看板FreeBSD
标 题Re: [请益] 关於natd & firewall
发信站枫桥驿站 (Thu Nov 27 16:08:55 2008)
转信站ptt!news.ntu!ctu-gate!news.nctu!newsfeed.nthu!news.cs.nthu!MapleBBS
你真是一个很可爱的学姊啦~~
不好意思再问一个...指令这样下好吗?
================ this is my /etc/rc.firewall shell script ========
/sbin/ipfw add deny all from 192.168.0.1 to any
/sbin/ipfw add deny all from 192.168.0.2 to any
..
..
/sbin/ipfw add deny all from 192.168.0.253 to any #254是我的gateway
================this is my /etc/rc.firewall shell script ========
※ 引述《[email protected] (我是很可爱的学姊啦~~)》之铭言:
> ※ 引述《[email protected] (Xiao Jin)》之铭言:
> > 我有一台nat server
> > 可是不想被人家盗用nat service(in my LAN)
> > 请问有方法可以挡吗??
> > 谢谢~
> 有两个方法
> 1.把内部网域独立出来,里面不要有其他电脑(不同的switch/VLAN) <== 钱多的建议方案
> 可以连NAT的电脑---Switch A--(网卡A)NAT Server(网卡B)---Switch B---外部网域
> (不想让他连NAT的电脑)
> 2.用ipfw把没有在用的内部ip都挡住
--
▂__ˍ(_▇▆' * ◣_ ◣◢▆▇ ▁_ ▄▆▇。
.枫桥驿站.telnet://imaple.tw◆◣}
=▁
▔﹊ ̄ *. ▆川@▋ ▃▔
▂~+ ◤兀
 ̄
▃▂▁▂。▁▂ˍ_◢〢_▇.* ├=rom:123.204.42.14
﹊ ̄﹊ ̄ ̄﹊﹊ ̄ ̄﹊ ̄﹊ ̄ ̄﹊@人 ̄ ̄﹊ ̄﹊ ̄ ̄﹊﹊ ̄ ̄﹊﹊ ̄ ̄﹊﹊ ̄﹊ ̄