ãã®å³èã©ãã§ã¯ãGNU / Linuxã䜿çšãããããã¯ãŒãã³ã°ã匷調ããŸãã
次ã®ãããã¯ãæ€èšããŠãã ããã
- åŠç¿VLANã 1ã€ã®VLANã§vm1ãvm2ã®éã«ãããã¯ãŒã¯ãæ§ç¯ããŸãã pingãå®è¡ãããã±ããããã£ããããèŠåºãã調ã¹ãŸãã
- vm1 vm2ãç°ãªãVLANã«åå²ããŸãã R1ã䜿çšããintervlanã«ãŒãã£ã³ã°ã®æ§æã
- Iptablesã ãã¹ã«ã¬ãŒããã«ã¹ã¿ãã€ãºããŸãã å€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãã·ãã¥ã¬ãŒãããŸãã
- Iptablesã NATã®èåŸã«ããvm1ããã³v2ã®ãµãŒãã¹ã®ããŒã転éãæ§æããŸãã
- Iptablesã ã»ãã¥ãªãã£ãŸãŒã³ãæ§æããŸãã tcpã»ãã·ã§ã³ãå匷ããŸãã
Z.Y. ãã¹ãŠã®äººãééã£ãŠããŸããããªãã®ã³ã¡ã³ããåãå ¥ããŸããæãããæžãããããããä¿®æ£ããæºåãã§ããŠããŸãïŒ
æå®ïŒVM1ãVM2ã§æ§æãããããŒã«ã«ãšãªã¢ãããã¯ãŒã¯ã R1ã«ãŒã¿ãŒïŒä»®æ³ãã·ã³ã§ããããŸãïŒãS1 WebãµãŒããŒã
Yandexãã£ã¹ã¯ãããã®ã©ãçšã®æ¢è£œã®ããŒãã£ã«ãããŠã³ããŒãã§ããŸã
ãªããªã ãã®èšäºãã¬ãã¹ã³ãšããŠéä¿¡ããããšããŸããããã»ãšãã©ã®å Žåãããã¹ãã§ã³ãã³ããæžãã®ã§ã¯ãªããã¹ã¯ãªãŒã³ã·ã§ãããæ®ã£ãŠèªåã®æã§ããããæäœããŸããã ããã«ãããããéãç解ããèŠãããããªããŸãã ãããäžäŸ¿ã§ããããšã¯ååã«ç解ããŠããŸããããã®ã¢ãããŒããéžæããããšã«ããŸããã
ãããã¯ãŒã¯å³
VBOXã§ã®ä»®æ³ãã·ã³ã®äŸ
VM1ã®èšå®-ã€ã³ã¿ãŒãã§ãŒã¹ãšããŠããªããžãšããŠæ¥ç¶ããŸãã ä»»æã®ã€ã³ã¿ãŒãã§ã€ã¹ãéžæããŠããã®ãã¹ãŠãé²èŠ§ã§ããŸãã å®å šãæãããã«ãã·ã¹ãã 2ããªããžã¢ããã¿ãŒïŒbr0ãbr1ïŒã«ã¢ããã¿ãŒãäœæããvm1ãvm2ãr1ïŒã¢ããã¿ãŒ1ïŒãbr0ã«ãs1ãr1ïŒã¢ããã¿ãŒ2ïŒãbr2ã«æ¥ç¶ããŸããã
ã¢ããã¿ã®ã»ããã¢ããäŸ
æ®ãã®3ã€ã®èšå®ã¯äŒŒãŠããŸãã
I. VLANã調æ»ããŸãã 1ã€ã®VLANã§vm1ãvm2ã®éã«ãããã¯ãŒã¯ãæ§ç¯ããŸãã pingãå®è¡ãããã±ããããã£ããããèŠåºãã調ã¹ãŸãã
vm1ãšvm2ãèµ·åããã³ãã³ãã䜿çšããŠã·ã¹ãã ã®ã€ã³ã¿ãŒãã§ã€ã¹ã確èªããŸã
ïŒIP aãšçç¥ïŒip addr
çµæ
æ°ããããã€ã¹ãè¿œå ããŸããããã¯eth0.100ãšåŒã°ããid = 100ã®ã¿ã°ä»ãã€ã³ã¿ãŒãã§ãŒã¹ã«ãªããŸãã
çµæ
ip link add -
link eth0 - eth0
name eth0.100 - . , vlan.
type vlan - . 8021q - vlan
id 100 - id vlan
次ã«ããã®ã€ã³ã¿ãŒãã§ã€ã¹ã«IPã¢ãã¬ã¹ãå²ãåœãŠãŸãã
ip addr add 10.10.10.10/24 dev eth0.100
ã¬ã³ãŒãã®çããã¥ãŒïŒ
ip aa 10.10.10.10/24 dev eth0.100
çµæ
ç§ãã¡ã¯æ¬¡ã®ããšã«æ³šæãæã£ãŠããŸãïŒããŒãã£ãªã¢ãšããŠã³
ããã¯ãã€ã³ã¿ãŒãã§ã€ã¹ã«ãããã¯ãŒã¯ã±ãŒãã«ãæ¥ç¶ãããŠããããã€ã³ã¿ãŒãã§ã€ã¹èªäœãããŠã³ããŠããããšãæå³ããŸãã
çµæ
ã±ãŒãã«ãæ¥ç¶ãããšã次ã®å³ã衚瀺ãããŸãã
çµæ
ãããŠãã³ãã³ãã§ã€ã³ã¿ãŒãã§ãŒã¹ãæå¹ã«ããŸãããïŒ
ip link set dev eth0.100 up
çµæ
ãããã£ãŠãvlan id = 100ã®ã¿ã°ä»ããã±ãããåä¿¡ããã€ã³ã¿ãŒãã§ã€ã¹ãäœæããããããã®ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠãã±ããããããã¯ãŒã¯ã«ãªãªãŒã¹ããããšãã¿ã°100ããã±ããã«ãã³ã°ã¢ããããŸãã ãããŠåœŒã«IPã¢ãã¬ã¹10.10.10.10/24ãå²ãåœãŠãŸãã
VM2ã§ãåãããšãè¡ããã¢ãã¬ã¹10.10.10.20/24ãå²ãåœãŠãŸã
çµæ
VM1ãšVM2éã®æ¥ç¶ã®ç¢ºèªïŒVM2ã§10.10.10.10ã«pingãå®è¡ããŸã
çµæ
èŠçŽãããšã1çªç®ã®ããŒã«ã«ãããã¯ãŒã¯ã®2å°ã®ãã·ã³ã§äœæãã100çªç®ã®VLANã®2ã€ã®ã¿ã°ä»ãã€ã³ã¿ãŒãã§ã€ã¹ãäœæãããããã®éã®æ¥ç¶ã確èªããŸããã
ããã¯ãã¹ãŠåãæçºã§ã¯ãªãããšã確èªããŸãïŒ VM1ã§ãªã¹ããŒãèµ·åããVM2ãšãã©ãã£ãã¯ãã©ãã£ãã¯ã§ãªã¹ããŒãããã¯ããŸãã
1. VM1ã§å®è¡ãã
nohup nc -lvp 3000 &
tcpdump -n host 10.10.10.20 -i eth0 -e
2. VM2ã§å®è¡ãã
nc 10.10.10.10 3000
çµæ
ãã£ãã«ã¬ãã«vlan 100ã®ããããŒã«è¡šç€ºãããŸãããããã£ãŠããããã¯ãŒã¯äžã®ãã±ããã¯å®éã«ã¯ã¿ã°ä»ãã§ãããããã¯ãã¶ãŒã°ãŒã¹ã®çºæã§ã¯ãããŸããã
IIã vm1 vm2ãç°ãªãVLANã«åå²ããŸãã R1ã䜿çšããintervlanã«ãŒãã£ã³ã°ã®æ§æã
次ã«ããã€ã³ãçªå·2ã«é²ã¿ãŸããããã2ã€ã®ä»®æ³ãã·ã³ãç°ãªãVLANã«åå²ããã«ãŒã¿ãŒãæ§æããŸãã
VM1ã®å ŽåïŒ
ã¿ã°200ã®eth0.200ã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ããã¢ãã¬ã¹192.168.0.2ãå²ãåœãŠãŸã
VM2ã®å ŽåïŒ
ã¿ã°300ã®eth0.300ã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ããã¢ãã¬ã¹172.16.0.2ãå²ãåœãŠãŸã
ïŒç¬ç«ããŠïŒ
çµæïŒVM1ïŒ
çµæïŒVM2ïŒ
R1ã«ãŒã¿ãŒããªã³ã«ããŠæ§æããŸãã ã«ãŒã¿ãŒã§ã¯ãVM1ãVM2ãšã¯ç°ãªããvlan 200ãšvlan 300ã®äž¡æ¹ã«ã€ã³ã¿ãŒãã§ãŒã¹ãäœæããå¿ èŠããããŸã-ãã®ã€ã³ã¿ãŒãã§ãŒã¹ã¯ãããã®ãããã¯ãŒã¯ã®ã²ãŒããŠã§ã€ã«ãªããŸãã ãããã«ã¢ãã¬ã¹192.168.0.1ã172.16.0.1ãå²ãåœãŠãŸãã
çµæ
æ¥ç¶ã確èªããŠãã ããã 192.168.0.2ããã³172.16.0.2ã®ã«ãŒã¿ãŒããpingãå®è¡ããŸãã ïŒãšããã§ãVM2ã§eth0.300ãèšå®ããã®ãééãããããããã«å°ããªåé¡ããããŸããã
ãšã©ãŒãèŠã€ãããŸããã§ãã
id = 300ã®ä»£ããã«ãid = 200ãç»é²ããŸãã
çµæ
ããã§ãVM1ãR1ãšVM2ãR1ã®éã«æ¥ç¶ãã§ããŸããã VM1ãVM2ãR1çµç±ã§æ¥ç¶ããŠã¿ãŸãããã
ã«ãŒã¿ãŒãã€ã³ã¿ãŒãã§ã€ã¹éã§ãã±ããã転éã§ããããã«ããã«ã¯ãèš±å¯ããå¿ èŠããããŸãã /etc/sysctl.confãã¡ã€ã«ã®net.ipv4.ip_forward = 1ãã£ã¬ã¯ãã£ãã®ã³ã¡ã³ããå€ã ã sysctl -pã³ãã³ãã§å€æŽãé©çšããå¿ èŠããããŸãã
# nano /etc/sysctl.conf # sysctl -p net.ipv4.ip_forward = 1
çµæ
ãããŠä»ãæãéèŠãªããšã ã«ãŒãã£ã³ã°ãæ§æããå¿ èŠããããŸãã ãããè¡ãã«ã¯ã3ã€ã®äžè¬çãªæ¹æ³ããããŸãã
1.ããã©ã«ãã«ãŒããæå®ããŸãã ã€ãŸã å®å IPã®å Žæãããããªããããã«ãŒã¿ãŒã®ããŒã«ã«ãããã¯ãŒã¯ãã«ã¡ããã«å±ããªããã¹ãŠã®ãã±ããã
2.ç¹å®ã®ãµããããã®ã²ãŒããŠã§ã€ãæå®ããŸãã ãããã¯ãŒã¯ãç°ãªãã«ãŒã¿ãŒã®èåŸã§ã¢ã¯ã»ã¹å¯èœãªå Žåããããè¡ãå¿ èŠããããŸãã
3.ããã±ãŒãžãåãåã人ã®èåŸã«ããã€ã³ã¿ãŒãã§ã€ã¹ã瀺ããŸãã ãã®ç¶æ³ã¯ãããšãã°ãå¿ èŠã«å¿ããŠããµãããããã«ãŒãã£ã³ã°ããããã«ããŒã¿ã»ã³ã¿ãŒã§çºçããŸããã ã€ãŸã ããŒã¿ã»ã³ã¿ãŒãç§ã«å²ãåœãŠããããµãããããéçã«ã«ãŒãã£ã³ã°ããå€éšã¢ãã¬ã¹ãžã®ä»®æ³ã«ãŒã¿ãŒããããŸããã 次ã«ããã®ãµããããã®IPã¢ãã¬ã¹ããå éšã«ããã«ãŒã¿ãŒã®ã€ã³ã¿ãŒãã§ã€ã¹ã®1ã€ã«ããããšãææããŸããã ãã±ããã¯ãã®ã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããããããã®ãã¯ã€ãã¢ãã¬ã¹ãå²ãåœãŠãããä»®æ³ãã·ã³ã«ãã£ãŠå察åŽã§åä¿¡ãããŸããã ã€ãŸã ãã®ç¶æ³ã§ã¯ãã²ãŒããŠã§ã€ã®æå®ã¯å®å šã«ãªãã·ã§ã³ã§ããã
VM1ã®ã«ãŒãã®ãªã¹ããèŠãŠã¿ãŸãããã
ip ro
çµæ
ä»®æ³ãã·ã³ã¯ã2ã€ã®ãµããããïŒ10.10.10.0/24ãš192.168.0.0/24ïŒã®ã¿ãèªèããŠããŸãã ãã¹ã172.16.0.2ã«ã€ããŠã¯äœãèšãããŠããŸããïŒ pingãè©ŠããŠããäœãæ©èœããªãããã§ãã
çµæ
ãµãããã172.16.0.0/24ãžã®ã«ãŒããè¿œå ããŸãã
ip ro add 172.16.0.0/24 via 192.168.0.1
via-誰ãçµç±ããããæå³ããŸãã ã€ãŸã ãã¹ã192.168.0.1ã«ãã±ãããéä¿¡ãããšããããããããŸãã
ã«ãŒãã£ã³ã°ããŒãã«ã調ã¹ããšã次ã®æ±ºå®ãè¡ãããŸãã
1.ãã®ããã±ãŒãžã®å¯Ÿè±¡è ãã¹ã172.16.0.2
2.ãã±ãã172.16.0.2ã誰ã«éä¿¡ããã°ããã§ããïŒ ãã¹ã192.168.0.1
3.ãã¹ã192.168.0.1ã«ã€ããŠäœãç¥ã£ãŠããŸããïŒ åœŒã¯çŽæ¥æ¥ç¶ãããŠããŸãã ãã®ãµããããã¯ç§ãã¡ã®ãã®ã§ãã ãã£ãã«ã¬ãã«ã§ã¯ããœãŒã¹MACã¢ãã¬ã¹ãäœæãããã¹ãMACã¢ãã¬ã¹ã¯192.168.0.1ããœãŒã¹IPã¯192.168.0.2ãå®å IPã¢ãã¬ã¹ã¯172.16.0.2ã§ãããeth0.200ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠéä¿¡ããŸãã ããããã£ã¹ããæå°ã®ãããã¯ãŒã¯ãã®èè ãèšã£ãããã«ãããã±ãŒãžã®éåœã¯ç§ãã¡ãæ©ãŸããŸããã
é£æ¥VLANã®ã²ãŒããŠã§ã€ã«pingãè©Šè¡ããŠã¿ãŸãããã
ping 172.16.0.1
çµæ
åäœããŸãïŒ ãããã172.16.0.2ã«pingãå®è¡ãããšã©ããªããŸããïŒ åŸ©è·¯ããªããããæ©èœããŸããã ãã±ããã¯ãã¹ãVM2ã«å°éããŸãããVM2ã¯ãããéãè¿ãããšãã§ããŸããã ã©ããããããªã VM2ã«æ»ãã«ãŒããè¿œå ããŠã¿ãŸãããã
VM2ã®ããã©ã«ãã«ãŒããè¿œå ããŸãã ãããè¡ãã«ã¯ããµãããããšãã¹ã¯ïŒ0.0.0.0/0-ã€ãŸãã絶察ã«ãã¹ãŠã®ã¢ãã¬ã¹ã該åœããïŒãæå®ããããããã©ã«ãã®ããŒã¯ãŒãã䜿çšããŸãã
çµæ
åãçµæãåŸãããŸãã ãããŠæåŸã«ãVM1ã¯VM2ã«èªç±ã«pingãå®è¡ããŸãã ãã£ãïŒ
èŠçŽãããšãLinuxã«ãŒã¿ãŒã䜿çšããŠ2ã€ã®VLANéãã«ãŒãã£ã³ã°ããæ¹æ³ãåŠã³ãŸããã
IIIã Iptablesã ãã¹ã«ã¬ãŒããã«ã¹ã¿ãã€ãºããŸãã å€éšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãã·ãã¥ã¬ãŒãããŸãã
ãããªãã¯ãµãŒããŒS1ãè¿œå ããŸãã ãã®äžã«apache2ãã€ã³ã¹ããŒã«ãïŒapt install apache2ïŒãã€ã³ã¿ãŒãããäžã®WebãµãŒããŒãæš¡å£ããŸãã äžæ¹ãVM1ãVM2ã¯ã«ãŒã¿ãŒã®èåŸã«ãããã©ã€ããŒããã·ã³ã§ãã 2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ãŒã¿ãŒã¯ããã®å Žãã®ãã®ã€ã³ã¿ãŒããããèŠãŸãã
R1ã®2çªç®ã®ã€ã³ã¿ãŒãã§ãŒã¹-eth1ãè¿œå ããVLANãªãã§IPã¢ãã¬ã¹8.8.8.100ãèšå®ããS1-8.8.8.8ã«èšå®ããŸãã
çµæ
ã³ã³ãœãŒã«ã«å ¥åãããã¹ãŠã®ã³ãã³ãã¯ãåèµ·åãããŸã§æ©èœããªãããšã«æ³šæããŠãã ããã 2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ãè¿œå ããŠä»®æ³ãã·ã³ããªãã«ããåŸãåèµ·ååŸã«æªæ§æã®ãã·ã³ãåãåã£ãããããã¹ãŠã®ã³ãã³ããå床é©çšããå¿ èŠããããŸããã
çµæ
ç§ã®åŸã«VBOXã®æ§æãç¹°ãè¿ãå ŽåãS1ãšR1ã®äž¡æ¹ã§br1ã«äž¡æ¹ã®ãããã¯ãŒã¯ã«ãŒããè¿œå ããããšãå¿ããªãã§ãã ããã 次ã®ã³ãã³ãã䜿çšããŠãã·ã¹ãã ã®ããªããžã€ã³ã¿ãŒãã§ã€ã¹ãäœæã§ããŸãã
ip link add br1 type bridge
ã
ãã ããäžè¬çã«ãã©ãå šäœãäœæãã1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§äœãäœæããããšã¯ã§ããŸããã
ã¹ã€ããã®ãããªããªããžãã·ãã¥ã¬ãŒãããããã«ãåé¢ã匷調ããŸãã
S1ãR1ãæ§æããåŸãæ¥ç¶ã確èªããŸãïŒping 8.8.8.8.8ãå®è¡ããŸãïŒ-R1ã§åäœããã¯ãã§ãã ããã«ãVM2ã§pingãå®è¡ãããšãpingã¯å®è¡ãããŸããã
ãªãã§ïŒ
S1ã¯ãããã¯ãŒã¯172.16.0.0ã«ã€ããŠç¥ããªãããã§ãã R1ãS1ã®ããã©ã«ãã²ãŒããŠã§ã€ãšããŠè¿œå ããŸãã
ip ro add default via 8.8.8.100
ããã«ãVM1ã䜿çšããŠãµãŒããŒã«pingãå®è¡ãããšãéåžžããããã¯ãŒã¯ãå©çšã§ããªããšè¡šç€ºãããŸãã
ãªãã§ïŒ
ããã©ã«ãã®gwããŸã£ããç»é²ããªãã£ããããããã¯ãŒã¯172.16.0.0/24ã®å Žæã瀺ããããã§ãã
ã²ãŒããŠã§ã€ãäœæããŠããããä¿®æ£ããŸãããã
çµæ
ããã§ã4å°ãã¹ãŠãå®å šã«çžäºã«pingãå®è¡ããŸããã ããããããã¯ãã¹ãã§ã¯ãããŸããã ç°è²ã®ã¢ãã¬ã¹ã¯ãªã³ã©ã€ã³ã«ããªãã§ãã ããïŒ ãŸããR1ã2çªç®ã®ã€ã³ã¿ãŒãã§ã€ã¹ãåç §ãããããã¯ãŒã¯ã¯ãã¢ãã¬ã¹172.16ã*ã*ã192.168ã*ã*ãã©ãã«ããããç¥ããªãã¯ãã§ãã
S1ã§ããã©ã«ãã®gwãåé€ããŸãã
ip ro del default
èŠçŽãããšãå¿ èŠãªãããã¯ãŒã¯ãžã®ã«ãŒããç»é²ããæ¹æ³ãšãã«ãŒã¿ãŒã®èåŸã«ããã°ã¬ãŒã¢ãã¬ã¹ããé衚瀺ãã«ããŠã1ã€ã®ãã¯ã€ãã¢ãã¬ã¹ã®ã¿ãããã¹ãŠã®ãã©ãã£ãã¯ããåºåãããæ¹æ³ãåŠã³ãŸããã
ããã¯NATã«ã€ããŠè©±ãæéã§ãã NATïŒè±èªçããããã¯ãŒã¯ã¢ãã¬ã¹å€æ-ããããã¯ãŒã¯ã¢ãã¬ã¹å€æãïŒã¯ãTCP / IPãããã¯ãŒã¯ã®ã¡ã«ããºã ã§ãããééãã±ããã®IPã¢ãã¬ã¹ãå€æã§ããŸãã IPãã¹ã«ã¬ãŒãã£ã³ã°ããããã¯ãŒã¯ãã¹ã«ã¬ãŒãã£ã³ã°ããã€ãã£ãã¢ãã¬ã¹å€æãšãåŒã°ããŸãã ãã¹ã«ã¬ãŒããæ€èšããŸãã ããã¯SourceNATïŒSNATïŒ&& DestinationNATïŒDNATïŒã§ãã
NATã«ã¯æ¬åœã«äœãå¿ èŠã§ããïŒ ãã ããã«ãŒã¿ãŒã®éä¿¡å IPã¢ãã¬ã¹ãåä¿¡ããã«ã¯ãS1ãžã®çºä¿¡ãã±ãããå¿ èŠã§ãããæ»ã£ãŠãããšãå®å ã¢ãã¬ã¹ãšããŠä»®æ³ã¢ãã¬ã¹ãå床ååŸããŸãã
17.16.0.0/24ãµããããã®ãã¹ã«ã¬ãŒããèšå®ããŸããã-ã«ãŒã¿ã§ã³ãã³ããå®è¡ããŸãïŒ
iptables -t nat -A POSTROUTING -p tcp -m tcp -s 172.16.0.0/24 ! -d 172.16.0.0/24 -j MASQUERADE
iptablesã®ä»çµã¿ã«ã€ããŠã¯è©³ãã説æããŸããã ããã¯éåžžã«å€ãã®ããã§ããããã®èšäºã¯æããã«ããã®ããã§ã¯ãããŸããã ããã¯å匷ããã®ã«ãšãŠãè¯ãèšäºã§ãã
泚æããã ã
! -d 172.16.0.0/24
! -d 172.16.0.0/24
ïŒãããå¿ èŠãªçç±ã ããã¯ãã«ãŒã¿ãŒã®èåŸã«ããå¯èœæ§ã®ãã172.16.0.0/24ãµããããã®ãã¹ãïŒãªã¢ãŒãvpnã¯ã©ã€ã¢ã³ããªã©ïŒããã®ã«ãŒã«ã«è©²åœããªãããã«ããããã«å¿ èŠã§ãã
iptables-save
ã³ãã³ãã§åŸãããçµæãèŠãããšãã§ããŸã
ããã§ãç§ãã¡ã¯äœãéæããŸãããïŒ VM2ã®ãã¹ã«ã¬ãŒããèšå®ããŸãã ã€ãŸããS1ãããã¯ãããšãS1ã¯VM2ã®ã¢ãã¬ã¹ã§ã¯ãªããã«ãŒã¿ãŒã®ã¢ãã¬ã¹ãèŠãããšã«ãªããŸãïŒ ããã€ãã®èšŒæïŒ
çµæ
ãããããã®æç¹ã§S1ã¯äœãèŠãŸããïŒ
çµæ
8.8.8.8ã¯8.8.8.100ãšå®å šã«éä¿¡ãã172.16.0.2ãšã¯éä¿¡ãããèããããŸããã§ããïŒ
ãããããã®ç¬éã«ã«ãŒã¿ãŒã§äœãèµ·ããã®ã§ããããïŒ ãã®ãããã³ã¯ã©ã®ããã«æ©èœããŸããïŒ ãç°è²ãeth0.300ã€ã³ã¿ãŒãã§ãŒã¹ã®çèŽ
çµæ
ãããŠãããã¯ãå€éšããããã¯ãŒã¯ãžã®åºåãã©ã®ããã«èŠããã§ãïŒ
çµæ
ã«ãŒãã«ã¯ãããåŠçãããã±ããã®æ¹åã«å¿ããŠæ£ããIPã¢ãã¬ã¹ã«çœ®ãæããŸãã ãã ããVM1ã§åãæäœãè¡ããšãS1ã«ã¯ç°è²ã®ã¢ãã¬ã¹ã衚瀺ãããŸãã åçŽã«ãã®ãªã¯ãšã¹ãã«å¿çããŸããã èªåã§èŠãŠãã ããã S1ã®GWãåé€ããå¿ èŠãããããšãæãåºãããŠãã ããã
èŠçŽãããšãç°è²ã®ãããã¯ãŒã¯ãé ããã«ãŒã¿ãŒã®èåŸã«ãããã¹ãããªãªãŒã¹ãããœãŒã¹ã¢ãã¬ã¹ipãã«ãŒã¿ãŒã¢ãã¬ã¹ã«çœ®ãæããŸããã ãããŠå¥ã®æ¹å-ç¹å®ã®ä»®æ³ãã·ã³ã®ç¹å®ã®ããŒãããå€éšãã«è»¢éããæ¹æ³ãåŠã³ãS1ãµãŒããŒããããããªãã¯ããããã¯ãŒã¯ããVM1ä»®æ³ãã·ã³ã®ã°ã¬ãŒã¢ãã¬ã¹ã«æ¥ç¶ããããšãã§ããŸããã
IVã Iptablesã NATã®èåŸã«ããvm1ããã³v2äžã®ãµãŒãã¹ã®ããŒã転éãæ§æãã
S1ãã€ã³ã¿ãŒãããããã®ç¹å®ã®ã¯ã©ã€ã¢ã³ãã§ãããVM1ïŒã«ãŒãããªãããã¹ã«ã¬ãŒããæ§æãããŠããªãã¯ã©ã€ã¢ã³ãïŒã«æ¥ç¶ããããšããŸãã sshãä»ããŠæ¥ç¶ããããšããŸãã ããã©ã«ãã§ã¯SSHã¯ããŒã22ã§ãã³ã°ããŸããããããã®ãµãŒããŒãè€æ°ããå Žåã¯ã©ãã§ããããïŒ äžè¬ã«ãæãåçŽãªãããã¯ãŒã¯ã¹ãã£ããŒãåé€ããã«ã¯ãããŒã22ããsshãåžžã«åé€ããå¿ èŠããããŸãã ããšãã°ãããŒã30022ã䜿çšããŠãsshçµç±ã§VM1ã«ã¢ã¯ã»ã¹ããŸãã
ã©ã®ããã«æ©èœããŸããïŒ
S1ã¯ãR1ã«å°çãããã±ããïŒs.ip = S1.ipãd.ip = R1.ipãs.port = Nãd.port = 30022ïŒãéä¿¡ããŸãã
R1ã¯iptablesãèŠãŠDNATã«ãŒã«ãé©çšãããã±ããã圢æããŸãïŒã«ãŒã«ã«åŸã£ãŠïŒïŒïŒs.ip = S1.ipãd.ip = VM1.ip; s.port = Nãd.port = 22ïŒ
ã«ãŒãã£ã³ã°ããŒãã«ãã¹ãã£ã³ããeth0.200ãä»ããŠvm1ãã±ãããéä¿¡ããŸãã
次ã«ãVM1ã¯ãã±ãããåä¿¡ããããŒã¿ãåä¿¡ããå¿çãçæããŸãïŒs.ip = VM1.ipãd.ip = S1.ip; s.port = 22ãd.port = NïŒã
R1ã¯ãã±ãããåä¿¡ããs1ãæåã«ã¢ã¯ã»ã¹ããå ã®s.ipã埩å ããŸãã
ïŒs.ip = R1.ipãd.ip = S1.ipãs.port = 22ãd.port = NïŒ
ããã¯æ¬¡ã®ããã«ããŠéæã§ããŸãã
çµæ
æ¥ç¶ããŠã¿ãŠãã ããïŒ
çµæ
èŠçŽãããšãç¹å®ã®ã«ãŒã¿ãŒã®èåŸã«ããä»®æ³ãã·ã³ã«ãããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæäŸããæ¹æ³ãåŠã³ãŸããïŒããã§ãªããã°ãNATã®èåŸã«ããä»®æ³ãã·ã³ã«ã¢ã¯ã»ã¹ã§ããŸããããã¯ãæãé »ç¹ã«å¿ èŠãšããããã®ã§ãïŒ
V. iptablesã ã»ãã¥ãªãã£ãŸãŒã³ãæ§æããŸãã tcpã»ãã·ã§ã³ãå匷ããŸãã
ãã®ã¬ãã¹ã³ã§æåŸã«æ€èšãããã®ã¯ãtcpã»ãã·ã§ã³ãšãããã®ã»ãã·ã§ã³ã®ã€ã³ã¹ããŒã«ã®æ¹åã§ãã ãããã£ãŠãããšãã°ããµãŒããŒãšã¯ã©ã€ã¢ã³ãã®2ã€ã®ã»ã°ã¡ã³ããæ€èšããŠãã ããã ããšãã°ãã¯ã©ã€ã¢ã³ãã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒãžã®ãµãŒããŒã»ã°ã¡ã³ãã«ã移åãã§ããå¿ èŠããããŸãã ãã ãããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ã¯ã©ã€ã¢ã³ããã·ã³äžã§ã¯äœã®é¢ä¿ããããŸããã ãã®ãããªäŸã¯æ°å€ãããããããããã¯ãŒã¯ã»ã°ã¡ã³ãããå¥ã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ç§»åã§ããçç±ãšããã§ãªãçç±ã¯ãããŸãã ãªããããå¿ èŠãªã®ã§ããããïŒ ããšãã°ãã€ã³ã¿ãŒãããããç£èŠãããæ»æè ã«ã奪ããããWebãµãŒããŒããããŸãã ãã®ãµãŒããŒããã圌ã¯äŒæ¥ãããã¯ãŒã¯ãããã¯ããããšãããããããŸããã ãã ãããã®ã»ã°ã¡ã³ãããã®ã»ãã·ã§ã³ã®ç¢ºç«ãçŠæ¢ãããšãããã¯èµ·ãããŸããã ã€ãŸã å°ãªããšãæ»æè ã®ç掻ãè€éã«ããŸãã VM2ãVM1ã«ç§»åããããšãçŠæ¢ããã«ãŒã«ãè¿œå ããŠãVM1ããVM2ã«ç§»åã§ããããã«ããŸãã
çµæ
VM1ããVM2ã«ç§»åããããšããŸãã
çµæ
ãããŠå察æ¹åã«ïŒ
çµæ
ãªããããèµ·ãã£ãŠããã®ã§ããïŒ TCPã»ãã·ã§ã³ã確ç«ããç¬éã«ãTCP SYNãã±ãããå°çããŸãïŒSYN ACKãããã«å¿çããACKãšã»ãã·ã§ã³ã確ç«ããããšèŠãªãããŸãïŒã æåã«æžãçããã«ãŒã«ïŒNEWã䜿çšïŒã§ã¯ãTCP SYNãã±ããã192.168.0.0ãããã¯ãŒã¯ãã172.16.0.0ã«è»¢éã§ããŸãã
2çªç®ã®åå è ããããšåŸç¶ã®ãã±ããã«å¿çãããšã確ç«ãããã»ãã·ã§ã³ã®2ã€ã®ã«ãŒã«ãã¢ã¯ã·ã§ã³ã«è©²åœãããããã¯ãŒã¯172.16.0.0ããã®ãã®ãããªãã±ãããééããŸãã ãããã圌èªèº«ãã»ãã·ã§ã³ïŒãŸãã¯pingïŒã確ç«ããããšãããšã1.2ã®èŠåã«ã¯è©²åœããããã®ããã±ãŒãžããããããã3çªç®ã®èŠåã«è©²åœããŸãã åºæ¥äžããïŒ
èŠçŽãããšãã»ãã¥ãªãã£ãŸãŒã³éã®ãã©ãã£ãã¯ã®æ¹åãå¶åŸ¡ããããã«ãtcpã»ãã·ã§ã³ã®ã€ã³ã¹ããŒã«ã®æ¹åã管çããæ¹æ³ãåŠã³ãŸããã
ãæž èŽããããšãããããŸããïŒ
è¬çŸ©ã®èæ¡ãé»å ±ãã£ã³ãã«t.me/bykvaadmã«æçš¿ããŸã