用freebsd ports安裝完之後修改sockd.conf
sockd.conf
logoutput: /var/log/sockd/sockd 可用來查看連線的紀錄
internal: eth0 port = 1080
external: eth1 method: none username pam
clientmethod: none
user.libwrap: libwrap 自己vipw加入 user libwrap
#user.privileged: sockd
user.notprivileged: sockd 自己vipw加入user sockd
connecttimeout: 30
# Allow everyone from my LAN
client pass {
from: 192.168.0.0/24 port 1-65535 to: 0.0.0.0/0
log: connect disconnect
}
# Block everyone else
client block {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: connect error
}
# Block everyone connection to lo
block {
from: 0.0.0.0/0 to: 127.0.0.0/8
log: connect error
}
# Block subnet 172.16.0.0/32
block {
from: 0.0.0.0/0 to: 172.16.0.0/12
log: connect error
}
# Allow replys to bind and incoming udp
pass {
from: 0.0.0.0/0 to: 192.168.0.0/24 command: bindreply udpreply
log: connect error
}
# Allow tcp and upd connections from our lan to everywhere
pass {
from: 192.168.0.0/24 to: 0.0.0.0/0 protocol: tcp udp
log: error
}
# Log all the rest
block {
from: 0.0.0.0/0 to: 0.0.0.0/0
log: connect error
}
用flashfxp 可成功 ftp出去。log有socks的連線紀錄,可幫助debug
No comments:
Post a Comment