Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
* HanIRCÀÇ #coffeenix ¹æ
[ Àåºñ ¹× ȸ¼± ÈÄ¿ø ]
HOME > ³×Æ®¿öÅ©(network) µµ¿ò¸»
°Ë»ö : »çÀÌÆ® WHOIS À¥¼­¹ö Á¾·ù

TCP/IP, ÇÁ·ÎÅäÄÝ, Æ÷Æ® (11, ±Û 2, ÀÚ·á 25)
ÀÎÅÍ³Ý Á¢¼Ó (1, ±Û 3)
À¥ ¼­¹ö(web, httpd, apache) (48, ±Û 42, ÀÚ·á 31)
¸ÞÀÏ ¼­¹ö(mail) (31, ±Û 42, ÀÚ·á 23)
³×ÀÓ¼­¹ö(name server, dns, bind) (15, ±Û 18, ÀÚ·á 4)
FTP ¼­¹ö / rsync / ¹Ì·¯¸µ / CVSup (12, ±Û 13, ÀÚ·á 9)
¸Á°ü¸® / SNMP / QoS (13, ÀÚ·á 16)
»ï¹Ù (samba) (4, ±Û 1, ÀÚ·á 5)
ÇÁ¶ô½Ã ¼­¹ö(ÇÁ·Ï½Ã, proxy server) (6, ±Û 3, ÀÚ·á 2)
³×Æ®¿öÅ© Åø (15, ±Û 1, ÀÚ·á 11)
Ŭ·¯½ºÅ͸µ(cluster) (6, ÀÚ·á 1)
Àåºñ / ¶ó¿ìÅÍ / ½ºÀ§Äª (8, ±Û 3, ÀÚ·á 8)
IRC (Internet Relay Chat) / ¸Þ½ÅÀú (6)
ssh / telnet (10, ±Û 3, ÀÚ·á 2)
NFS / SHFS (5, ÀÚ·á 2)
VPN ¼­¹ö, FreeS/WAN (4)
DHCP (1, ÀÚ·á 1)
LDAP (3, ÀÚ·á 1)
SAN / NAS / ½ºÅ丮Áö (4, ±Û 2, ÀÚ·á 6)
À½¾Ç¹æ¼Û / icecast (3, ±Û 1)

  [Æ©´×] ¼Ö¶ó¸®½º¿¡¼­ ³×Æ®¿öÅ© ÆĶó¹ÌÅÍ ¼³Á¤ ÀÛ¼ºÀÏ : 2003/09/04 14:29
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 11047
          [ ÀÌÀüÈ­¸é / ¼öÁ¤ ]   ºñ¹Ð¹øÈ£ :     Àμâ¿ë È­¸é
      ±Û¾´ÀÌ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2001.4.18
    ¼öÁ¤ÀÏ : 2001.7.16
    Á¤¸®ÀÏ : 2003.9.4(¸ñ)

    ¼Ö¶ó¸®½º¿¡¼­´Â ¸®´ª½ºÀÇ sysctl ¸í·É¾î ó·³ ndd¸¦ ÀÌ¿ëÇؼ­ Ä¿³Î ÆĶó¹ÌÅ͸¦ º¯°æÇÒ ¼ö ÀÖ´Ù.

    1) Ä¿³Î ³×Æ®¿öÅ© ÆĶó¹ÌÅÍ ¼³Á¤

    ping ÀÀ´ä ¹«½ÃÇÏ°í, Æ÷¿öµùÀ» ¸·´Â IP°ü·Ã ³×Æ®¿öÅ© ÆĶó¹ÌÅ͸¦ ¼³Á¤ÇÏ´Â ¹æ¹ýÀº ´ÙÀ½°ú °°´Ù.
    ¶ÇÇÑ ¼Ö¶ó¸®½º¿¡¼­´Â ±× Àǹ̰¡ ¾àÇÑ SYN flooding °ø°Ý¿¡ ´ëóÇÏ´Â ÆĶó¹ÌÅÍ ¼³Á¤µµ ¸¶Áö¸·
    3ÁÙ¿¡ Æ÷ÇÔ¸þ¾ú´Ù.

    ------------------------------------------------
    # IP forwardingÀ» ÇÏÁö ¾ÊÀ½
    ndd -set /dev/ip ip_forwarding 0
    ndd -set /dev/ip ip_strict_dst_multihoming 0
    ndd -set /dev/ip ip_forward_directed_broadcasts 0
    ndd -set /dev/ip ip_forward_src_routed 0

    # echo request Broadcast ÇÎ ÀÀ´ä ¹«½Ã
    ndd -set /dev/ip ip_respond_to_echo_broadcast 0

    # TCP parameter
    ndd -set /dev/tcp tcp_ip_abort_cinterval 60000
    ndd -set /dev/tcp tcp_conn_req_max_q0 2048
    ndd -set /dev/tcp tcp_conn_req_max_q 512
    ------------------------------------------------

    TCP ÆĶó¹ÌÅÍ¿¡ ´ëÇØ ¼³¸íÇϸé.

    tcp_ip_abort_cinterval :
    ¿¬°áÀÌ ÀÖÀº ÈÄ Á¤»óÀûÀ¸·Î established °¡ ¾ÈµÇ¸é  ¿¬°áÀ» ²÷À» ½Ã°£À» ¼³Á¤ÇÑ´Ù.
    Áï, Abort timer °ªÀ» Á¤ÇÑ´Ù.
    ´ÜÀ§´Â ¹Ð¸®ÃÊ. µû¶ó¼­ 60000 = 60ÃÊÀÓ (default=180000 = 180ÃÊ)
    tcp_conn_req_max_q0 :
    ¿Ïº®È÷ Á¢¼ÓµÇÁö ¾ÊÀº »óÅÂÀÇ ¿¬°á(half-open)À» À§ÇÑ Å¥(default=1024)
    tcp_conn_req_max_q :
    established »óÅÂÀÇ ¿¬°áÀ» À§ÇÑ Å¥ (default=128)

    2) ºÎÆÃ¿ë ½ºÅ©¸³Æ®

    ºÎÆÃ¿ë ½ºÅ©¸³Æ®¸¦ ¿©±â¿¡ µÎ¾ú´Ù.

    http://coffeenix.net/doc/misc/tf.tcpparameter.txt

    tf.tcpparameter.txt¸¦ /etc/init.d¿¡ ¿Å±â°í
    rc2.d¿¡¼­ ¸µÅ©¸¦ °É¾î ºÎÆÃÇÒ ¶§ ½ÇÇàµÇµµ·Ï ÇÏ¸é µÈ´Ù.

    ------------------------------------------------
    # mv tf.tcpparameter.txt /etc/init.d/tf.tcpparameter
    # cd /etc/rc2.d ¶Ç´Â cd /etc/rc3.d
    # ln -s ../init.d/tf.tcpparameter S99tcpparameter
    ------------------------------------------------

    ¡Ø Âü°íÀÚ·á

    http://www.certcc.or.kr/paper/tr2001/tr2001-01/Solaris%20Network%20Kernel%20Tunning%20for%20Security.html
      Ä¿ÇǴнº Ä«Æä ÃÖ±Ù ±Û
    [04/25] ±¹°¡&#5
    [04/24] º¸Çè&#5
    [04/22] Re: OpenSSL Ãë¾àÁ¡ Á¤¸®, Logjam(·Î±×Àë)¿¡¼­ Heartbleed±îÁö
    [04/21] LET¡¯S START WITH ON
    [04/21] º¸Çè&#5
    [04/20] Á¦ÁÖ&#5
    [04/20] ±¹³»&#5
    [04/19] Á¦ÁÖ&#5
    [04/18] ??? ?????
    [04/17] ???? onion ?????? -
    [04/11] ±¹°¡&#5
    [04/10] Stride Into Dream:
    [03/20] Re: ¿Â¶óÀΰÔÀÓÀÇ Á¾ÁÖ±¹ ´ëÇѹα¹
    [10/20] Cross Compiler ±ò
    [07/14] SSL ¬¡¬°
      New!   ÃÖ±Ù¿¡ µî·ÏÇÑ ÆäÀÌÁö
      KiCad EDA Suite project (Free/Libre/Open-Source EDA Suite) (CAD)
      ¿ÀÇÂij½ºÄÉÀ̵å ijµå (OpenCASCADE CAD)
      QCad for Windows --- GNU GPL (Free Software)
      The Hello World Collection
      IPMI¸¦ È°¿ëÇÑ ¸®´ª½º ¼­¹ö°ü¸®
      DNS ¼³Á¤ °Ë»ç
      nagiosgraph ¼³Ä¡ ¹æ¹ý
      Slony-I ¼³Ä¡ ¹æ¹ý (postgresql replication tool)
      Qmail±â¹ÝÀÇ Anti spam ½Ã½ºÅÛ ±¸ÃàÇϱâ
      clusterssh

    [ ÇÔ²²ÇÏ´Â »çÀÌÆ® ]




    ¿î¿µÁø : ÁÁÀºÁøÈ£(truefeel), ¾ß¼ö(yasu), ¹ü³ÃÀÌ, sCag
    2003³â 8¿ù 4ÀÏ~