ºìÁªLinuxÃÅ»§
Linux°ïÖú

FreeBSDϵĴø¿í¿ØÖÆ -- ipfw+dummynet

·¢²¼Ê±¼ä:2006-05-02 23:31:22À´Ô´:ºìÁª×÷Õß:CMK
»·¾³£ºFreeBSD 4.5-Release
ÔÚFreeBSDÏ¿ÉÒÔͨ¹ýipfw+dummynetÀ´½øÐдø¿í¿ØÖÆ£¬¾ßÌåʵÏÖÈçÏ£º
1¡¢ ÐÞ¸Äkernel configuration file, ¼ÓÈë¶ÔIPFWºÍDUMMYNETµÄÖ§³Ö
options IPFIREWALL
options DUMMYNET
ÖØбàÒ룬°²×°ÐµÄkernel
×¢£ºÈç¹ûÔ­ÄÚºËÖÐÖ§³ÖIPFILTER, Çë×¢ÊÍ options IPFILTER¡£
# ---------------------------------------------------------------------------
firewall_enable="YES" # Set to YES to enable firewall functionality
firewall_script="/etc/rc.firewall" # Which script to run to set up the firewall
firewall_type="open" # Firewall type (see /etc/rc.firewall)
# ---------------------------------------------------------------------------
×¢£ºÒòΪÊDzâÊÔFreeBSDµÄ´ø¿í¹ÜÀí, ²»ÏëÔÚipfwÉÏÀË·Ñʱ¼ä£¬Òò´ËÎÒÃǽ«firewallÉèÖÃ
Ϊopen״̬, ÔÊÐíËùÓаüµÄin, out
3¡¢ ÖØÐÂÆô¶¯ÏµÍ³£¬ÈÃÐÂÄÚºËÆð×÷Óá£ÔÚipfwÀï¼ÓÈë×Ô¼ºµÄrulesÀ´½øÐдø¿í¹ÜÀí£º
# ipfw pipe 1 config bw 128Kbytes/s
# ipfw add 1000 pipe 1 ip from 172.22.4.90 to 172.22.0.0/24 out
×¢£º172.22.4.90ÊÇFreeBSDÍø¿¨µÄip address, 172.22.0.0/16ÊÇËüËùÔÚµÄÍø¶Î
µÚÒ»Ìõrule¶¨ÒåÁËÒ»¸ö128Kbytes/sµÄpipe
µÚ¶þÌõrule Êǽ«´Ó172.22.4.90-¡µ172.22.0.0/16 µÄpacketË͵½pipe 1´¦Àí
²âÊÔ½á¹û£º
¼ÓÈëÁ½ÌõruleÇ°´ÓFreeBSDÉÏÏÂÔØÎļþËÙÂÊÊÇ900K Bytes/s£¨10M¾ÖÓòÍø£©
¼ÓÈëÁ½Ìõruleºó´ÓFreeBSDÉÏÏÂÔØÎļþËÙÂÊÊÇ127K Bytes/s
ÒÔÉÏÖ»ÊÇÒ»¸öºÜ¼òµ¥µÄ²âÊÔ£¬µ«´Ó½á¹û¿´FreeBSDÏÂͨ¹ýipfw+dummynet¿ÉÒԺܺõĽøÐдø¿í
µÄ¿ØÖÆ¡£´ó¼Ò¿ÉÒԲο¼dummynetÊÖ²áÀ´¶¨ÖƸü¸´ÔÓµÄruleÀ´Âú×ã×Ô¼ºµÄÐèÇó£¡
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ