免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 2238 | 回复: 1
打印 上一主题 下一主题

[OpenBSD] 大家来给看看openbsd+pf建墙的问题 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2008-12-25 10:40 |只看该作者 |倒序浏览
方案:
1.现有10M的外网接入到fxp0,然后给fxp1 dmz区分 2M,给fxp2 int区分8M
2.出去的服务器地址有固定ip信用并限制固定端口外发
3.dmz区与int区可互访

|
|
wan 10m
|
|
bsd+pf---int 8m---juniper FW---mail and web server
|
|
dmz 2M
|
|
dns server---db server

问题:
1.请大家帮忙看看在nat和互访方面那配置的有问题
2.我仅是用altq作带宽分配,而不对具体协议作流量限制,不知altq部分还需要补充些什么

我的配置如下:
设置开机运行
#vi /etc/rc.conf.local
ifconfig_fxp0="inet x.x.x.1 netmask 255.255.255.240"
ifconfig_fxp_alias0="inet x.x.x.2 netmask 255.255.255.240"
ifconfig_fxp_alias1="inet x.x.x.3 netwask 255.255.255.240"
ifconfig_fxp_alias2="inet x.x.x.4 netwask 255.255.255.240"
ipconfig_fxp1="inet 192.168.2.1 netmask 255.255.255.0"
ipconfig_fxp2="inet 192.168.3.1 netmask 255.255.255.252"
hostname="bsd"
defaultrouter="x.x.x.1"
gateway_enable="YES"

sshd_enable="YES"
inetd_enable="YES"
syslogd_flags="-ss"

sendmail_enable="NO"
sendmail_submit_enable="NO"
sendmail_outbound_enable="NO"
sendmail_msp_queue_enable="NO"

pf="YES"
pf_rules="/etc/pf.conf"
pflog_enable="YES"
pflog_logfile="/var/log/pflog"

2.配置规则
#macros
ext_if="fxp0"
dmz_if="fxp1"
int_if="fxp2"

tcp_services="{25,53,80,110,5900}"
udp_services="{53}"
icmp_types="echoreq"
priv_nets="{127.0.0.0/8,192.168.0.0/16,172.16.0.0/12,10.0.0.0/8}"
dns_server="192.168.2.2"
db_server="192.168.2.3"
mail_server="192.168.3.2"
web_server="192.168.3.3"

dns_extip="x.x.x.2"
web_extip="x.x.x.3"
mail_extip="x.x.x.4"

#options
set block-policy return
set loginterface $ext_if

#scrub
scrub in all

#nat/rdr
binat on $ext_if from $dns_server port { 53 80 } to any -> $dns_extip
binat on $ext_if from $web_server port { 53 80 } to any -> $web_extip
binat on $ext_if from $mail_server port { 25 53 80 110 } to any -> $mail_extip

rdr on $ext_if proto tcp from any to $mail_extip port { 25 53 80 110 } -> $mail_server
rdr on $ext_if proto tcp from any to $dns_extip port { 53 80 } -> $dns_server
rdr on $ext_if proto tcp from any to $web_extip port { 53 80 } -> $web_server
rdr on $ext_if proto udp from any to any port 53 -> $dmz_if:network
rdr on $ext_if proto udp from any to any port 53 -> $int_if:network

#filter rules
block all
pass quick on lo0 all
block drop in quick on $ext_if from $priv_nets to any
block drop out quick on $ext_if from any to $priv_nets
pass in quick on $ext_if proto tcp from any to $mail_server port { 25 53 80 110 } flags S/SA synproxy state
pass in quick on $ext_if proto tcp from any to $dns_server port { 53 80 } flags S/SA synproxy state
pass in quick on $ext_if proto tcp from any to $web_server port { 53 80 } flags S/SA synproxy state
pass in quick on $ext_if proto udp from any to any port 53 flags S/SA synproxy state

pass in inet proto icmp all icmp-type $icmp_types keep state
pass in on $dmz_if form $dmz_if:network to any keep state
pass in on $int_if form $int_if:network to any keep state
pass out on $dmz_if form any to $dmz_if:network keep state
pass out on $int_if form any to $int_if:network keep state
pass out on $ext_if proto tcp all modulate state flags S/SA
pass out on $ext_if proto {udp,icmp} all keep state

#ALTQ
altq on fxp1 cbq 2Mb
altq on fxp2 cbq 8Mb

3.建立端口路由
#vi /etc/sysctl.conf
net.inet.ip.forwarding=1

[ 本帖最后由 ns_peanut 于 2008-12-25 17:27 编辑 ]

论坛徽章:
1
数据库技术版块每日发帖之星
日期:2016-08-04 06:20:00
2 [报告]
发表于 2008-12-26 09:42 |只看该作者
观注强人帮忙分析一下!
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP