Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?

LVSæ§ç¯ã«ãããæå¼·ã®æé æ¸ãæ®ãã¦ã¿ã¾ããã ã¯ããã« ãã¼ããã©ã³ãµï¼LVSï¼ã®éè¦ã¯ééããªãããã¨æãã®ã§ãããããããããããã«æ å ±ãå°ãªãã ãã®æåãªããµã¼ã/ã¤ã³ãã©ãæ¯ããæè¡ããåºçããã2008å¹´ãããããã¼ã¯ã®æãããã(Klabããã®è¨äºã«ã¯å¤§å¤ãä¸è©±ã«ãªãã¾ãã) Googleã§èª¿ã¹ã¦ãã¾ã¨ã¾ã£ãæ å ±ããªãã£ããããã®ã§ãæåã¯å¤§å¤ã§ããã æ®æ®µã¤ã³ãã©å¨ãã§ä»äºãã¦ããã®ã§ãããã§å¹ã£ããã¦ãã¦ãåºãããã¨æãã¾ãããã¤ããã°å²ä¸æ大ã®æ å ±éã ä»åã¯ãCentOS6.4 x86_64ãã·ã³ãã«ãææ°çkeepalived-1.2.7ãå°å ¥ãã§ãå²ãã¨æ¬çªéç¨ã«èããããæé ãã解説ããã¡ããå®çªã®IPVS + Keepalived ã®Direct Server Return(DSR)æ§æã â»æ¯éã³ã¡ã³ãæ¬ã§ãããã«æçãªæ å ±ãããã¾ãããæè¿ã§ãã å 容
管çä¸ã®ãµã¼ãã§è¡ã£ã¦ããã»ãã¥ãªãã£è¨å®ãå ¬éãã¾ããæ¬å½ã¯ãããããã¨ãå ¬éããã®ã¯ãããããªãã®ã§ãããèå¼±ãµã¼ãã氾濫ãã¦ããç¾ç¶ãããè¸ã¿å°ã¨ãªã£ã¦sshã¢ã¿ãã¯ãããã®ãè¿·æ極ã¾ããªãã®ã§ãæä½éãã£ã¨ãã¨ããå 容ã§ã¾ã¨ãã¾ããã*1 èµ·åãµã¼ãã¹ã¨æ¦è¦ iptables/Firewallã®è¨å® iptablesã®ä¸èº« limit-burstã«ã¤ã㦠hashlimitã«ã¤ã㦠hosts.allow/hosts.deny(TCP Wrapper)ã®è¨å® sshdã®è¨å® ãã®ä»ã®è¨å® Apacheã®è¨å® Postfixã®è¨å® Dovecotã®è¨å® ã¾ã¨ã èµ·åãµã¼ãã¹ã¨æ¦è¦ Apache (www) sshd smtp/pop bind (DNS) ntpd ããã¤ãã®æ³¨æç¹ã sftpã§ååãªã®ã§ftpdã¯ä½¿ããªããWinSCPçã使ãã°ffftpã«ä¾åããå¿ è¦ã¯ãªãã*2
æï¼Jack Wallenï¼Special to TechRepublicï¼Â ç¿»è¨³æ ¡æ£ï¼æä¸é ç« ã»éå´è£å 2009-03-03 08:00 iptablesããã¹ã¿ã¼ããã«ã¯æéãããããã®ã®ãã»ãã¥ãªãã£ã«é¢ããåºæ¬çãªãã¼ãºãæºãããã¨ã®ã§ããããã¤ãã®ã«ã¼ã«ãç¥ã£ã¦ããã ãã§ãããªãã®Linuxã·ã¹ãã ã®ã»ãã¥ãªãã£ãåä¸ããããã¨ãã§ãããæ¬è¨äºã§ã¯ããã®æå§ãã¨ãªãéè¦ãªã«ã¼ã«ã解説ããã iptablesã¯ãLinuxãã·ã³ãã»ãã¥ã¢ã«ããããã®å¼·åãªãã¼ã«ã ãã¨ã¯è¨ããã®ã®ããã®æ©è½ã®å¤ãã«ã¯å§åããã¦ãã¾ããã¡ã§ãããããã¦ãã³ãã³ãã®æ§é ããã£ããã¨ç解ãããã·ã³ã®ã©ã®é¨åãã©ã®ããã«ã»ãã¥ã¢ã«ãã¹ãããææ¡ããå¾ã§ãã£ã¦ããããããããã¨ã«å¤ããã¯ãªããããããiptablesã®è¯ãã¨ããã¯ã極ãã¦åºããã®é©ç¨ç¯å²ã«ããããã®ãããiptablesã®ã«ã¼ã«ã®ããã¤ãã
[ã»ãã¥ãªãã£] iptablesã§FTPãéãã«ã¯20çªãã¼ãã¨21çªãã¼ãããããã ãã§ã¯passive modeã®FTPã¯ãã¾ãéãã¦ããã¾ãããip_conntrack_ftpã¨ip_nat_ftpäºã¤ã®ã¢ã¼ã¸ã¥ã¼ã«ããã¼ãããå¿ è¦ãããã¾ããï¼ip_nat_ftpã¯å¿ é ã§ã¯ãªãããã»ã»ã»ï¼ [root@www etc]# lsmod Module Size Used by Not tainted ip_nat_ftp 3920 0 (unused) iptable_nat 22808 1 [ip_nat_ftp] ip_conntrack_ftp 5392 1 [ip_nat_ftp] ip_conntrack 29800 2 [ip_nat_ftp iptable_nat ip_conntrack_ftp] iptable_filter 2412 0 (autoclean) (
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}