<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Yuzifu Studio &#187; Unix/Linux</title>
	<atom:link href="http://blog.yuzifu.net/index.php/category/unixlinux/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.yuzifu.net</link>
	<description>Welcome to Yuzifu&#039;s website!</description>
	<lastBuildDate>Sun, 05 Sep 2010 14:48:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Vyatta里进行端口映射</title>
		<link>http://blog.yuzifu.net/index.php/2010/07/vyatta%e9%87%8c%e8%bf%9b%e8%a1%8c%e7%ab%af%e5%8f%a3%e6%98%a0%e5%b0%84/</link>
		<comments>http://blog.yuzifu.net/index.php/2010/07/vyatta%e9%87%8c%e8%bf%9b%e8%a1%8c%e7%ab%af%e5%8f%a3%e6%98%a0%e5%b0%84/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 16:08:00 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Unix/Linux]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[nat]]></category>
		<category><![CDATA[port forward]]></category>
		<category><![CDATA[vyatta]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2010/07/vyatta%e9%87%8c%e8%bf%9b%e8%a1%8c%e7%ab%af%e5%8f%a3%e6%98%a0%e5%b0%84/</guid>
		<description><![CDATA[一、在NAT里设置转发
vyatta@vyatta# show service nat rule 30    destination {    &#160;&#160;&#160;&#160; port 22222     }     inbound-interface pppoe0     inside-address {    &#160;&#160;&#160;&#160; address 192.168.1.186     }     protocol tcp     type destination    [edit]    vyatta@vyatta#
二、防火墙里放行
vyatta@vyatta# show firewall name OnWAN rule 15    action accept     destination {    &#160;&#160;&#160;&#160; port 22222     }     protocol tcp    [edit]    vyatta@vyatta#
]]></description>
			<content:encoded><![CDATA[<p>一、在NAT里设置转发</p>
<p>vyatta@vyatta# show service nat rule 30   <br /> destination {    <br />&#160;&#160;&#160;&#160; port 22222    <br /> }    <br /> inbound-interface pppoe0    <br /> inside-address {    <br />&#160;&#160;&#160;&#160; address 192.168.1.186    <br /> }    <br /> protocol tcp    <br /> type destination    <br />[edit]    <br /><a href="mailto:vyatta@vyatta">vyatta@vyatta</a>#</p>
<p>二、防火墙里放行</p>
<p>vyatta@vyatta# show firewall name OnWAN rule 15   <br /> action accept    <br /> destination {    <br />&#160;&#160;&#160;&#160; port 22222    <br /> }    <br /> protocol tcp    <br />[edit]    <br />vyatta@vyatta#</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2010/07/vyatta%e9%87%8c%e8%bf%9b%e8%a1%8c%e7%ab%af%e5%8f%a3%e6%98%a0%e5%b0%84/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Install pptp and radius on lenny</title>
		<link>http://blog.yuzifu.net/index.php/2010/01/install-pptp-and-radius-on-lenny/</link>
		<comments>http://blog.yuzifu.net/index.php/2010/01/install-pptp-and-radius-on-lenny/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 09:43:27 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[freeradius]]></category>
		<category><![CDATA[lenny]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[pptpd]]></category>
		<category><![CDATA[radius]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/?p=419</guid>
		<description><![CDATA[1,install all packages
#apt-get install pptpd freeradius radiusclient1
2,configure pptp
#vim /etc/pptpd.conf
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2010/01/install-pptp-and-radius-on-lenny/" title="Install pptp and radius on lenny" target="_blank">阅读全文——共1080字</a></span>]]></description>
			<content:encoded><![CDATA[<p>1,install all packages<br />
#apt-get install pptpd freeradius radiusclient1</p>
<p>2,configure pptp<br />
#vim /etc/pptpd.conf</p>
<p>localip 192.168.42.122<br />
remoteip 192.168.42.123-200</p>
<p>#vim /etc/ppp/pptpd-options</p>
<p>ms-dns 8.8.4.4<br />
ms-dns 208.67.222.222<br />
plugin /usr/lib/pppd/2.4.4/radius.so<br />
radius-config-file /etc/radiusclient/radiusclient.conf</p>
<p>3,configure radius<br />
#vim /etc/freeradius/client.conf</p>
<p>client 127.0.0.1 {<br />
 secret  = mysecret<br />
 nastype     = other<br />
}</p>
<p>#vim /etc/freeradius/users</p>
<p>myusername Cleartext-Password := &#8220;mypassword&#8221;<br />
 Service-Type = Framed-User,<br />
 Framed-Protocol = PPP,<br />
 Framed-IP-Address = 192.168.42.123,<br />
 Framed-IP-Netmask = 255.255.255.0,<br />
 Framed-Routing = Broadcast-Listen,<br />
 Framed-Filter-Id = &#8220;std.ppp&#8221;,<br />
 Framed-MTU = 1500,<br />
 Framed-Compression = Van-Jacobsen-TCP-IP<br />
 <br />
 <br />
4,configure radclient<br />
#vim /etc/radiusclient</p>
<p>127.0.0.1           mysecret<br />
 <br />
#vim /etc/radiusclient/dictionary.microsoft</p>
<p>add content from <a href="http://wiki.freeradius.org/PopTop">http://wiki.freeradius.org/PopTop</a></p>
<p>#vim /etc/radiusclient/dictionary</p>
<p>INCLUDE /etc/radiusclient/dictionary.microsoft<br />
INCLUDE /etc/radiusclient/dictionary.merit<br />
5,test radius<br />
#radtest myusername mypassword 127.0.0.1 0 mysecret</p>
<p>6,if OS not exist /dev/ppp device,creat it<br />
#mknod /dev/ppp c 108 0</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2010/01/install-pptp-and-radius-on-lenny/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;本地设备名已在使用中&#8221;</title>
		<link>http://blog.yuzifu.net/index.php/2009/05/%e6%9c%ac%e5%9c%b0%e8%ae%be%e5%a4%87%e5%90%8d%e5%b7%b2%e5%9c%a8%e4%bd%bf%e7%94%a8%e4%b8%ad/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/05/%e6%9c%ac%e5%9c%b0%e8%ae%be%e5%a4%87%e5%90%8d%e5%b7%b2%e5%9c%a8%e4%bd%bf%e7%94%a8%e4%b8%ad/#comments</comments>
		<pubDate>Wed, 20 May 2009 01:31:12 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/05/%e6%9c%ac%e5%9c%b0%e8%ae%be%e5%a4%87%e5%90%8d%e5%b7%b2%e5%9c%a8%e4%bd%bf%e7%94%a8%e4%b8%ad/</guid>
		<description><![CDATA[环境：    两台交换机（一台DES3026,一台非网管）未经过任何设置连接若干PC，一台samba服务器连接在非网管交换机上提供文件共享服务。 
前因：    在DES3026上设置两个vlan，PC、非网管交换机和samba服务器接在相同vlan的端口。 
现象：    在PC里把samba共享目录映射成win盘符后，每次登录第一次打开这个盘符会弹出警告对话框：“本地设备名已在使用中。此连接尚未还原。” 
分析：    故障前后PC和samba服务器没有经过任何改动，唯一的变动是交换机划分了vlan，于是至电dlink客服，得到的回答是划分vlan后，连接另一台非网管交换机，把它当成一台PC就可以了。    后来尝试把samba服务器连接在非网管交换机上，这时故障解除。 
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/05/%e6%9c%ac%e5%9c%b0%e8%ae%be%e5%a4%87%e5%90%8d%e5%b7%b2%e5%9c%a8%e4%bd%bf%e7%94%a8%e4%b8%ad/" title="&#8220;本地设备名已在使用中&#8221;" target="_blank">阅读全文——共321字</a></span>]]></description>
			<content:encoded><![CDATA[<p><strong><font color="#0000ff">环境：</font></strong>    <br />两台交换机（一台DES3026,一台非网管）未经过任何设置连接若干PC，一台samba服务器连接在非网管交换机上提供文件共享服务。 </p>
<p><strong><font color="#0000ff">前因：</font></strong>    <br />在DES3026上设置两个vlan，PC、非网管交换机和samba服务器接在相同vlan的端口。 </p>
<p><strong><font color="#0000ff">现象：</font></strong>    <br />在PC里把samba共享目录映射成win盘符后，每次登录第一次打开这个盘符会弹出警告对话框：“本地设备名已在使用中。此连接尚未还原。” </p>
<p><strong><font color="#0000ff">分析</font></strong>：    <br />故障前后PC和samba服务器没有经过任何改动，唯一的变动是交换机划分了vlan，于是至电dlink客服，得到的回答是划分vlan后，连接另一台非网管交换机，把它当成一台PC就可以了。    <br />后来尝试把samba服务器连接在非网管交换机上，这时故障解除。 </p>
<p><strong><font color="#0000ff">原因：</font></strong>    <br />不明。</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/05/%e6%9c%ac%e5%9c%b0%e8%ae%be%e5%a4%87%e5%90%8d%e5%b7%b2%e5%9c%a8%e4%bd%bf%e7%94%a8%e4%b8%ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DES-3026 + m0n0 1.3 b16 实现vlan</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/des-3026-m0n0-13-b16-%e5%ae%9e%e7%8e%b0vlan/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/des-3026-m0n0-13-b16-%e5%ae%9e%e7%8e%b0vlan/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 06:30:30 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/04/des-3026-m0n0-13-b16-%e5%ae%9e%e7%8e%b0vlan/</guid>
		<description><![CDATA[我原先的网络是192.168.0.0/24，后来为了设置vlan,就把m0n0的lan IP改为192.168.12.2/24了。 
 
具体过程如下： 
一、交换机设置 
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/des-3026-m0n0-13-b16-%e5%ae%9e%e7%8e%b0vlan/" title="DES-3026 + m0n0 1.3 b16 实现vlan" target="_blank">阅读全文——共1045字</a></span>]]></description>
			<content:encoded><![CDATA[<p>我原先的网络是192.168.0.0/24，后来为了设置vlan,就把m0n0的lan IP改为192.168.12.2/24了。 </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142518.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142518" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142518-thumb.jpg" width="326" height="133" /></a> </p>
<p>具体过程如下： </p>
<p><strong>一、交换机设置</strong> </p>
<p>有人说在交换机上做好vlan后，把连接m0n0的端口设置trunking，但是我的3026交换机做不到。 </p>
<p>所以改为这种方法： </p>
<p>vlan10:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 2-19 untag   <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 20 tag </p>
<p>vlan20:&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 20 tag   <br />&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; 21-26 untag </p>
<p>m0n0连接到3026的20端口 </p>
<p><strong>二、m0n0设置</strong> </p>
<p>1,Interfaces &#8211;&gt; (assign) &#8211;&gt; vlans </p>
<p>在这里添加vlan10和vlan20 </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142048.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142048" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142048-thumb.jpg" width="587" height="163" /></a> </p>
<p>2,Interfaces &#8211;&gt; (assign) &#8211;&gt; Interface assignments </p>
<p>在这里指定vlan 10的接口为vlan10，vlan 20的接口为vlan20 </p>
<p>(其实这里只是点+号而已) </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142100.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142100" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142100-thumb.jpg" width="424" height="246" /></a> </p>
<p>3.1,Interfaces &#8211;&gt; (assign) &#8211;&gt; OPT1   <br />在这里激活vlan10的接口 </p>
<p>&quot;description&quot;填写为&quot;vlan10&quot;   <br />打勾&quot;enable optional 1 interface&quot;    <br />&quot;bridge with&quot;选为&quot;none&quot;    <br />&quot;ip address&quot;填为&quot;192.168.0.2/24&quot; </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142122.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142122" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142122-thumb.jpg" width="390" height="290" /></a> </p>
<p>3.2,Interfaces &#8211;&gt; (assign) &#8211;&gt; OPT2   <br />在这里激活vlan20的接口 </p>
<p>&quot;description&quot;填写为&quot;vlan20&quot;   <br />打勾&quot;enable optional 2 interface&quot;    <br />&quot;bridge with&quot;选为&quot;none&quot;    <br />&quot;ip address&quot;填为&quot;192.168.5.2/24&quot; </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142135.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142135" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142135-thumb.jpg" width="392" height="283" /></a> </p>
<p>4.1 Firewall &#8211;&gt; Rules &#8211;&gt; vlan10   <br />这里要添加允许vlan10网段上网的规则    <br />vlan互访限制也在这里设置，这里的规则直接影响到vlan间的互访 </p>
<p>同时要限制vlan10客户端的上网行为也是这里设置规则 </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142159.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142159" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142159-thumb.jpg" width="562" height="222" /></a> </p>
<p>4.2 Firewall &#8211;&gt; Rules &#8211;&gt; vlan20   <br />这里要添加允许vlan20网段上网的规则    <br />vlan互访限制也在这里设置，这里的规则直接影响到vlan间的互访 </p>
<p>同时要限制vlan20客户端的上网行为也是这里设置规则 </p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142209.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="2009-04-14_142209" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/20090414-142209-thumb.jpg" width="563" height="223" /></a> </p>
<p>题外话：   <br />以上方法虽然实现了我的要求，但跟我想象中的效果相差很大。    </p>
<p>我的想法是：   <br />只是在交换机上划分vlan，原来所有客户端不做更改，还是原来的IP，原来的网关，各客户机都能上网，但不同vlan的客户端不能互访。</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/des-3026-m0n0-13-b16-%e5%ae%9e%e7%8e%b0vlan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>iptables tutorial中的图</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/iptables-tutorial%e4%b8%ad%e7%9a%84%e5%9b%be/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/iptables-tutorial%e4%b8%ad%e7%9a%84%e5%9b%be/#comments</comments>
		<pubDate>Sun, 12 Apr 2009 16:04:45 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/04/iptables-tutorial%e4%b8%ad%e7%9a%84%e5%9b%be/</guid>
		<description><![CDATA[ip包头：
 
tcp包头：
 
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/iptables-tutorial%e4%b8%ad%e7%9a%84%e5%9b%be/" title="iptables tutorial中的图" target="_blank">阅读全文——共65字</a></span>]]></description>
			<content:encoded><![CDATA[<p>ip包头：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/ipheaders1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="ip-headers" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/ipheaders-thumb1.jpg" width="240" height="60" /></a> </p>
<p>tcp包头：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/tcpheaders1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="tcp-headers" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/tcpheaders-thumb1.jpg" width="240" height="65" /></a> </p>
<p>udp包头：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/udpheaders1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="udp-headers" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/udpheaders-thumb1.jpg" width="240" height="42" /></a> </p>
<p>icmp包头：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/icmpbasicheaders1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="icmp-basic-headers" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/icmpbasicheaders-thumb1.jpg" width="240" height="55" /></a> </p>
<p>数据包流程：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/tables-traverse1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="tables_traverse" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/tables-traverse-thumb1.jpg" width="141" height="240" /></a> </p>
<p>tcp连接状态：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/statetcpconnecting1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="state-tcp-connecting" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/statetcpconnecting-thumb1.jpg" width="240" height="105" /></a> </p>
<p>tcp关闭状态：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/statetcpclosing1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="state-tcp-closing" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/statetcpclosing-thumb1.jpg" width="240" height="155" /></a> </p>
<p>icmp ping状态：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/stateicmpping1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="state-icmp-ping" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/stateicmpping-thumb1.jpg" width="240" height="112" /></a> </p>
<p>udp连接状态：</p>
<p><a href="http://blog.yuzifu.net/wp-content/uploads/2009/04/stateudpconnection1.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" border="0" alt="state-udp-connection" src="http://blog.yuzifu.net/wp-content/uploads/2009/04/stateudpconnection-thumb1.jpg" width="240" height="105" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/iptables-tutorial%e4%b8%ad%e7%9a%84%e5%9b%be/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>debian控制服务的几个命令</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/debian%e6%8e%a7%e5%88%b6%e6%9c%8d%e5%8a%a1%e7%9a%84%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/debian%e6%8e%a7%e5%88%b6%e6%9c%8d%e5%8a%a1%e7%9a%84%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 17:36:12 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/04/debian%e6%8e%a7%e5%88%b6%e6%9c%8d%e5%8a%a1%e7%9a%84%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4/</guid>
		<description><![CDATA[以前我是用rcconf来控制服务的自启动的，当然有的时候也会直接去/etc/rcX.d目录下把SXXservicename改成KXXservicename来停止自启动服务，不过现在又看到了两个新命令：
第一个是invoke-rc.d
这个命令可以停止或启动服务，比如：
invoke-rc.d exim4 stop
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/debian%e6%8e%a7%e5%88%b6%e6%9c%8d%e5%8a%a1%e7%9a%84%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4/" title="debian控制服务的几个命令" target="_blank">阅读全文——共265字</a></span>]]></description>
			<content:encoded><![CDATA[<p>以前我是用rcconf来控制服务的自启动的，当然有的时候也会直接去/etc/rcX.d目录下把SXXservicename改成KXXservicename来停止自启动服务，不过现在又看到了两个新命令：</p>
<p><strong>第一个是invoke-rc.d</strong></p>
<p>这个命令可以停止或启动服务，比如：</p>
<p>invoke-rc.d exim4 stop</p>
<p>invoke-rc.d nfs-common start</p>
<p>&#160;</p>
<p><strong>第二个是update-rc.d</strong></p>
<p>这个命令可以启用或禁止服务自启动</p>
<p>update-rc.d –f exim4 remove</p>
<p>update-rc.d nfs-common start 20 3 4 5</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/debian%e6%8e%a7%e5%88%b6%e6%9c%8d%e5%8a%a1%e7%9a%84%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vyatta限速测试3</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%953/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%953/#comments</comments>
		<pubDate>Sat, 11 Apr 2009 04:05:20 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/?p=282</guid>
		<description><![CDATA[今天接着测试vyatta的限速。
我把匹配的地址改为192.168.0.5/32之后，限速生效了，0.5的下载速度大约在180k，其它的IP下载速度大约在40k，当我把匹配的IP改为192.168.0.5/24后，限速又不生效了。
不知道vyatta的out和in是怎么定义的，如果它是如下所定义的话：
download: internet ===&#62; (in)Vyatta(out) ===&#62; client
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%953/" title="Vyatta限速测试3" target="_blank">阅读全文——共879字</a></span>]]></description>
			<content:encoded><![CDATA[<p>今天接着测试vyatta的限速。</p>
<p>我把匹配的地址改为192.168.0.5/32之后，限速生效了，0.5的下载速度大约在180k，其它的IP下载速度大约在40k，当我把匹配的IP改为192.168.0.5/24后，限速又不生效了。</p>
<p>不知道vyatta的out和in是怎么定义的，如果它是如下所定义的话：</p>
<blockquote><p>download: internet ===&gt; (in)Vyatta(out) ===&gt; client<br />
up:       internet &lt;=== (out)Vyatta(in) &lt;=== client</p></blockquote>
<p>那么当我在LAN接口的out方向做限速时，匹配的IP位置就应该是destination而非source,但是我在官方文档上所看到的实例以及网上一些文章都指定为source，不得其解。<br />
根据上面的定义，是不是可以在WAN接口的out方向做限速，从而达到做上传限速呢？</p>
<p>另外vyatta 5.0.2也开始支持in的限速了，类型是traffic-limiter，不过它没有default class，有时间用它在WAN接口上测试一下下载的限速。</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
</pre></td><td class="code"><pre class="cshare" style="font-family:monospace;">vyatta@vyatta# show qos-policy
 traffic-shaper ALL {
     bandwidth 2mbit
     class 10 {
         bandwidth 2mbit
         burst 3k
         ceiling 2mbit
         match IP5 {
             ip {
                 destination {
                     address 192.168.0.5/32
                 }
             }
         }
     }
     default {
         bandwidth 512kbit
         burst 1k
         ceiling 512kbit
     }
 }
[edit]
vyatta@vyatta# show interfaces
 ethernet eth0 {
     address 192.168.0.2/24
     hw-id 00:05:5d:72:ed:**
     qos-policy {
         out ALL
     }
 }
 ethernet eth1 {
     duplex auto
     hw-id 00:05:5d:72:ed:**
     pppoe 1 {
         default-route auto
         password *********
         user-id ********
     }
 }
[edit]
vyatta@vyatta#</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%953/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vyatta又不能限速</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%b8%8d%e8%83%bd%e9%99%90%e9%80%9f/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%b8%8d%e8%83%bd%e9%99%90%e9%80%9f/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 06:43:02 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/?p=278</guid>
		<description><![CDATA[昨晚我在实验环境中测试vyatta的限速成功了，今天中午我把方法应用到我的工作环境中去，却发现不能限速。
工作环境的限速规则如下：

1
<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%b8%8d%e8%83%bd%e9%99%90%e9%80%9f/" title="Vyatta又不能限速" target="_blank">阅读全文——共496字</a></span>]]></description>
			<content:encoded><![CDATA[<p>昨晚我在实验环境中测试vyatta的限速成功了，今天中午我把方法应用到我的工作环境中去，却发现不能限速。<br />
工作环境的限速规则如下：</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
</pre></td><td class="code"><pre class="cshare" style="font-family:monospace;">vyatta@vyatta# show qos-policy
 traffic-shaper ALL {
     bandwidth 2mbit
     class 10 {
         bandwidth 2mbit
         burst 3k
         ceiling 2mbit
         match IP5 {
             ip {
                 destination {
                     address 192.168.0.5/24
                 }
             }
         }
     }
     default {
         bandwidth 512kbit
         burst 1k
         ceiling 512kbit
     }
 }
[edit]
vyatta@vyatta# show interfaces
 ethernet eth0 {
     address 192.168.0.2/24
     hw-id 00:05:5d:72:ed:**
     qos-policy {
         out ALL
     }
 }
 ethernet eth1 {
     duplex auto
     hw-id 00:05:5d:72:ed:**
     pppoe 1 {
         default-route auto
         password **********
         user-id **********
     }
 }
[edit]
vyatta@vyatta#</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%b8%8d%e8%83%bd%e9%99%90%e9%80%9f/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>vyatta使用手记：更新3322.org</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%bd%bf%e7%94%a8%e6%89%8b%e8%ae%b0%ef%bc%9a%e6%9b%b4%e6%96%b03322org/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%bd%bf%e7%94%a8%e6%89%8b%e8%ae%b0%ef%bc%9a%e6%9b%b4%e6%96%b03322org/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 05:34:15 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%bd%bf%e7%94%a8%e6%89%8b%e8%ae%b0%ef%bc%9a%e6%9b%b4%e6%96%b03322org/</guid>
		<description><![CDATA[以前用过3322.org的客户端、lynx、w3m来更新3322.org，然而vyatta没有lynx、w3m，所以就用搜到的另一段脚本来更新3322.org。
 
把下面这段脚本放到一个命名为ddns的脚本文件里去

<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%bd%bf%e7%94%a8%e6%89%8b%e8%ae%b0%ef%bc%9a%e6%9b%b4%e6%96%b03322org/" title="vyatta使用手记：更新3322.org" target="_blank">阅读全文——共266字</a></span>]]></description>
			<content:encoded><![CDATA[<p>以前用过3322.org的客户端、lynx、w3m来更新3322.org，然而vyatta没有lynx、w3m，所以就用搜到的另一段脚本来更新3322.org。</p>
<p> </p>
<p>把下面这段脚本放到一个命名为ddns的脚本文件里去</p>
<blockquote><p>
#!/bin/bash<br />
wget -q -O- &#8216;http://username:password@members.3322.org/dyndns/update?system=dyndns&amp;hostname=domainname.3322.org&#8217;<br />
 </p></blockquote>
<p>然后加上可执行属性，再扔进/etc/ppp/ip-up.d/目录下去就可以了。</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/vyatta%e4%bd%bf%e7%94%a8%e6%89%8b%e8%ae%b0%ef%bc%9a%e6%9b%b4%e6%96%b03322org/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vyatta限速测试实验2</title>
		<link>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%95%e5%ae%9e%e9%aa%8c2/</link>
		<comments>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%95%e5%ae%9e%e9%aa%8c2/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 12:18:28 +0000</pubDate>
		<dc:creator>yuzifu</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Note]]></category>
		<category><![CDATA[Unix/Linux]]></category>

		<guid isPermaLink="false">http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%95%e5%ae%9e%e9%aa%8c2/</guid>
		<description><![CDATA[今天接着做实验，因为前面在WAN接口做限速的各种设置都测试过了，所以现在改在LAN接口，结果如下：



<span class="readmore"><a href="http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%95%e5%ae%9e%e9%aa%8c2/" title="Vyatta限速测试实验2" target="_blank">阅读全文——共640字</a></span>]]></description>
			<content:encoded><![CDATA[<p>今天接着做实验，因为前面在WAN接口做限速的各种设置都测试过了，所以现在改在LAN接口，结果如下：</p>
<table border="0" cellspacing="0" cellpadding="2" width="521">
<tbody>
<tr>
<td width="32" valign="top">序号</td>
<td width="40" valign="top">接口</td>
<td width="118" valign="top">类型</td>
<td width="40" valign="top">方向</td>
<td width="56" valign="top">内网IP</td>
<td width="91" valign="top">IP位置</td>
<td width="55" valign="top">速度</td>
<td width="87" valign="top">备注</td>
</tr>
<tr>
<td width="32" valign="top">1</td>
<td width="40" valign="top">LAN</td>
<td width="118" valign="top">traffic-shaper</td>
<td width="40" valign="top">out</td>
<td width="56" valign="top">1.2</td>
<td width="91" valign="top">destination</td>
<td width="55" valign="top">55k</td>
<td width="87" valign="top"> </td>
</tr>
<tr>
<td width="32" valign="top">2</td>
<td width="40" valign="top">LAN</td>
<td width="118" valign="top">traffic-shaper</td>
<td width="40" valign="top">out</td>
<td width="56" valign="top">1.2</td>
<td width="91" valign="top">source</td>
<td width="55" valign="top">110k</td>
<td width="87" valign="top"> </td>
</tr>
</tbody>
</table>
<p>这就意味着限速成功，2号实验速度为110k，原因是它没有匹配class 10规则，所以就应用了default的规则。</p>
<p>下面是1号实验的相关配置</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
</pre></td><td class="code"><pre class="cshare" style="font-family:monospace;">interfaces {
      ethernet eth0 {
          address 192.168.1.1/24
          duplex auto
          hw-id 00:0c:29:98:9e:cf
          qos-policy {
              out OFFICE
          }
          speed auto
      }
      ethernet eth1 {
          address 192.168.8.16/24
          duplex auto
          hw-id 00:0c:29:98:9e:d9
          speed auto
      }
  }
  protocols {
      static {
      }
  }
  qos-policy {
      traffic-shaper OFFICE {
          bandwidth 2mbit
          class 10 {
              bandwidth 512kbit
              burst .5k
              ceiling 512kbit
              match IP2 {
                  ip {
                      destination {
                          address 192.168.1.2/24
                      }
                  }
              }
              queue-type fair-queue
          }
          default {
              bandwidth 1mbit
              burst 1k
              ceiling 1mbit
              queue-type fair-queue
          }
      }
  }</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.yuzifu.net/index.php/2009/04/vyatta%e9%99%90%e9%80%9f%e6%b5%8b%e8%af%95%e5%ae%9e%e9%aa%8c2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
