ã¿ã¹ã¯ïŒDNSãä»ããŠãã³ããªã³ã°ããããšã«ãããã€ã³ã¿ãŒãããïŒåæ³ïŒïŒã¡ãœãããååŸããŸãã
解決çïŒlinux +ãšãŠçŽ +ã«ãŒãã£ã³ã°+ NAT + squidããããã¯ãã¹ãŠãããã¯ãŒã¯ãããŒãžã£ãŒã«ãã£ãŠç®¡çãããŸãã
èšäºã§ã¯ããšãŠçŽ ããã°ã©ã ã䜿çšããDNSãã³ãã«ã®æ§æã®èª¬æã圢æããããã³ãã«ãéãã«ãŒãã£ã³ã°ã®æ§æã®ãã¥ã¢ã³ã¹ããšãŠçŽ ã®èªå©ãã«ããŒãããã³ãããã¯ãŒã¯ãããŒãžã£ãŒã
æè©ïŒéåœã¯ç§ããããã¹ã®èŒããã島ã«é£ããŠè¡ããŸããããããã¹ã¯ãã®P /ããã¹ããã©ãããã€ã³ã¿ãŒãããã§æåã§ããã®åŸãã·ã¢ã®ãªããœã¹ã¯èã®å€©äœ¿ã®ããã«èŠãå§ããŸãã ç¹ã«ãã€ã³ã¿ãŒããããžã®æ¥ç¶ã®è©Šã¿ã¯ãããŒã«ã«ãããã€ããŒïŒytaïŒãæ æ²ãæã£ãŠãããšã®æåŸ ã§çµäºããŸãããããã®ãã©ããã飲ãã§äžæœãªADSL 4Mb / 768kbitããã£ã151ãŠãŒãïŒæ¥ç¶ïŒ+æ40ãŠãŒãïŒ4ã¡ã¬ãããïŒ ïŒ> _ <ïŒã åŸ æ©ã¯åŒãããããŠäŒžã³ïŒ3é±ç®ããã§ã«éãããã®ããã«ïŒãè¿ãã«ã¯èŒãããPrimeTelãããŸããã圌ã¯ããã§ãä»ã§ã¯ã»ãšãã©ç®ã«èŠããªãWiFiã1æéããã4ãŠãŒãïŒ172r /æéïŒã§ã€ã³ã¿ãŒãããã«æºè¶³ãããŠãããŸããã ç§ãåæããŸãããã¢ã¯ã»ã¹ãã€ã³ãã¯ãã«ã³ããŒã§ã®ã¿è¡šç€ºãããã¢ããŒãã§ã¯æ¥ç¶ãäžå®å®ã§ããã°ãã°å€±ãããŸããã ãããã£ãŠãPrimeTelãæªç»é²ã®ãµãã³ãã¯ã¿ã«æäŸããDNSãµãŒãã¹ãç¡æã§ãã€ãŸãç¡æã§æªçšãããšãããé£äººã®WEPãããã¯ãŒã¯ã®ãããã³ã°ã«å ããŠãå®å šã«ç¯çœªçãª1ã€ã®ãœãªã¥ãŒã·ã§ã³ãããããŸããã§ããã
ãããŠããŒãã«èå³ã®ãã人ã¯ãããã¹ãã®åŸåã§è§£æ±ºçãèŠã€ããã§ãããããä»ã®ãšããã¯ããã»ã¹ã®çè«ããå§ããŸãããã
DNSãã³ããªã³ã°
䜿çšå¯èœãªDNSãªãŸã«ããŒïŒã€ãŸããååž°ãæå¹ã«ãªã£ãŠããDNSãµãŒããŒïŒãæå ã«ããå Žåã.comã®foobar.example.comãã¹ãã®IPã¢ãã¬ã¹ã®ãªã¯ãšã¹ãã«é²ã¿ãããã§å¿çãããµãŒããŒã®ã¢ãã¬ã¹ãèŠã€ããŸãã comãexample.comã«ã¢ã¯ã»ã¹ããŠãfoobarã®è²¬ä»»è ãèŠã€ããæå®ããããµãŒããŒã§è©³çŽ°ã確èªããŸãã IPã¢ãã¬ã¹ïŒAããã³AAAAã¬ã³ãŒãïŒã ãã§ãªããDNSã«ä¿åã§ãããã®ä»ã®æ å ±ãèªèã§ããŸãã ç¹ã«ïŒ
- MX-foobar.example.comã«ã¡ãŒã«ãéä¿¡ãããŠãŒã¶ãŒã®èª¬æãå«ãè¡ãå«ãŸããŠããŸã
- SRV-ã©ã®ïŒæ°ããïŒãµãŒãã¹ãã©ã®ã¢ãã¬ã¹ã«ãããã«é¢ããæ å ±ãå«ãè¡ãå«ãŸããŸã-ããšãã°ãjabberã«ãã£ãŠäœ¿çšãããŸã
- TXT-ããã¹ã圢åŒã®ã©ã³ãã ãªæ å ±ã ã»ãšãã©ã®å Žåãå®éã«ã¯SPFïŒfoobar.example.comãã¡ã€ã³ããã¡ãŒã«ãéä¿¡ã§ãããŠãŒã¶ãŒã説æããèŠåïŒã§äœ¿çšãããŸãã
ïŒããã§ã¯ãDNSãšã¯äœãããããŠãããã©ã®ããã«æ©èœãããã«ã€ããŠã®300kbã®è¬çŸ©ã¯å€±ãããŸããïŒã
å¿ èŠã«å¿ããŠãããããç°¡åãªããšãè¡ããŸããfoobar.example.comããå°ããªæ å ±ãèŠã€ããããã«ãªãŸã«ããŒã«äŸé Œã§ããŸãã ãªãŸã«ããŒã¯ããã£ãã·ã¥ãæ€çŽ¢ããå床æ€çŽ¢ãããã£ãã·ã¥ããåçããŸãã ïŒãã®ãŸãŒã³å ã®ç°ãªãååãŸãã¯ç°ãªãã¿ã€ãã®ã¬ã³ãŒãã«å¯ŸããŠïŒç°ãªãã¬ã³ãŒããèŠæ±ãããã³ã«ããªãŸã«ããŒã¯çŽ çŽã«æ©ããŠè§£æ±ºããŸãã æ¯åã ããã»ã¹ãé«éåããããã«ãã誰ããã®ãããªæ å ±ã«ã¢ã¯ã»ã¹ãã¹ããããšããæ å ±ããã£ãã·ã¥ããããã»ã¹ã¯1ãããã§ç¶è¡ããããšã«æ³šæããŠãã ããã
äžãäžããµãŒããŒããç§ãã¡ã«æ å ±ãéä¿¡ããããã®ãã£ãã«ããããŸãã ãããŠæ»ãïŒ ãã ããfoobar.example.comã§ã¯ãªãexample.comããåŠç¿ããããã«äŸé Œããããšã¯ã§ããŸãããããšãã°ã
0ahb282M-J2hbM-> M-nYM-VgdM-OJM- CM-> M-nivlm4M-T5M-FM-p1M-t5M- fM-uM-IvLM-HM-NM-aM-IM-eLAM- BM-TM-qM-KM-UDM-NM-uM-] M-WM- jM-DdbM-> Mk.QVM-lM-uM-`v M-@3kGfM-fqFa.example.com
ïŒããã¯ã€ã³ã¿ãŒãããäžã®1ã€ã®é·ãWebãµã€ãã®ã¢ãã¬ã¹ã§ãããå人ãšã®ä»ãåããç¶ããããã«åã«èšèŒãããŠããŸãïŒ
ãªãŸã«ããŒã¯example.comã«ã¢ã¯ã»ã¹ãããã®ã¢ãã¬ã¹ã«ã€ããŠå°ããŸãã ãããŠãã¢ãã¬ã¹ããšã³ã³ãŒããããã¡ãã»ãŒãžã§ããå Žåã¯ïŒ ïŒæå·äººã¯åæºãå§ããŸãã-ååã«ãšã³ã³ãŒããããã¡ãã»ãŒãžïŒïŒ
ãããŠãããïŒ..ã¯ããæ£ç¢ºã«ã ååã«ã¯æå·åãããã¡ãã»ãŒãžãå«ãŸããŸãã ãµãŒããŒã«æ å ±ãéä¿¡ããæ¹æ³ãèŠã€ããŸããã DNSãµãŒã㌠ãŸãã¯ãDNSãµãŒããŒã«ãªãããŸããããå®éã«ã¯ååã§æå·åãããã¡ãã»ãŒãžããªãã¹ã³ããèŠæ±ã«å¿ããŠæå·åãããã¡ãã»ãŒãžã§å¿çããåœã®ãµãŒããŒã
ã€ãŸãããµãŒããŒãžã®ããŒã¿ãã£ãã«ãšãDNSãªãŸã«ããŒãä»ããŠãµãŒããŒããã¯ã©ã€ã¢ã³ããžã®ããŒã¿ãã£ãã«ãååŸããŸãã
ãšãŠçŽ ãŠãŒãã£ãªãã£ã¯ãã®åçã«åºã¥ããŠããŸãã çŸæç¹ã§ã¯ãç§ã®èŠ³å¯ã«ãããšãããã¯åŠ¥åœãªéã®ã«ã¹ã¿ãã€ãºãè¡ãå¯äžã®å®éã«æ©èœããã¢ããªã±ãŒã·ã§ã³ã§ãã
ãšãŠçŽ ã®ã»ããã¢ãã
ãšãŠçŽ ã®èšå®ã¯ã3ã€ã®éèŠãªã¹ãããã«ãªããŸãã
ãã¡ã€ã³ãŸãŒã³ãæºåããŸãã
èšå®ã§ãµãŒããŒãèµ·åããŸãã
èšå®ã䜿çšããŠã¯ã©ã€ã¢ã³ããå®è¡ããŸãã
ãã®åŸããã®ãã£ãã«ã®äœ¿çšæ¹æ³ãåŠç¿ããå¿ èŠããããŸãããããã¯æ¬¡ã®ç« ã§ãã
ããã§ã¯ãé£ããéšåããå§ããŸããã-DNSã®æºåã
1ã€ã®æã§èšå®ïŒãã¡ã€ã³ãŸãŒã³ãå°æ¥ã®ãšãŠçŽ ãµãŒããŒã«å§ä»»ããå¿ èŠããããŸãã
èšå®ã®è©³çŽ°ïŒ
ãã¡ã€ã³åã管çããããã®ã¢ã¯ã»ã¹æš©ãå¿ èŠã§ãã ãã¡ã€ã³ããµãŒããŒã«å§ä»»ãããŠããå Žåãåé¡ãããŸããããµããã¡ã€ã³ããã³ã«ç»é²ããããããšãŠçŽ ãµãŒããŒã«å§ä»»ã§ããŸãã ããããã€ããŒç®¡çè ããã«ãã®ã¿ãããå Žå-åé¡ã¯ã¯ããã«è€éã§ã-äœããã®æ¹æ³ã§2ã€ã®ãµããã¡ã€ã³ãç»é²ããå¿ èŠããããŸãããã®ãã¡ã®1ã€ã¯NSã瀺ãã2çªç®ã®ãµããã¡ã€ã³ã瀺ããŸãã
æ··ä¹±ããïŒ ããäžåºŠãããŸãããã ç§ã®èšå®ãã€ã³ãã®äŸã次ã«ç€ºããŸãã
NS j IN A 256.257.258.259
i.example.comã«ã¯NSãšããŠj.example.comãµãŒããŒãããããã®IPã¢ãã¬ã¹ã¯256.257.258.259ã§ãã
habrã«ã¯ããã¡ã€ã³åãå¶åŸ¡ããã«åé¡ã解決ããæ¹æ³ã«é¢ããèšäºããããŸãã ããããå®éã®ç®¡çè ã«ãšã£ãŠã¯ãå°ãªããšãäžéšã®ãã¡ã€ã³åãå¶åŸ¡ã§ããªãã®ã¯å¥åŠãªããšã§ããããïŒ
2çªç®ã®éšåã¯ãµãŒããŒã®ã»ããã¢ããã§ãã éèŠãªè©³çŽ°ããããŸãããéåžžã«ç°¡åã§ã ïŒ éåžžã®DNSãµãŒããŒãå®è¡ãããµãŒããŒã§ãšãŠçŽ ãå®è¡ããããšã¯ã§ããŸãã ã çç±ã¯ç°¡åã§ã-ããŒãçªå·ã¯53 / UDPã§ãå€æŽããæš©å©ã¯ãããŸããã
ãµãŒããŒã®èµ·åïŒiodinedïŒã¯ç°¡åã§ãïŒ
iodined 10.99.99.1/24 -c i.example.com
ïŒãAãã¬ã³ãŒãã®ååã§ã¯ãªããNSãæå®ããååãæå®ããå¿ èŠããããŸãããããè¡ãããªãå ŽåããªãŸã«ããŒã¯ãšãŠçŽ ã«å°éããŸããïŒã -cã¯IPãã§ãã¯ãç¡å¹ã«ããŸãã 詳现ã«ã¯è§ŠããŸããã§ããããä»ã®äººã®DNSã«åãæ®ãããåã«ããã®ããšãå®è¡ããæ¹ãè¯ãã§ãã å é ã®ã¢ãã¬ã¹ã¯ããµãŒããŒãæã€ãã³ãã«ïŒtuntapïŒã®ã¢ãã¬ã¹ã§ãã 顧客ã¯ã次ã®ã¢ãã¬ã¹ïŒ.2ã.3ãªã©ïŒãåãåããŸãã
ãšãŠçŽ ã®æã¡äžããã¹ã¯ãªããåãããŠããå Žåã§ãããã¹ã¯ãŒããè¿œå ã§ããŸãïŒ
iodined -P SECRET 10.99.99.1/24 -c i.example.com
ã ãšãŒãããã³ãã«ãè¿œå ã§ããããã«ãã«ãŒãããå®è¡ããå¿ èŠããããŸãã ååãšããŠãrc.localã«è¿œå ããããåã«ååã®åŸã«ïŒãä»ããŠå®è¡ã§ããŸãã
éèŠïŒãšãŠçŽ /ãšãŠçŽ åããŒãžã§ã³ã¯äžèŽããå¿ èŠããããŸãã å³å¯ã«ã ãã以å€ã®å Žåãæ¥ç¶ã¯ãããŸããã Linuxã®1ã€ã®ããŒãžã§ã³ããã¹ã¯ãããã«ããããµãŒããŒã«å¥ã®ããŒãžã§ã³ãããå ŽåïŒããã¯äžè¬çã§ãïŒããµãŒããŒäžã®ã¯ã©ã€ã¢ã³ãããããŒãžã§ã³ãã€ã³ã¹ããŒã«ããããšããå§ãããŸãã ãªããžããªããdeb'kuãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããã ãã§ãïŒå©ç¹ã¯äŸåé¢ä¿ããªãããšã§ãïŒã
ã¯ã©ã€ã¢ã³ãã®èµ·åãç°¡åã§ãïŒ
iodine -P SECRET i.example.com
ã
æ¥ç¶åŸããªã¢ãŒããµãŒããŒã䜿çšå¯èœãªã¢ãã¬ã¹ïŒãã®å Žåã¯10.99.99.1ïŒã®ãã³ãã«ãååŸããŸãã
䜿çšã§ããŸãã
ã§ããŸãã
䜿çšããã
ãããŠã©ããã£ãŠïŒ
ãã³ãã«ã®çµããã®äººç
ãªã¢ãŒããµãŒããŒã«å¯ŸããŠsshãäœæããæ©èœä»¥å€ã®ãã®ã«èå³ãããå Žåã¯ãä»ã®ãã¹ãŠãè¡ãå¿ èŠããããŸãã ãã®æç¹ãŸã§æé£ããããšã¯ãããã®èžè¡çãªèª¬æã«ãããŸããã§ããã ããããçµæãšããŠçãããã³ãã«ãå®éã«äœ¿çšããã«ã¯ãã²ãŒããŠã§ã€ã®å€æŽãDNSãµãŒããŒã®ãéåžžã®ãã«ãŒãã®ç¶æãæçåããããã±ããã®åé¡ã®å æã«é¢ããåé¡ã解決ããå¿ èŠããããŸãã
ãããããçµæã®ãã³ãã«ã䜿çšããæ¹æ³ã¯3ã€ãããŸãã
- ãµãŒããŒäžã®ã«ãŒãã£ã³ã°ãšNAT
- ãœãã¯ã¹ãããã·
- http-proxyïŒsquidïŒ
ãããããã¹ãŠåæããŸãïŒãããŠãããããæ§æããæ¹æ³ã«ã€ããŠèª¬æããŸãïŒã ã«ãŒãã£ã³ã°ã®äž»ãªåé¡ã¯ããããã¯ãŒã¯ãééãããã±ããã®MTUã1500ãã€ãæªæºã§ããããšã§ãã ã¯ããã«å°ãªãã 䜿çšããŠããªããããã€ããŒã®DNSãµãŒããŒã«å¿ããŠïŒåŠå®çãªæå³ã§ã䜿çšãïŒã1344ïŒçæ³çãªã·ããªãªïŒãã740ãã€ããŸã§ã®MTUãååŸããŸãã ã€ãŸãããã±ããã®æçåãçºçããŸãã ãããŠããã±ããã®æçåã¯éåžžã«æªãã§ãã ããã¯ãããã±ãŒãžã®æ«å°Ÿã倱ããšå šäœã倱ããããããããã±ãŒãžã倱ãå¯èœæ§ã2ã3åã«ãªãããšãæå³ããŸãã ãã©ã¹ã¯ããœãªã¥ãŒã·ã§ã³ã®ã·ã³ãã«ããšåªé ããããã³ãã¹ãŠã®ãœãããŠã§ã¢ã®ãŒãæ§æã§ãã ãªã³ã«ããŠåäœããŸãã ãŸããäžéšã®ãµã€ãã®äžéšã®æããªCDN / IDCã¯ãæçåããããã±ããããããã¯ããŸãã
äžæ¹ããã³ãã«ãä»ããŠãªã¢ãŒããµãŒããŒïŒãšãŠçŽ åãããïŒãšTCPã»ãã·ã§ã³ã確ç«ããæ©äŒããããŸãããã®å Žåããã±ããã¯ãã³ãã«MTUãµã€ãºã§éä¿¡ãããæçåã¯çºçããŸããã ãã®ãã³ãã«ã«ä»ã®tcpæ¥ç¶ãå€éåãããšïŒãããŒã¬ãã«ãã€ãŸããœã±ããïŒãç§ãã¡ã«åã£ããã®ãµã€ãºã®å€ã®äžçã®ãã±ãããšéä¿¡ã§ããããã«ãªããŸãã ãã ããããã§ã¯å¥ã®ã»ããã¢ãããåŸ ã£ãŠããŸãã ãã£ãã«ãæªãå ŽåãTCPã¯éåžžã«å«ãããŸãã ããã¯äœã§è¡šçŸãããŠããŸããïŒ çªç¶ã®æ倱ãšåè©Šè¡ã䌎ããã£ãã«ã§ã®TCPã®å®è¡æéãé·ãã»ã©ãéä¿¡ãå°ãªããªããŸãïŒã茻茳ãåå ã§ããã±ããã倱ããããšä»®å®ïŒã ãã®çµæãå€éåããããã£ãã«ã®é床ã¯åŸã ã«äœäžããäœäžããäœäžããŸã...ãã³ããªã³ã°ãSSHãä»ããŠçºçããå Žåãæå·åãªãŒããŒãããã課ãããŸãã çŽ10ååŸãDNSãäžååãªå ŽåãTCPã»ã°ã¡ã³ãã®ééã¯tcpdump / wiresharkã§åå¥ã«èª¿ã¹ãããšãã§ããŸãã å¥ã®åé¡ã¯ãè€æ°ã®dup ackã«ã€ãªããé ãå¿çã§ã®çªç¶ã®é 延ã§ãïŒTCPãæªããæªãããèšãã®ã¯ããŸãããããããŸããïŒã ããããã»ã°ã¡ã³ããTCPã«éä¿¡ããããã®ã¿ã€ã ã¢ãŠããå€æŽããããã®ã«ãŒãã«èšå®ãèŠã€ããããšãã§ããŸããã§ããïŒrawsã§å®çŸ©ãããã®ãé€ãããdns-tunnelã®äžã§ã«ãŒãã«ãåæ§ç¯ããããšãã§ããŸããã§ãã-ã€ã³ã¿ãŒããããæ¥ç¶ãããåé¡ãéçºããèå³ãå°ãæ¶ããŸããïŒ ããã¯ããªã¢ãŒããµãŒããŒã§å€§ããªå€æŽãè¡ããªãæ¹ãè¯ãå Žåã«äœ¿çšã§ããå¯äžã®æ¹æ³ã§ããããšã«æ³šæããŠãã ããã ãã®å Žåãã³ãã³ã
ssh -CD 1080 10.99.99.1
ã䜿çšããŠãµãŒããŒã«æ¥ç¶ãããã©ãŠã¶ãŒã§127.0.0.1:1080ã«socks-proxyãç»é²ããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããŸãã ãã©ãŠã¶ããã ã®ã¿ã æ®ãã®ãœãããŠã§ã¢ã¯ããã«å¿ããŠæ§æãããŸãã
ååãšããŠãäžéšã®ããã°ã©ã ã§ã¯ãtsocksãŠãŒãã£ãªãã£ã圹ç«ã¡ãã¢ããªã±ãŒã·ã§ã³ããsocks-proxyãžã®ãã©ãã£ãã¯ã匷å¶çã«ã©ããããŸãã ããã¯æ¬¡ã®ããã«äœ¿çšãããŸããæ£ãããããã·ã¢ãã¬ã¹ã/etc/tsocks.confïŒ127.0.0.1ãããŒã1080ã
tsocks my_net_appication app-arguments
ãŸãïŒã«ç»é²ããŠããã
tsocks my_net_appication app-arguments
å®è¡ã
tsocks my_net_appication app-arguments
ã
å¥ã®ããèå³æ·±ãæ¹æ³ããããŸãïŒãµãŒããŒã§odidã䜿çšããŠsquidãèµ·åããiondã€ã³ã¿ãŒãã§ãŒã¹ã§ïŒãŸãã¯ãã³ãã«ã¢ãã¬ã¹ã§aclã䜿çšããŠïŒãªãã¹ã³ããã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®æå·åãããŠããªãæ¥ç¶ã䜿çšããããã«æ瀺ã§ããŸãã ãããã£ãŠãæåã«æçåãããŠããªããã±ãããåä¿¡ãã次ã«ãDNSãµãŒããŒã®çæçãªé 延ã«ããå£åãã¯ããã«å°ãªãå€ãã®TCPã»ãã·ã§ã³ããããŸãã
æ¬ ç¹ã2ã€ãããŸãã1ã€ç®ã¯å§çž®ããªãããšã§ãïŒsshã¯ãã©ãã£ãã¯ãååŸã§ããŸããã€ãŸããHTTPã§éä¿¡ãããããããŒã¯ãã¹ãŠåªããŠããããšãããããŸãïŒã2ã€ç®ã¯ãSSLãããã®ãŸãŸãééããããŸã£ããééããŸããã
ãã³ãã«ã®å§ãŸãã®ç掻ïŒãšãŠçŽ -mn-ãã«ããŒ
ãã1ã€ã®åé¡ã¯ããã³ãã«å ã®ããã©ã«ãã²ãŒããŠã§ã€ã®æ§æã§ãã squidã¯httpã®ã¿ã§ãããããä»ã®ãã¹ãŠïŒIMAPã¡ãŒã«ãJabberãªã©ïŒã®ã«ãŒãã£ã³ã°ã¯NATãä»ããŠè¡ãå¿ èŠããããŸãã
åé¡ã¯ãããã©ã«ãã²ãŒããŠã§ã€ã®æ§æã§ãã åé¡ã®æ¬è³ªã¯ãDNSãµãŒããŒãäžããããã»ã°ã¡ã³ãã«ãªãå ŽåïŒããšãã°ã5.10.10.10 / 24ãäžããããDNSãµãŒããŒã5.11.11.22ãš5.11.12.33ã«ãã£ãå ŽåïŒãããã©ã«ãã²ãŒããŠã§ã€ãå€æŽãããšå€±ãããŸãDNSãµãŒããŒãšã®éä¿¡ã
çŸåšã®DNSãµãŒããŒãèŠã€ããã®ãããªãéå±ã§ãã èŠåŽããåŸããã«ããŒã¹ã¯ãªãããäœæããŸããïŒ github.com/amarao/iodine-nm-helper
ããã¯éåžžã«äžå®å šã§ããããããªãæ¹åãæè¿ããŸãã ããããDNSã®åé¡ã解決ããæ¹æ³ãããããªããšãŠçŽ -ã¯ã©ã€ã¢ã³ã-éå§ã¹ã¯ãªããïŒãšãŠçŽ ã§ããã±ãŒãžã«æ·»ä»ïŒããæããã«äŸ¿å©ã§ãã
ãã®ã¹ã¯ãªããã¯ãNetworkMangerã䜿çšããããã«èšèšãããŠããŸãã æ®å¿µãªãããDHCPãªãŒã¹ãæŽæ°ããåŸãã¹ã¯ãªããã®ç¹°ãè¿ãèªå·±åèµ·åããã¹ã¿ãŒããªãã£ãããããªãŒã¹ãæŽæ°ããããã³ã«ãã«ãŒãã£ã³ã°ãäžæããã¹ã¯ãªãããåèµ·åããå¿ èŠããããŸãã
ããã©ãŒãã³ã¹ãšé話å質
æ¯åã®åèªããæ人ãç§ã¯å€±æããããšãæ¥ãã å®éã®æ¡ä»¶ïŒå®éšå®€å€ïŒã§ã®DNSãã³ãã«ã¯éåžžã«äœéã§ãããéåžžã®ã€ã³ã¿ãŒãããã®ä»£ããã«ã¯ãªããŸããã tele2ããã®ãšããžã§ããããã¬ãŒãã³ã°ã«é¢ããŠã¯ããã«é«éã§ãã 以äžã¯ãgithubãéãããšãã®firebugããã®åçã§ãã èŠãŠãæ¶ãæµããŠãã ãã-ãããã¯æ°åã®è² è·ã§ããããã¹ãŠããŸãã«ããã§ãã
é床ã¯éåžžã«äžåäžã«å€åããŸãã ãã³ãã«ãä»ããŠäœæ¥ããŠãããšãã«tcpã§äœãèµ·ãã£ãŠãããã調æ»ããã®ã«å°ãæéãè²»ãããŸãã-ç¹å®ã®åäœã®ãããå€ãã®åéä¿¡ãšéè€ããackããããŸããã€ãŸããtcpã¯æ°ç§éãã±ããããéããå Žåã極端ã«äžåäžãªã¬ã€ãã³ã·ãŒã«é©å¿ã§ããŸããããŸããæ°å/æ°çŸããªç§ãããå ŽåããããŸãã
æå°éã®ãç¡ã§ã¯ãªãäœãããšããŠäœ¿çšã§ããŸãã ããšãã°ãããŠã³ããŒãã®ããŒã¯æïŒum ...ãµã€ãºã1.6MBã®å·šå€§ãã¡ã€ã«ïŒãæ倧8kb / sã®é床ã芳枬ããŸããããããã«ãŒãã«äœäžããããã»ã¹ãæ°ååèµ·åããå¿ èŠããããŸããã ä»åŸæ°æ¥éã§è¯ãcytaãç§ãæ¥ç¶ããªãå Žåããã®å€§åãªãåéä¿¡ã¿ã€ã ã¢ãŠãããèŠã€ããããã«ãTCPã®èéãããå°ãæ·±ãæãäžããŸãã
dhcpã®åé¡ã PrimeTelã«ã¯DHCPã®çæãªãŒã¹ããããŸãã åæã«ããªãŒã¹ãæŽæ°ãããšãã«ãŒãã®èªåæŽæ°ãè¡ãããŸããã€ãŸããããã©ã«ãã²ãŒããŠã§ã€ãPaimtelovskyã«çœ®ãæããããŸãã é ãæ©ãŸããåŸããããã¯ãŒã¯0.0.0.0/0ïŒããäžåºŠããŒãã§å²ã£ãå€ïŒãžã®ã«ãŒãã¯ãã£ãšã¯ãŒã«ã«ãªããšæ±ºããŸããã åæã«ããŸã 解決ããŠããªãDHCPãžã®ã«ãŒããæ¶ãããšããåé¡ãæ®ã£ãŠããŸãïŒã¢ãã¬ã¹ã¯ç°ãªããããã¯ãŒã¯ããçºè¡ããããã®ãããªãããã¯ãŒã¯ã¯ããããç¬èªã®ã²ãŒããŠã§ã€ãæã£ãŠãããããéä»ããããã«ãŒãã¯è¯ããããŸããããå¥ã®ãããã¯ãŒã¯ã®ã¢ãã¬ã¹ãååŸããããšã¯éå«ççã§éçã§ãããšèããŸããïŒãããã¯ãŒã¯äœ¿çšïŒã
ãããã£ãŠãäžè¬çã«èšãã°ã質åã¯æªè§£æ±ºã§ãã
åæ³æ§ã®åé¡
ããããæãé£ããã æ£åŒã«ã¯ãããã«å¯ŸããŠå€é¡ãå€é¡ãå€é¡ã®ãŠãŒããæ¯æãããšãªããåãåãã¹ãã§ã¯ãªãã£ããã®ãæã«å ¥ããŸãã äžæ¹ãWiFiãªãã¬ãŒã¿ãŒã®ãããã¹ãããã¯ãèªçºçãã€æèçã«DNSãµãŒããŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸããã ãµãŒãã¹ãã©ã®ããã«äœ¿çšãããã¯ãã§ã«ç§ã®åé¡ã§ããã©ã®ãããªçš®é¡ã®ãããã³ã°ãå®è¡ããªãããšãéèŠã§ãïŒããšãã°ããã¹ã¯ãŒãã®æšæž¬ã¯ãã§ã«æãããªç¯çœªè¡çºã§ãããã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ãžã®äžæ£ã¢ã¯ã»ã¹ã§ãïŒã
ç§ã¯ããã®åé¡ã¯ã°ã¬ãŒãŸãŒã³ã«ãããšä¿¡ããŠããŸãïŒã€ãŸããèŠç¹ã¯è£å€æã®åŒè·å£«ã®ã¹ãã«ã«äŸåããŸãïŒã å®ç掻ã§ã¯ã誰ãæ°ã«ããŸããã ããæ£ç¢ºã«ã¯ããªãã¬ãŒã¿ãŒã¯èªåã®DNSãµãŒããŒãå£ããŠãããã©ããã¯æ°ã«ããªããããããŸãããããããæ©èœããéãåé¡ãããŸããã ãšãŠçŽ ã瀺ãçŽ æŽãããé床ã«ç §ãããŠãæ°çŸãããããã®ãã©ãã£ãã¯ã®ãæ倱ãã«ã€ããŠçå£ã«è°è«ããããšããã§ããŸããã ååãšããŠããã®å Žåã®ãªãã¬ãŒã¿ãŒã«ãšã£ãŠæãäžå¿«ãªã®ã¯ãDNSã®è² è·ãšwifiãããã¯ãŒã¯ã®ã¹ããªã¢ã¹ãã©ãã£ãã¯ã§ãã
èšå®
ïŒãã¥ãŒãã³ã°ãã人ãé€ãå šå¡ã«ãšã£ãŠããã«éå±ã§ãïŒã
ãµãŒããŒäžïŒ
sysctl net.ipv4.ip_forward = 1
iptables -t nat -A POSTROUTING -s 10.99.99.0/24 -j MASQUERADE
ãšãŠçŽ å-P SECRET 10.99.99.1/24 -c i.example.com
ã¯ã©ã€ã¢ã³ãã§ïŒ
vim /etc/iodine-nm-helper.confïŒèšå®ãè¿œå ïŒ
./iodine-nm-helper
ïŒã¹ã¯ãªããã¯ãã³ãã«ãéãã«ãŒãã£ã³ã°ãä¿®æ£ããŸãïŒ
firefoxã§ã¯ããã³ãã«ãµãŒããŒã®IPãä»ããŠhttpãããã·ãèšå®ããŸãã
ã€ã«èšå®ïŒ
acl good src 10.99.99 / 24
http_accessã¯é©åãªlocalhostãèš±å¯ããŸã
http_accessãã¹ãŠæåŠ