²©¿Íͳ¼ÆÐÅÏ¢

Óû§Ãû£ºsookk
ÎÄÕÂÊý£º169
ÆÀÂÛÊý£º78
·ÃÎÊÁ¿£º250180
ÎÞÓDZңº588
²©¿Í»ý·Ö£º1084
²©¿ÍµÈ¼¶£º5
×¢²áÈÕÆÚ£º2008-08-20

ÎÒ×î½ü·¢±íµÄÆÀÂÛ

¶Ô Ò»¼üDDOS·À»ðǽ°².. »Ø¸´
еİ汾´ø×Ô¶¯¸üзÀÓù¹¥»÷¿â£¬µ¥..
¶Ô Ò»¼üDDOS·À»ðǽ°².. »Ø¸´
×îеİ汾ÓиĽøÁË£¬¿ÉÒÔÊÔÊÔ¿´
¶Ô CentOS 5.5»·¾³ÏÂ.. »Ø¸´
»¹ÊDz»´í
¶Ô Ò»¼üDDOS·À»ðǽ°².. »Ø¸´
²âÊÔ¹ýÁË£¬ºÜ°²È«£¬·À»ðǽЧ¹ûÒ²ºÜÇ¿´ó
¶Ô shell½áºÏiptable.. »Ø¸´
¼à²â»úÖÆ»¹Ã»£¬Õâ¸ö´úÂëÊÇÒÔǰ¿ªÊ¼..
 Ò»¡¢»·¾³
OS: CENTOS5.3
 
VIP:192.168.0.181  £¨ÍâÍø·ÃÎÊIPµØÖ·£©
 
LVS_SRV: 192.168.0.180 £¨LVSÖ÷·þÎñÆ÷£©
 
R1£º192.168.0.185
 
R2£º192.168.0.186
 
¶þ¡¢LVS°²×°
 
1.Èí¼þ°²×°£¨°²×°ÖÁLVS_SRV£©
 
yum install ipvsadm modcluster system-confi-cluster
 
Ò²¿ÉÒÔÑ¡ÔñÊÖ¹¤ÏÂÔØÔ´Âë±àÒë°²×°£¬ÕâÀï²»ÔÙÐðÊö¡£
 
2.ÅäÖÃ(lvs.sh)
 
1) lvs_srvÅäÖÃ
 
    #¿ªÆôIPת·¢£¬½öµ±DRģʽÏÂ
 
echo "1" >/proc/sys/net/ipv4/ip_forward
 
2)       RnÅäÖÃ(rs.sh)
 
#!/bin/sh
 
# ghb in 20120212
 
# description: Config realserver tunl port and apply arp patch
 
VIP=192.168.0.181
 
. /etc/rc.d/init.d/functions
 
case $1 in
 
    start)
 
    echo "Tunl port starting"
 
    ifconfig lo:0 $VIP netmask 255.255.255.255 broadcast $VIP up
 
    /sbin/route add -host $VIP dev lo..
 

HTTP³¤Á¬½Ó200Íò³¢ÊÔ¼°µ÷ÓÅ·½·¨



¶ÔÓÚÒ»¸öserver£¬ÎÒÃÇÒ»°ã¿¼ÂÇËûËùÄÜÖ§³ÅµÄqps£¬µ«ÓÐÄÇôһÖÖÓ¦Ó㬠ÎÒÃÇÐèÒª¹Ø×¢µÄÊÇËüÄÜÖ§³ÅµÄÁ¬½ÓÊý¸öÊý£¬¶ø²¢·Çqps£¬µ±È»qpsÒ²ÊÇÎÒÃÇÐèÒª¿¼ÂǵÄÐÔÄܵãÖ®Ò»¡£ÕâÖÖÓ¦Óó£¼ûÓÚÏûÏ¢ÍÆËÍϵͳ£¬Ò²³ÆÎªcometÓ¦Ó㬱ÈÈçÁÄÌìÊÒ»ò¼´Ê±ÏûÏ¢ÍÆËÍϵͳµÈ¡£cometÓ¦ÓþßÌå¿É¼ûÎÒ֮ǰµÄ½éÉÜ£¬Ôڴ˲»¶à½²¡£¶ÔÓÚÕâÀàϵͳ£¬ÒòΪºÜ¶àÏûÏ¢ÐèÒªµ½²úÉúʱ²ÅÍÆË͸ø¿Í»§¶Ë£¬ËùÒÔµ±Ã»ÓÐÏûÏ¢²úÉúʱ£¬¾ÍÐèÒªholdס¿Í»§¶ËµÄÁ¬½Ó£¬ÕâÑù£¬µ±ÓдóÁ¿µÄ¿Í»§¶Ëʱ£¬¾ÍÐèÒªholdס´óÁ¿µÄÁ¬½Ó£¬ÕâÖÖÁ¬½ÓÎÒÃdzÆÎª³¤Á¬½Ó¡£
Ê×ÏÈ£¬ÎÒÃÇ·ÖÎöһϣ¬¶ÔÓÚÕâÀà·þÎñ£¬ÐèÏûºÄµÄϵͳ×ÊÔ´ÓУºcpu¡¢ÍøÂç¡¢ÄÚ´æ¡£ËùÒÔ£¬ÏëÈÃϵͳÐÔÄÜ´ïµ½×î¼Ñ£¬ÎÒÃÇÏÈÕÒµ½ÏµÍ³µÄÆ¿¾±ËùÔÚ¡£ÕâÑùµÄ³¤Á¬½Ó£¬ÍùÍùÎÒÃÇÊÇûÓÐÊý¾Ý·¢Ë͵ģ¬ËùÒÔÒ²¿ÉÒÔ¿´×÷Ϊ·Ç»î¶¯Á¬½Ó¡£¶ÔÓÚϵͳÀ´Ëµ£¬ÕâÖַǻÁ¬½Ó£¬²¢²»Õ¼ÓÃcpuÓëÍøÂç×ÊÔ´£¬¶ø½ö½öÕ¼ÓÃϵͳµÄÄÚ´æ¶øÒÑ¡£ËùÒÔ£¬ÎÒÃǼÙÏ룬ֻҪϵͳÄÚ´æ×ã¹»£¬ÏµÍ³¾ÍÄܹ»Ö§³ÖÎÒÃÇÏë´ïµ½µÄÁ¬½ÓÊý£¬ÄÇôÊÂʵÊÇ·ñÕæµÄÈç´Ë£¿Èç¹ûÕæÄÜÕâÑù£¬ÄÚºËÀ´Î¬»¤ÕâÏ൱´óµÄÊý¾Ý½á¹¹£¬Ò²ÊÇÒ»ÖÖ¿¼Ñé¡£
ÒªÍê³É²âÊÔ£¬ÎÒÃÇÐèÒªÓÐÒ»¸ö·þÎñ¶Ë£¬»¹ÓдóÁ¿µÄ¿Í»§¶Ë¡£ËùÒÔÐèÒª·þÎñ¶Ë³ÌÐòÓë¿Í»§¶Ë³Ì..
 





http://www.17rumen.com/archives/57.html
£¨ÓÐÊÓÆµ£©ÐèÒª2¸öÃüÁîÒ»Æë
iptables -A INPUT -P tcp -s 192.168.0.0 -j ACCEPT
iptables -A OUTPUT -p tcp -d 192.168.0.0 -j ACCEPT
ÒÔÏÂÊǶ˿ڣ¬ÏÈÈ«²¿·âÔÙ¿ªÄ³Ð©µÄIP
iptables -I INPUT -p tcp --dport 9889 -j DROP 
iptables -I INPUT -s 192.168.1.0/24 -p tcp --dport 9889 -j ACCEPT
Èç¹ûÓÃÁËNATת·¢¼ÇµÃÅäºÏÒÔϲÅÄÜÉúЧ
iptables -I FORWARD -p tcp --dport 80 -j DROP 
iptables -I FORWARD -s 192.168.1.0/24 -p tcp --dport 80 -j ACCEPT
 

³£ÓõÄIPTABLES¹æÔòÈçÏ£º
Ö»ÄÜÊÕ·¢Óʼþ£¬±ðµÄ¶¼¹Ø±Õ
iptables -I Filter -m mac --mac-source 00:0F:EA:25:51:37 -j DROP
iptables -I Filter -m mac --mac-source 00:0F:EA:25:51:37 -p udp --dport 53 -j ACCEPT
iptables -I Filter -m mac --mac-source..
 LinuxÓÐʱ»á³öÏÖ“You have new mail in /var/spool/mail/root”£¬ºÜ·³ÈË£¬ÈçºÎ½ûÖ¹µôÄØ£¿
ÐèÒªÐÞ¸ÄϵͳÅäÖÃÎļþ£¬¸æËßϵͳ²»ÒªÈ¥¼ì²éÓÊÏä
[root@localhost ~]#echo "unset MAILCHECK">> /etc/profile
Æäʵ¾ÍÊǰÑunset MAILCHECK¼Óµ½Îļþ/etc/profile µÄβ²¿¼´¿É
È»ºóÖØÐµÇ½¿ØÖÆÌ¨¾ÍûÓÐÕâ¸öÌÖÑáµÄÌáÐÑÁË¡£
 
 iis Èç¹û·ÅÔÚ·´Ïò´úÀíºóÃæ£¬ÈÕÖ¾ÀïµÄc-ipÊÇ·´Ïò´úÀí·þÎñÆ÷µÄip£¬²»ÊÇÕæÕýÓû§µÄip£¬ÏëÒª¼Ç¼Óû§µÄipÒª×öÁ½¼þÊ¡£
 
Ò»¡£ÔÚ·´Ïò´úÀíÉèÖÃX-Forwarded-For¶Î£¬ÒÔÏÂΪnginxϵÄÅäÖÃʾÀý£º
 
server 
 
     £û
      location
      £û
        ........
        proxy_set_header   X-Forwarded-For  $proxy_add_x_forwarded_for;
        ........
       £ý
      £ý
¶þ¡£ÔÚiisÕ¾µãÉϰ²×°ÏÂÃæÕâ¸öisapi filter£¬Õâ¶«Î÷ÊÇÔÚf5µÄ¿ª·¢ÂÛ̳ÉÏÕÒµ½µÄ£¬°´¿ª·¢ÕߵĻ°Ëµ£¬ÊÇΪÁ˽â¾öiis·ÅÔÚf5ºó¼Ç¼²»µ½Óû§ipµÄÎÊÌ⣬-_-# ¹ÜËûǰ¶ËÊÇf5»¹ÊÇnginx»¹ÊÇsquid»¹ÊÇhaproxy¡£¶¼¿ÉÒÔÓá£Ó¦¸Ã²»´í¡£×°ÍêÖ®ºóÖØÆôÏÂiis¾Í¸ã¶¨ÁË¡£








 
http://devcentral.f5.com/weblogs/Joe/archive/2009/08/19/x_forwarded_for_log_filter_for_windows_servers.aspx








»ØÍ·¿´ÏÂiisµÄÈÕÖ¾£¬ÀïÃæµÄc-ipÒѾ­ÊÇÓû§¶ËµÄipÁË
[/img]..
 <<   1   2   3   4   5   >>   Ò³Êý ( 1/34 )