http://q.hatena.ne.jp/1228454656ãã«è³ã£ãæèã®çµè·¯
å ã®è³ªåè ã®ç°å¢ãä¸è¨ã®ããã«ä»®å®
(1) ç©ççé
ç·ã¯ ONU - ã«ã¼ã¿ - (* 1) - ãµã¼ã
ã *1) ãã®ä½ç½®ã« HUB ãå
¥ã£ã¦ããå¯è½æ§ãããããHUB ã®æç¡ã¯å½±é¿ãç¡ãã®ã§ç¡è¦ããã
(2) åçã§ãONU ã¨ã«ã¼ã¿ã®éã« HUB ããããã«ã¼ã¿ã ONU ã«å¯¾ãã¦ä¸¦åããããããã®ã«ã¼ã¿ãã PPPoE ã®ã»ãã·ã§ã³ãå¼µããã¨ãææ¡ãããã
ãç©ççé ç·ï¼ ããããONU â HUB â ã«ã¼ã¿A ããããããããâââã«ã¼ã¿B
(3) åçã§ã¯ã«ã¼ã¿ãããµã¼ãã¸ã®é
ç·ãããã³ããµã¼ãã®è¨å®ã«é¢ãã¦è¨åããã¦ããªããã¨ãããä¸è¨ã®äºãä»®å®ã
ãã»ãµã¼ãã® NIC ã¯ï¼ã¤
ãã»ãµã¼ãã«å²ãå½ã¦ããã¦ãã IP ã¢ãã¬ã¹ã¯ï¼ã¤
ãã»ã«ã¼ãã£ã³ã°ãããã³ã«ï¼RIPãOSPF ãªã©ï¼ã¯æå¹ã«ãªã£ã¦ãããï¼å°ãªãã¨ããWindowsãLinux ã§ã¯ããã©ã«ãã§ã¯ç¡å¹ï¼ãããã©ã«ãã²ã¼ãã¦ã§ã¤ãè¨å®ããã¦ããã®ã¿ã
(4) ã¾ããå
ã®è³ªåè
ã®ã«ã¼ã¿ã«é¢ãã¦è©³ç´°ã¯ä¸æã ããæåã®æ§æããå
¸åçãªããã¡ãµã¼ãã®æ§æã¨èãã
ãã»ãµã¼ãã«å²ãå½ã¦ã¦ãã IP ã¢ãã¬ã¹ã¯ãã©ã¤ãã¼ãã¢ãã¬ã¹ã
ãã»ã«ã¼ã¿ã«ãã㦠1 対 1 ã®ã¹ã¿ãã£ã㯠NATããããã¯ããµã¼ãã Web ãµã¼ãã§ãããã¨ãããå®å
ãã¼ã 80 ã«å¯¾ã㦠NAPT ä¸ã«ããããã¼ã¨ãã©ã¯ã¼ãã£ã³ã°ã«ããããµã¼ãã¨ã¤ã³ã¿ã¼ãããå´ã®ä»»æã®ç«¯æ«ã¨ã®éã«ããããã±ããã®éåä¿¡ãå¯è½ãªç¶æ
ã«ãã¦ããã
(5) ä¸è¨ã®ä»®å®ãããåçè ã示ãã«ã¼ã¿ã追å ããå¾ã®æ§æãä¸è¨ã®ããã«ä»®å®ã
ãç©ççé ç·ï¼ ããONU â HUB â ã«ã¼ã¿A â HUBï¼*2) â ãµã¼ã ããããããâââã«ã¼ã¿B âââ
ã*2) ãã® HUB ã¯å¿ ãããå¿ è¦ã§ã¯ãªããï¼ã¤ã®ã«ã¼ã¿ã®éãã¯ãã¹ã±ã¼ãã«ã§çµã¶ãããã»ã©å¤ãã«ã¼ã¿ã§ç¡ãéããAuto-MDI ã«ãããèªåçã«çµç·ãã¯ãã¹ã®ç¶æ ã«å¤æ´ãããã
(6) ã¾ããä¸è¨ã®é ç·ãã¨ããNAT ããã¦ãããä»®å®ãçµã¿åããã¦ãIP ã¬ãã«ã§ã®è«ççãªæ§æã¯ä¸è¨ã®ããã«ãªãã
ãè«ççé ç·ï¼ ããã¯ã©ã¤ã¢ã³ã â ã¤ã³ã¿ã¼ããã網 â ISP-A â ã«ã¼ã¿ A ââ¬â ãµã¼ã ããããããããããããã ââââââ ISP-B â ã«ã¼ã¿ B ââ
ã*3) å³å¯ã«ã¯ãISP-A ã ISP-B ãã¤ã³ã¿ã¼ããã網ãæ§æãã¦ããã
ã*4ï¼ã¯ã©ã¤ã¢ã³ããé常ã¯ä½ããã® ISP ã®é
ä¸ã«ãããã¯ã©ã¤ã¢ã³ãã ISP-A ã®é
ä¸ã®å ´åãããã°ãISP-B ã®é
ä¸ã«ããå ´åãããã°ããã®ã©ã¡ãã§ããªãå ´åãããã
(7) ã¾ãã説æã®é½åä¸ãIP ã®ã¢ãã¬ã¹ä¸è¨ã®ããã«ä»®å®ããã
ãã¯ã©ã¤ã¢ã³ãï¼ 11.22.33.44 ãã«ã¼ã¿ A: ISP å´ï¼ã22.33.44.55 ãµã¼ãå´ï¼192.168.1.1 ãã«ã¼ã¿ B: ISP å´ï¼ã33.44.55.66 ãããããããµã¼ãå´ï¼192.168.1.2 ããµã¼ãï¼ãããããã192.168.1.3
(8) åè¿°ã® (1)ã(3) ã®ä»®å®ããããµã¼ããæã£ã¦ããã«ã¼ãã£ã³ã°ãã¼ãã«ã¯ãã«ã¼ã¿è¿½å åã¨å¤æ´ãç¡ããã°ä¸è¨ã®ããã«ãªãã
ããå®å ãããã¯ã¼ã¯ã¢ãã¬ã¹ãâãéä¿¡å ããââââââââââââââ¼ââââââââââââ ãã192.168.1.0/24ããããããâèªåã®ãããã¯ã¼ã¯ ãã0.0.0.0/0 ã â192.168.1.1
以ä¸ã®æ§æããã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãã®éã§éåä¿¡ããããã±ããã«é¢ãã¦èå¯ããã
(9) ãã®æ§æä¸ã§ãã¯ã©ã¤ã¢ã³ããããµã¼ãã«åãã£ã¦éããã IP ãã±ããã¯ä¸è¨ã®ããã«ãªãã
ãã¯ã©ã¤ã¢ã³ãã 22.33.44.55 ã¸ãã±ãããéä¿¡ï¼ ãããããããããããããããããããããâéä¿¡å ã¢ãã¬ã¹âå®å ã¢ãã¬ã¹ ããââââââââââââââââââââ¼ââââââââ¼âââââââ ããã¯ã©ã¤ã¢ã³ããéåºãããã±ããããããâ11.22.33.44 â22.33.44.55 ããã«ã¼ã¿ A ãåãåã£ããã±ãã ããããâ11.22.33.44 â22.33.44.55 ããã«ã¼ã¿ A ããµã¼ãã¸éãåºãããã±ãã â11.22.33.44 â192.168.1.3 ãããµã¼ããåãåã£ããã±ããããããããâ11.22.33.44 â192.168.1.3 ãã¯ã©ã¤ã¢ã³ãã 33.44.55.66 ã¸ãã±ãããéä¿¡ï¼ ãããããããããããããããããããããâéä¿¡å ã¢ãã¬ã¹âå®å ã¢ãã¬ã¹ ããââââââââââââââââââââ¼ââââââââ¼âââââââ ããã¯ã©ã¤ã¢ã³ããéåºãããã±ããããããâ11.22.33.44 â33.44.55.66 ããã«ã¼ã¿ A ãåãåã£ããã±ãã ããããâ11.22.33.44 â33.44.55.66 ããã«ã¼ã¿ A ããµã¼ãã¸éãåºãããã±ãã â11.22.33.44 â192.168.1.3 ãããµã¼ããåãåã£ããã±ããããããããâ11.22.33.44 â192.168.1.3
(10) éã«ããµã¼ããã¯ã©ã¤ã¢ã³ãã¸ãã±ãããéä¿¡ããå ´åãèªèº«ãä¿æããã«ã¼ãã£ã³ã°ãã¼ãã«ã«å¾ãã°ãããã©ã«ãã²ã¼ãã¦ã§ã¤ï¼(8) ã«å¾ã£ã¦ã«ã¼ã¿ Aï¼ã«åãã£ã¦ãã±ãããéåºãããã¨ã«ãªãã
(11) ä»ãã¯ã©ã¤ã¢ã³ããããµã¼ãã«åãã£ã¦ãTCP ã®ã³ãã¯ã·ã§ã³ã確ç«ãããã¨ãèãããTCP ã®ã³ãã¯ã·ã§ã³ã確ç«ããããã«ã¯ãæåã« RFC 793 ã® 3-way handshake ãè¡ãããã3-way handshake ã¯ä¸è¨ã®ï¼ã¤ã®ãã±ããã®ããåããè¡ãããã
ãã»ã¯ã©ã¤ã¢ã³ããããµã¼ãã¸åãã£ã¦ãSYN ãã©ã°ã¤ãã®ãã±ãããéãã
ãã»ãµã¼ãã¯ãSYN ãã©ã°ã¤ãã®ãã±ãããåãåãã¨ãéã主ã«å¯¾ã㦠SYN/ACK ãã©ã°ã¤ãã®ãã±ãããéãã
ãã»ã¯ã©ã¤ã¢ã³ãã¯ããµã¼ããã SYN/ACK ãã©ã°ã¤ãã®ãã±ãããæ»ã£ã¦ããäºã確èªãã¦ãACK ãã©ã°ã¤ãã®ãã±ããããµã¼ãã¸éãã
ã*5) å³å¯ã«ã¯ãã·ã¼ã±ã³ã¹çªå·ã«å¯¾å¿ãã ACK ã®çªå·ï¼åãåã£ããã±ããã®ã·ã¼ã±ã³ã¹çªå·ã« 1 ãå ããæ°å¤ï¼ãã»ããããã¦ããå¿ è¦ãããã
(12) ãµã¼ãã 3-way handshake ã®ï¼ã¤ã®ãã±ãããã¯ã©ã¤ã¢ã³ãã«è¿ããã¨ãã¦ãã±ãããçµã¿ç«ã¦ãã¨ããã® IP ãã±ããã®éä¿¡å ã¢ãã¬ã¹ãå®å ã¢ãã¬ã¹ã¯ä¸è¨ã®ããã«ãªãã
ããéä¿¡å ã¢ãã¬ã¹âå®å ã¢ãã¬ã¹ ããââââââââ¼âââââââ ãã192.168.1.3 â11.22.33.44
(13) ãã®ãã±ããã¯ããµã¼ãã®ã«ã¼ãã£ã³ã°ãã¼ãã«ã«å¾ãã°ãã«ã¼ã¿ A ãçµç±ãã¦ã¯ã©ã¤ã¢ã³ãã«å±ããããã
ããããããããããããããããããããããããããâéä¿¡å ã¢ãã¬ã¹âå®å ã¢ãã¬ã¹ ããâââââââââââââââââââââââââ¼ââââââââ¼âââââââ ãããµã¼ããéåºãããã±ããããããããããããããâ192.168.1.3 â11.22.33.44 ããã«ã¼ã¿ A ãåãåã£ããã±ãã ãããããããããâ192.168.1.3 â11.22.33.44 ããã«ã¼ã¿ A ãã¤ã³ã¿ã¼ãããå´ã¸éãåºãããã±ãã â22.33.44.55 â11.22.33.44 ããã¯ã©ã¤ã¢ã³ããåãåã£ããã±ããããããããããâ22.33.44.55 â11.22.33.44
(14) (13) ã«ç¤ºããã±ããã¯ãããããµã¼ããã«ã¼ãã£ã³ã°ãã¼ãã«ã«å¾ã£ã¦ãã±ãããéåºããã°ã(9) ã§ç¤ºããï¼ã¤ã®ã±ã¼ã¹ã®ãããã®å ´åã§ãåãã«ãªãã
(15) ããããã¨ã
ãã»ã¯ã©ã¤ã¢ã³ãã 22.33.44.55 ã«åãã£ã¦ TCP ã®ã³ãã¯ã·ã§ã³ã確ç«ãããã¨ããå ´åã¯ãéã£ãç¸æã¨åã IP ã¢ãã¬ã¹ãã SYN/ACK ã®ãã±ãããå±ãã
ãã»ã¯ã©ã¤ã¢ã³ãã 33.44.55.66 ã«åãã£ã¦ TCP ã®ã³ãã¯ã·ã§ã³ã確ç«ãããã¨ããå ´åã¯ãéã£ãç¸æã¨éã IP ã¢ãã¬ã¹ãã SYN/ACK ã®ãã±ãããå±ãã
ã¨ããäºãçºçããã
(16) éã IP ã¢ãã¬ã¹ãã 3-way handshake ã®ï¼ã¤ç®ã®ãã±ãããå±ãã¦ãã以éã® TCP ã®å¦çã«é¢ä¿ãªãï¼ï¼ã¤ç®ã®ãã±ããã®éä¿¡å ã¢ãã¬ã¹ã¯ãã©ãããå±ãããé¢ä¿ç¡ãã«ãï¼ã¤ç®ã® ACK ãã±ãããéåºãã¦ãTCP ã®ã³ãã¯ã·ã§ã³ã確ç«ããï¼ã®ã§ããã°ãã¯ã©ã¤ã¢ã³ããã©ã¡ãã® IP ã¢ãã¬ã¹ã«ç¹ããã¨ãã¦ãï¼ã¾ãããµã¼ããã©ã£ã¡ã®ã«ã¼ã¿ãçµè·¯ã¨ãã¦é¸æãã¦ãï¼TCP ã¨ãã¦ã®éä¿¡ãæç«ããã®ã§åé¡ãªãã
ã*6) ä½ããå¤ã¸éä¿¡ããããã±ãããçæ¹ã® ISP ããçµç±ããªããã¨ããåé¡ã¯æ®ãããããã§ã¯ãã®åé¡ã¯èæ ®ããªãã
ããã§ãããã²ã¨ã¤ã®ä»®å®ãããã
(17) TCP ã® 3-way handshake ãæç«ããããã«ãï¼ã¤ç®ã® SYN ãã©ã°ã¤ãã®ãã±ããã®å®å ã¢ãã¬ã¹ã¨ï¼ã¤ç®ã® SYN/ACK ä»ããã±ããã®éä¿¡å ã¢ãã¬ã¹ãåè´ãã¦ããå¿ è¦ããããã¨ããã
(18) (17) ã®ä»®å®ãæãç«ã¦ã°ãã¯ã©ã¤ã¢ã³ãã 33.44.55.66 㸠TCP ã®ã³ãã¯ã·ã§ã³ã確ç«ãããã¨ããæã«åãåãï¼ã¤ç®ã®ãã±ããã 22.33.44.55 ããå±ãã¨ã(18) ã®ä»®å®ã«ãããTCP ã®ã³ãã¯ã·ã§ã³ã確ç«ã§ããªãã
(19) (17) ã®ä»®å®ãæãç«ã¤å ´åã«ãã¯ã©ã¤ã¢ã³ããã©ã¡ãã® IP ã¢ãã¬ã¹ã¸æ¥ç¶ãããã¨ãã¦ããã³ãã¯ã·ã§ã³ãæç«ããããã«ã¯ããµã¼ãå´ã§ã3-way handshake ã®ï¼ã¤ç®ã®ãã±ãããçµç±ããã«ã¼ã¿ã¨åãã«ã¼ã¿ã«å¯¾ãã¦ãï¼ã¤ç®ã®ãã±ãããéåºããå¿ è¦ãããã
(20) (9) ãè¦ãã¨ããµã¼ãåãåããã±ããã® IP ã¢ãã¬ã¹ããã¯ãã©ã£ã¡ã®ã«ã¼ã¿ãçµç±ãããã±ãããªã®ãã¯å¤å¥ã§ããªããå¤å¥ã§ããæ å ±ã¯ãã¤ã¼ãµãã¬ã¼ã ã®éä¿¡å MAC ã¢ãã¬ã¹ã§ããã
(21) TCP ã®ã¬ã¤ã¤ã¼ã§ã¯ã¤ã¼ãµãã¬ã¼ã ã®æ å ±ã«ä¾åããªãããªããªããIP ããä¸ã®ã¬ã¤ã¤ã¼ãã¤ã¼ãµãããã¨ã¯éãããPPPï¼PPPoE ãå«ãï¼ããã¬ã¼ã ãªã¬ã¼ãFDDI ãªã©ãæ§ã ãªã¬ã¤ã¤ã¼ãèãããããããã®éã㯠IP ã®ã¬ã¤ã¤ã¼ã§å¸åãããã
(22) (21) ã®ãã¨ãããTCP ã®ã¬ã¤ã¤ã¼ã§ã¯ãhandshake ã«å¯¾ããï¼ã¤ç®ã®ãã±ãããéãéã«ä¸ä½ã®ã¬ã¤ã¤ã¼ã«æå®ããã®ã¯ IP ã¢ãã¬ã¹ã®ã¿ã§ããã
(23) (22) ã®ãã¨ãã IP ã®ã¬ã¤ã¤ã¼ã¯ã(12) ã§ç¤ºããã¦ããã¢ãã¬ã¹æ å ±ãæã¤ãã±ãããçæããã
(24) ã¢ãã¬ã¹æ å ±ããã«ã¼ãã£ã³ã°ãã¼ãã«ãåç §ããã¨(7) ã«å¾ã£ã¦ãããã©ã«ãã²ã¼ãã¦ã§ã¤ã«æå®ãããã«ã¼ã¿ãé¸æãããã¨ã«ãªããããã§ã¯ã(19) ã®æ¡ä»¶ãæºãããã¨ãåºæ¥ãªãã
(25) (19) ã®æ¡ä»¶ãæºããããã«ã¯ãä¸è¨ã«ä¸ããããããã®ã¡ã«ããºã ãå¿
è¦ã¨ãªãã
ã(i) ãµã¼ãã®ã«ã¼ãã£ã³ã°ãã¼ãã«ããã¯ã©ã¤ã¢ã³ããã SYN ãã©ã°ä»ããã±ããã«åå¿ãã¦æ´æ°ãããã
ã(ii) ã«ã¼ãã£ã³ã°ãã¼ãã«ã¨ã¯å¥ã®ãã¸ãã¯ã«ãã£ã¦çµè·¯é¸æãè¡ãããï¼ä¾ãã°ãéä¿¡å
IP ã¢ãã¬ã¹ã¨éä¿¡å
MAC ã¢ãã¬ã¹ã®ãã¢ãä¿æããéä¿¡å
IP ã¢ãã¬ã¹ããã®æ
å ±ã«è¦ã¤ãã£ãå ´åã«ããã®æ
å ±ãåªå
ãã¦éä¿¡å
ã® MAC ã¢ãã¬ã¹ãæ¡ç¨ããï¼ã
(26) (25)-(i) ã«é¢ãã¦ãå°ãªãã¨ãçè ã¯ãã«ã¼ãã£ã³ã°ãããã³ã«ï¼RIPãOSPFãBGPï¼ã«ãã£ã¦æ´æ°ãããã±ã¼ã¹ãé¤ãã¦ãæåè¨å®ãããå 容以å¤ã®æ å ±ã追å ã»åé¤ãããã±ã¼ã¹ã¯ç¥ããªããããã(23)-(i) ã®ãããªã¡ã«ããºã ã§ã«ã¼ãã£ã³ã°ãã¼ãã«ãæ´æ°ãããã¨ããã°ããµã¼ãã®ã«ã¼ãã£ã³ã°ãã¼ãã«ã¯åæã«è¿½å ãããã¨ã³ããªã§ãã£ã±ãã«ãªã£ã¦ãããã¨ã容æã«æ³åã§ããã
以ä¸ãã¾ã¨ããã¨ã
ã»(16) ãæç«ããã°ãå¤ã¸åºã¦è¡ããã±ãããã©ã¡ãã® ISP ãçµç±ãã¦ããTCP ã®ã³ãã¯ã·ã§ã³ã¯æç«ãåé¡ãªãï¼ä½ãããµã¼ãã®è¨å®ãåä½åç次第ã§ã¯ãéåºããããã±ãããçæ¹ã® ISP ã«åãå¯è½æ§ãããï¼ã
ã»(16) ãæç«ããªãã¨ãªãã°ãTCP ã®ã³ãã¯ã·ã§ã³ãæç«ããããã«ã¯ãã¯ã©ã¤ã¢ã³ããéã£ãæåã® SYN ãã©ã°ä»ããã±ãããçµç±ããã«ã¼ã¿ãããµã¼ããå¿ ãé¸æããã¡ã«ããºã ãå¿ è¦ã