ÃÑ ÆäÀÌÁö ¼ö : 3224
![]()
|
Facebook Joinc ±×·ì
Joinc QA »çÀÌÆ®
![]()
Tweet
joinc´Â Firefox¿Í chrome¿¡¼ Å×½ºÆ® Çß½À´Ï´Ù. IE¿¡¼´Â Å×À̺íÀÌ ±úÁö°Å³ª À̹ÌÁö°¡ º¸ÀÌÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ƯÈ÷ ±¸±Û DocsÀ̹ÌÁöÀÇ °æ¿ì ¿¢¹Úó¸®µÉ ¼ö ÀÖ½À´Ï´Ù. 1 GNS3·Î ¾Ë¾Æº¸´Â OSI7 - L2
³×Æ®¿öÅ© °øºÎ´ÂOSI7ÀÇ °¢ °èÃþÀ» ÀÌÇØÇÏ´Â °Í¿¡¼ºÎÅÍ ½ÃÀÛÇÕ´Ï´Ù. °¢ °èÃþÀÇ ÇÁ·ÎÅäÄÝÀÇ Æ¯¼ºÀ» ÀÌÇØÇϰí ÀÀ¿ëÇÏ´Â °ÅÁÒ.
¾ó¸¶Àü ºÎÅÍ ³×Æ®¿öÅ© ½Ã¹Ä·¹ÀÌ¼Ç µµ±¸ÀÎ GNS3¸¦ »ç¿ëÇÏ°Ô µÆ½À´Ï´Ù. ÁÁÀº Åøµµ ¼Õ¿¡ Áã°Ô µÆÀ¸´Ï À̹ø Âü¿¡ OSI7À» óÀ½ºÎÅÍ °øºÎÇØº¸±â·Î ¸¶À½ ¸Ô¾ú½À´Ï´Ù. ´ë·« ¾Ë°í ÀÖ±â´Â ÇÏÁö¸¸, (¿¡¹Ä·¹¾îÅÍ À̱ä ÇÏÁö¸¸)Àåºñ¸¦ °¡Áö°í Á÷Á¢ °æÇèÇÏ´Â °Í°ú´Â ºÐ¸íÈ÷ Â÷À̰¡ ÀÖÀ»Å×´Ï ¸»ÀÔ´Ï´Ù. ¾Ë°í ÀÖ¾ú´ø °ÍÀº È®½ÇÈ÷ È®ÀÎÇϰí, ±×·¯¸é¼ »õ·Î¿î °Íµµ ¹è¿ì°í.
´ë°ÔÀÇ ¼ÒÇÁÆ®¿þ¾î °³¹ßÀÚµéÀÌ ±×·¸µíÀÌ, Àú ¿ª½Ã OSI7 °èÃþ¿¡ ´ëÇØ¼´Â ÀÌ·±°Ô ÀÖ±¸³ª ÇÏ´Â Á¤µµ¸¸ ¾Ë°í ÀÖ½À´Ï´Ù. °øºÎÇÏ¸é¼ ¹®¼¸¦ ¸¸µå´Â °ÅÁÒ. µû¶ó¼ À߸øµÈ ³»¿ëÀÌ ÀÖÀ» ¼ö ÀÖÀ½À» ¹àÇôµÓ´Ï´Ù. 2 OSI 7 Layer
OSI7¿¡ ´ëÇÑ ³»¿ëÀº OSI7°ú ¸µÅ© ¹®¼µéÀ» Âü°íÇϽðí.. 3 L2
L1Àº ¹°¸®Àû ¼¼ºÎ »çÇ×µéÀ» Á¤ÀÇÇÏ´Â °èÃþÀ¸·Î ¼ÒÇÁÆ®¿þ¾î °³¹ßÀÚ¿¡°Ô´Â Çʿ䰡 ¾øÀ» °ÍÀ̶ó »ý°¢µË´Ï´Ù. ±×·¡¼ °Ç³Ê¶Ù°í L2ºÎÅÍ °øºÎÇϱâ·Î ÇÕ´Ï´Ù.
L2´Â µ¥ÀÌÅÍ ¸µÅ© °èÃþÀÔ´Ï´Ù. point-to-point°£ ½Å·Ú¼ºÀÖ´Â Àü¼ÛÀ» À§ÇÑ °èÃþÀÔ´Ï´Ù. point-to-point ¶ó°í ÇÏ´Ï Á» Çê°¥¸± ¼ö ÀÖÀ» °Í °°Àºµ¥, ÀÌ´õ³Ý Ä«µå¿Í ÀÌ´õ³Ý Ä«µå°¡ Á÷Á¢ ¿¬°áµÇ´Â ±¸Á¶¶ó°í º¸½Ã¸é µË´Ï´Ù. ¶§¶§·Î ÄÄÇ»ÅÍ¿Í ÄÄÇ»ÅͰ¡ ¿¬°áµÈ À̶ó°í ¼³¸íÇϱ⵵ Çϴµ¥, ºü¸¥ ÀÌÇØ¸¦ À§Çؼ´Â µµ¿òÀÌ µÇÁö¸¸ ³ªÁß¿¡ Çê°¥¸®°Ô µÇ¹Ç·Î ÄÄÇ»ÅͰ¡ ¾Æ´Ñ ÀÌ´õ³Ý Ä«µå¸¦ ÃÖ¼Ò´ÜÀ§·Î ÇϰڽÀ´Ï´Ù.
ÀÌ´õ³Ý Ä«µå¿Í ÀÌ´õ³Ý Ä«µå°¡ Á÷Á¢ ¿¬°áÇÏ´Â ±¸Á¶·Î ÀÌ´õ³Ý Ä«µå¸¦ Áß°èÇÏ´Â ³×Æ®¿öÅ© ºê¸®Áö, ½ºÀ§Ä¡ µîÀÌ ´ëÇ¥ÀûÀÎ L2ÀåºñÀÔ´Ï´Ù.
°¡Àå ÀϹÝÀûÀÎ L2±¸Á¶´Â ¾Æ·¡¿Í °°ÀÌ ÇϳªÀÇ ½ºÀ§Ä¡¿Í Çϳª ÀÌ»óÀÇ ÀÌ´õ³Ý Ä«µå·Î ±¸¼ºµÈ ³×Æ®¿öÅ© ±¸¼ºÀÔ´Ï´Ù. 3.1 Eternet Frame
L2 ¿¡¼ »ç¿ëÇÏ´Â ÆÐŶ ÇÁ·¹ÀÓ±¸Á¶¸¦ ¸ÕÀú ¾Ë¾Æ¾ß °Ú½À´Ï´Ù. L2´Â Ethernet FrameÀ» »ç¿ëÇÕ´Ï´Ù. L2¸¦ ÀÌÇØÇÑ´Ù´Â °ÍÀº Ethernet Frame¿¡ ÀÖ´Â Á¤º¸¸¦ ÀÌÇØÇÑ´Ù´Â °ÅÁÒ.
4 MAC Address
½ºÀ§Ä¡¸¦ Áß½ÉÀ¸·Î ÀÌ´õ³Ý Ä«µå¸¦ ¿¬°áÇߴµ¥¿ä. µ¥ÀÌÅÍ Åë½ÅÀ» ÇÏ·Á¸é ¾Æ·¡ÀÇ µÎ °¡Áö Á¶°ÇÀÌ ¸¸Á·µÅ¾ß ÇÕ´Ï´Ù.
½ºÀ§Ä¡´Â ¿¬°áµÅ ÀÖ´Â ÀÌ´õ³Ý Ä«µåÀÇ MAC Address Å×À̺íÀ» À¯ÁöÇϰí ÀÖ½À´Ï´Ù. ÀÌ Å×À̺í Á¤º¸¸¦ ÀÌ¿ëÇØ¼ ÆÐŶÀ» ¾î´À Æ÷Æ®·Î º¸³¾Áö¸¦ °áÁ¤ÇÕ´Ï´Ù. MAC Address <-> Port Á¤º¸¸¦ ÀúÀåÇÏ´Â °ÅÁÒ. 5 GNS3·Î L2 ȯ°æ ±¸¼º
L2 ³×Æ®¿öÅ©¿Í L2 ³×Æ®¿öÅ©¿¡¼ »ç¿ëÇÏ´Â ÇÁ·ÎÅäÄÝÀ» Å×½ºÆ® ÇϱâÀ§Çؼ GNS3·Î L2 ȯ°æÀ» ±¸¼ºÇß½À´Ï´Ù.
VBOX1 ¼³Á¤ # ifconfig eth2 192.168.105.1 up
VBOX2 ¼³Á¤ # ifconfig eth2 192.168.105.2 up
ÀÌ´õ³ÝÀÇ MAC Address´Â ifconfig ¸í·ÉÀ¸·Î È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. # ifconfig -a
...
eth2 Link encap:Ethernet HWaddr 08:00:27:6c:b0:73
inet addr:192.168.105.2 Bcast:192.168.105.255 Mask:255.255.255.0
inet6 addr: fe80::1278:d2ff:fe2f:a253/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:52458 errors:0 dropped:0 overruns:0 frame:0
TX packets:46654 errors:0 dropped:0 overruns:0 carrier:1
collisions:0 txqueuelen:1000
RX bytes:50772538 (50.7 MB) TX bytes:8457892 (8.4 MB)
Interrupt:44
6 SwitchÀÇ MAC Address Table È®ÀÎ
ÀÌ´õ³Ý ½ºÀ§Ä¡ÀÎ SW1ÀÇ MAC Address Å×À̺íÀ» È®ÀÎÇØ º¸°Ú½À´Ï´Ù. gns3»ó¿¡¼ SW1À» ¼±ÅÃÇÑ´ÙÀ½ ¸¶¿ì½º ¿ìŬ¸¯Çϸé "MAC Address Table" ¸í·ÉÀÌ ³ª¿À´Âµ¥, ÀÌ ¸í·ÉÀ¸·Î ½ºÀ§Ä¡°¡ °ü¸®Çϰí ÀÖ´Â MAC Address Table¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. 0800.272f.b464 learned from port 1 0800.276c.b073 learned from port 2VBOX1°ú VBOX2ÀÇ Mac Address¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
VBOX1¿¡¼ VBOX2·Î º¸³¾ ÆÐŶÀ» ¸¸µé¸é ÀÌ´õ³Ý ÇÁ·¹ÀÓ¿¡ VBOX2ÀÇ MAC Address¸¦ Àû½À´Ï´Ù. ÀÌ ÆÐŶÀ» ¹ÞÀº SW1Àº Mac Accress Table¿¡ ÀÏÄ¡ÇÏ´Â MAC Address°¡ ÀÖ´ÂÁö È®ÀÎÇØ¼, ÀÏÄ¡ÇÏ´Â Æ÷Æ®·Î ÆÐŶÀ» ³»º¸³»ÁÒ. 7 ARP
VBOX1Àº VBOX2·Î µ¥ÀÌÅ͸¦ Àü¼ÛÇÏ·Á¸é VBOX2ÀÇ MAC Address¸¦ ¾Ë°í ÀÖ¾î¾ß ÇÕ´Ï´Ù. ÀÌ ¿Ü¿¡µµ IP ÁÖ¼Ò¸¦ ¾Ë°í ÀÖ¾î¾ß ÇÏÁÒ. ±×·±µ¥ ¿ì¸®°¡ ½ÇÁ¦ µ¥ÀÌÅ͸¦ Àü¼ÛÇÒ ¶§´Â MAC Address°¡ ¾Æ´Ñ IP ÁÖ¼Ò¸¦ »ç¿ëÇϱ⠶§¹®¿¡, IP ÁÖ¼Ò¿Í MAC Address¸¦ ¸ÊÇÎÇØÁÖ´Â Á¤º¸°¡ ÀÖ¾î¾ß ÇÕ´Ï´Ù.
IP ÁÖ¼Ò¿Í MAC AddressÀÇ ¸ÊÇÎ Á¤º¸¸¦ ¸¸µé±â À§Çؼ »ç¿ëÇÏ´Â ÇÁ·ÎÅäÄÝÀÌ ARP(Address resolution protocol)ÇÁ·ÎÅäÄÝÀÔ´Ï´Ù.
óÀ½ ¿î¿µÃ¼Á¦°¡ ¿Ã¶ó¿À¸é, ÀÌ ¿î¿µÃ¼Á¦´Â ÁÖº¯ÀÇ ³×Æ®¿öÅ© »óȲÀ» ¾ËÁö ¸øÇÕ´Ï´Ù. ±×·¡¼ ÁÖº¯ÀÇ ¿î¿µÃ¼Á¦¿Í Åë½ÅÇØ¾ßÇÒ »óȲÀÌ ¿À¸é, ½ºÀ§Ä¡·Î ARP ¿äûÀ» Àü¼ÛÇÕ´Ï´Ù. À̶§ ARP ÆÐŶÀº ºê·Îµåij½ºÆÃ ÁÖ¼Ò·Î º¸³À´Ï´Ù. ±×·¯¸é ½ºÀ§Ä¡´Â ¸ðµç ¸µÅ©·Î ARP ÆÐŶÀ» º¸³À´Ï´Ù. ARP ÆÐŶÀ» ¹ÞÀº ¿î¿µÃ¼Á¦´Â ÀÚ½ÅÀÇ MACÁÖ¼Ò¿Í IPÁÖ¼Ò¸¦ ARPÇì´õ¿¡ ä¿ö¼ ÀÀ´äÇÏ´Â °ÅÁÒ.
ARP ÀÀ´äÀ» ¹ÞÀº ¿î¿µÃ¼Á¦´Â ARP Å×À̺íÀ» °ü¸®ÇÕ´Ï´Ù. ÀÌÈÄ µ¥ÀÌÅÍ Àü¼ÛÀº ARP Å×À̺íÀ» ÀÌ¿ëÇÏÁÒ. ¸®´ª½º¿¡¼´Â arp ¸í·ÉÀ» ÀÌ¿ëÇØ¼ arp Å×À̺íÀ» È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. # arp -anÀÌÁ¦¸· ¿î¿µÃ¼Á¦¸¦ ºÎÆÃÇß´Ù¸é, arp Å×ÀÌºí¿¡´Â ¾Æ¹«·± Á¤º¸°¡ ¾øÀ» °Ì´Ï´Ù. »ç¿ëÀÚ°¡ arp Å×ÀÌºí¿¡ ¾ø´Â IP·Î µ¥ÀÌÅÍ Àü¼ÛÀ» ½ÃµµÇϸé, ±×¶§ arp ¿äûÀ» ºê·Îµåij½ºÆÃ ÇÕ´Ï´Ù.
tcpdump·Î È®ÀÎ ÇØº¸°Ú½À´Ï´Ù. ¾ÆÁ÷ ¾î¶² Åë½Åµµ ÇÏÁö ¾Ê´Â »óÅÂ, ±×·¯´Ï±î arp table¿¡ ¾Æ¹«·± ³»¿ëÀÌ ¾ø´Â »óÅ¿¡¼ VBOX2¿¡¼ tcpdump¸¦ ¶ç¿ü½À´Ï´Ù. # tcpdump -ennqti eth1 \(arp or icmp\)
ÀÌÁ¦ VBOX1¿¡¼ VBOX2·Î PINGÀ» º¸³À´Ï´Ù. # ping 192.168.105.2
VBOX2ÀÇ tcpdump Á¤º¸ÀÔ´Ï´Ù. # tcpdump -ennqti eth1 \(arp or icmp\) listening on eth1, link-type EN10MB (Ethernet), capture size 65545 bytes 08:00:27:2f:b4:64 > ff:ff:ff:ff:ff:ff, ARP, length 60: Request who-has 192.168.105.2 tell 192.168.105.1, length 46 08:00:27:6c:b0:73 > 08:00:27:2f:b4:64, ARP, length 42: Reply 192.168.105.2 is-at 08:00:27:6c:b0:73, length 46 08:00:27:2f:b4:64 > 08:00:27:6c:b0:73, IPv4, length 98: 192.168.105.1 > 192.168.105.2: ICMP echo request, id 935, seq 1,length 64 ...VBOX1¿¡¼ 192.168.105.2·Î PINGÀ» º¸³À´Ï´Ù. 192.168.105.2´Â °°Àº ¼ºê³Ý IP ÁÖ¼ÒÀ̹ǷΠL2 Åë½ÅÀ» ÇÏ·Á°í ÇϰÚÁÒ. ±×·²·Á¸é ARP Å×ÀÌºí¿¡ 192.168.105.2ÀÇ MAC ÁÖ¼Ò Á¤º¸°¡ ÀÖ¾î¾ß Çϴµ¥, ãÀ» ¼ö ¾ø½À´Ï´Ù. ±×·¡¼ PINGÀ» º¸³»±â Àü¿¡ ¸ÕÀú ARP¸¦ ºê·Îµåij½ºÆÃ ÇÕ´Ï´Ù.
# arp -an ? (192.168.105.2) at 08:00:27:6c:b0:73 [ether] on eth2
Á¤¸» ARP°¡ ºê·ÎµåÄɽºÆÃ µÇ´ÂÁö È®ÀÎÇÏ°í ½Í´Ù¸é, VMÀ» Çϳª ´õ ºÙÀÌ¸é µË´Ï´Ù. ºê·ÎµåÄɽºÆÃ µÈ´Ù¸é ¸ðµç VM¿¡ ARP°¡ Àü¼ÛµÇ´Â °É È®ÀÎÇÒ ¼öÀÖÀ» Å״ϱî¿ä. Á÷Á¢ ÇØº¸¼¼¿ä. 7.1 ´Ù¸¥ subnetÀ¸·Î ARP¸¦ Àü¼ÛÇϸé ?
À§ ¿¹Á¦¿¡¼ VBOX1°ú VBOX2´Â °°Àº subnet¿¡ ÀÖ½À´Ï´Ù. ´Ù¸¥ subnetÀ» °¡Áø´Ù¸é ¾î¶»°Ô µÉ±î¿ä. VBOX1Àº 192.168.105.1 VBOX2´Â 192.168.205.1ÀÎ °æ¿ì¿¡µµ ARP°¡ Àü¼ÛµÉ±î¿ä ?
ARP´Â ºê·Îµå ij½ºÆÃÀ̴ϱî. ¼ºê³ÝÀÌ ´Ù¸£´õ¶óµµ Àü¼ÛµÉ °Å¶ó´Â »ý°¢ÀÌ µé±äÇÕ´Ï´Ù. ÇÏÁö¸¸ ½ÇÁ¦ Å×½ºÆ® ÇØº¸¸é, ARP ¿äûÀÌ °¡Áö ¾Ê´Â °É È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌÀ¯´Â ´ÙÀ½°ú °°½À´Ï´Ù. VBOX1À» ±âÁØÀ¸·Î ¼³¸íÇØ º¸°Ú½À´Ï´Ù.
VBOX1ÀÇ routeÁ¤º¸¸¦ º¸¸é Default gateway°¡ ¾ø´Â °É È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. # route -n Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 192.168.105.0 0.0.0.0 255.255.255.0 U 0 0 0 eth2¸¸¾à 192.168.205.1·Î µ¥ÀÌÅ͸¦ º¸³»·Á°í ÇÑ´Ù¸é, ÀÌ ÁÖ¼Ò´Â ¶ó¿ìÆÃ °æ·Î¸¦ Á¤ÇÒ ¼ö°¡ ¾ø½À´Ï´Ù. µû¶ó¼ ÆÐŶÀ» Æó±âÇØ¹ö¸³´Ï´Ù. ¾Æ¿¹ ½ºÀ§Ä¡·Î °¡Áöµµ ¾Ê´Â °ÅÁÒ. ´ç¿¬ÇÑ °á°úÀÔ´Ï´Ù.
Çϳª ÀÌ»óÀÇ ¼ºê³ÝÀ» °¡Áú·Á¸é ¿øÄ¢ÀûÀ¸·Î ¼ºê³ÝÀÇ °¹¼ö ¸¸Å ½ºÀ§Ä¡°¡ ÀÖ¾î¾ß ÇÕ´Ï´Ù. 7.2 arping
arpingÀ» ÀÌ¿ëÇØ¼ ÁÖº¯ È£½ºÆ®¿¡ arp ¿äûÀ» Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. # arping -q -c 3 -A -I eth1 192.168.105.1
192.168.105.1¿¡¼ tcpdump·Î arp ÆÐŶÀ» È®ÀÎÇß½À´Ï´Ù. # tcpdump -c 3 -nni eth2 arp tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth2, link-type EN10MB (Ethernet), capture size 65535 bytes 22:51:02.431907 ARP, Request who-has 192.168.105.1 tell 192.168.105.2, length 46 22:51:02.431936 ARP, Reply 192.168.105.1 is-at 08:00:27:2f:b4:64, length 28 22:51:02.432818 ARP, Request who-has 192.168.105.1 tell 192.168.105.2, length 46 7.3 arp cache
¸®´ª½º´Â arp cache Å×À̺íÀ» À¯ÁöÇÕ´Ï´Ù. ¸¸¾à µ¥ÀÌÅ͸¦ Àü¼ÛÇÏ·Á´Â IP¿¡ ´ëÇÑ MAC ÁÖ¼Ò Á¤º¸°¡ ÀÖ´Ù¸é, arp¸¦ ³¯¸®Áö ¾Ê°í ¹Ù·Î µ¥ÀÌÅ͸¦ Àü¼ÛÇÕ´Ï´Ù. arp cache¸¦ À¯ÁöÇÔÀ¸·Î½á, ÆÐŶ ³¶ºñ¿Í ¹ÝÀÀ ¼Óµµ ³¶ºñ¸¦ ÁÙÀÏ ¼ö ÀÖ½À´Ï´Ù.
arp¿Í ip¸í·ÉÀ¸·Î arp cache Å×À̺íÀÇ Á¤º¸¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. # arp -na ? (192.168.105.2) at 08:00:27:6c:b0:73 [ether] on eth2 # ip neigh show 192.168.105.2 dev eth2 lladdr 08:00:27:6c:b0:73 STALE
# cat /proc/sys/net/ipv4/neigh/eth2/gc_stale_time 60
7.4 arp flux
¸®´ª½º ¿©·¯°³ÀÇ ³×Æ®¿öÅ© Ä«µå·Î ³×Æ®¿öÅ©¿¡ ¿¬°áÇÒ °æ¿ì MAC ÁÖ¼Ò¿Í IP ÁÖ¼Ò¸¦ ¸ÊÇο¡ ¹®Á¦°¡ »ý±æ ¼öµµ ÀÖ½À´Ï´Ù. ÀÀ´äÇϴ ȣ½ºÆ®°¡ °¡Áö°í ÀÖ´Â ´Ù¼öÀÇ ÀÌ´õ³Ý ÀÎÅÍÆäÀ̽º¸¦ °¡Áö°í ÀÖÀ» °æ¿ì ¿©·¯ °³ÀÇ ARP ÀÀ´äÀ» º¸³¾ ¼ö Àִµ¥, ÀÌ ¶§ À߸øµÈ Á¤º¸°¡ Àü¼ÛµÉ ¼ö ÀÖ½À´Ï´Ù. ARP´Â L2 MAC ÁÖ¼Ò¿Í L3 IP ÁÖ¼Ò¸¦ ¸ÊÇÎÇÏ´Â ÇÁ·ÎÅäÄÝÀε¥, ¼·Î ´Ù¸¥ ·¹À̾ ¸ÊÇÎÇÏ´Ùº¸´Ï ¹ß»ýÇÏ´Â ¹®Á¦ÀÔ´Ï´Ù.
±×¸²À» º¸¸é¼ ¼³¸íÇϰڽÀ´Ï´Ù.
arp_filter arp ¿äûÀÌ ¿Ã ¶§, arp¸¦ ¿äûÇÑ È£½ºÆ®¿Í °°Àº ¼ºê³Ý¿¡ ÀÖ´Â ÀÌ´õ³Ý ÀÎÅÍÆäÀ̽º¸¸ ÀÀ´äÀ» º¸³»µµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. [root@real-server]# echo 1 > /proc/sys/net/ipv4/conf/all/arp_filter
[root@real-server]# echo 1 > /proc/sys/net/ipv4/conf/eth0/arp_filter
[root@real-server]# echo 1 > /proc/sys/net/ipv4/conf/eth1/arp_filter
[root@real-server]# ip address show dev eth0
2: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:80:c8:e8:1e:fc brd ff:ff:ff:ff:ff:ff
inet 10.10.20.67/24 scope global eth0
[root@real-server]# ip address show dev eth1
3: eth1: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:80:c8:7e:71:d4 brd ff:ff:ff:ff:ff:ff
inet 192.168.100.1/24 brd 192.168.100.255 scope global eth1
[root@real-client]# arping -I eth0 -c 3 10.10.20.67
ARPING 10.10.20.67 from 10.10.20.33 eth0
Unicast reply from 10.10.20.67 [00:80:C8:E8:1E:FC] 0.882ms
Unicast reply from 10.10.20.67 [00:80:C8:E8:1E:FC] 1.221ms
Unicast reply from 10.10.20.67 [00:80:C8:E8:1E:FC] 1.487ms
Sent 3 probes (1 broadcast(s))
Received 3 response(s)
[root@real-client]# arping -I eth0 -c 3 192.168.100.1
ARPING 192.168.100.1 from 192.168.100.2 eth0
Unicast reply from 192.168.100.1 [00:80:C8:7E:71:D4] 0.804ms
Unicast reply from 192.168.100.1 [00:80:C8:7E:71:D4] 1.381ms
Unicast reply from 192.168.100.1 [00:80:C8:7E:71:D4] 2.487ms
Sent 3 probes (1 broadcast(s))
Received 3 response(s)
arp_hidden
ȤÀº arp_hidden °ªÀ» ÀÌ¿ëÇÒ ¼öµµ ÀÖ½À´Ï´Ù. [root@real-client]# arping -I eth0 -c 1 172.19.22.254 ARPING 172.19.22.254 from 172.19.22.2 eth0 Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2D] 0.704ms Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2E] 0.844ms Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2F] 0.918ms Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2C] 0.974ms Sent 1 probes (1 broadcast(s)) Received 4 response(s) [root@real-server]# for i in all eth2 eth3 eth4 eth5 ; do > echo 1 > /proc/sys/net/ipv4/conf/$i/hidden > done [root@real-client]# arping -I eth0 -c 2 172.19.22.254 ARPING 172.19.22.254 from 172.19.22.2 eth0 Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2D] 0.710ms Unicast reply from 172.19.22.254 [00:60:F5:08:8A:2D] 0.624ms Sent 2 probes (1 broadcast(s)) Received 2 response(s) |
|
|||
|
EmailÀ» ±âÀÔÇϸé, ´ñ±ÛÀÌ ¸ÞÀÏ·Î Àü´ÞµË´Ï´Ù. |
|