è¿½è¨ 2009-04-03
ã¾ã£ãããã£ã¦ãã³ã¡ã§ããã ããææã®éãã§ãï¼ï¼
h2onda linux, tcpdump tcpdump(ã¨ãããlibpcap)ã¯ããã¼ã¿ãªã³ã¯å±¤(OSI layer2)ã¬ãã«ã§ãã±ãããåå¾ãã packet ãããã³ã«ã使ã£ã¦ãã®ã§ããããªãã¾ããåç §: man packet(7) 2009/04/02
はてなブックマーク - h2ondaのブックマーク / 2009年4月2日
tt_clown network ç´°ãããã©ï¼å³ã¯éï¼NIC ãä¸ï¼ã®ãè¯ãããªã¨æã£ãï¼/ "ip"tables ã¨è¨ãä½ã ããï¼IP層ã§ãã±ããããã£ã«ã¿ãã¦ãã¦äºã ãããªï¼tcpdumpã¯Ethernet Frameãè¦ããã®ã§ï¼å¾ã¯åãããªï¼ã»ã»ã»ã¦ã¨ããï¼ 2009/04/02
はてなブックマーク - tt_clownのブックマーク / 2009年4月2日
packet(7)ã«ããã°ã
packet ã½ã±ããã¯ãããã¤ã¹ãã©ã¤ã (OSI ã¬ã¤ã¤ 2) ã¬ãã«ã§ çã®ãã±ãã (raw packet) ãéåä¿¡ããããã«ç¨ããããã packet ã½ã±ããã使ãã¨ãã¦ã¼ã¶ã¼ç©ºéã§ç©ç層ã®ä¸ã« ãããã³ã«ã¢ã¸ã¥ã¼ã«ãå®è£ ãããã¨ãã§ããã
http://www.linux.or.jp/JM/html/LDP_man-pages/man7/packet.7.html
...
ocket_type ã«ã¯ SOCK_RAW 㨠SOCK_DGRAM ã®ãããããæå®ããã SOCK_RAW ã¯ãªã³ã¯ã¬ãã«ããããå«ã raw ãã±ãããã
...
SOCK_RAW ãã±ããã§ã¯ããã±ãããããã¤ã¹ãã©ã¤ãã¨åã渡ãããéããã±ãããã¼ã¿ã«å¤æ´ãè¡ããããã¨ã¯ãªãããã±ããã®åä¿¡æã«ã¯ãã¢ãã¬ã¹ã®è§£æã ãã¯è¡ãããæ¨æºç㪠sockaddr_ll ã¢ãã¬ã¹æ§é ä½ã«æ¸¡ãããã
ã¨ã®ãã¨ãªã®ã§ã((SOCK_RAWã使ã£ã¦ãã)libpcapã使ã£ã¦ãã)tcpdumpã¯ãL2ã®ä¸ã§ãããã¤ã¹ãããã¡ã°ãè¿ãã¨ããã§ããããã®ãã±ããã観測ã§ããããã§ãããã§ã次ã®ã¹ãããã¨ãã¦ãOSIçã«ããä¸ä½ã®L3ã«æ¸¡ãããããã§iptablesã§ãã£ã«ã¿ãªã³ã°ãªã©ãè¡ãããã¨ã
ãã¨ããã¯è£ãåã£ã¦ãªããã§ãããL2ã®Ethernetãã¬ã¼ã ããã£ã«ã¿ãªã³ã°ã§ãã ebtables ã¯ãåãL2ã§ãSOCK_RAWããä¸ä½ã«ä½ç½®ãã¦ããã§ãããã¼ L2:{SOCK_RAWâebtables} â L3:{iptables} â L4:... ã¿ãããªã
ã¨ã«ãããid:h2onda ãããid:tt_clown ããã¯ãããã¯ããã¦ãã ãã£ãã¿ãªããããããã¨ããããã¾ããï¼
è¿½è¨ ãããã¦èªã¿ãã
- ebtables/iptables interaction on a Linux-based bridge
- iptables (ç·) 㨠ebtables (ã·ã¢ã³) ã®çµ¡ã¿ãå³ç¤ºããã¦ãã¦é¢ä¿ãã¤ãã¿ãããã§ãã
- DSAS開発者の部屋:ネットワークパケットを覗いちゃえ
æ¬æ
Linuxã§iptablesãipvsãip routeã¨ããã®ã¸ãã®ãããã¯ã¼ã¯ç³»ã®è¨å®ãããéã«ããã±ããã®å°é確èªãããã®ã«tcpdumpã¯é常ã«æçãªããã§ãããtcpdumpã®ã¬ã¤ã¤ã¨iptablesãªã©ã®ã¬ã¤ã¤ã®é¢ä¿ãææ¡ãã¦ããªãã¨æ··ä¹±ãããã¨ãå¹´ã«æ°åã¯ããã¾ãã
ä¾ãã°ãINPUTãã§ã¤ã³ã§DROPãã¦ããã®ã«tcpdumpã§è¦ãã¨ãã±ãããå±ãã¦ããâ¦ãã¨ãã
ã³ã¼ãã¬ãã«ã§ãªãã¦æå観å¯ã¬ãã«ã§ãããtcpdumpã¨iptablesã®ä¸çã®é¢ä¿ã¯ãããªæãã£ã½ãã§ãã
ãã®é層æ§é ãæèãã¦ãã±ããã®æ°æã¡ã«ãªãã¨ã
- INPUTã§DROPãã¦ã¦ããtcpdumpã§ã¯(DROPåã®)ãã±ããã観測ã§ãã
- tcpdumpã§è¦³æ¸¬ããéããINPUTã§DROPãã¦ããã®ã¨OUTPUTã§DROPãã¦ããã®ã¨ã¯è¦åããããªã
- PREROUTINGã§DNATãã¦ã¢ãã¬ã¹å¤æãã¦ããå ´åãå¤æå¾ã®ã¢ãã¬ã¹ã¯tcpdumpã§ã¯è¦³æ¸¬ã§ããªã
- POSTROUTINGã§SNATãã¦ã¢ãã¬ã¹å¤æãã¦ããå ´åãå¤æå¾ã®ã¢ãã¬ã¹ã¯tcpdumpã§è¦³æ¸¬ã§ãã
- PREROUTINGã§REDIRECTãã¦ããå ´åãtcpdumpã§è¦³æ¸¬ã§ããdestinationã¢ãã¬ã¹ã¯å ã ã®ãã®ã§ãã
ã¨ããã®ãç解ã§ããã§ãããã
ãããã¦è¦ãã
ãã£ãã®å³ã®å ãã¿ã¯ãã®ã¸ãã§ãï¼
- Linux netfilter Hacking HOWTO: Netfilter Architecture
- 28. LVS: Running a firewall on the director: Interaction between LVS and netfilter (iptables).
ç¹ã«å¾è ã®LVS-HOWTOã¯ãiptables(netfilter)ã®ä¸çã®ã©ã®ã¸ãã«ipvsãé£ãè¾¼ãã§ããããããã®ã§ããã±ããããã³ã°ã«ï¼ãã³ã°ã«ï¼ããæ¹ã«ã¯å¿ è¦ã®å³ã¨æãã¾ãã