<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-566025169101662036</id><updated>2011-11-27T15:24:47.933-08:00</updated><title type='text'>생각 THINK 더하기</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://thinkplay.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/566025169101662036/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://thinkplay.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Pete</name><uri>http://www.blogger.com/profile/11210091684240727558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-566025169101662036.post-6900427315035834472</id><published>2011-02-11T23:26:00.000-08:00</published><updated>2011-02-11T23:26:26.625-08:00</updated><title type='text'>Router 보안 - 안전한 라우터 운영을 위한 튜닝 전체공개</title><content type='html'>Router 보안 - 안전한 라우터 운영을 위한 튜닝 &lt;br /&gt;불필요한 Global Service 정지&lt;br /&gt;Disabling service finger – Finger Service 정지&lt;br /&gt;Disabling service pad – PAD(X.25) Service 정지&lt;br /&gt;Disabling udp &amp;amp; tcp small servers – Echo,Discard,Chargen,Daytime Service 정지&lt;br /&gt;Enabling service password encryption – Password 암호화 기능 구동&lt;br /&gt;Enabling service tcp-keepalives-in/out – Session Keepalive Service 구동&lt;br /&gt;Disabling the cdp protocol – CDP Service 정지&lt;br /&gt;Disabling the bootp server – Bootp Server Service 정지&lt;br /&gt;Disabling the http server – Http Server 기능 정지&lt;br /&gt;Disabling source routing – IP 변조 방지를 위한 Source Routing 기능 정지&lt;br /&gt;Disabling gratuitous arp – PPP connection,IP negotiation 등에 사용되는 ARP 도용 서비스 차단&lt;br /&gt;Configuring aaa local authentication – AAA 생성 서비스&lt;br /&gt;외부로 부터의 접속 강화 서비스 – Telnet,Console,Aux 등…&lt;br /&gt;Banner 자동 생성 기능&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;불필요한 Interface Service 정지&lt;br /&gt;no ip redirects – icmp redirect message 차단&lt;br /&gt;no ip proxy-arp – Proxy arp service 정지&lt;br /&gt;no ip unreachables – ICMP unreachable service 정지&lt;br /&gt;no ip directed-broadcast – Broadcast service 정지&lt;br /&gt;no ip mask-reply – ICMP mask-reply 정지&lt;br /&gt;&lt;br /&gt;성능 강화와 IP filtering&lt;br /&gt;CEF Enable &lt;br /&gt;Ingress Filtering – 사용하지 않는 사설 IP, IANA address&lt;br /&gt;uRPF - IP 변조방지 구성&lt;br /&gt;&lt;br /&gt;“Auto Secure” 명령어를 통한 보안 강화&lt;br /&gt;&amp;nbsp;&amp;nbsp;“One Touch” device lock down process – command 한줄로 라우터의 보안구성을 자동으로 실행&lt;br /&gt;&lt;br /&gt;CPP 구성&lt;br /&gt;CPP (Control Plane Policing) 구성 예제 &lt;br /&gt;&lt;br /&gt;##Access-list 작성##&lt;br /&gt;Router(config)# access-list 141 permit icmp any any port-unreachable&lt;br /&gt;&lt;br /&gt;##Class-Map 작성##&lt;br /&gt;Router(config)# class-map icmp-class&amp;nbsp;&lt;br /&gt;Router(config-cmap)# match access-group 141 &lt;br /&gt;&lt;br /&gt;##Policy-Map 작성##&lt;br /&gt;Router(config)# policy-map control-plane-out-policy &lt;br /&gt;Router(config-pmap)# class icmp-class &lt;br /&gt;Router(config-pmap-c)# police 80000 conform transmit exceed drop &lt;br /&gt;&lt;br /&gt;##Control Plane 에 적용##&lt;br /&gt;Router(config)# control-plane &lt;br /&gt;Router(config-cp)# service-policy output control-plane-policy &lt;br /&gt;&lt;br /&gt;Port Security – MAC 변조 방지 기능&lt;br /&gt;Switch(config)# interface fastethernet 5/12&lt;br /&gt;Switch(config-if)# switchport mode access&lt;br /&gt;Switch(config-if)# switchport port-security&lt;br /&gt;Switch(config-if)# switchport port-security maximum 5&amp;nbsp;&amp;nbsp;à 최대 허용 MAC Address&lt;br /&gt;Switch(config-if)# switchport port-security mac-address 1000.2000.3000&amp;nbsp;&amp;nbsp; à 허용 MAC address&lt;br /&gt;Switch(config-if)# switchport port-security violation [protect/restrict/shutdown] &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 규칙 위반 시 Action&lt;br /&gt;&lt;br /&gt;Port Security – MAC flooding 방어&lt;br /&gt;Console&amp;gt; (enable) set port security 2/1 enable&lt;br /&gt;Console&amp;gt; (enable) set port security 2/1 enable 00-90-2b-03-34-08&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 허용 MAC address&lt;br /&gt;Console&amp;gt; (enable) set port security 2/1 maximum 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à 최대 허용 MAC Address&lt;br /&gt;Console&amp;gt; (enable) set port security 2/1 violation [restrict/shutdown]&amp;nbsp;&amp;nbsp; à 규칙 위반 시 Action&lt;br /&gt;&lt;br /&gt;Port Security – 공격자 MAC 제어 기술&lt;br /&gt;Attacker로 의심이 되는 특정 MAC Address 만을 Filtering &lt;br /&gt;4500(config)# mac-address-table static 0050.3e8d.4444 vlan (해당vlan) drop&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 해당 Vlan Interface에 올라오는 MAC Address Filtering&lt;br /&gt;4500(config)# show mac-address-table dynamic &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 현재 Switch로 올라오는 CAM Table 조회 명령&lt;br /&gt;&lt;br /&gt;Console&amp;gt; (enable) set cam static filter 00-02-03-04-05-06 12(해당 Vlan 번호)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 해당 Vlan Interface에 올라오는 MAC Address Filtering &lt;br /&gt;Console&amp;gt; (enable) clear cam 00-02-03-04-05-06 12(해당 Vlan 번호)&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à filtering 해제 &lt;br /&gt;Console&amp;gt; show cam static&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à 현재 Switch로 올라오는 CAM Table 조회 명령&lt;br /&gt;&lt;br /&gt;Multi/Broadcast Flooding 제어기술 : Storm Control (Bandwidth 대비 Percentage 적용)&lt;br /&gt;Router# configure terminal&lt;br /&gt;Router(config)# interface gigabitethernet 3/16&lt;br /&gt;Router(config-if)# storm-control multicast level 70.5&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à Multicast 70.5% 이상이면 억제&lt;br /&gt;&lt;br /&gt;Console&amp;gt; (enable) set port broadcast 2/1 80% multicast enable &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à Multicast 70.5% 이상이면 억제 : default packet drop &lt;br /&gt;Console&amp;gt; (enable) clear port broadcast 2/1 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à 구성 해제&lt;br /&gt;Console&amp;gt; (enable) set port broadcast 4/6 90% violation errdisable &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à Broadcast 90% 이상 이면 Interface errdisable로 만듦&amp;nbsp;&lt;br /&gt;&lt;br /&gt;공격자 MAC 추적 기술 : L2 Trace&lt;br /&gt;(Cat OS, Native IOS 지원 : 특정 MAC이 연결된 장비 및 포트 현황 추적 기능 지원)&lt;br /&gt;Cat OS Layer 2 Trace를 통한 MAC address 추적&lt;br /&gt;의심이 가는 Switch에서 Layer 2 trace 명령을 통한 추적&lt;br /&gt;6509&amp;gt; (enable) l2trace 00-00-e8-34- 00-01-e6-27- detail &lt;br /&gt;l2trace vlan number is 222.&lt;br /&gt;Attention: Source 00-00-e8-34-d2-96 is not directly attached to this system.&lt;br /&gt;Source 00-00-e8-34- found in WS-C4006 : 100.248.2.254 &lt;br /&gt;WS-C4006 : cat4006 : 100.248.2.254:&amp;nbsp;&amp;nbsp;4/27 10MB half duplex -&amp;gt; 2/1-2 1000MB full duplex&lt;br /&gt;WS-C6509 : cat6509 : 100.248.117.78: 3/14,4/14 1000MB full duplex &lt;br /&gt;-&amp;gt;&amp;nbsp;&amp;nbsp;8/44 10MB half duplex&lt;br /&gt;Destination 00-01-e6-27- found in WS-C6509 named BB_6509 &lt;br /&gt;on port&amp;nbsp;&amp;nbsp;8/44 10MB half duplex&lt;br /&gt;DHCP사용환경, IP Spoofing 시 유용한 추적&lt;br /&gt;&lt;br /&gt;Cisco IOS Layer 2 Trace를 통한 MAC address 추적&lt;br /&gt;의심이 가는 Switch에서 Layer 2 trace 명령을 통한 추적&lt;br /&gt;Switch# traceroute mac 0000.0201.0601 0000.0201.0201 detail&lt;br /&gt;Source 0000.0201.0601 found on con6[WS-C3750-12T] (2.2.6.6)&lt;br /&gt;con6 / WS-C3750-12T / 2.2.6.6 :&lt;br /&gt;Gi0/0/2 [auto, auto] =&amp;gt; Gi0/0/3 [auto, auto]&lt;br /&gt;con5 / WS-C2950G-24-EI / 2.2.5.5 :&lt;br /&gt;Fa0/3 [auto, auto] =&amp;gt; Gi0/1 [auto, auto]&lt;br /&gt;con1 / WS-C3550-12G / 2.2.1.1 :&lt;br /&gt;Gi0/1 [auto, auto] =&amp;gt; Gi0/2 [auto, auto]&lt;br /&gt;con2 / WS-C3550-24 / 2.2.2.2 :&lt;br /&gt;Gi0/2 [auto, auto] =&amp;gt; Fa0/1 [auto, auto]&lt;br /&gt;Destination 0000.0201.0201 found on con2[WS-C3550-24] (2.2.2.2)&lt;br /&gt;Layer 2 trace completed.&lt;br /&gt;DHCP사용환경, IP Spoofing 시 유용한 추적&lt;br /&gt;&lt;br /&gt;Snooping 방지 : Private VLAN&lt;br /&gt;Private Vlan : 동일 Vlan 내부에서의 불필요한 Traffic 제어&lt;br /&gt;Community Vlan : C-vlan 간 Host만 통신이 가능&lt;br /&gt;Isolated Vlan : I-Vlan 간 Host도 통신 불가&lt;br /&gt;Promiscuous Port : 모든 Pvlan Host는 P-port를 통한 외부 통신 가능&lt;br /&gt;&lt;br /&gt;Private VLAN 생성 및&amp;nbsp;&amp;nbsp;Sub VLAN 역할 담당&lt;br /&gt;vlan 65&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan primary&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan association 651-653&lt;br /&gt;vlan 651&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan community&lt;br /&gt;vlan 652&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan isolated&lt;br /&gt;vlan 653&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan community&lt;br /&gt;Primary VLAN과 Secondary VLAN Association 구성&lt;br /&gt;vlan 65&lt;br /&gt;&amp;nbsp;&amp;nbsp;private-vlan association 651,652,653&lt;br /&gt;interface vlan 65&lt;br /&gt;private-vlan mapping add 651,652,653&lt;br /&gt;물리적 포트에 secondary vlan 할당&lt;br /&gt;Router(config)# interface fastethernet 9/1&lt;br /&gt;Router(config-if)# switchport mode private-vlan host&lt;br /&gt;Router(config-if)# switchport private-vlan host-association 65 651&lt;br /&gt;Layer 2 장비로 운용시 promiscuous port 할당&lt;br /&gt;Router(config)# interface fast&amp;nbsp;&amp;nbsp;9/48&lt;br /&gt;Router(config-if)# switchport mode private-vlan promiscuous&lt;br /&gt;Router(config-if)# switchport private-vlan mapping 65,651,652,653&lt;br /&gt;※ Catalyst 4000 / 4500 series 는 Isolated VLAN 만 구성가능 / Community VLAN 구성 불가&lt;br /&gt;&lt;br /&gt;Cat OS에서의 PVLAN 구성 방법&lt;br /&gt;set vlan 65 pvlan-type primary&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: Pvlan Primary Vlan 생성&lt;br /&gt;set vlan 651 pvlan-type community&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: Pvlan Secondary Vlan 생성 – Community Vlan&lt;br /&gt;set vlan 652 pvlan-type isolated&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Pvlan Secondary Vlan 생성 – Isolated Vlan&lt;br /&gt;set vlan 65 651 9/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: 물리적 Port에 Secondary Vlan 할당&lt;br /&gt;set vlan 65 652 9/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 물리적 Port에 Secondary Vlan 할당&lt;br /&gt;set vlan mapping 7 651 5/11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: Promiscuous 생성 및 할당&lt;br /&gt;set vlan mapping 7 652 5/11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;Private Vlan Edge 기능&lt;br /&gt;Isolated Vlan : Protected기능을 통한 특정 Host 보호간 상호 독립 기능&lt;br /&gt;Protected와 설정되지 않은 Port간, G/W를 통한 외부 통신 가능&lt;br /&gt;&lt;br /&gt;Private VLAN edge 기능 구성 예제&lt;br /&gt;3550(config)# interface gigabitethernet0/3 &lt;br /&gt;3550(config-if)# switchport protected &lt;br /&gt;3550(config-if)# end &lt;br /&gt;3550# show interfaces gigabitethernet0/3 switchport &lt;br /&gt;Name: Gi0/3 &lt;br /&gt;Switchport: Enabled &lt;br /&gt;&amp;lt;output truncated&amp;gt;&lt;br /&gt;Protected: True &lt;br /&gt;Unknown unicast blocked: disabled &lt;br /&gt;Unknown multicast blocked: disabled &lt;br /&gt;Broadcast Suppression Level: 100 &lt;br /&gt;Multicast Suppression Level: 100 &lt;br /&gt;&lt;br /&gt;IP 변조 방지 기능 : uRPF(Unicast Reverse Path Forwarding)&lt;br /&gt;&lt;br /&gt;DHCP request flooding 공격 방어 : DHCP snooping rate limit 기능&lt;br /&gt;-&amp;gt; DHCP Scope Size 전체에 IP 할당을 요청하여, DHCP Server 과부하 발생 시킴&lt;br /&gt;DHCP Request Flooding 공격 방어 구성 예제.&lt;br /&gt;Switch(config)# ip dhcp snooping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à DHCP Snooping enable&lt;br /&gt;Switch(config)# ip dhcp snooping vlan 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à DHCP Snooping 적용 Vlan 정의 &lt;br /&gt;Switch(config-if)# ip dhcp snooping limit rate 100(pps)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à DHCP Request 허용 수치 제한&lt;br /&gt;&lt;br /&gt;DHCP Server 위조 공격 방어 : DHCP snooping Trust 기능&lt;br /&gt;-&amp;gt; DHCP Request 에 대해, 공격자가 거짓된 정보를 전달함&lt;br /&gt;DHCP Request Flooding 공격 방어 구성 예제.&lt;br /&gt;Switch(config)# ip dhcp snooping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;à DHCP Snooping enable&lt;br /&gt;Switch(config)# ip dhcp snooping vlan 10&amp;nbsp;&amp;nbsp;à DHCP Snooping 적용 Vlan 정의 &lt;br /&gt;Switch(config-if)# ip dhcp snooping trust&amp;nbsp;&amp;nbsp;à DHCP discover, request 등 메시지를 해당 Port만 수용&lt;br /&gt;&lt;br /&gt;DHCP Snooping을 통한 MAC 변조 방지 기능 – ARP Inspection&lt;br /&gt;DHCP Snooping을 통한 IP 변조 방지 기능 – IP Source Guard&lt;br /&gt;&lt;br /&gt;-&amp;gt; ARP Inspection&lt;br /&gt;S1(config)# ip arp inspection vlan 1&lt;br /&gt;S1(config-if)# ip arp inspection trust&lt;br /&gt;S1# show ip dhcp snooping binding&lt;br /&gt;MacAddress&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IpAddress&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Lease(sec)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;VLAN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&lt;br /&gt;------------&amp;nbsp;&amp;nbsp; ---------&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-------------&lt;br /&gt;01:01:01:11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1.1.1.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4993&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;dhcp-snooping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FastEthernet6/4&lt;br /&gt;00:12:08: %SW_DAI-4-DHCP_SNOOPING_DENY: 2 Invalid ARPs (Req) on Fa6/4, vlan&lt;br /&gt;1.([01.01.01.11/1.1.1.22/0000.0000.0000/0.0.0.0/02:42:35 UTC Tue Jul 10 2001])&lt;br /&gt;&lt;br /&gt;-&amp;gt; IP Source Guard 구성&lt;br /&gt;Switch(config)# ip dhcp snooping&lt;br /&gt;Switch(config)# ip dhcp snooping vlan 10 20&lt;br /&gt;Switch(config-if)# no ip dhcp snooping trust&lt;br /&gt;Switch(config-if)# ip verify source vlan dhcp-snooping port-security&lt;br /&gt;Switch(config)# ip source binding ip-addr ip vlan number interface interface&lt;br /&gt;Switch# sh ip verify source interface f6/1&lt;br /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter-type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Filter-mode&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IP-address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mac-address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Vlan&lt;br /&gt;-------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-----------&amp;nbsp;&amp;nbsp;-----------&amp;nbsp;&amp;nbsp;-------------&amp;nbsp;&amp;nbsp;-------&lt;br /&gt;Fa6/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ip-mac&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;active&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1 10&lt;br /&gt;Fa6/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ip-mac&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;active&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; deny-all&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11-20&lt;br /&gt;&lt;br /&gt;Packet filtering을 위한 ACL의 이해 – Nachi Worm 취약점 Blocking &lt;br /&gt;일반적인 ACL 정의&lt;br /&gt;Switch(config)#ip access-list extended worm_block&lt;br /&gt;Switch(config)# deny tcp any any 135&lt;br /&gt;Switch(config)# deny tcp any any 139&lt;br /&gt;Switch(config)# deny tcp any any 445&lt;br /&gt;Switch(config)# deny tcp any any 4444&lt;br /&gt;Switch(config)# deny tcp any any 707&lt;br /&gt;Switch(config)# deny udp any any 69&lt;br /&gt;Switch(config)# deny icmp any any echo&amp;nbsp;&amp;nbsp; &lt;br /&gt;Switch(config)# deny icmp any any echo-reply&lt;br /&gt;Switch(config)# permit ip any any&lt;br /&gt;à ICMP Echo Service 막을 경우 network 진단 방법이 어려워지므로,&amp;nbsp;&amp;nbsp;PBR을 권고&lt;br /&gt;&lt;br /&gt;Vlan AccessMap 정의&lt;br /&gt;Switch(config) #vlan access-map worm_vacl 10&lt;br /&gt;Switch(config)#match ip address worm_block à 앞서 정의된 일반적인 ACL을 불러들임&lt;br /&gt;Switch(config)#action forward &lt;br /&gt;à 일반적인 ACL에 정의된 내용에 대한 부분은 모두 Drop 해당 Vlan Interface에 적용&lt;br /&gt;Switch(config)#vlan filter worm_vacl vlan-list 100 - 150 &lt;br /&gt;à VACL이 적용될 해당 Vlan을 선언해 주는 부분&lt;br /&gt;&lt;br /&gt;-&amp;gt; Catalyst OS를 통한 VACL 구성 방법&lt;br /&gt;Vlan 기반 ACL 정의&lt;br /&gt;set security acl ip VACL deny udp any eq 4444 any &lt;br /&gt;set security acl ip VACL deny udp any any eq 4444 &lt;br /&gt;set security acl ip VACL deny tcp any eq 135 any &lt;br /&gt;set security acl ip VACL deny tcp any any eq 135 &lt;br /&gt;à Blaster Worm 관련 config&lt;br /&gt;set security acl ip VACL deny tcp any eq 707 any &lt;br /&gt;set security acl ip VACL deny tcp any any eq 707&lt;br /&gt;à Nachi worm 관련 config&lt;br /&gt;set security acl ip VACL permit ip any any &lt;br /&gt;à Worm을 제외한 모든 traffic permit&lt;br /&gt;정의된 VACL을 해당 Vlan에 적용&lt;br /&gt;commit security acl VACL&lt;br /&gt;set security acl map VACL &amp;lt;적용하고자 하는 VLAN번호&amp;gt;&lt;br /&gt;VACL 해제 방법&lt;br /&gt;clear security acl VACL&lt;br /&gt;commit secuirty acl VACL&lt;br /&gt;&lt;br /&gt;유연한 ACL 구성 – Time Based ACL&lt;br /&gt;“ MSN Messenger 를 Work Time에만 사용토록 설정 “&lt;br /&gt;“ 주말에는 모든 시간대에 사용토록 설정 “&lt;br /&gt;Router#sh clock&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;- 현재 라우터 또는 스위치의 시간 설정 확인&lt;br /&gt;16:58:53.719 KST Sat Nov 1 2003&lt;br /&gt;Time-Based ACL 구성 방법&lt;br /&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip any 207.46.104.0 0.0.0.255&amp;nbsp;&amp;nbsp;time-range msn&lt;br /&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; tcp any any eq 1863 time-range msn&lt;br /&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; tcp any any range 6891 6900 time-range msn&lt;br /&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; udp any any eq 6901 time-range msn&lt;br /&gt;access-list 101 permit ip any any&amp;nbsp;&lt;br /&gt;&lt;br /&gt;ACL 적용&lt;br /&gt;interface fastethernet 0 --&amp;gt; 내부 이더넷&lt;br /&gt;ip access-group 101 in&lt;br /&gt;Time Rule 설정&lt;br /&gt;Router(config)#time-range msn&lt;br /&gt;Router(config-time-range)#periodic weekdays 09:00 to 18:00&amp;nbsp;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; 월요일 부터 금요일 까지 매일 아침 9시 부터 저녁 6시 까지만 적용&lt;br /&gt;&amp;nbsp;&amp;nbsp;정상 작동 확인&lt;br /&gt;Router#sh access-lists&lt;br /&gt;Extended IP access list 101&lt;br /&gt;deny ip any 207.46.104.0 0.0.0.255 time-range msn (inactive)&lt;br /&gt;--&amp;gt; 현재 시각이 토요일 이므로 자동 비활성&lt;br /&gt;deny tcp any any eq 1863 time-range msn (inactive)&lt;br /&gt;deny tcp any any range 6891 6900 time-range msn (inactive)&lt;br /&gt;deny udp any any eq 6901 time-range msn (inactive)&lt;br /&gt;permit ip any any &lt;br /&gt;&lt;br /&gt;Catalyst 4500 에서의 QoS를 통한 TCP Synflood Attack 방어 요령&lt;br /&gt;qos aggregate-policer limit 32000 bps 4000 byte conform-action transmit exceed-action drop &lt;br /&gt;qos&lt;br /&gt;!&lt;br /&gt;class-map match-all c_syn&lt;br /&gt;match access-group 101&lt;br /&gt;!&lt;br /&gt;policy-map p_syn&lt;br /&gt;&amp;nbsp;&amp;nbsp;class c_syn&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;police aggregate limit&lt;br /&gt;!&lt;br /&gt;interface FastEthernet4/34&lt;br /&gt;switchport access vlan 45&lt;br /&gt;switchport mode access&lt;br /&gt;qos vlan-based&lt;br /&gt;!&lt;br /&gt;interface Vlan45&lt;br /&gt;ip address 10.10.45.2 255.255.255.0&lt;br /&gt;service-policy input p_syn&lt;br /&gt;!&lt;br /&gt;ip classless&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 10.10.45.1&lt;br /&gt;no ip http server&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;ip access-list extended syn_acl&lt;br /&gt;permit tcp any any syn&lt;br /&gt;!&lt;br /&gt;access-list 101 permit tcp any any syn&lt;br /&gt;&lt;br /&gt;잠재적인 공격 대비 QoS 구성 : Cat6500 Policing&lt;br /&gt;mls qos &lt;br /&gt;-&amp;gt; mls QoS enable&lt;br /&gt;access-list 113 permit icmp any any echo&lt;br /&gt;access-list 113 permit icmp any any echo-reply&lt;br /&gt;-&amp;gt; icmp attack marking&lt;br /&gt;access-list 111 permit tcp any any eq 135&lt;br /&gt;access-list 111 permit tcp any any eq 4444&lt;br /&gt;access-list 111 permit tcp any any eq 707&lt;br /&gt;access-list 111 permit udp any any eq 69&lt;br /&gt;-&amp;gt; Blaster worm,Nachi worm marking&lt;br /&gt;access-list 112 permit tcp any any syn&lt;br /&gt;-&amp;gt; syn flooding attack 방어 marking&lt;br /&gt;access-list 101 permit tcp any any syn&lt;br /&gt;-&amp;gt; syn flooding attack 방어 marking&lt;br /&gt;&lt;br /&gt;해당 Class-map 정의 &lt;br /&gt;class-map match-all icmp_attack&lt;br /&gt;&amp;nbsp;&amp;nbsp;match access-group 113&lt;br /&gt;class-map match-all Blaster_0815_attack&lt;br /&gt;&amp;nbsp;&amp;nbsp;match access-group 112&lt;br /&gt;class-map match-all Blaster_Nachi&lt;br /&gt;&amp;nbsp;&amp;nbsp;match access-group 111&lt;br /&gt;각 Class에 해당되는 ACL 포함시킴&lt;br /&gt;&lt;br /&gt;policy-map QoS&lt;br /&gt;&amp;nbsp;&amp;nbsp;class icmp_attack&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;police 32000 1000 1000 conform-action transmit exceed-action drop violate-action drop&lt;br /&gt;&amp;nbsp;&amp;nbsp;class Blaster_0815_attack&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;police 32000 1000 1000 conform-action transmit exceed-action drop violate-action drop&lt;br /&gt;&amp;nbsp;&amp;nbsp;class Blaster_Nachi&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;police 32000 1000 1000 conform-action transmit exceed-action drop violate-action drop&lt;br /&gt;-&amp;gt; 각 Class 모두 32Kbps 이상이면 모두 Drop 시킴&lt;br /&gt;&lt;br /&gt;set qos enable&lt;br /&gt;&amp;nbsp;&amp;nbsp;à QoS 활성화 시키기&lt;br /&gt;set qos policer aggregate policer_worm rate 32 policed-dscp erate 32 drop burst 4 eburst 4 &lt;br /&gt;&amp;nbsp;&amp;nbsp;à 32Kbps 이상 worm에 관련된 ACL이 들어올 경우 Drop 시킨다.&lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm tcp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;eq 135 &lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm tcp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;eq 4444 &lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm tcp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;eq 707 &lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm udp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;eq 69 &lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm icmp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;echo &lt;br /&gt;set qos acl ip worm dscp 8 aggregate policer_worm icmp any&amp;nbsp;&amp;nbsp;any&amp;nbsp;&amp;nbsp;echo-reply&lt;br /&gt;à Blaster worm, Nachi worm,ICMP Attack 관련 정의&lt;br /&gt;&lt;br /&gt;활성화 및 적용/해제/Monitoring&lt;br /&gt;commit qos acl worm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à QoS ACL 활성화&lt;br /&gt;set qos acl map worm 100 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à 적용하고자 하는 Vlan or Interface 적용&lt;br /&gt;&lt;br /&gt;Clear qos acl worm&lt;br /&gt;Commit qos acl worm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; à QoS 해제 &lt;br /&gt;Cat6500&amp;gt; (enable) sh qos statistics aggregate-policer policer_worm&lt;br /&gt;QoS aggregate-policer statistics:&lt;br /&gt;Aggregate policer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Allowed packet Packets exceed Packets exceed&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;normal rate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;excess rate&lt;br /&gt;------------------------------- -------------- -------------- --------------&lt;br /&gt;policer_worm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 268&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&lt;br /&gt;à 해당 QoS 에 적용되어 Drop 되는 packet monitoring&lt;br /&gt;&lt;br /&gt;NBAR(Network Based Application Recognition) – 어플리케이션 레벨의 특정 서비스 인지&lt;br /&gt;※ Virus Pattern 인식 –&amp;nbsp;&amp;nbsp;Code Red, Nimda&lt;br /&gt;-&amp;gt; 인지 후 DSCP Marking을 통해 Drop Action 가능&lt;br /&gt;※ 다양한 Service Protocol 인식을 통한 통계 분석 가능&lt;br /&gt;※ Core Router/Switch 구간의 NBAR Enable을 통한 P2P 통계치 분석 가능 &lt;br /&gt;-&amp;gt; MIB 지원, QPM, QDM 을 통한 GUI 환경의 사용자 기반 관리 도구 제공&lt;br /&gt;&lt;br /&gt;DoS 방어를 위한 CAR Rate Limiting&lt;br /&gt;※ Limit outbound ping to 256 Kbps &lt;br /&gt;interface xy &lt;br /&gt;rate-limit output access-group 102 256000 8000 8000&lt;br /&gt;conform-action transmit exceed-action drop &lt;br /&gt;!&lt;br /&gt;access-list 102 permit icmp any any echo&lt;br /&gt;access-list 102 permit icmp any any echo-reply&lt;br /&gt;※ Limit inbound TCP SYN packets to 8 Kbps&lt;br /&gt;interface xy &lt;br /&gt;rate-limit input access-group 103 8000&amp;nbsp;&amp;nbsp;8000 8000&lt;br /&gt;conform-action transmit exceed-action drop &lt;br /&gt;!&lt;br /&gt;access-list 103 permit tcp any any syn&lt;br /&gt;&lt;div style="margin: 15px 0px 0px;"&gt;출처 : &lt;a href="http://tong.nate.com/boxitem/post.do?action=read&amp;amp;_boxID=2592282&amp;amp;_tongID=1104853&amp;amp;_boxItemID=37196881&amp;amp;_reloadTag=y" target="_blank" title="제목 부분을 클릭하면원 게시물을 볼 수 있습니다."&gt;Tong - eelee777님의 network통&lt;/a&gt;&lt;/div&gt;네이트 통 이제 서비스 안하네요.&lt;br /&gt;자료 저장도 못했는데.... 다른분이 복사해간걸 다시 복사..^^ by&amp;nbsp; 파란 - 천사&lt;br /&gt;&lt;script&gt;function hrefMark(){ }function hrefPageGo(mark){ try{  if(mark == 'top'){   parent.window.scrollTo(0,0);  }else{   document.location.href=this.location.href+"#comment";  } }catch(e){}}//포스트 글로딩후 top포커수 주기setTimeout('hrefPageGo("top")',300);&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/566025169101662036-6900427315035834472?l=thinkplay.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thinkplay.blogspot.com/feeds/6900427315035834472/comments/default' title='댓글'/><link rel='replies' type='text/html' href='http://thinkplay.blogspot.com/2011/02/router.html#comment-form' title='0개의 덧글'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/566025169101662036/posts/default/6900427315035834472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/566025169101662036/posts/default/6900427315035834472'/><link rel='alternate' type='text/html' href='http://thinkplay.blogspot.com/2011/02/router.html' title='Router 보안 - 안전한 라우터 운영을 위한 튜닝 전체공개'/><author><name>Pete</name><uri>http://www.blogger.com/profile/11210091684240727558</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
