ããããããããDeadããšããæåã®ããè¯ãäŒç€Ÿã®ã«ãŒã¿ãŒããããŸããã ãŸããããã¯å®éã«åœŒã«èµ·ãã£ãã
ç§ã¯æ°ãããã®ã®äŸ¡æ Œãé
ã«ããããããã®ã³ã³ãã¥ãŒã¿ãŒã®ãŽããèªå®
ã®ã³ã³ãã¥ãŒã¿ãŒã®æ¥ç¶ãªã¹ããèŠãŸãã...ãããŠãã«ãŒã¿ãŒãå¿
èŠãªãããšã«æ°ä»ããŸããã éåžžã®ã«ãŒãã£ã³ã°ãDNSãWINSãi2pã
ãã©ãã¯ãžã£ãã¯ãªã©ã䜿çšããŠãç¬èªã«æ§ç¯ããŸãã
ã©ãã ã£ãïŒ
éé±åºã®çãæåã®åŸã次ã®ãã®ãæœåºãããŸããã
â¢Intel Core 2 Duoããã»ããµãŒE8400 @ 3GHz
â¢ããã§ãAsus P5Qãã¶ãŒããŒã
â¢2Gbã®2ã¹ãããDDR2
â¢PCI-eãããã¯ãŒã¯ã«ãŒãTP-Link TG-3468
â¢Ralink RT3060ã«åºã¥ãæªç¢ºèªã®WiFiïŒb / g / nïŒãããã¯ãŒã¯ã«ãŒã
â¢Seagate 250GbããŒããã©ã€ã
lshwã®åºåã¯
ããã§èŠãããšãã§ã
ãŸã ã
ãããã¯ãã¹ãŠãã»ãããåãé€ãããé»æºã®ããããŠãžã³ã°ã«åãä»ããããmemtestããã³mhddã§èµ·åããã³ãã¹ããããŸããã æ¬ é¥ãèŠã€ãããªãã£ããããå¿
èŠãªãã®ããã¹ãŠã€ã³ã¹ããŒã«ãå§ããŸããã
åºç€
åºç€ãšããŠãDebootstrapãéããŠå
¬éãããDebian Testingãã£ã¹ããªãã¥ãŒã·ã§ã³ãåãäžããŸããã openssh-serverãfirmware-ralinkãpppoe / pppoeconfãããã«ã€ã³ã¹ããŒã«ãããŸããã
æ°ãã«ã€ã³ã¹ããŒã«ãããã·ã¹ãã ã«å
¥ã£ãŠãããã«SSHã192.168.1.1ã«ç§»è¡ãããã¹ã¯ãŒãèªèšŒãç¡å¹ã«ããŸããïŒæåã«ããŒãèšå®ããŸããïŒã
ãããã¯ãŒã¯ãäœããïŒ
æåã«ãpppoeconfãèµ·åãããŸããã eth1ãšããååã®ãããã¯ãŒã¯ã«ãŒããDOCSISã¢ãã ã«æ¥ç¶ãããããã次ã®config / etc / ppp / peers / rtãåä¿¡ãããŸããã
noipdefault defaultroute replacedefaultroute hide-password noauth persist plugin rp-pppoe.so eth1 user "ptn" usepeerdns
ããããããã ãã§ã¯ãããŸãã-ããªãã¯ãŸã / etc / network / interfacesã次ã®ããã«èšå®ããå¿
èŠããããŸãïŒ
auto rt iface rt inet ppp pre-up /sbin/ifconfig eth1 up provider rt
ã«ãŒã¿ãŒãWiFi-APã«å€ãã
å
ã®ã¢ã€ãã¢ã¯ã2ã€ã®WiFiãããã¯ãŒã¯ãäœæããããšã§ããã1ã€ã¯ã³ã³ãã¥ãŒã¿ãŒãšã©ãããããçšã§ã匷åãªãã¹ã¯ãŒããšãã¹ãŠã®å¿
èŠãªãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããã1ã€ã¯ãªã³ã©ã€ã³ã«ãªããããç¥ããªãã²ã¹ãçšã§ããç§ã®ãããã¯ãŒã¯ã§äœãèµ·ãã£ãŠããã®ãã
ãã®çµæãhostapdã¯æ¬¡ã®æ§æã§ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŸããïŒãã¹ãŠã®ãããã¯ãŒã¯åãšãã¹ã¯ãŒããå€æŽãããŸããïŒã
interface=wlan0 driver=nl80211 country_code=RU ieee80211d=1 hw_mode=g channel=9 ssid=Private bridge=br0 preamble=1 ignore_broadcast_ssid=0 wpa=3 wpa_key_mgmt=WPA-PSK wpa_pairwise=TKIP CCMP rsn_pairwise=CCMP wpa_passphrase=MyVeryStrongPassword wmm_enabled=1 ieee80211n=1 ht_capab=[HT40-][SHORT-GI-20][SHORT-GI-40] internet=1 bss=wlan0_0 ssid=Guest preamble=1 ignore_broadcast_ssid=0 wpa=3 wpa_key_mgmt=WPA-PSK wpa_pairwise=TKIP CCMP rsn_pairwise=CCMP wpa_passphrase=passw0rd wmm_enabled=1 ieee80211n=1 ht_capab=[HT40-][SHORT-GI-20][SHORT-GI-40] internet=1
ããã§ã¯ãeth0ãšwlan0ã®ããªããžãé
眮ããŸããããã«ããããããã¯ãŒã¯ã«æ¥ç¶ãããŠãŒã¶ãŒã¯ãã¯ã€ã€ã¬ã¹ã»ã°ã¡ã³ãã§ã¯ãªãããããã¯ãŒã¯å
šäœãèŠãããšãã§ããŸãã ãããã¯ãŒã¯ãå€æŽããŸãã
auto eth0 wlan0 wlan0_0 br0 iface eth0 inet manual allow-hotplug wlan0 allow-hotplug wlan0_0 iface wlan0 inet manual pre-up ifconfig wlan0 hw ether f2:7d:68:6d:51:30 iface br0 inet static bridge_ports eth0 wlan0 address 192.168.1.1 netmask 24 iface wlan0_0 inet static address 192.168.254.1 netmask 24
wlan0ã®æºåã®éæ³ã«ã€ããŠå°ã説æããŸããè€æ°ã®APã䜿çšããã«ã¯ãè€æ°ã®MACã¢ãã¬ã¹ã䜿çšããå¿
èŠããããŸãã Hostapdã¯ä»®æ³ã€ã³ã¿ãŒãã§ã€ã¹ïŒãã®å Žåã¯wlan0_0ïŒã«MACãèªåçã«å²ãåœãŠãŸããããã®ããã«æåã®ã¢ã¯ã»ã¹ãã€ã³ãã®ã¢ãã¬ã¹ã«ã¯æåŸã«ããã€ãã®ã空ã®ãããããå¿
èŠã§ãã ç§ã¯ããããªããšã¯ãããããã«4åããªãªãŒã¹ããŸããã èªå®
ã§ã®ã¿ã¹ã¯-1æã®ã«ãŒãã§å®è¡ã§ããæ倧APã®éãèšç®ããŸãã
Fly-ãã¹ãŠã®äººãšãã¹ãŠã®äººãžã®IPãç¡æã§ïŒ
æ®å¿µãªããããããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã«ã¯IPã¢ãã¬ã¹ãäžããå¿
èŠããããŸãã ã¯ããããããŸãã
åèããããšãªãã次ã®æ§æã®DHCPãµãŒããŒããµãŒããŒã§èµ·åãããŸããã
update-static-leases on; authoritative; allow unknown-clients; use-host-decl-names on; log-facility local7; subnet 192.168.1.0 netmask 255.255.255.0 { interface br0; authoritative; range 192.168.1.2 192.168.1.254; option subnet-mask 255.255.255.0; option ntp-servers 192.168.1.1; option domain-name-servers 192.168.1.1; option netbios-name-servers 192.168.1.1; option routers 192.168.1.1; option domain-name "local"; } subnet 192.168.254.0 netmask 255.255.255.0 { interface wlan0_0; authoritative; range 192.168.254.2 192.168.254.254; option subnet-mask 255.255.255.0; option domain-name-servers 8.8.8.8, 8.8.4.4; option routers 192.168.254.1; } local-address 192.168.1.1;
192.168.1.1/24ã®å ŽåãDNSãWINSãNTPãã²ãŒããŠã§ã€192.168.1.1ãçºè¡ãããŠããããšãããããŸããããããèšå®ãããšããæ¥ãŸããã
ã²ãŒããŠã§ã€ã®ãã¹ãŠã¯ã·ã³ãã«ã§ããæ zyãªäººã ãããããã®ã³ãã³ããç¥ããªããšæããŸãïŒ
sysctl net.ipv4.ip_forward=1 iptables ât nat -A POSTROUTING -o ppp0 -j MASQUERADE
ãã¡ãããèšå®ãä¿åããããã«iptables-persistentãèšå®ãã/ etc / sysctl.confã«é©åãªãã©ã¡ãŒã¿ãŒãèšå®ããŸãã
çŸåšããµãŒããŒã¯10ãã«ã®æ¬æ Œçãªäžåœè£œã«ãŒã¿ãŒã§ãã ãªã«ïŒ 匱ãããã«èŠããŸããïŒ ç§ãã ããã«é²ãã§ããŸãã
å³æžé€šãžã®è¡ãæ¹
DNSãå¿
èŠãªããšã誰ãå¿ããŠããªãã£ããšæããŸããïŒ æãåçŽãªè»¢éã¯åçŽã«äžåçã«èšå®ãããŸããã解決ãŸãŒã³ãšéåŒããŸãŒã³ãåããæ¬æ ŒçãªãµãŒããŒãäœæããŸã... bind9ãé
眮ãã以äžãèšå®ããŸãã
options { directory "/var/cache/bind"; forwarders { 8.8.8.8; 8.8.4.4; }; dnssec-validation auto; auth-nxdomain no; listen-on { 127.0.0.1; 192.168.1.1; }; allow-transfer { none; }; version none; }; zone "local" IN { type master; file "/var/lib/bind/db.localnet"; }; zone "1.168.192.in-addr.arpa" IN { type master; file "/var/lib/bind/db.localnet-rev"; };
次ã«ãé ãŸãŒã³ãã¡ã€ã«ãšéãŸãŒã³ãã¡ã€ã«ãå¿
èŠã§ãã
/var/lib/bind/db.localnet $ORIGIN . $TTL 86400 ; 1 day local IN SOA ns.local. router.local. ( 200216990 ; serial 28800 ; refresh (8 hours) 7200 ; retry (2 hours) 604800 ; expire (1 week) 86400 ; minimum (1 day) ) NS ns.local. $ORIGIN local. $TTL 86400 ; 1 day ns A 192.168.1.1 server A 192.168.1.1 router A 192.168.1.1
/var/lib/bind/db.localnet-rev $ORIGIN . $TTL 86400 ; 1 day 1.168.192.in-addr.arpa IN SOA ns.local. router.local. ( 2001105214 ; serial 28800 ; refresh (8 hours) 14400 ; retry (4 hours) 3600000 ; expire (5 weeks 6 days 16 hours) 86400 ; minimum (1 day) ) NS ns.local. $ORIGIN 1.168.192.in-addr.arpa. $TTL 3600 ; 1 hour 1 PTR router.local.
ãã ïŒ æ¬¡ã«ããããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãIPã§ã¯ãªããDNSåã§è¡šç€ºãããããã«ããŸãã
ãããè¡ãã«ã¯ãDDNSãæ§æããå¿
èŠããããŸãã ãã®ãã¯ãããžãŒã«ãããã¢ãã¬ã¹ãçºè¡ããDHCPãµãŒããŒãšDNSãµãŒããŒãæ¥ç¶ã§ããŸãã
ãŸããDDNSã®ããŒãäœæããŸãã
dnssec-keygen -a HMAC-MD5 -b 128 -r /dev/urandom -n USER DDNS_UPDATE
ãã®ã³ãã³ãã¯ãDDNSããŒãæã€2ã€ã®ãã¡ã€ã«ãäœæããŸãã ããŒã®å
容ãå¿
èŠã§ãã
cat Kddns_update.+157+36693.key DDNS_UPDATE. IN KEY 0 3 157 HEyb0FU9+aOXnYFQiXfiVA==
ãHEyb0FU9 + aOXnYFQiXfiVA ==ããããŒã§ãã
DHCPèšå®ãå°ãç·šéããŠã次ã®ãªãã·ã§ã³ãè¿œå ããŠã¿ãŸãããã
ddns-updates on; ddns-update-style interim; key rndc-key { algorithm HMAC-MD5; secret HEyb0FU9+aOXnYFQiXfiVA==; } zone local. { primary 192.168.1.1; key rndc-key; } zone 1.168.192.in-addr.arpa. { primary 192.168.1.1; key rndc-key; } subnet 192.168.1.0 netmask 255.255.255.0 { ⊠ddns-domainname "local."; ddns-rev-domainname "in-addr.arpa."; }
DNSã§ãåãããšãè¡ããŸãã
key "rndc-key" { algorithm hmac-md5; secret "HEyb0FU9+aOXnYFQiXfiVA=="; }; zone "local" IN { ⊠allow-update { key rndc-key; }; }; zone "1.168.192.in-addr.arpa" IN { ⊠allow-update { key rndc-key; }; };
åºæ¥äžãã-ãã®ãã©ãŒæ©èœã¯åäœããŸãã
æªæ¥ã¯ãŸã ããã«ãããŸãã 第6ããŒãžã§ã³
ç§ã®ãããã€ããŒïŒRostelecomãžã®è»œcornçãªèŠæ¹ïŒã¯IPv6ãçºè¡ããŸããã§ããïŒæŽå²çã«
çŽæããŸããã ïŒã
çŸåšããã¹ãã¬ã³ã ãããã¯ãŒã¯ã®å
šé·ã¯ãIPv6ãä»ããŠåäœããæ©èœãæäŸããŠããŸããããªãã¬ãŒã¿ãŒã®ãã¬ã¹ãµãŒãã¹ã«ãŠã³ã¿ãŒã
ãŸãããããä¿®æ£ããã®ã¯èª€è§£ã§ãã ãããŒã«ãŒãšããŠ
sixxs.netãéžæããŸããããã·ã¢ã«ãã³ãã«ãµãŒããŒããããåçIPã®å Žåããã³ãã«ãç°¡åã«æ§æã§ããŸãã
ãã³ãã«/ãµããããèšå®ãç»é²ããã³åä¿¡ããããã»ã¹ã¯çç¥ããŸã-ãã¹ãŠãéåžžã«ç°¡åã§ãã èšå®ã«ã€ããŠèª¬æããŸãã
ãµãŒããŒèªäœã§ã®IPv6ã®ã»ããã¢ããã¯2段éã§è¡ãããŸãã ãŸããaiccuããã±ãŒãžãã€ã³ã¹ããŒã«ããŸã-ããã¯ãã³ããªã³ã°ããã°ã©ã ã§ãã ã€ã³ã¹ããŒã«äžã«ãsixxsããã®ãã°ã€ã³ãšãã¹ã¯ãŒããããã³ãã®ä»ã®ããŒã¿ã®å
¥åãæ±ããããŸãã çºå£²åŸãæ°ããã€ã³ã¿ãŒãã§ãŒã¹ãã§ããŸãïŒ
sixxs Link encap:IPv6-in-IPv4 inet6 addr: 2a02:578:5002:xxx::2/64 Scope:Global UP POINTOPOINT RUNNING NOARP MTU:1280 Metric:1 âŠ
ãµãŒããŒã¯v6ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãããä»ã®ãŠãŒã¶ãŒãšå
±æããŠã¿ãŸãããïŒ
ãŸããIPv6-forwardingãæå¹ã«ããŸãããïŒ/etc/sysctl.confã«æžã蟌ãããšãå¿ããªãã§ãã ããïŒïŒ
sysctl net.ipv6.conf.all.forwarding=1
iptablesã§èšå®ãè¡ãå¿
èŠã¯ãããŸãã-ããã«ã¡ã¯ã21äžçŽã§ãïŒ
次ã«ãsixxs Webãµã€ãã§ããµãããããååŸããŸãã 圌女ã®ã¢ãã¬ã¹ã¯ããã³ãã«ã®ã¢ãã¬ã¹ãšéåžžã«äŒŒãŠããŸãã泚æããŠãã ããããããã¯ç°ãªã£ãŠããŸãïŒ
2a02ïŒ578ïŒ5002ïŒxxxx :: / 64ã®åœ¢åŒã®ã¢ãã¬ã¹ãåãåã£ãåŸãèšå®ãé²ããŸãã ãŸãããµãŒããŒã¢ãã¬ã¹2a02ãèšå®ããŸãããïŒ578ïŒ5002ïŒxxxx :: 1ã次ã®è¡ãã€ã³ã¿ãŒãã§ã€ã¹ã«è¿œå ããŸãã
iface br0 inet6 static address 2a02:578:5002:xxxx::1 netmask 64
次ã«ããããã¯ãŒã¯äžã®ã³ã³ãã¥ãŒã¿ãŒã«IPv6ãçºè¡ã§ããããã«ããŸãã radvdããã±ãŒãžãã€ã³ã¹ããŒã«ãã次ã®ããã«æ§æããŸãã
interface br0 { AdvSendAdvert on; prefix 2a02:578:5002:xxxx::/64 { AdvOnLink on; AdvAutonomous on; AdvRouterAddr on; }; RDNSS 2a02:578:5002:xxxx::1 { }; };
ãã€ã³ãèšå®ã«IPv6 DNSãè¿œå -å®å
šãªé¢šæ°Žã®ããã«ïŒ
options { forwarders { ⊠2001:4860:4860::8888; 2001:4860:4860::8844; }; listen-on-v6 { ::1/128; 2a02:578:5002:xxxx::/64; }; ⊠};
ããã§ãã¹ãŠã§ããããšãã°ã
ipv6.google.comã«ã¢ã¯ã»ã¹ã§ããããã«ãªã
ãŸãã ãããã«äŸ¡å€ã®ãã
ipv6.nnm-club.meã«ã¢ã¯ã»ã¹ã§ããããã«ãªã
ãŸãã ;ïŒ
çªã®å€ãèŠãŠãã³ã®ã³
ãããã¯ãŒã¯äžã®ãã¹ãŠãçŸãããšãã倧奜ãã§ãã ãããŠãããã¯å®å
šãªèª¿åã®å Žåã«ã®ã¿å¯èœã§ãã ããšãã°ããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒããäºããèŠããšãã Windowsã¯ãŒã¯ã¹ããŒã·ã§ã³ã®å ŽåãWINSããªã³ãŒã«ããã®ã劥åœã§ãïŒãã®èšå®ã¯DHCPã§ãçºè¡ããããšãæãåºããŠãã ããïŒã
ãã®æ§æã¯éåžžã«ç°¡åã§ãïŒsambaããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãã ããã©ã«ãã®èšå®ãå°ãå€æŽããå¿
èŠããããŸãã
workgroup = WORKGROUP wins support = yes dns proxy = yes interfaces = lo br0 bind interfaces only = yes server role = standalone server
çµæã®ç¢ºèª...ãããããã§ãã¹ãŠãããŸããããŸããïŒ

ãšããã§ãsambaãããã®ã§ãããã«ãã¡ã€ã«ãŠã©ãã·ã¥ãæ§æã§ããŸãã ããããããã¯éåžžã«ãããã³ã°ããããããã¯ãªã®ã§ãGoogleã®è©ã«çœ®ããŠãããŸãã å®éã«ã¯ããšã«ãããã¹ãŠãç®±ããåºããŠåäœããã¯ãã§ã-家ã®èªã¿åãå°çšãyes
smbpasswd -a userããªãã«ããªãéã...
ä»äœæïŒ
ãµãŒããŒã§æéã®ååžãã»ããã¢ããããŸããntpãã€ã³ã¹ããŒã«ããŸãã æ§æã䜿çšãããšããã¹ãŠããšãŠã€ããªãç°¡åã§ãã
server 0.ru.pool.ntp.org server 1.ru.pool.ntp.org server 2.ru.pool.ntp.org server 3.ru.pool.ntp.org ⊠broadcast 192.168.1.1
çµæã¯æ¬¡ã®ãšããã§ãã

ãã§ã«150ãã«ãã200ãã«ã§microtikã«ãŒã¿ãŒã«è¿ã¥ããŠããŸãã ããããããã ãã§ã¯ãããŸãããïŒ ãã¡ããéããŸãã
ãã©ãŒæ©èœïŒ1ïŒI2P
ãããŠãèšå®ãªãã§ããããã·ãµãŒããŒãªã©ãªãã§ããã®ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ããªãã®ã¯ãªãã§ããïŒ ã ãããããªãããšæãã æåã«ãå¥å
šãªããŒãžã§ã³ã®Javaãã€ã³ã¹ããŒã«ããŸãã
echo "deb http://ppa.launchpad.net/webupd8team/java/ubuntu precise main" >> /etc/apt/sources.list apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys EEA14886 apt-get update apt-get install oracle-java7-installer
ãããŠãã«ãŒã¿ãŒèªäœãã€ã³ã¹ããŒã«ããŸãã
echo "deb http://deb.i2p2.no/ unstable main" >> /etc/apt/sources.list wget "http://www.i2p2.de/_static/debian-repo.pub" -O- -q | apt-key add - apt-get update apt-get install i2p i2p-keyring
ããã§ã* .i2pãžã®ãã¹ãŠã®ãªã¯ãšã¹ãããµãŒããŒã«éä¿¡ãããŸãŒã³ãäœæããŸãã ãã€ã³ãæ§æïŒ
zone "i2p" IN { type master; file "/etc/bind/db.i2p"; };
ãŸãŒã³èªäœïŒ
$ORIGIN i2p $TTL 7200 i2p. IN SOA ns.i2p. hostmaster.i2p. ( 2010020701 ; serial 7200 ; refresh 1800 ; retry 7200 ; expire 7200 ; minimum ) i2p. IN NS ns.i2p. ns.i2p. IN A 192.168.1.1 *.i2p. IN A 192.168.1.1 *.i2p. IN AAAA 2a02:578:5002:xxxx::1
çŽ æŽãããã§ãããä»ãããã©ããã£ãŠåŠçããã®ã§ãã ã«ãŒã¿ãŒããŒããžã®ãã¹ãŠã®ãã©ãã£ãã¯ãç Žæãããããšã«æåããŸããã§ãã-ãããã·ã¯ãããããã®ããã«æ©èœããªãããšãèªããŸããã ããããã®nginx + php5-fpmãæ§æããå°ããªã¹ã¯ãªãããæžãå¿
èŠããããŸããã æåã®éšåãäœæããæ¹æ³-é·ãéæ¢ãå¿
èŠã¯ãããŸããããããã¯ãŒã¯äžã®ããã¥ã¢ã«ã®å©ç¹ã¯ååã§ãã 第äºéšïŒ
/ etc / nginx /ãµã€ã察å¿/ i2p server { listen [2a02:578:5002:xxxx::1]:80; listen 192.168.1.1:80; # server_name localhost.i2p; location / { proxy_pass http://127.0.0.1:7657; } } server { listen [2a02:578:5002:xxxx::1]:80; listen 192.168.1.1:80; server_name *.i2p; location / { fastcgi_pass unix:/var/run/php5-fpm; include fastcgi_params; # fastcgi_param SCRIPT_FILENAME /etc/nginx/proxy.php; # HTTP proxy i2p fastcgi_param PROXY_PASS 127.0.0.1:4444; } }
ã¹ã¯ãªããèªäœã¯
ããã§èŠãããšãã§ã
ãŸã ã
以äžã§ãïŒ é»è©±ããã§ãi2pã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã-åé¡ãããŸããã
ãã©ãŒæ©èœïŒ2ïŒè·å Žãè·å Žãããã¯ãŒã¯ã«ãã
æŽå²çã«ã©ã¯ç§ãè€æ°ã®äŒæ¥ã§äžåºŠã«ãªã¢ãŒãããžãã¹ã®ã·ã¹ãã 管çè
ã§ããããšãçºçããŸããã ãŸãããããã¯ãŒã¯äžã®ä»»æã®ã³ã³ãã¥ãŒã¿ãŒããã¢ã¯ã»ã¹ã§ãããšéåžžã«äŸ¿å©ã§ãã ä»ã®ã¯ã©ã€ã¢ã³ããšåæ§ã«ããµãŒããŒã®OpenVPNïŒãŸãã¯ãã®ä»ïŒãæ§æããŸãã ããšãã°ããããã®ã¢ã¯ã·ã§ã³ã®åŸãIP 10.0.0.7/24ã®tap0ã€ã³ã¿ãŒãã§ãŒã¹ãååŸããŸããã ãããã10.0.0.1ã®ããŒã«ã«ãããã¯ãŒã¯ããæ¹å転æãããšããã©ãã£ãã¯ã¯ãããã€ããŒã®ããã©ã«ãã²ãŒããŠã§ã€ã«éãããŸãã ãã®æ¬ é¥ãä¿®æ£ããŸãã
iptables -t nat -A POSTROUTING -d 10.0.0.0/24 -o tap0 -j MASQUERADE iptables-save > /etc/iptables/rules.v4
ãµãŒããŒäžã®ãã¹ãŠã®ãããã¯ãŒã¯ã«å¯ŸããŠåãããšãè¡ããŸãã
çµè«ã®ä»£ããã«
ç¬èªã®è£éã§äœ¿çšã§ããæ¬æ ŒçãªãµãŒããŒããããŸãã DNSãnginxãIPv6ãi2p ...ãŸãã* .devãªã©ã®ããŒã«ã«éçºçšã®ãŸãŒã³ãèšå®ããããŒã«ã«ãããã¯ãŒã¯äžã®ä»»æã®ããã€ã¹ãããµã€ãããã¹ãããããšãã§ããŸãã ãããã¯ãŒã¯äžã®åã³ã³ãã¥ãŒã¿ãŒã«ã¯ç¬èªã®æ°žç¶çãªIPv6ã¢ãã¬ã¹ããããããäžçäžã®ã©ãããã§ãã¢ã¯ã»ã¹ã§ããŸãïŒã»ãã¥ãªãã£èŠåïŒãã¡ã€ã¢ãŠã©ãŒã«ãæ£ããæ§æããŠãã ããïŒïŒã
ãããŠããããã¯ãã¹ãŠæ°·å±±ã®äžè§ã«ãããŸããã æ°Žäžã®éšåã¯ããªã次第ã§ãã
ç§ã¯ã³ã¡ã³ããææ¡ãå¥å
šãªæ¹å€ãªã©ãèããŠããããã§ãã ããããšã