lissyara писал(а):файрволл, маршрутизация....
Офис:
vpn# ifconfig -a
rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=8<VLAN_MTU>
inet 126.128.3.2 netmask 0xff000000 broadcast 126.255.255.255
ether 00:02:44:38:b2:43
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=8<VLAN_MTU>
inet ххх.ххх.ххх.ххх netmask 0xffffff00 broadcast ххх.ххх.ххх.ххх
ether 00:02:44:3c:05:27
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet 127.0.0.1 netmask 0xff000000
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 126.128.3.2 --> 126.128.4.2 netmask 0xff000000
Opened by PID 514
vpn# netstat -rn
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 126.128.1.24 UGS 0 92 rl0
126 link#1 UC 0 0 rl0
126.128.1.19 00:0e:7f:a6:e6:86 UHLW 1 4 rl0 1195
126.128.1.24 00:02:44:3a:8a:47 UHLW 2 0 rl0 1191
126.128.4.2 link#1 UHLW 1 0 rl0
127.0.0.1 127.0.0.1 UH 0 0 lo0
ххх.ххх.ххх link#2 UC 0 0 rl1
vpn# ipfw -a list
65535 494 73595 allow ip from any to any
Филиал:
filial# ifconfig -a
rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=8<VLAN_MTU>
inet6 fe80::250:fcff:fe8f:d1ed%rl0 prefixlen 64 scopeid 0x1
inet 126.128.4.2 netmask 0xff000000 broadcast 126.255.255.255
ether 00:50:fc:8f:d1:ed
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
rl1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=8<VLAN_MTU>
inet6 fe80::205:5dff:fe28:17f9%rl1 prefixlen 64 scopeid 0x2
inet 192.168.1.2 netmask 0xffffff00 broadcast 192.168.1.255
ether 00:05:5d:28:17:f9
media: Ethernet autoselect (100baseTX <full-duplex>)
status: active
plip0: flags=108810<POINTOPOINT,SIMPLEX,MULTICAST,NEEDSGIANT> mtu 1500
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4
inet 127.0.0.1 netmask 0xff000000
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 126.128.4.2 --> 126.128.3.2 netmask 0xff000000
inet6 fe80::250:fcff:fe8f:d1ed%tun0 prefixlen 64 scopeid 0x5
Opened by PID 424
filial# netstat -rn
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 192.168.1.1 UGS 0 324 rl1
126 link#1 UC 0 0 rl0
126.128.1.19 link#1 UHLW 1 17 rl0
126.128.3.2 link#1 UHLW 1 0 rl0
126.128.4.1 00:19:21:3c:74:b8 UHLW 1 20 rl0 1015
126.128.4.13 00:13:8f:7a:f3:f3 UHLW 1 394 rl0 1186
127.0.0.1 127.0.0.1 UH 0 0 lo0
192.168.1 link#2 UC 0 0 rl1
192.168.1.1 00:17:9a:10:4b:ea UHLW 2 0 rl1 1195
filial# ipfw -a list
00050 325 30783 divert 8668 ip4 from any to any via rl1
00100 0 0 allow ip from any to any via lo0
00200 0 0 deny ip from any to 127.0.0.0/8
00300 0 0 deny ip from 127.0.0.0/8 to any
65000 1358 118308 allow ip from any to any
65535 1 64 allow ip from any to any
Вот такие вот пирожки
