亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? cipe.texinfo

?? cipe 編程
?? TEXINFO
?? 第 1 頁 / 共 5 頁
字號(hào):
SOCKS5 protocol.@c --------------------------------------------------------------------------@page@node PKCIPE, Examples, Configuration, Top@chapter        The PKCIPE toolThe @command{pkcipe} program, included in the CIPE package since version1.5, eases configuration and running of CIPE links. With@command{pkcipe} it is not necessary to use long lived static keys. Apublic key based scheme (using Diffie-Hellman key exchange and RSAsignatures) is used instead. @command{pkcipe} also automatically handlesdynamic carrier addresses.@menu* How it works::        Short overview on PKCIPE.* Public Keys::         What public keys are and how to use them.* pkcipe invocation::   Running the pkcipe program.@end menu@node  How it works, Public Keys, PKCIPE, PKCIPE@section        How it worksTo start a CIPE link, two instances of the @command{pkcipe} program, oneon each side of the link, are connected via TCP. They do a key exchange,yielding a new random key which is used as the @code{key} parameter forCIPE. They tell each other their @emph{identity} and send a@emph{signature} built with their private key.Each side verifies the signature using the other side's public key.Additional parameters are exchanged as necessary. Currently theseadditional parameters are only the carrier IP addresses, which the@command{pkcipe} program obtains from the system at run time.After all parameters are set up, @command{pkcipe} writes an options filecontaining the new key and other parameters and starts @command{ciped}with this options file. Then @command{pkcipe} exits and the TCPconnection is closed.@node  Public Keys, pkcipe invocation, How it works, PKCIPE@section        Public KeysWith PKCIPE, each host has a public/private key pair. The private(secret) key is kept in the file @file{/etc/cipe/identity.priv} andnever copied anywhere else. The @file{/etc/cipe/pk} directory containsthe public keys of all peers. For all key files, the same restrictionson file and directory permissions apply as for options files.@xref{Specifying options}.Each host has an @dfn{identity} (usually its host name, but really it isan arbitrary string) by which it is known to its peers. The public keyfiles are named according to these identities. Each public key filesalso contains options (as in a CIPE options file) for this peer. Thepeer which has the right private key is allowed toconnect.@footnote{Note the similarity to the @command{ssh} program.}@cindex identityA public key pair may be generated with the @command{rsa-keygen} script.This generates two files, one with the public and one with the privatekey, the latter having the file name ending @code{.priv}. The Makefileautomatically does this on installation time if necessary.The secret key may be encrypted with a passphrase. In this case@command{pkcipe} asks for the passphrase every time it starts. This maybe useful e.g. for mobile systems which connect manually to a centralhost.The @option{-p} argument to @command{rsa-keygen} allows to set apassphrase on the newly generated secret key. For existing secret keys,the passphrase can be changed with the command@exampleopenssl rsa -des3 -out newfile -in oldfile@end exampleand deleted with the command@exampleopenssl rsa -out newfile -in oldfile@end examplewhere @file{oldfile} is the existing secret key file; the result will bestored in @file{newfile}.@node  pkcipe invocation,  , Public Keys, PKCIPE@section        Running the @command{pkcipe} programThe @command{pkcipe} program must be run as @emph{root}. (@strong{Do not}make it setuid.) @command{pkcipe} takes the following command lineparameters:@table @option@item -c @var{host}:@var{port}Run in client mode, connect to the given address.@item -t @var{timeout}Set the timeout for each network read (default is 60 seconds).@item -r @var{host}Give the host where the actual CIPE UDP packets are routed to. Thisoption is necessary when the TCP connection is done via a SOCKS or otherproxy (e.g. SSH redirection).@item -k @var{keyfile}Specify the private key file. Default is @file{/etc/cipe/identity.priv}.@item -p @var{proto}Set the PKCIPE protocol level to use. Currently there exists only theprotocol level 2.@item -D @var{debug}Debug logging flags.@item -ELog to standard error instead of syslog. For debugging purposes.@item @var{identity}(non-option parameter)Specify the identity to use. Default is the host name.@end table@xref{Example 2}, for how @code{pkcipe} is run in server mode.The location of the @code{ciped} command to be run by PKCIPE, as well asthe auxiliary files read from and written to, is currently hardcoded atcompile time.@c --------------------------------------------------------------------------@node Examples, Protocol descriptions, PKCIPE, Top@chapter        Usage examplesHere are some tips, examples and additional information on how to designa network structure with CIPE and configure the devices accordingly.@menu* Tips::                General useful tips on CIPE configuration.* Example 1::           The classic VPN setups.* Example 2::           A PKCIPE setup.* Connection modes::    Overview on different carrier network situations.@end menu@node Tips, Example 1, Examples, Examples@section        General tips@itemize @bullet@itemThe IP address of a CIPE device and it's UDP carrier @emph{must} bedifferent. Chose a @dfn{transit network} (e.g.@: 192.168 address) forthe CIPE devices if these don't fit into existing structures.@cindex transit network@itemThe route to the UDP carrier ("peer" address) @emph{can not} go throughthe CIPE device. If both are on the same route (e.g.@: both are on thesame network, IP-address-wise), add a host route to the "peer" addressthrough the right device or gateway.@itemIn Linux 2.0, the @code{route add -host $5 dev $1} in @file{ip-up} is required.Without it the link won't work. This also means the @file{ip-up} script itselfis mandatory.@item@cindex Setting routesRoutes through a CIPE device should be set only in the @file{ip-up}script. Use case selections on @code{$1} or @code{$5} if you haveseveral CIPE links. Use @code{route add ... gw $5}, not @code{route add... dev $1}. Remember that Linux deletes any routes through a devicewhen this device goes down.@item@cindex reject routeIf you have a default route, the addresses reachable via the CIPE linkare routed via the default when the link is down. This can defeat thepurpose of an encrypted link. To guard against this, set a reject routeto the affected addresses with higher metric in the system startup script.@item@cindex Proxy-ARPSometimes it is necessary or advisable to announce the address of thepeer via proxy-ARP to avoid more complicated routing setups. The example@file{ip-up} shows how this can be done. In Linux 2.4 a sysctl can beused to use proxy-ARP for the whole network "behind" the peer.@item@cindex gatedOn a system running @command{gated}, gated is the only thing responsiblefor setting any routes and the routes through the CIPE device routesbelong in @file{gated.conf} as static routes, or are to be set via a routingprotocol. To gated, a CIPE link looks and behaves exactly like a dial-uplink. It is strongly recommended to put @command{gdc interface} in@file{ip-up} as well as @file{ip-down} to tell gated about statuschanges.@itemThe configuration of both ends of a link is symmetric. One side's@code{ipaddr} is the other's @code{ptpaddr}, and one side's @code{me}is the other's @code{peer}. Since CIPE 0.5, @code{peer} is picked updynamically and the real peer may be different from that set in theconfig file (but this config item must still be present, it shouldspecify the other end's reverse as a reasonable default).@item@cindex Designing network structureWhen designing a network structure, draw the CIPE links as if theywere SLIP/PPP links. Build the routing with these links enabled. Thenlook at the picture as if the CIPE links weren't there, so you can seethe routing needed for the UDP adresses.@item@cindex firewall rulesFirewall rules which contain a device are independent of the device'sexistence. This means that they can be established before the module isloaded and @command{ciped} run, and that an explicit @code{device} optionshould be used if the device name is used in firewall rules.@itemWith PKCIPE, the location and content of the PID files from the@code{ip-up} sample scripts is mandatory as they are used as lock files.Omitting these can cause confusion when several instances of@code{pkcipe} run at the same time.@end itemize@page@node Example 1, Example 2, Tips, Examples@section        Example 1@cindex Classic VPN setup@cindex Unofficial subnets@cindex Branch office --- head office@cindex Mobile hostThis basic example shows how to connect hosts and networks withunofficial network numbers through the Internet. Uses for this areclassic VPN setups:@enumerate@itemConnecting two unofficial subnets through an Internet link@itemConnecting a branch office to the head office through a one-address dialup@itemConnecting a mobile host with varying access points@end enumerate@format@group@t{               Internet               Internet                  ^                      ^                  |                      |                           hostz                  |ppp0                  |eth1                  200.0.24.3                  |200.0.24.65           |200.0.24.1                     |     +---------routera                routerb         eth0 200.0.24.1    |     |    eth0        \_ _ _ _ _ _ _ _/      \---------------+-------+---+     |  10.0.1.1   cipcb0         cipcb0      eth0           |       |   hosta           10.0.1.1      10.0.2.1     10.0.2.1       |       | 10.0.1.88                                                hostx   hosty                                                       10.0.2.5  10.0.2.6}@end group@end formatAs can be seen from the picture, a CIPE device and another networkdevice can have the same IP address if there are no overlapping routesbetween them.The CIPE devices are configured like this:@multitable @columnfractions .25 .35 .4@item                   @tab routera            @tab routerb@item			@tab cipcb0             @tab cipcb0@item ipaddr            @tab 10.0.1.1           @tab 10.0.2.1@item ptpaddr		@tab 10.0.2.1		@tab 10.0.1.1@item me		@tab 200.0.24.65:9999	@tab 200.0.24.1:9999@item peer		@tab 200.0.24.1:9999	@tab 200.0.24.65:9999@item static routes	@tab 10.0.1.0/24 dev eth0  @tab 10.0.2.0/24 dev eth0@item			@tab default dev ppp0      @tab 200.0.24.0/26 dev eth0@item			@tab                       @tab default dev eth1@item routes in ip-up   @tab 10.0.2.0/24 gw 10.0.2.1                                                @tab 10.0.1.0/24 gw 10.0.1.1@end multitableFor case 3, assume @code{routera} to be the mobile host, think of@code{eth0} missing and @code{ppp0} having a dynamic address. The@code{routerb} config remains unchanged. For @code{routera} simply omitthe @code{eth0} stuff, add the @code{dynip} flag for ciped. @code{routerb}picks up its peer dynamically. This even works when @code{routerb} isplugged behind a firewall and has to rely on a SOCKS5 server for outsideaccess. (Yes, this can be used to punch holes into firewalls. No, it'snot my intention to do anything about it. Local policy issues have to bedealt with locally.)@cindex Hole in firewall@page@node Example 2, Connection modes, Example 1, Examples@section        Example 2This example shows how to set up PKCIPE. The overall setup is symmetric,there are no designated servers and clients. However, one end has toaccept incoming TCP connections on a chosen port (@dfn{server mode}) andthe other one has to connect to it (@dfn{client mode}).@cindex PKCIPE, modes@cindex @command{pkcipe}, programThe basic configuration of a link is like this: assuming @code{routera}has the address (of the CIPE device) @code{10.0.1.1} and @code{routerb}has the address @code{10.0.2.1} like in Example 1. Each@file{/etc/cipe/pk/@var{host}} file contains the public key of that hosttogether with options applying to that host:On @code{routera}, @file{/etc/cipe/pk/routerb} looks like this:@example-----BEGIN PUBLIC KEY-----(here is the public key of routerb)-----END PUBLIC KEY-----ipaddr  10.0.1.1ptpaddr 10.0.2.1@end exampleand on @code{routerb}, @file{/etc/cipe/pk/routera} looks like this:@example-----BEGIN PUBLIC KEY-----(here is the public key of routera)-----END PUBLIC KEY-----ipaddr  10.0.2.1ptpaddr 10.0.1.1

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號(hào) Ctrl + =
減小字號(hào) Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
欧美丝袜丝交足nylons图片| 欧美日本不卡视频| 欧美性xxxxx极品少妇| 日韩欧美国产综合| 亚洲视频狠狠干| 麻豆国产精品视频| 欧美性极品少妇| 中文字幕欧美日韩一区| 奇米四色…亚洲| 色一区在线观看| 国产三级精品三级在线专区| 亚洲成av人**亚洲成av**| 懂色av中文一区二区三区| 欧美三级乱人伦电影| 中文字幕一区三区| 精品在线你懂的| 欧美三级乱人伦电影| 亚洲人精品午夜| 风间由美一区二区三区在线观看| 日韩一级完整毛片| 午夜不卡av免费| 欧美中文字幕不卡| 亚洲免费观看在线观看| 成人app下载| 中文字幕国产一区| 国产精品自在欧美一区| 日韩视频一区二区三区| 天天影视色香欲综合网老头| 欧美在线看片a免费观看| 亚洲人xxxx| 91在线你懂得| 一区二区三区丝袜| 在线看不卡av| 夜夜爽夜夜爽精品视频| 色综合视频一区二区三区高清| 国产女同性恋一区二区| 国产成a人亚洲| 国产欧美日韩精品一区| 成人理论电影网| 中文字幕高清一区| 99久久精品国产麻豆演员表| 欧美韩国日本不卡| av在线不卡免费看| 中文字幕亚洲在| eeuss国产一区二区三区| 国产人成一区二区三区影院| 福利一区福利二区| 亚洲视频在线观看一区| 91九色最新地址| 亚洲精品免费视频| 欧美精品一级二级| 奇米在线7777在线精品| 亚洲精品一区二区三区影院| 国产一区二区在线视频| 亚洲欧美中日韩| 久久久不卡网国产精品一区| 日韩av一区二区三区四区| 欧美伦理影视网| 视频一区二区三区在线| 欧美一级国产精品| 韩国理伦片一区二区三区在线播放| 久久亚洲一区二区三区四区| 成人v精品蜜桃久久一区| 亚洲另类中文字| 在线综合+亚洲+欧美中文字幕| 麻豆精品国产传媒mv男同 | 欧美α欧美αv大片| 另类中文字幕网| 国产欧美日韩综合| 欧美美女喷水视频| 国产精品亚洲专一区二区三区| 国产精品入口麻豆原神| 日本乱人伦一区| 轻轻草成人在线| 日韩一区在线免费观看| 欧美高清视频www夜色资源网| 国产综合久久久久影院| 日韩毛片在线免费观看| 欧美精品高清视频| 国产91精品一区二区| 亚洲一区二区成人在线观看| 欧美一区二区在线免费观看| 99re成人在线| 九九在线精品视频| 亚洲精品国产一区二区三区四区在线| 91精品国产综合久久精品app| 成人av在线播放网站| 轻轻草成人在线| 樱桃国产成人精品视频| 国产亚洲一二三区| 欧美三级韩国三级日本三斤| av电影在线观看一区| 精品一区二区在线观看| 亚洲大片精品永久免费| 国产精品国产精品国产专区不片| 欧美一级日韩不卡播放免费| 色婷婷精品久久二区二区蜜臂av | 亚洲素人一区二区| 欧美va亚洲va在线观看蝴蝶网| 99久久久久久| 国产麻豆精品theporn| 日一区二区三区| 最新国产の精品合集bt伙计| 久久久久久久久蜜桃| 欧美久久久影院| 欧美日韩精品欧美日韩精品一综合| 日韩欧美亚洲一区二区| 色综合天天狠狠| 色婷婷综合久久久久中文| 国产精品一区二区三区网站| 免费视频一区二区| 亚洲mv在线观看| 亚洲一区二区精品3399| 亚洲美女区一区| 久久精品一区二区| www国产成人| 精品欧美久久久| 日韩视频一区在线观看| 日韩亚洲欧美在线观看| 在线不卡中文字幕播放| 成人h精品动漫一区二区三区| 国产精品一二三四| 国产尤物一区二区在线| 免费成人深夜小野草| 久久精品国产77777蜜臀| 亚洲成人福利片| 夜夜嗨av一区二区三区网页| 亚洲色图在线视频| 亚洲精品高清视频在线观看| 中文字幕亚洲欧美在线不卡| 日韩一区欧美一区| 中文字幕亚洲视频| 中文字幕乱码亚洲精品一区 | 美女视频黄 久久| 日本成人中文字幕| 国产综合久久久久久鬼色 | 国产日韩欧美精品一区| 国产亚洲欧美激情| 亚洲免费电影在线| 午夜伊人狠狠久久| 麻豆精品精品国产自在97香蕉| 国产一区二区三区在线看麻豆| 国产乱国产乱300精品| 风间由美一区二区av101 | 欧美一二三区在线观看| 日韩欧美中文字幕公布| 久久综合久久99| 国产精品丝袜久久久久久app| 亚洲欧洲国产日韩| 亚洲国产精品一区二区www在线| 日韩精品福利网| 狠狠色狠狠色综合| 99精品久久99久久久久| 欧美剧情电影在线观看完整版免费励志电影 | 亚洲成av人片在线| 激情综合色综合久久| 91猫先生在线| 日韩欧美的一区| 亚洲精品videosex极品| 日本中文在线一区| 懂色av一区二区三区免费看| 91久久精品网| 国产女人18水真多18精品一级做 | 青娱乐精品视频| 成人网男人的天堂| 这里是久久伊人| 亚洲视频在线观看一区| 裸体歌舞表演一区二区| 成人国产精品免费| 欧美一区二区精品在线| 国产精品美女久久久久aⅴ | 亚洲一区二区三区在线播放 | 午夜精品久久一牛影视| 国产成人午夜视频| 91精品国产综合久久久久久| 亚洲欧美在线视频观看| 国产一区二区三区免费播放| 欧美日本韩国一区二区三区视频| 中国色在线观看另类| 黄色日韩三级电影| 欧美在线一区二区| 国产精品国产三级国产普通话蜜臀| 免费高清成人在线| 欧美在线免费观看亚洲| 亚洲欧美日韩国产成人精品影院| 国产一区二区精品久久99| 欧美精品久久99久久在免费线| 亚洲美女精品一区| 成人黄色电影在线| 国产日韩欧美精品一区| 国模一区二区三区白浆| 欧美日本在线一区| 亚洲免费观看高清完整版在线观看 | 5858s免费视频成人| 亚洲精品成人a在线观看| 99久久精品免费观看| 中文字幕精品—区二区四季| 国产高清不卡一区二区| 欧美va在线播放| 六月丁香婷婷色狠狠久久|