FreeBSD + 网关 + 防火(Ipfilter) 配置
2009-05-13 03:01:50来源:未知 阅读 ()
最近配置了台FreeBSD6.0的网关(带防火).下面把配置文件帖出:
双网卡 rl0 & rl1
rl0:用于ADSL拨号;rl1用于内网网络,地址为:192.168.1.1
[linyin@linyin ~]$ more /etc/rc.conf
# -- sysinstall generated deltas -- # Wed May 3 01:52:57 2006
# Created: Wed May 3 01:52:57 2006
# Enable network daemons for user convenience.
# Please make all changes to this file, not to /etc/defaults/rc.conf.
# This file now contains just the overrides from /etc/defaults/rc.conf.
# -- sysinstall generated deltas -- # Wed May 3 09:56:21 2006
# Hostname
ifconfig_rl1="inet 192.168.1.1 netmask 255.255.255.0"
defaultrouter="192.168.1.1"
hostname="linyin.8800.org"
# Service
sshd_enable="YES"
apache_enable="YES"
gateway_enable="YES"
inetd_enable="YES"
sendmail_enable="NONE"
sendmail_submit_enable="NO"
sendmail_outbound_enable="NO"
sendmail_msp_queue_enable="NO"
/usr/local/bin/ez-ipupdate -c /root/dns.conf
/usr/local/nessus/sbin/nessusd -D
# ADSL
ppp_enable="YES"
ppp_mode="ddial"
ppp_profile="linyin"
# Security
ipfilter_enable="YES"
ipfilter_rules="/etc/ipf.conf"
ipnat_enable="YES"
ipnat_rules="/etc/ipnat.conf"
[linyin@linyin ~]$ more /etc/ipf.conf
block in all
block out all
block in log quick on tun0 proto icmp from any to any
block in log quick all with short
block in log quick all with ipopts
block in log quick all with frag
block in log quick all with opt lsrr
block in log quick all with opt ssrr
pass out quick on lo0
pass in quick on lo0
pass out quick on rl1
pass in quick on rl1
block in log body quick on tun0 from 192.168.0.0/16 to any
block in log body quick on tun0 from 172.16.0.0/12 to any
block in log body quick on tun0 from 10.0.0.0/8 to any
block in log body quick on tun0 from 192.0.2.0/24 to any
block in log body quick on tun0 from 0.0.0.0/8 to any
block in log body quick on tun0 from 127.0.0.0/8 to any
block in log body quick on tun0 from 169.254.0.0/16 to any
block in log body quick on tun0 from 224.0.0.0/3 to any
block in log body quick on tun0 from 204.152.64.0/23 to any
block out log body quick on tun0 from any to 192.168.0.0/16
block out log body quick on tun0 from any to 172.16.0.0/12
block out log body quick on tun0 from any to 10.0.0.0/8
block out log body quick on tun0 from any to 127.0.0.0/8
block out log body quick on tun0 from any to 0.0.0.0/8
block out log body quick on tun0 from any to 169.254.0.0/16
block out log body quick on tun0 from any to 192.0.2.0/24
block out log body quick on tun0 from any to 204.152.64.0/23
标签:
版权申明:本站文章部分自网络,如有侵权,请联系:west999com@outlook.com
特别注意:本站所有转载文章言论不代表本站观点,本站所提供的摄影照片,插画,设计作品,如需使用,请与原作者联系,版权归原作者所有
上一篇:FreeBSD系统编程
- 有没有FreeBSD内核配置文件的中文版解释文档呢? 2009-05-13
- freebsd的目录结构 2009-05-13
- nfs配置 2009-05-13
- FreeBSD 内建的防火墙指令ipfw英译汉 2009-05-13
- 【转载】freebsd sysctl.conf配置说明 2009-05-13
IDC资讯: 主机资讯 注册资讯 托管资讯 vps资讯 网站建设
网站运营: 建站经验 策划盈利 搜索优化 网站推广 免费资源
网络编程: Asp.Net编程 Asp编程 Php编程 Xml编程 Access Mssql Mysql 其它
服务器技术: Web服务器 Ftp服务器 Mail服务器 Dns服务器 安全防护
软件技巧: 其它软件 Word Excel Powerpoint Ghost Vista QQ空间 QQ FlashGet 迅雷
网页制作: FrontPages Dreamweaver Javascript css photoshop fireworks Flash