@·~¨t²Îºô¸ô ºÞ²z¦³Ãö®Ñ¨Ó°Ñ¦Ò¡F°£¤F¤Ö¼ÆÅãµÛªº¤£¦P¥~¡AFreeBSD ªººô¸ôºÞ²z°ò¥»¤W©M SunOS 4.0 ©M Ultrix ¬O¤@¼Ëªº¡C

12.8. §Ú¦p¦ó«Ø¥ß Ethernet aliases¡H

¦pªG§Aªº alias ¦ì§}¸ò§A¥Ø«eºô¸ô¤¶­±ªº¦ì§}¦b¦P¤@­Ó¤lºô¸ô¤Uªº ¸Ü¡A¥[¤J¤@­Ó netmask 0xffffffff ¦b§Aªº ifconfig(8) command-line¡A½d¨Ò¦p¤U¡G

# ifconfig ed0 alias 192.0.2.2 netmask 0xffffffff

¤£µMªº¸Ü¡A´N¦p¦P¥[¤J¤@­Ó·sªººô¸ô¦ì§}¤@¼Ë¿é¤J§Aªººô¸ô¦ì§}»P¤l ºô¸ô¾B¸n¡G

# ifconfig ed0 alias 172.16.141.5 netmask 0xffffff00

12.9. §Ú¦p¦ó«ü©w§Úªº 3C503 ¨Ï¥Î¨ä¥L¤£¦Pªºªº network port¡H

¦pªG±z·Q¨Ï¥Î¨ä¥Lªº port¡A§A¥²¶·¦b ifconfig(8) ªº©R¥O¤¤ «ü©wÃB¥~ªº°Ñ¼Æ¡C¤º©wªº port ¬O link0¡C­n¨Ï¥Î AUI port ¥N´À BNC port ªº¸Ü¡A§ï¥Î link2¡C³o¨Ç flags À³¸Ó§ïÅÜifconfig_* ªºÅܼƨӫü©w¡A §A¥i¥H¦b /etc/rc.conf ³o­ÓÀɮ׸̭±§ä¨ì (½Ð°Ñ¦Ò rc.conf(5))¡C

12.10. ¬°¤°»ò§Ú¦b¨Ï¥Î FreeBSD ªº NFS ®É¥X²{°ÝÃD¡H

§Ú­Ì¥Î§t»W¤@ÂIªº»¡ªk¡A¬Y¨Ç PC ªººô¸ô¥d¤ñ¨ä¥Lªº¦n¡A³oºØª¬ªp¦b ³y¦¨ NFS ³oºØ¹ïºô¸ô±Ó·Pªºµ{¦¡¦³®É·|¥X²{°ÝÃD¡C

°Ñ¦Ò the Handbook entry on NFS ¥HÀò±o³o­Ó¥DÃDªº§ó¦h¸ê°T¡C

12.11. ¬°¤°»ò§Ú¤£¯à NFS-mount Linux ªº¾÷¾¹¡H

¬Y¨Çª©¥»ªº Linux NFS µ{¦¡½X¥u±µ¨ü privileged port ªº mount request¡F¸Õ¥Î³o¦æ«ü¥O¬Ý¬Ý

# mount -o -P linuxbox:/blah /mnt

12.12. ¬°¤°»ò§Ú¤£¯à NFS-mount Sun ªº¾÷¾¹¡H

¶] SunOS 4.X ªº Sun ¤u§@¯¸¥u±µ¨ü¨Ó¦Û privileged port ªº mount request¡F¸Õ¥Î³o¦æ«ü¥O¬Ý¬Ý

# mount -o -P sunbox:/blah /mnt

12.13. ¬°¤°»ò mountd ¤@ª½°­¥s»¡ ¡§can't change attributes¡¨ ¦Ó¥B§Ú¤@ª½¬Ý¨ì ¡§bad exports list¡¨ ³o­Ó°T®§¦b§Úªº FreeBSD NFS ¦øªA¾¹¤W¡H

³o­Ó°ÝÃD³Ì±`µo¥Íªº­ì¦]¬O¦b©ó¤£¤F¸Ñ /etc/exports ªº¥¿½T®æ¦¡¡C½Ð¸ÔŪ exports(5) ¥H¤Î¤â¥U¤¤Ãö©ó NFS ªº³¡¤À¡A¯S§O¬Oconfiguring NFS³o¤@¬q¡C

12.14. ¬°¤°»ò§Ú¦b¨Ï¥Î PPP ³s½u¨ì NeXTStep ¾÷¾¹®É¦³°ÝÃD¡H

§â TCP extensions ¨ú®ø¡A³o­Ó³]©w¦b /etc/rc.conf ¸Ì­±(°Ñ¦Ò rc.conf(5)) §â ¥H¤U³o­Ó­È³]¦¨ NO¡G

tcp_extensions=NO

Xylogic ªº Annex ¥D¾÷¤]¦³¬Û¦Pªº°ÝÃD¡A±z­n°µ¬Û¦Pªº­×§ï¤~¯à³s ¤W³o¨Ç¥D¾÷¡C

12.15. §Ú­n«ç¼Ë¤~¯à§â IP multicast support ¥´¶}¡H

FreeBSD 2.0 ¥H«áªºª©¥»¤º©w³£¦³ ¤ä´© Multicast host ¾Þ§@¡C¦pªG ±z·Q±N±zªº¥D¾÷³]©w¦¨ multicast router ªº¸Ü¡A±z¥²¶·­«·s compile ±z ªº kernel¡A¥[¤J MROUTING ªº¿ï¶µ¡A¨Ã¥B°õ¦æ mrouted(8) FreeBSD 2.2 ¤Î¤§«áªºª©¥»·|¦b¶}¾÷®É°õ¦æ mrouted(8) ¦pªG¦b /etc/rc.conf ¤¤ mrouted_enable ³]©w¬° "YES"

MBONE ªº¦UºØ¤u¨ã¥i¥H¦b¥L­Ì ports ¤U©ÒÄÝ¥s°µ mbone ¥Ø¿ý ¤¤§ä¨ì¡C¦pªG±z¦b§äµø°T·|ijªº¤u¨ã¦p vic ¥H¤Î vatªº¸Ü¡A¨ì¨ºÃä§ä§ä§a¡I

12.16. ­þ¨Çºô¸ô¥d¬O¨Ï¥Î DEC PCI chipset¡H

¥H¤U¬O Glen Foster ´£¨Ñªº²M³æ¡G

Table 12-1. Network cards based on the DEC PCI chipset

Vendor Model
ASUS PCI-L101-TB
Accton ENI1203
Cogent EM960PCI
Compex ENET32-PCI
D-Link DE-530
Dayna DP1203, DP2100
DEC DE435, DE450
Danpex EN-9400P3
JCIS Condor JC1260
Linksys EtherPCI
Mylex LNP101
SMC EtherPower 10/100 (Model 9332)
SMC EtherPower (Model 8432)
TopWare TE-3500P
Znyx (2.2.x) ZX312, ZX314, ZX342, ZX345, ZX346, ZX348
Znyx (3.x) ZX345Q, ZX346Q, ZX348Q, ZX412Q, ZX414, ZX442, ZX444, ZX474, ZX478, ZX212, ZX214 (10mbps/hd)

12.17. ¬°¤°»ò­n¥Î FQDN ¤~¯à³s¨ì¨ä¥L¾÷¾¹¡H

§A¤]³\·|µo²{­n³sªº¾÷¾¹¨ä¹ê¬O¦b¥t¤@­Óºô°ì¡CÁ|­Ó¨Ò¤l¡A°²³]§A¬O¦b foo.bar.edu ³o­Óºô°ì¤¤¡A·Q­n³s¨ì¦b¤@¥x¥s mumble ªº¥D¾÷¡A¥L¦b example.org ºô°ì¤U¡A §A¥²¶·¥Î Fully-Qualified Domain Name mumble.example.org¡A¦Ó¤£¬O¥u¥Î mumble¡C

¶Ç²Îªº BSD BIND resolver ¤¹³\¥Î³oºØ¤è¦¡¸Ñ¥X¾÷¾¹ªº¦ì§}¡A¦ý¬O FreeBSD ¤ºªþ bind (see named(8)) ª©¥»¤º©w¤è¦¡¡A«h¬O°£¤F§A©Ò¦bªººô°ì¥H¥~¡A¤£¤ä´©¨ä¥L«D FQDN ªºÁY¼g¡C ©Ò¥H¦p mumble ¥²¶·¦b mumble.foo.example.org¡A§_«h´N·|±qºô°ìªº³Ì©³ ¼h¶}©l§ä¡C

³o©M¥ý«eªº°µªk¤£¦P¡A¤]´N¬O¤£¥Î mumble.example.org¡A©M mumble.edu Ä~Äò·j´M¡C ¬Ý¤@¤U RFC 1535¡A¸Ì­±¦³´£¨ì¬°¤°»ò¤§«eªº°µªk¤£¦n¡A¬Æ¦Üºâ¬O­Ó¦w¥þ º|¬}¡C

³o¸Ì¦³­Ó¤£¿ùªº¸Ñªk, §A¥i¥H¥[¤J¤@¦æ

search foo.example.org example.org

instead of the previous

domain foo.example.org

¦b§Aªº /etc/resolv.conf Àɮפ¤ (½Ð°Ñ¦Ò resolv.conf(5))¡C¦ý¬O­n½T©w·j´M¶¶§Ç¤£·|¹H¤Ï RFC 1535 ©Ò¿×ªº ¡§boundary between local and public administration¡¨¡C

12.18. ¬°¤°»ò§Ú¦b³s½u®É¤@ª½¥X²{ ¡§Permission denied¡¨ ªº¿ù»~°T®§¡H

¦pªG¦b½sĶ kernel ®É¥[¤J IPFIREWALL ¿ï¶µ¡A ½Ðª`·N 2.1.7R ¤º©w¬O©Úµ´©Ò¦³¥¼¸g®Ö­ãªººô¸ô«Ê¥](¦ý¦b¶}µo 2.1-STABLE ®É§ï±¼¤F)¡C

I¦pªG¤£¤p¤ß§Ë¿ù¤F firewall ªº³]©w¡A§A¥i¥H¥H root °õ¦æ¥H¤U©R¥Oºô¸ô¥\¯à´N·|«ì´_¥¿±`¡G

# ipfw add 65534 allow all from any to any

¤]¥i¥H¦b /etc/rc.conf ¥[¤J firewall_type="open" ªº¿ï¶µ¡C

¦pªG·Qª¾¹D¦p¦ó³]©w FreeBSD firewall¡A½Ð°Ñ¦Ò ¤â¥U¤¤¬ÛÃö³¹¸`¡C

12.19. IPFW ·|³y¦¨¦h¤jªººô¸ô©µ¿ð¡H

½Ð°Ñ¦Ò¤â¥U¤¤ Firewalls ³¹¸`¡A¯S§O¬O IPFW Overhead & Optimization ³o¤@¬q¡C

12.20. ¬°¤°»ò§Úªº ipfw ¡§fwd¡¨ redirect ³W«h±NªA°ÈÂà¦V¨ä¥L¾÷¾¹®ÉµLªk¥¿±`¹B§@¡H

¥i¯à¬O§A°£¤FÂà°e«Ê¥]¥H¥~ÁÙÃB¥~·Q¶i¦æ¦ì§}ÂàĶ (network address translation, NAT)¡A¡§fwd¡¨ ³W«h©Ò¶i ¦æªº°Ê§@´N¦p¦P¦r­±©Ò¥Ü¡F¶ÈÂà°e«Ê¥]¡A¥¦¨Ã¤£·|¥h­×§ï«Ê¥]¤¤ªº¸ê®Æ¡C °²³]§Ú­Ì¦³¦p¤Uªº³W«h¡G

01000 fwd 10.0.0.1 from any to foo 21

·í¤@­Ó³q©¹¯S©w¥Ø¼Ð¦ì§} foo ªº«Ê¥] °e¹F¥D¾÷®É¡A®Ú¾Ú³o±ø³W«h¡A«Ê¥]±N³QÂà°e¦Ü 10.0.0.1¡A¦ý¬O¥¦ªº¥Ø¼Ð¦ì§}«o¤´µM¬O foo¡I«Ê¥]ªº¥Ø¼Ð¦ì§}¨Ã ¨S¦³ §ó§ï¬° 10.0.0.1¡C¤j³¡¤Àªº¥D¾÷·|±N«Ê¥]¥á±ó¡A ¦]¬°¥L­Ì¨Ã¤£¬O³o­Ó¥Ø¼Ð¦ì§}¡C¦]¦¹¡A¨Ï¥Î ¡§fwd¡¨ ³W«h ®É©¹©¹¤£¦p¨Ï¥ÎªÌ©Ò¹w´Áªº¨º¯ë¶¶§Q¡C³oºØ¦æ¬°¬O¨t²Î¯S©Ê¡A¦Ó«D¿ù»~¡C

°Ñ¦Ò Ãö©óªA°ÈÂà¦Vªº±`¨£°Ý µª¶°¡A natd(8) ¤â¥U¡A©ÎªÌ¬O¨Ï¥Î ports collection ¤¤³\ ¦hªA°ÈÂà¦Vªº¤u¨ã¨Ó¥¿½Tªº§¹¦¨§A·Q¶i¦æªº¤u§@¡C

12.21. ­n¦p¦ó§â¹ï¬Y¥x¾÷¾¹ªººô¸ôªA°È­n¨D(service request)Âà¦V¨ì¥t¤@¥x¡H

¦b ports ¥Ø¿ýªº¡§sysutils¡¨¤ÀÃþ¤¤¦³­Ó¥s socket ªº®M¥ó¡A¥i¥HÀ°§AÂà¦V FTP ©Î¨ä¥LÃþ¦üªº ºô¸ôªA°È¡C¥u­n§â¸Óºô¸ôªA°Èªº©R¥O§ï¦¨©I¥s socket §Y¥i¡A¦p¤U©Ò¥Ü¡G

ftp stream tcp nowait nobody /usr/local/bin/socket socket ftp.example.com ftp

¨ä¤¤ ftp.example.com »P ftp ¤À§O¬O³QÂà¨ìªº¾÷¾¹©M port ¦WºÙ¡C

12.22. ¨º¸Ì¥i¥H§ä¨ìºÞ²zÀW¼eªº¤u¨ã¡H

FreeBSD ¤W¦³¤T®MÀW¼eºÞ²z¤u¨ã¡G dummynet(4) ¤w¸g¾ã¦X¶i¤J FreeBSD ¨t²Î(§ó¸Ô²Óªº¥Î³~, ipfw(4)); ALTQ ¥i¥H§K¶O¨Ï¥Î¡AEmerging Technologies ±À¥Xªº Bandwidth Manager «h¬O°Ó¥Î³nÅé¡C

12.23. «ç»ò·|¶]¥X ¡§/dev/bpf0: device not configured¡¨³o­Ó°T®§¡H

§A°õ¦æ¤F¤@­Ó»Ý­n¬f§JµÜ«Ê¥]¹LÂo¾¹ (Berkeley Packet Filter) ªº µ{¦¡ (bpf(4))¡A¦ý¬O§A¦b kernel ¤¤¨S¦³±Ò°Ê¥¦¡C§â¤U­±³o¤@¦æ¥[ ¤J kernel ³]©wÀɤ¤¡A½sͤ@­Ó·sªº kernel¡G

pseudo-device bpf        # Berkeley Packet Filter

¦b­«·s¶}¾÷¤§«á¡AÁÙ­n°µ¥X device node¡A¦b /dev ¤U°õ¦æ¡G

# sh MAKEDEV bpf0

¦pªG·Q­n§ó¶i¤@¨Bª¾¹D¦p¦ó°µ¥X¦UºØ device node¡A½Ð°Ñ¾\ Handbook Ãö©ó¶gÃä¸`ÂIªº»¡©ú ¡C

12.24. §Ú­n«ç¼Ë¤~¯à±N Windows ¾÷¾¹¤¤ªººÏºÐ±¾¤J¨t²Î, ´N¹³ Linux ´£¨Ñ ªº smbmount ¨º¼Ë¡H

¨Ï¥Î SMBFS ¤u¨ã²Õ¡C³o®M¤u¨ã²Õ¤¤ ¥]§t¤F¤@¨t¦Cªº kernel ­×§ïÁÙ¦³¨Ï¥ÎªÌªº¤u¨ãµ{¦¡(userland programs)¡C ³o¨Çµ{¦¡©M¸ê°T¦b ports ¦¬Âä¤ net/smbfs ¤U¥i¥H§ä¨ì¡C¦b 4.5-RELEASE ¤§«áªºª©¥»«h¬O¨t²Î¤¤¤º«Ø¡C

12.25. §Ú¦b¨t²Î¤é»x¤¤µo²{¥H¤U°T®§¡G ¡§icmp-response bandwidth limit 300/200 pps¡¨¡A³o¬O ½¼¦Ì¸J¿|¡H

³o¬O¨t²Î®Ö¤ß§i¶D§A¦³¬Y¨Ç¬¡°Ê¤Þµo¥¦°e¥X¤ñ¥¦©Ò»{¬°À³¸Ó°e¥X§ó ¦hªº ICMP ©Î TCP ­«¸m°T®§ (RST)¡CICMP ¦^À³°T®§±`±`¬O¦]¬°¦³¤H¹Á ¸Õ³s±µ¥¼³Q¨Ï¥Îªº UDP ³q°T°ð¡CTCP ­«¸m°T®§«h¬O¦³¤H¹Á¸Õ³s±µ¥¼¶} ©ñ TCP ³q°T°ð³y¦¨ªºµ²ªG¡C¥H¤U³o¨Ç¬¡°Ê¥i¯à´N¬O³y¦¨³o¨Ç°T®§ªº­ì¦]¡G

  • ¼É¤OªkªºªA°È²Õµ´§ðÀ»(DoS)¤è¦¡ (¬Û¸û©ó°w¹ï¯S®í®zÂI¨Ï¥Î³æ¤@«Ê¥]ªº§ðÀ»¤è¦¡)¡C

  • ¤j¶qªº³q°T°ð±½´y(¬Û¸û©ó¶È¹Á¸Õ¤Ö¼Æªº±`¨£ªA°È³q°T°ð)¡C

¥X²{ªº¼Æ¦r¤¤²Ä¤@­Ó¥Nªí®Ú¾Ú³o¨Ç¬y¶q kernel À³¸Ó°e¥Xªº«Ê¥]¼Æ¡A ²Ä¤G­Ó¼Æ¦r«h¬O kernel ¥Ø«e­­¨î³Ì¤jµo°e¼Æ¡C§A¥i¥H§Q¥Î sysctl ­×§ï net.inet.icmp.icmplim ÅܼƭȨӧó§ï³Ì¤j­È¡CÁ| ¨Ò¨Ó»¡,¦pªG§Æ±æ­×§ï­­¨î¬° 300 packets per second¡G

# sysctl -w net.inet.icmp.icmplim=300

¦pªG§A¤£·Q¦b¨t²Î¬ö¿ý¤¤¬Ý¨ì³o¨Ç°T®§¡A¦ý¬O¤´µM§Æ±æ«O«ù¦^À³ªº­­ ¨îªº¸Ü¡A§A¥i¥H§Q¥Î sysctl ­×§ï net.inet.icmp.icmplim_output ÅܼƨӨú®ø³o¨Ç°T ®§¡G

# sysctl -w net.inet.icmp.icmplim_output=0

³Ì«á¡A¦pªG§A·Q¨ú®ø³o¨Ç­­¨îªº¸Ü¡A§A¥i¥H³]©w net.inet.icmp.icmplim (¦p¤W¨Ò©Ò¥Ü) ¬° 0¡C°ò©ó¤W­z²z¥Ñ¡A§Ú­Ì¤£«ØÄ³§A¨ú®ø³o¨Ç­­¨î¡C

12.26. ³o­Ó¿ù»~°T®§ ¡§arp: unknown hardware address format¡¨ ¬O¤°»ò·N«ä¡H

³o¥Nªí§Aªº°Ï°ìºô¸ô³s½u¤W¦³¤@¨Ç³]³Æ¨Ï¥Î FreeBSD ¬Ý¤£À´ªº MAC ®æ¦¡¡C³o³q±`¬O¥Nªí¦³¤H¦b§Aªº°Ï°ìºô¸ô¤W¶i¦æ¹êÅç¡A³Ì±`¨£ªº´N¬O cable modem ªº³s½u¡C³o°T®§µL®`¡A¦Ó¥BÀ³¸Ó¤£¦Ü©ó¼vÅT¨ì FreeBSD ¥D ¾÷ªº®Ä¯à¡C

12.27. §Ú­è­è¸Ë¦n CVSup ®M¥ó¡A¦ý¬O¦b¹Á¸Õ°õ¦æ®Éµo¥Í¤F¿ù»~¡A­n«ç»ò¿ì¡H

­º¥ý¡A¬Ý¬Ý¿ù»~ªº°T®§¬O§_¦p¤U¡G

/usr/libexec/ld-elf.so.1: Shared object "libXaw.so.6" not found

³oºØ¿ù»~°T®§¥Nªí§A¥D¾÷¤W¦w¸Ëªº net/cvsup ¨S¦³¥]§t XFree86 ®M¥ó¡C¦pªG§A·Q­n¨Ï¥Î CVSup ¤º«Øªº¹Ï§Î¤¶­± GUI ªº¸Ü¡A§A»Ý­n¦w¸Ë XFree86¡C¦¹¥~¡A¦pªG§A¥u·Q¥H©R¥O¦C¤è ¦¡¨Ï¥Î CVSup ªº¸Ü¡A§AÀ³¸Ó¥ý²¾°£¤§«e ¦w¸Ëªº®M¥ó¡C¨Ã¦w¸Ë net/cvsup-without-gui ³o®M ³nÅé¡C¦b FreeBSD ¤â¥U¤¤ CVSup ¬q¸¨¤¤¦³§ó¸Ô²Óªº»¡©ú¡C

¥»¤å¤Î¨ä¥L¤å¥ó¡A¥i¥Ñ¦¹¤U¸ü¡Gftp://ftp.FreeBSD.org/pub/FreeBSD/doc/¡C

­Y¦³ FreeBSD ¤è­±ºÃ°Ý¡A½Ð¥ý¾\Ū FreeBSD ¬ÛÃö¤å¥ó¡A¦p¤£¯à¸Ñ¨Mªº¸Ü¡A¦A¬¢¸ß <questions@FreeBSD.org>¡C
Ãö©ó¥»¤å¥óªº°ÝÃD¡A½Ð¬¢¸ß <doc@FreeBSD.org>¡C