<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>sddlzz's Blog In WordPress</title>
	<atom:link href="http://sddlzz.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://sddlzz.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 30 Dec 2005 12:30:34 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='sddlzz.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>sddlzz's Blog In WordPress</title>
		<link>http://sddlzz.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://sddlzz.wordpress.com/osd.xml" title="sddlzz&#039;s Blog In WordPress" />
	<atom:link rel='hub' href='http://sddlzz.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Google Search Tips</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/google-search-tips/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/google-search-tips/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 16:16:09 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
		
		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/google-search-tips/</guid>
		<description><![CDATA[After reading a thread on Digital Point, I realized that a lot of people still donï¿½ï¿½t know about all the Google Operator commands. This list will help you control your Google search. There are a few more commands out there, but these are the ones I find most usefulï¿½ï¿½ feel free to add your own [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=37&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After reading a thread on Digital Point, I realized that a lot of people still donï¿½ï¿½t know about all the Google Operator commands. This list will help you control your Google search. There are a few more commands out there, but these are the ones I find most usefulï¿½ï¿½ feel free to add your own in the comments.</p>
<p>link:www.yoursite.com &#8211; This command will show you all of the backlinks to your site. Handy tool for finding out who is linking to you.</p>
<p>related:www.yoursite.com &#8211; This command will show you a list of pages that Google thinks are related to your site in some way.</p>
<p>site:www.yoursite.com &#8211; Searches only those pages from the site you list.</p>
<p>allinurl: &#8211; If you start a query with [allinurl:], Google will restrict the results to those with all of the query words in the url. For instance, [allinurl: google search] will return only documents that have both ï¿½ï¿½googleï¿½ï¿½ and ï¿½ï¿½searchï¿½ï¿½ in the url.</p>
<p>define: &#8211; The query [define:] will provide a definition of the words you enter after it, gathered from various online sources. The definition will be for the entire phrase entered (i.e., it will include all the words in the exact order you typed them).</p>
<p>inurl: &#8211; If you include [inurl:] in your query, Google will restrict the results to documents containing that word in the url. For instance, [inurl:google search] will return documents that mention the word ï¿½ï¿½googleï¿½ï¿½ in their url, and mention the word ï¿½ï¿½searchï¿½ï¿½ anywhere in the document (url or no). Note there can be no space between the ï¿½ï¿½inurl:ï¿½ï¿½ and the following word.</p>
<p>allintitle: &#8211; If you start a query with [allintitle:], Google will restrict the results to those with all of the query words in the title. For instance, [allintitle: google search] will return only documents that have both ï¿½ï¿½googleï¿½ï¿½ and ï¿½ï¿½searchï¿½ï¿½ in the title.</p>
<p>intitle: &#8211; If you include [intitle:] in your query, Google will restrict the results to documents containing that word in the title. For instance, [intitle:google search] will return documents that mention the word ï¿½ï¿½googleï¿½ï¿½ in their title, and mention the word ï¿½ï¿½searchï¿½ï¿½ anywhere in the document (title or no). Note there can be no space between the ï¿½ï¿½intitle:ï¿½ï¿½ and the following word.</p>
<p>cache: &#8211; If you include other words in the query, Google will highlight those words within the cached document. For instance, [cache:www.subnixus.com web] will show the cached content with the word ï¿½ï¿½webï¿½ï¿½ highlighted.</p>
<p>info: &#8211; The query [info:] will present some information that Google has about that web page. For instance, [info:www.google.com] will show information about the Google homepage. Note there can be no space between the ï¿½ï¿½info:ï¿½ï¿½ and the web page url.</p>
<p>spell: &#8211; Does a spell check of any given word.</p>
<p>stocks: &#8211; If you begin a query with the [stocks:] operator, Google will treat the rest of the query terms as stock ticker symbols, and will link to a page showing stock information for those symbols. For instance, [stocks: intc yhoo] will show information about Intel and Yahoo. (Note you must type the ticker symbols, not the company name.)</p>
<p>filetype: &#8211; Does a search for a specific file type, or, if you put a minus sign (-) in front of it, it wonï¿½ï¿½t list any results with that filetype.</p>
<p>daterange: &#8211; Is supported in Julian date format only. 2452384 is an example of a Julian date.</p>
<p>maps: &#8211; Is a shortcut to do a google maps search.</p>
<p>phone: &#8211; Searches for anything that looks like a phone number.</p>
<p>allinlinks: &#8211; Searches only within links, not text or title.</p>
<p>allintext: &#8211; searches only within text of pages, but not in the links or page title.<br />dsfdsfasd</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/37/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/37/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=37&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/google-search-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>DHCP + DNS (bind) == DDNS</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/dhcp-dns-bind-ddns/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/dhcp-dns-bind-ddns/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 16:10:58 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/dhcp-dns-bind-ddns/</guid>
		<description><![CDATA[DHCP + DNS (bind) == DDNS æ‘˜è¦?Linuxæœ?åŠ¡å™¨å®žçŽ°åŠžå…¬å®¤å†…ç½‘IPåŠ¨æ€?åˆ†é…?å?Žçš„æœºå™¨å??è®¿é—®ã€‚(2004-06-21 22:11:13) By lanf, å‡ºå¤„ï¼šhttp://bbs.chinaunix.net/forum/viewtopic.php?t=344701 ä½œè€…ï¼šq1208c æˆ‘ä»¬åœ¨åŠžå…¬å®¤çš„æ—¶å€™ï¼Œæœ‰æ—¶ä¼šåŽ»è®¿é—®åˆ«çš„æœºå™¨ï¼Œå¦‚æžœæ˜¯åœ¨windowsä¸‹ï¼Œæˆ‘ä»¬å¤šæ•°æ—¶å€™ä¼šç”¨æœºå™¨å??åŽ»è®¿é—®ï¼Œå› ä¸ºnetbios/winsä¼šå¸®æˆ‘ä»¬æ?¥æŠŠ æœºå™¨å?? è½¬æˆ?IPçš„ã€‚ä¸‹é?¢ç»™å¤§å®¶ä»‹ç»?ä¸€ç§?ç”¨åŠ¨æ€?DNSæ?¥è§£æž?æœºå™¨å??çš„åŠžæ³•ã€‚ä¸?è¿‡ï¼Œä¸?æ˜¯ç”¨çš„w2kçš„DDNSï¼Œè€Œæ˜¯ç”¨çš„Linux. å‡†å¤‡ï¼šä¸€å?°ï¼ˆæˆ–ä¸¤å?°ï¼‰Linuxæœ?åŠ¡å™¨ï¼Œç”¨æ?¥å?šDHCP serverå’ŒDNS serverã€‚ä¹Ÿå?¯ä»¥æŠŠå®ƒå?šæˆ?ä¸¤å?°æœ?åŠ¡å™¨ã€‚ å®‰è£…ï¼šæœ?åŠ¡å™¨çš„å®‰è£…è¿‡ç¨‹ï¼Œè¯·å?‚è€ƒå…¶å®ƒæ–‡æ¡£ï¼Œè®°ä½?æŠŠ dhcp å’Œ bind, bind-utils è£…ä¸Šå°±è¡Œäº†ã€‚ é…?ç½®ï¼š ä¸€ã€?DHCPçš„é…?ç½®ï¼š é…?ç½®DHCP server æ—¶å¾ˆç®€å?•ï¼Œå?¯ä»¥å?‚è€ƒ /usr/share/doc/dhcp-x.xx/dhcpd.conf.sampleæ?¥å?šã€‚ä¹Ÿå?¯ä»¥å…ˆæŠŠè¿™ä¸ªæ–‡ä»¶cp åˆ° /etc/dhcpd.confï¼Œç„¶å?Žæ ¹æ?®è‡ªå·±çš„éœ€è¦?å?šé€‚å½“ä¿®æ”¹ã€‚ä¸‹é?¢è´´å‡ºæˆ‘çš„ä¸€ä¸ª/etc/dhcpd.confï¼Œä¾›å¤§å®¶å?‚è€ƒï¼š ddns-update-style interim;ignore client-updates; key DHCP_UPDATER {algorithm HMAC-MD5;secret qhB++OR5yWo8BTXwk/m4ng;}; zone bj.pnx. {primary 127.0.0.1;key DHCP_UPDATER;} zone 251.168.192.in-addr.arpa. {primary 127.0.0.1;key DHCP_UPDATER;} subnet 192.168.251.0 netmask 255.255.255.0 {range [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=35&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>
<p>DHCP + DNS (bind) == DDNS</p>
<blockquote><p><strong>æ‘˜è¦?</strong><br />Linuxæœ?åŠ¡å™¨å®žçŽ°åŠžå…¬å®¤å†…ç½‘IPåŠ¨æ€?åˆ†é…?å?Žçš„æœºå™¨å??è®¿é—®ã€‚(2004-06-21 22:11:13)</p>
</blockquote>
<hr /> <strong>By <a href="mailto:lanf%20at%20linuxaid%20dot%20com%20dot%20cn">lanf</a></strong>, å‡ºå¤„ï¼šhttp://bbs.chinaunix.net/forum/viewtopic.php?t=344701
<p> ä½œè€…ï¼šq1208c</p>
<p>æˆ‘ä»¬åœ¨åŠžå…¬å®¤çš„æ—¶å€™ï¼Œæœ‰æ—¶ä¼šåŽ»è®¿é—®åˆ«çš„æœºå™¨ï¼Œå¦‚æžœæ˜¯åœ¨windowsä¸‹ï¼Œæˆ‘ä»¬å¤šæ•°æ—¶å€™ä¼šç”¨æœºå™¨å??åŽ»è®¿é—®ï¼Œå› ä¸ºnetbios/winsä¼šå¸®æˆ‘ä»¬æ?¥æŠŠ æœºå™¨å?? è½¬æˆ?IPçš„ã€‚ä¸‹é?¢ç»™å¤§å®¶ä»‹ç»?ä¸€ç§?ç”¨åŠ¨æ€?DNSæ?¥è§£æž?æœºå™¨å??çš„åŠžæ³•ã€‚ä¸?è¿‡ï¼Œä¸?æ˜¯ç”¨çš„w2kçš„DDNSï¼Œè€Œæ˜¯ç”¨çš„Linux.</p>
<p>å‡†å¤‡ï¼šä¸€å?°ï¼ˆæˆ–ä¸¤å?°ï¼‰Linuxæœ?åŠ¡å™¨ï¼Œç”¨æ?¥å?šDHCP serverå’ŒDNS serverã€‚ä¹Ÿå?¯ä»¥æŠŠå®ƒå?šæˆ?ä¸¤å?°æœ?åŠ¡å™¨ã€‚</p>
<p>å®‰è£…ï¼šæœ?åŠ¡å™¨çš„å®‰è£…è¿‡ç¨‹ï¼Œè¯·å?‚è€ƒå…¶å®ƒæ–‡æ¡£ï¼Œè®°ä½?æŠŠ dhcp å’Œ bind, bind-utils è£…ä¸Šå°±è¡Œäº†ã€‚</p>
<p>é…?ç½®ï¼š</p>
<p>ä¸€ã€?DHCPçš„é…?ç½®ï¼š</p>
<p>é…?ç½®DHCP server æ—¶å¾ˆç®€å?•ï¼Œå?¯ä»¥å?‚è€ƒ /usr/share/doc/dhcp-x.xx/dhcpd.conf.sampleæ?¥å?šã€‚ä¹Ÿå?¯ä»¥å…ˆæŠŠè¿™ä¸ªæ–‡ä»¶cp åˆ° /etc/dhcpd.confï¼Œç„¶å?Žæ ¹æ?®è‡ªå·±çš„éœ€è¦?å?šé€‚å½“ä¿®æ”¹ã€‚ä¸‹é?¢è´´å‡ºæˆ‘çš„ä¸€ä¸ª/etc/dhcpd.confï¼Œä¾›å¤§å®¶å?‚è€ƒï¼š</p>
<table align="center" border="0" cellpadding="3" cellspacing="1" width="90%">
<tbody>
<tr>
<td>ddns-update-style interim;<br />ignore client-updates;
<p>key DHCP_UPDATER {<br />algorithm HMAC-MD5;<br />secret  qhB++OR5yWo8BTXwk/m4ng;<br />};</p>
<p>zone bj.pnx. {<br />primary 127.0.0.1;<br />key DHCP_UPDATER;<br />}</p>
<p>zone 251.168.192.in-addr.arpa. {<br />primary 127.0.0.1;<br />key DHCP_UPDATER;<br />}</p>
<p>subnet 192.168.251.0 netmask 255.255.255.0 {<br />range 192.168.251.100 192.168.251.200;<br /># â€” default gateway<br />option routers                  192.168.251.254;<br />option subnet-mask              255.255.255.0;</p>
<p>#       option nis-domain               â€œdomain.orgâ€?;<br />option domain-name              â€œbj.pnxâ€?;<br />option domain-name-servers      192.168.251.63,192.168.251.254;</p>
<p>#       option time-offset              28800;  # PRC Standard Time<br />#       option ntp-servers              192.168.251.220;<br />#       option netbios-name-servers     192.168.1.1;</p>
<p>#       range dynamic-bootp 192.168.0.128 192.168.0.255;<br />default-lease-time 21600;<br />max-lease-time 43200;</p>
<p>}</p>
</td>
</tr>
</tbody>
</table>
<p>å‡ ä¸ªè¦?æ³¨æ„?çš„åœ°æ–¹ï¼š<br />1. â€˜ddns-update-styleâ€™<br />è¿™ä¸ªå°±æ˜¯åŠ¨æ€?DNSçš„æ›´æ–°æ–¹å¼?ï¼Œæœ‰å‡ ä¸ªé€‰é¡¹ï¼Œæˆ‘ç”¨çš„æ˜¯interimï¼Œå?¯ä»¥ç”¨ man dhcpd.confæ‰¾åˆ°å?¦å¤–çš„å‡ ä¸ªé€‰é¡¹ã€‚</p>
<p>2. â€˜ignore client-updatesâ€™<br />è¿™ä¸ªé€‰é¡¹æ˜¯ä¸?å…?è®¸å®¢æˆ·æœºæ›´æ–°DNSè®°å½•ã€‚å½“ç„¶ï¼Œä¹Ÿå?¯èƒ½å…?è®¸ï¼Œä½†ä¼šæœ‰ä¸€ç‚¹é—®é¢˜ã€‚</p>
<p>3. â€˜key DHCP_UPDATERâ€™<br />è¿™ä¸ªæ˜¯æ›´æ–°DNSçš„KEYï¼Œæ˜¯å¿…é¡»çš„ã€‚å…¶ä¸­algorithm å?Žçš„æ˜¯ç”Ÿæˆ?keyçš„ç®—æ³•ï¼Œkeyçš„ç”Ÿæˆ?æ˜¯ç”¨ â€˜dnssec-keygen -a HMAC-MD5 -b 128 -n USER DHCP_UPDATERâ€™ã€‚</p>
<p>4. â€˜zoneâ€™<br />è¦?æ›´æ–°çš„zoneï¼Œå¦‚æžœæ˜¯æœ¬æœºå°±æ˜¯DNS serverï¼Œprimay å°±å†™127.0.0.1ï¼Œè¦?æ˜¯å…¶å®ƒæœºå™¨æ˜¯DNS server, å°±å†™é‚£å?°æœºå™¨çš„IPã€‚</p>
<p>åˆ«çš„éƒ½æ˜¯ä¸€èˆ¬DNSè¯¥æœ‰çš„äº†ï¼Œè¦?æ³¨æ„?çš„æ˜¯ä¸€å®šè¦?æœ‰ range é‚£ä¸€è¡Œï¼Œä¸?ç„¶å°±åˆ†ä¸?äº†IPå•¦ã€‚</p>
<p>é…?å¥½ä»¥å?Žï¼Œå?¯ä»¥å?¯åŠ¨ä¸€ä¸‹è¯•è¯•ï¼Œ service dhcpd startï¼Œå¦‚æžœæ²¡é—®é¢˜ï¼ŒæŠŠdhcpdæ”¹æˆ?å¼€æœºå°±å?¯åŠ¨ï¼Œchkconfig â€“level 2345  dhcpd onã€‚</p>
<p>äºŒã€?bind(named)çš„é…?ç½®ã€‚</p>
<p>å…³äºŽbind(named)é…?ç½®çš„æ–‡ç« æœ‰å¾ˆå¤šäº†ã€‚è¿™é‡Œå?ªæŠŠä¸Žæ™®é€šé…?ç½®ä¸?å?Œçš„åœ°æ–¹å†™å‡ºæ?¥ã€‚<br />ä¸‹é?¢ç»™æˆ‘çš„named.confä¾›å¤§å®¶å?‚è€ƒï¼š</p>
<table align="center" border="0" cellpadding="3" cellspacing="1" width="90%">
<tbody>
<tr>
<td>// generated by named-bootconf.pl
<p>options {<br />directory â€œ/var/namedâ€?;<br />/*<br />* If there is a firewall between you and nameservers you want<br />* to talk to, you might need to uncomment the query-source<br />* directive below.  Previous versions of BIND always asked<br />* questions using port 53, but BIND 8.1 uses an unprivileged<br />* port by default.<br />*/<br />//   forwarders { 192.168.1.254; };<br />// query-source address * port 53;<br />};</p>
<p>//<br />// a caching only nameserver config<br />//<br />controls {<br />inet 127.0.0.1 allow { localhost; } keys { rndckey; };<br />};</p>
<p>key DHCP_UPDATER {<br />algorithm HMAC-MD5;<br />secret qhB++OR5yWo8BTXwk/m4ng;<br />};</p>
<p>zone â€œ.â€? IN {<br />type hint;<br />file â€œnamed.caâ€?;<br />};</p>
<p>zone â€œlocalhostâ€? IN {<br />type master;<br />file â€œlocalhost.zoneâ€?;<br />allow-update { none; };<br />};</p>
<p>zone â€œ0.0.127.in-addr.arpaâ€? IN {<br />type master;<br />file â€œnamed.localâ€?;<br />allow-update { none; };<br />};</p>
<p>zone â€œ1.168.192.in-addr.arpaâ€? IN {<br />type master;<br />file â€œ1.168.192.zoneâ€?;<br />allow-update { key DHCP_UPDATER; };<br />};</p>
<p>zone â€œtest.comâ€? IN {<br />type master;<br />file â€œtest.comâ€?;<br />allow-update { key DHCP_UPDATER; };<br />};<br />include â€œ/etc/rndc.keyâ€?;</p>
</td>
</tr>
</tbody>
</table>
<p>å…¶ä¸­å¤šäº†çš„æ˜¯</p>
<table align="center" border="0" cellpadding="3" cellspacing="1" width="90%">
<tbody>
<tr>
<td>key DHCP_UPDATER {<br />algorithm HMAC-MD5;<br />secret qhB++OR5yWo8BTXwk/m4ng;<br />};</td>
</tr>
</tbody>
</table>
<p>è¿™å°±æ˜¯æ›´æ–°dnsè¦?ç”¨çš„keyï¼Œå¿…é¡»å’Œdhcpd.confé‡Œçš„ä¸€æ ·ã€‚</p>
<p>è¿˜æœ‰å°±æ˜¯æ¯?ä¸ª zone éƒ½å?¯ä»¥ç”¨ key æ?¥updateäº†ã€‚</p>
<p>è¿™æ ·å°±è¡Œäº†ã€‚ç„¶å?Žå?¯åŠ¨ä¸€ä¸‹è¯•è¯•å?§ã€‚</p>
<p>ä½ å°±å?¯ä»¥ping æœºå™¨å??æ?¥æ‰¾ä½ å?Œäº‹çš„æœºå™¨äº†ã€‚</p>
<p>æœ¬äººå?ªåœ¨windowså®¢æˆ·æœºä¸Šè¯•éªŒè¿‡ï¼ŒLinuxå¥½è±¡ä¼šæœ‰ä¸€ç‚¹é—®é¢˜ã€‚å“ªä½?æœ‰å…´è¶£ï¼Œå…±å?Œç ”ç©¶ä¸€ä¸‹ã€‚ç»™Linuxåˆ†é…?çš„IPéƒ½ã€€æ˜¯æ²¡æœ‰ä¸»æœºå??çš„ã€‚   å› ä¸ºæˆ‘çš„å®¢æˆ·æœºéƒ½æ˜¯windowsçš„ï¼ŒLinuxçš„æˆ‘éƒ½ç”¨é?™æ€?IPã€‚<br /><strong> hongfengyue çš„è¡¥å……</strong><br />å½“å®¢æˆ·ç«¯æ˜¯linuxæ—¶ï¼Œéœ€è¦?åœ¨linuxå®¢æˆ·ç«¯ç¼–è¾‘ä¸€ä¸ªæ–‡ä»¶/etc/dhclient.confDNSæ‰?èƒ½æ›´æ–°ï¼Œä¸?ä¿¡ä½ å?¯ä»¥çœ‹çœ‹/var/lib/dhcp/çš„æ–‡ä»¶çš„å†…å®¹ï¼Œå®¢æˆ·ç«¯åˆ†é…?çš„IPæ²¡æœ‰Hostnameçš„è®°å½•ã€‚<br />æˆ‘çš„/etc/dhclient.confå†…å®¹å¦‚ä¸‹ï¼š</p>
<table border="1" cellpadding="5" cellspacing="0" width="100%">
<tbody>
<tr>
<td>
<pre>send fqdn.fqdn "hostname";send fqdn.encoded on;send fqdn.server-update off;</pre>
</td>
</tr>
</tbody>
</table>
<p>ä½†æ˜¯æˆ‘åœ¨Redhat8&amp;9ä¸­è¿˜æ˜¯ä¸?è¡Œï¼Œå?ªæœ‰åœ¨/etc/rc.d/rc.localä¸­åŠ å…¥ä¸‹é?¢çš„å‘½ä»¤ï¼š<br />/sbin/dhclient<br />æ³¨æ„?å¿…é¡»åœ¨/sbinå­˜åœ¨è¿™ä¸ªå?¯æ‰§è¡Œçš„æ–‡ä»¶ã€‚æˆ‘çŸ¥é?“åœ¨redhatä¸­æ˜¯å­˜åœ¨çš„ã€‚ </p>
</p></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/35/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/35/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=35&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/dhcp-dns-bind-ddns/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>activate tun device in linux</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/activate-tun-device-in-linux/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/activate-tun-device-in-linux/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 16:08:25 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
		
		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/activate-tun-device-in-linux/</guid>
		<description><![CDATA[Even if you enabled the TUN/TAP module in the kernel you have to: - mkdir /dev/net- mknod /dev/net/tun c 10 200 (Linux kernel 2.4.x) This is documented in install.html at the homepage. greetings christoph Kai Dittmann schrieb: Am Do, den 15.04.2004 schrieb Mike Dickson um 19:45: Also, forgot to mention that the tun stuff is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=33&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>
<pre>Even if you enabled the TUN/TAP module in the kernel you have to:</pre>
<p>
<pre>- mkdir /dev/net- mknod /dev/net/tun c 10 200  (Linux kernel 2.4.x)</pre>
<p>
<pre>This is documented in install.html at the homepage.</pre>
<p>
<pre>greetings</pre>
<p>
<pre>christoph</pre>
<p>
<pre>Kai Dittmann schrieb:</pre>
<p>
<pre>Am Do, den 15.04.2004 schrieb Mike Dickson um 19:45:</pre>
<p>
<blockquote>
<pre>Also, forgot to mention that the tun stuff is compiled directly intothe kernel:</pre>
<p>
<pre>CONFIG_NET_IPIP=y</pre>
<p>or</p>
<p>&lt; *&gt; IP: tunneling</p></blockquote>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/33/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/33/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/33/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=33&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/activate-tun-device-in-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title></title>
		<link>http://sddlzz.wordpress.com/2005/12/24/flash%e7%bd%91%e9%a1%b5%e5%8f%98%e9%87%8f/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/flash%e7%bd%91%e9%a1%b5%e5%8f%98%e9%87%8f/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 16:06:27 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/flash%e7%bd%91%e9%a1%b5%e5%8f%98%e9%87%8f/</guid>
		<description><![CDATA[åœ¨flashä¸­å®šä¹‰ä¸€ä¸ªå?˜é‡?ï¼Œä¾‹å¦‚theurlï¼Œ æŒ‰é’®ä¸Šå†™ on (release) { _root.getURL(theurl); } åœ¨htmlé¡µé?¢ä¸­ï¼Œç”¨flashVarså?‚æ•°å?¯ä»¥ç»™flashé‡Œé?¢çš„å?˜é‡?èµ‹å€¼ï¼š<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=31&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>åœ¨flashä¸­å®šä¹‰ä¸€ä¸ªå?˜é‡?ï¼Œä¾‹å¦‚theurlï¼Œ æŒ‰é’®ä¸Šå†™ on (release) { _root.getURL(theurl); }  åœ¨htmlé¡µé?¢ä¸­ï¼Œç”¨flashVarså?‚æ•°å?¯ä»¥ç»™flashé‡Œé?¢çš„å?˜é‡?èµ‹å€¼ï¼š</pre>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/31/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/31/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=31&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/flash%e7%bd%91%e9%a1%b5%e5%8f%98%e9%87%8f/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>Running qmail under Gentoo Linux</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/running-qmail-under-gentoo-linux/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/running-qmail-under-gentoo-linux/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 16:04:56 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
		
		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/running-qmail-under-gentoo-linux/</guid>
		<description><![CDATA[Running qmail under Gentoo Linuxby Kris Kelley NOTE: This guide was written for use with qmail ebuild 1.03-r13. The currentstable qmail ebuild is 1.03-r15. Several other ebuilds mentioned in thisdocumentation also have been updated since the last revision. Unfortunately,I do not expect to update this guide again any time soon, if ever. I nolonger work [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=32&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre>Running qmail under Gentoo Linuxby Kris Kelley

NOTE:  This guide was written for use with qmail ebuild 1.03-r13.  The currentstable qmail ebuild is 1.03-r15.  Several other ebuilds mentioned in thisdocumentation also have been updated since the last revision.  Unfortunately,I do not expect to update this guide again any time soon, if ever.  I nolonger work as an email system administrator, I no longer have qmail running onany of my systems, and my time away from work is now devoted to other projects.The good news is that the Gentoo website now has Gentoo-specific documentationabout qmail and its related software packages.  I now recommend using theofficial documentation, as well as the Gentoo forums and the qmail mailinglist.

This guide will remain available at its original URL(http://www.skunkworx.org/guides/QmailOnGentoo.txt), for reference.  Also, foranybody who might wish to adapt and/or update this guide, I am making itavailable under the Creative Commons Attribution-ShareAlike 2.0 license;details are available at the license website(http://creativecommons.org/licenses/by-sa/2.0/).

I would like to thank everyone who provided constructive criticism and words ofencouragement while I was actively maintaining this guide.  I still believeqmail is the best email server program out there, for any platform, and I hopethe qmail and Gentoo communities continue to thrive.

Introduction

This document gives instructions on how to install, configure, and run qmail ona system running Gentoo Linux.  I originally wrote this after I could not findany qmail documentation specific to Gentoo, despite Gentoo offering packages(or "ebuilds", to use Gentoo's terminology) for qmail and related software.

You are probably not reading this if you are not familiar with Gentoo Linux,but just in case, Gentoo is a relatively new distribution that aims at strikinga compromise between the convenience and compatibility of a linux installationbased on ready-made software packages, and the power and configurability of alinux installation built from source.  For more details, visit Gentoo's website(http://www.gentoo.org).  Gentoo's promise of being able to tailor softwareexactly to a system's specifications, while at the same time having a packagemanager easily keep track of it all, is what attracted me to this distribution,to say nothing of the recommendations I received from friends and coworkers.

You are probably also not reading this if you have not heard of qmail, but tobe thorough, Daniel J. Bernstein's qmail is an email server software package,providing the same general functionality of packages like Sendmail or ssmtp.qmail is undebatably the most secure email server software available forUnix-compatible operating systems, and I would argue that it is the most secureemail server software period.  qmail also provides plenty of configurability,enough to suit the needs of almost any email-related task.  The fact that qmailhas not had an official release since 1997, and yet continues to grow inpopularity without a single security alert, is testimony of its quality.  qmailis not for the faint of heart, however.  Even with a versatile package managerlike Gentoo's Portage, qmail requires some manual intervention, not to mentionfirm knowledge of what you are doing, to run optimally.

Things to Know before Starting

These instructions were written using Gentoo Linux 1.4, installed followingthe distributors' instructions, and the qmail ebuild provided by Gentoothrough its package manager, Portage.  As of this writing, the recommendedGentoo ebuild for qmail is 1.03-r13.  There may be instructions here that arespecific to these versions; in particular, earlier versions of the qmailebuild are significantly different from 1.03-r13, and I do not recommendtrying to use this guide with them.  Also, Gentoo and Portage are highlycustomizable, and experienced Gentoo users who have heavily tweaked theirsystems may find these instructions completely off base.

The qmail ebuild is modeled on the process prescribed by "Life with qmail"(LWQ, http://www.lifewithqmail.org), written by Dave Sill.  LWQ is *required*reading; the instructions given here mostly highlight the differences betweenLWQ and the qmail ebuild, as well as the manual steps needed to completeqmail's installation and configuration.

Gentoo's qmail ebuild includes several patches to the original source code.These patches fix minor, non-critical bugs, and also provide additionalfeatures not present in the author's distribution of qmail 1.03, such as theability to encrypt SMTP sessions with SSL, and the ability to authenticatesessions with passwords unique to each user on your system.

(NOTE:  The current version of LWQ makes use of a package called netqmail.netqmail 1.05 is a patched version of qmail 1.03.  Bugs and incompatibilitiesfixed by netqmail 1.05 are also fixed by Gentoo's 1.03-r13 ebuild for qmail,and therefore LWQ is still an essential source of information, even for Gentoousers.)

IMPORTANT:  qmail, as well as any software package written in the Cprogramming language, relies on a package called glibc to provide the basicC function libraries.  As of this writing, Gentoo's recommended glibc ebuildis version 2.3.2-r9.  Because of an old coding method that is no longersupported by the authors of glibc, all qmail ebuilds older than 1.03-r10 (aswell as the unpatched source code for qmail 1.03) ARE NOT COMPATIBLE with anyebuilds based on glibc 2.3.2!  To ensure smooth installation, make sure youare using the latest unmasked ebuilds of qmail and all software packagesqmail depends on (including daemontools, ucspi-tcp, checkpassword,cmd5checkpw, dot-forward, and queue-fix; more information about these packagesis provided below.)

Part One - Configuring Gentoo to Allow qmail's Installation

Before you can install qmail, you may need to configure Gentoo to allow youto do so.  This requires knowing a few things about Gentoo and Portage.

One of Portage's features is the ability to keep track of "virtual" packages.Virtual packages are not specific software packages, but are definitionsthat can be matched by any Gentoo ebuild claiming to do so.  When you install(or "merge") an ebuild that matches the definition of a virtual package,Portage considers that virtual package present on your system.

Gentoo keeps a list of default ebuilds it will use to satisfy virtual packageneeds.  An ebuild from this list is merged whenever the associated virtualpackage is requested and a matching ebuild is not already present.  Many ofthese ebuilds are added to the system during Gentoo's initial set-up.

Much of Gentoo's behavior is governed by a set of configuration filescollectively known as a "profile."  Included in a profile is the default listfor satisfying virtual package requirements.  Regardless of what profile youuse, you can look at the associated files in /etc/make.profile.  Editingthese files is not a good idea, unless you are planning on building your ownprofiles for distribution.

Besides the default list supplied by a profile, Gentoo also keeps a list ofvirtual packages actually present on your system, and the ebuilds thatrepresent those virtual packages.  Gentoo keeps this list in the file/var/cache/edb/virtuals.  Whenever you merge an ebuild that satisfies therequirements for a virtual package, that virtual package's entry is createdor updated in /var/cache/edb/virtuals.

Gentoo ebuilds can be designed to block their own installation if they wouldconflict with other software already present on the system.  These blocks canbe based on virtual packages as well as specific ebuilds.

Gentoo controls the presence of an email server (or, more accurately, a "mailtransfer agent") with the virtual package "virtual/mta".  Gentoo's qmail ebuildis a virtual/mta package, but of course it is not the only one.  If youfollowed all instructions for installing Gentoo, ssmtp will be present on yoursystem, and will be listed in /var/cache/edb/virtuals.  Because most systemsreally only need one mail transfer agent, the ebuilds for ssmtp, qmail, andother MTAs will block installation if a virtual/mta package is already present.

So, if ssmtp or some other virtual/mta package is already installed on yoursystem, you will need to allow qmail to be installed on your system.  There aretwo good ways of doing this:

1.  Uninstall the virtual/mta package currently on your system.  Anyconfiguration you may have performed to run the current MTA on yoursystem, such as having it start automatically during system boot, willneed to be undone prior to removal.

2.  Edit the qmail ebuild script to remove the virtual/mta block.  Forversion 1.03-r13, the ebuild script is usually kept at/usr/portage/net-mail/qmail-1.03-r13.ebuild.  The edit involves findingthe two lines that look like this:

RDEPEND="!virtual/mtavirtual/glibc

and replacing them with this one line:

RDEPEND="virtual/glibc

#2 is the recommended choice, as other components of your system may complainabout the sudden lack of a virtual/mta package.  It is safe to keep yourcurrent MTA while installing and configuring qmail, as long as you do not tryto run both MTAs at the same time.

Once you have removed any currently installed virtual/mta packages, or havemodified the qmail ebuild script, you will be ready to install qmail.

IMPORTANT:  Before you can emerge qmail and related ebuilds, you must alsohave the right system users and groups on your system.  You will need usersnamed "alias", "qmaild", "qmaill", "qmailq", "qmailr", and "qmails", and groupsnamed "nofiles" and "qmail".  Also, the alias user's home directory must be setto /var/qmail/alias.  Normally this is all taken care of during Gentoo'sinstallation, specifically, when the baselayout package is emerged.  If youhave since edited your users and groups files, removing entries you believedwere unnecessary, make sure you have the right users and groups beforeproceeding!

Part Two - Installing and Configuring qmail and Related Software

Thanks to Portage and the "emerge" command, all of the software required forrunning qmail is installed with a single command.  However, keep in mind thatthe authors of Gentoo recommend you always run emerge with the "pretend" flagprior to installing any new packages, so that you know for certain what isabout to be installed on your system.

# emerge -p qmail

These are the packages that I would merge...

(NOTE:  The 1.03-r13 qmail ebuild uses one USE flag, "ssl".  You must set thisUSE flag, either in /etc/make.conf or in your shell's USE environmentvariable, if you want to install qmail with encrypted SMTP support.  Moreinformation about encrypted SMTP is in appendix B.5)

Depending on what you already have available, you will see a number ofebuilds that Portage would merge along with qmail.  Most likely you will see"ucspi-tcp", "daemontools", "dot-forward", "checkpassword", "cmd5checkpw", and"queue-fix" in this list.  Except for "cmd5checkpw" and "queue-fix", these areadditional tools written by Bernstein, designed to provide a stable, easilyconfigurable environment for qmail.  "ucspi-tcp" and "daemontools" inparticular are required packages for a qmail installation that conforms to LWQ,and Gentoo's default configuration appropriately defines qmail as dependent onthese packages.

(NOTE:  "cmd5checkpw" is used to offer authenticated SMTP; see appendix B.3 formore information.  "queue-fix" is used to initially create the qmail queue,that is, the folders qmail uses to temporarily store email that is beingprocessed; it can also be used to repair or recreate the queue when needed.)

Once you are satisfied in knowing what is going to be added to your system,run emerge again without the "pretend" flag.

# emerge qmail

When this command finishes, the system will be almost ready.  Portage not onlyinstalls qmail and all related software, but also performs a number ofnecessary system configurations, and installs several scripts documented in LWQ.

Gentoo's qmail ebuild includes an option that allows for some additionalautomatic configuration.  In fact, this extra configuration will be enough forqmail to run securely and effectively on many systems.  However, while Irecommend taking advantage of this option to prevent any security checkpointsfrom being accidentally overlooked, this feature should not be considered asubstitute for following the rest of this guide, especially if qmail is to beused in a production environment.  To perform the additional automaticconfiguration, run this command:

# ebuild /var/db/pkg/net-mail/qmail-1.03-r13/qmail-1.03-r13.ebuild config

If run, the above command will look up the machine's fully qualified domainname, and set up qmail to treat as local any email bound for this namespecifically.  For example, if the fully qualified domain name ismachine.example.com, qmail will process for local delivery any email bound foraddresses ending in "@machine.example.com" (but not "@example.com").  qmailwill also be set up to allow SMTP (mail transport) connections from anywhere.For local connections, all email will be accepted, and any email notdestined for local delivery will be directed (or "relayed") to the appropriatedestination.  For all other connections, only email destined for local deliverywill be accepted.  These configurations may not be exactly what you want, socontinue reading to learn how to configure qmail to suit your needs.

(NOTE:  Running the above ebuild command will also generate a self-signed SSLcertificate for use with encrypted SMTP.  See appendix B.5 for moreinformation.  If you plan on making use of encrypted SMTP, first edit/var/qmail/control/servercert.cnf, particularly the values in the "req_dn"section, before running the above ebuild command.  This will ensure your newSSL certificate contains the correct information for your system.  Rememberthat qmail needs to be emerged with the "ssl" USE flag for encrypted SMTP towork.)

From this point, follow LWQ starting with section 2.7.  Refer to theinstructions below for Gentoo-specific notes related to each section.

2.7.  daemontools has already been installed by Portage by this point,however, the daemontools ebuild does not change /etc/inittab.  Instead,the ebuild provides an rc script for svscan in /etc/init.d.  To ensurethat svscan will start during system boot, use Gentoo's rc-update commandto link the svscan rc script within the appropriate runlevel directoryor directories.  If you plan on running qmail from the default runlevel,enter this command:

rc-update add svscan default

Note that starting svscan from an rc script does not protect it fromunexpected termination.  If you would like to take advantage of init'sability to recreate processes that have died, do *not* use Gentoo's rcscript for svscan.  Instead, edit /etc/inittab, adding this line:

SV:12345:respawn:/usr/bin/svscanboot

Note that the ebuild uses a different directory for daemontools'executables than the author's original package.

2.8.1.  The qmail ebuild supplies a /var/qmail/rc script and a/var/qmail/control/defaultdelivery control file similar to the onesgiven in LWQ.  In the Gentoo ebuild versions, comments are allowed in/var/qmail/control/defaultdelivery; any line starting with "#" will beignored.

The ebuild configures qmail to use maildirs, however, note that the name ofeach user's maildir directory is slightly different than that given in LWQ(".maildir/" instead of "Maildir/").

2.8.2.1.  The qmail ebuild does not provide the /var/qmail/bin/qmailctlscript.  Instead, a script named qmail-control is created and placed in/var/qmail/bin.  qmail-control allows for qmail's services to be stoppedand started, and for the locals and virtualdomains control files (seebelow) to be reread.  qmailctl offers the same functionality and more,providing an easy, convenient alternative to remembering several differentcommands.  So, while creating /var/qmail/bin/qmailctl as documented in thissection of LWQ is not necessary, it is highly recommended.

The comments for Red Hat Linux's chkconfig tool are not needed.  PATHdoes not have to include /usr/local/bin or /usr/local/sbin; thesedirectories are empty on a typical Gentoo system.

2.8.2.2.  Gentoo's qmail ebuild creates all the necessary supervisescripts that are documented in this section of LWQ.

/var/qmail/supervise/qmail-send/log/run and/var/qmail/supervise/qmail-smtpd/log/run, as created by the qmail ebuild,are slightly different than those given by LWQ.  The difference enables themultilog program to rotate the log files of qmail-send and qmail-smtpd whenthey reach approximately 2.5MB in size, instead of the default 100kB.

(NOTE:  See http://cr.yp.to/daemontools/multilog.html for more informationabout how multilog maintains log files.)

/var/qmail/supervise/qmail-smtpd/run as provided by the ebuild is verydifferent from the one presented in LWQ.  Generally speaking, version1.03-r13 of the qmail ebuild was designed so that qmail's functionalitycould be changed entirely with configuration files, removing the need formanipulating any qmail-related scripts or programs.  In particular,the Gentoo version of /var/qmail/supervise/qmail-smtpd/run relies on theGentoo-specific control files /var/qmail/control/conf-common and/var/qmail/control/conf-smtpd for configuring qmail's SMTP service.Editing these files is not essential for basic qmail and SMTPfunctionality, and is also not recommended for those installing qmail forthe first time.  Once you are comfortable with how qmail operates, andwould like to take advantage of features like authenticated SMTP or spamblacklisting, you can edit these configuration files to suit your needs.See appendix B for more information about editing the/var/qmail/control/conf-common and /var/qmail/control/conf-smtpdconfiguration files.

Creating the concurrencyincoming control file is optional.  You can usethis file for setting the maximum number of concurrent connections allowed,or instead edit the appropriate section of /var/qmail/control/conf-common.If neither action is taken, qmail will limit the number of possibleconcurrent incoming SMTP connections to 40.

All log files under /var/log already exist by this point, as does the/service directory.  You will need to create the symbolic links within the/service directory.  Note that qmail will *not* start automatically afterthese links are created, *unless* svscan is running (see the notes above forLWQ section 2.7).

2.8.2.3.  This section is not necessary if you used the optional "emerge"command for extra automatic configuration, described above.  Otherwise,perform the steps in this section as given.  Note that this sectionexpects you to have created the /var/qmail/bin/qmailctl script given in LWQsection 2.8.2.1.

2.8.3.  If you haven't done so already, now is a good time to remove anyother virtual/mta packages from your system.  For example, you can run thesecommands to remove ssmtp:

emerge -C mailbaseemerge -C ssmtp

Note that you should first undo any configuration you may have performed torun another email server on your system, such as having it startautomatically during system boot.

If qmail services began running while another virtual/mta package was stillbeing utilized, stop qmail as documented in this step.  You can use theqmail-control script to do so if you decided not to create qmailctl.

The "sendmail" symbolic links will already exist by this point.

2.8.4.  The qmail ebuild creates all of the .qmail files under/var/qmail/alias mentioned in this section.  The .qmail files are empty,which means any email bound for the affected addresses will be directed touser alias's maildir.  If this is not the behavior you want, follow LWQ'sinstructions for editing these files.

2.8.5.  Again, svscan should be running before you try to start (orrestart) qmail using qmailctl (or qmail-control).  See the notes for LWQsection 2.7 above.

2.9.  Perform these steps as given to test your new installation.

Now follow the instructions given in LWQ section 3 to fully configure qmail toyour liking.  If you performed the optional configuration discussed above, anumber of control files documented in LWQ section 3.1 will already exist bythis point:

/var/qmail/control/me/var/qmail/control/defaultdomain/var/qmail/control/plusdomain/var/qmail/control/locals/var/qmail/control/rcpthosts

Each of these files will contain a single line, the fully qualified domainname of the machine.

Gentoo's installation of qmail allows for several extra control files inaddition to those documented in LWQ section 3.1  They are described below:

Control        Default       Used by          Descriptionbadmailto      (none)        qmail-smtpd      blacklisted To addressesbadrcptto      (none)        qmail-smtpd      blacklisted To addressesconf-common    as given      various          configuration common to allof qmail's network servicesconf-pop3d     as given      qmail-pop3d      configuration specific toqmail's POP3 serviceconf-qmqpd     as given      qmail-qmqpd      configuration specific toqmail's QMQP serviceconf-qmtpd     as given      qmail-qmtpd      configuration specific toqmail's QMTP serviceconf-smtpd     as given      qmail-smtpd      configuration specific toqmail's SMTP servicemorebadrcptto  (none)        qmail-smtpd      more blacklisted To addresses

Also, regular expressions can be used in badmailfrom and badmailto.

(NOTE:  Yes, badmailto and badrcptto provide essentially the samefunctionality.  That's what happens when a lot of different patches are used tomake a program as functional and configurable as possible.)

(NOTE:  QMTP, the Quick Mail Transfer Protocol, is an alternative to SMTP,designed by qmail's author.  QMTP is not compatible with SMTP, nor is it widelyused across the Internet.  If you wish to read more about QMTP, have a look atLWQ section 5.11, and also Daniel Bernstien's documentation for QMTP(http://cr.yp.to/proto/qmtp.txt).  More information about QMTP will be in afuture revision of this guide.)

(NOTE:  QMQP, the Quick Mail Queueing Protocol, was designed by qmail's authorto allow multiple servers running qmail to pool their messages into a singlequeue on a centralized server.  The outlying servers run a special configurationof qmail called "mini-qmail" and use QMQP to send their messages to the centralserver.  Bernstien has documentation for mini-qmail(http://cr.yp.to/qmail/mini.html) and QMQP (http://cr.yp.to/proto/qmqp.html).More information about these features will be in a future revision of thisguide.)

(NOTE:  The optional configuration discussed above will also create files"clientcert.pem", "rsa512.pem", and  "servercert.pem" in /var/qmail/control.These files are your self-signed SSL certificate and are necessary forencrypted SMTP; more information about them is provided in appendix B.5.  Theycan be safely ignored if you do not plan on using encrypted SMTP, or if youdid not emerge qmail with the "ssl" USE flag enabled.)

Part Three - After qmail Is Up and Running

Some tips for smooth operation and extended functionality.

* By default, Portage's "config file protection" extends to qmail'sconfiguration directory, /var/qmail/control.  This feature prevents qmail'sconfiguration from being blindly overwritten by any future upgrades orremovals.  Run "emerge -h config" for more information.

* Assuming you kept the default delivery instructions provided by Gentoo(/var/qmail/control/defaultdelivery), each user on your system will needa maildir named ".maildir" in his or her home directory.  See LWQ section4.1.3 for more information.

* Refer any users on your system to LWQ section 4 for information on how toexert control over their incoming email.

* LWQ section 5.2.1 provides information on how to install and configurethe POP3 server that comes with qmail.  If you decide to use this POP3server (qmail-pop3d), read through the steps given in LWQ section 5.2.1.2.If the standard checkpassword program meets your needs, then steps 1through 6 will already have been performed by the Gentoo qmail ebuild bythis point.  The supervise scripts set up by the ebuild for POP3service are different from those given in LWQ, and the differences aresimilar to those described above for qmail-smtpd./var/qmail/supervise/qmail-pop3d/run is designed to read configuration from/var/qmail/control/conf-common and /var/qmail/control/conf-pop3d.Modifying these configuration files is not necessary for standard POP3functionality, and not recommended for those running POP3 service for thefirst time.  Once you are familiar with how qmail's POP3 service operates,you can change these files to take advantage of features like alternativepassword checking programs, and POP-before-SMTP authentication.  Appendix Bprovides more information about how to edit the configuration files, if youdecide to do so.

When you are ready to offer POP3 service, run the following command to allowsvscan to automatically start and supervise the qmail-pop3d process:

ln -s /var/qmail/supervise/qmail-pop3d /service

(NOTE:  Gentoo used to provide a separate ebuild called qmail-pop3d thatwould install the necessary scripts for running qmail's POP3 server.  Thecurrent qmail ebuild provides the same functionality, therefore theqmail-pop3d ebuild is no longer necessary.)

If you created the /var/qmail/bin/qmailctl script discussed in LWQ section2.8.2.1, follow steps 7 through 12 to add features related to qmail-pop3d.If you decided to keep the /var/qmail/bin/qmail-control script instead, itis already capable of starting and stopping qmail-pop3d.

If svscan is currently running, POP3 service should now be available.

* Portage merges the dot-forward ebuild along with qmail.  dot-forwardallows people to create delivery instructions using Sendmail's format.Custom delivery instructions for Sendmail are usually kept in files named".forward", hence this package's name.  See LWQ appendix B.1 for moreinformation.

Conclusion - Any Questions?

Your qmail server should now be ready for action.  However, you may stillhave some questions or concerns.

If you are using Gentoo without many customizations, and you have a concernabout qmail's installation as performed by Portage, contact the maintainersof Gentoo, as they wish to be notified of any problems with their ebuilds.Their policy is to investigate the problem, and then notify the originalsoftware authors themselves if they determine the cause lies there.  VisitGentoo's bug page (http://bugs.gentoo.org) for more information.

If you have successfully installed qmail, but now you have a question aboutits performance and/or your configuration, the qmail mailing list is theplace to ask experienced qmail users for information.  However, please keepin mind these are people giving of their free time, and they are very tiredof reading the same questions over and over.  I cannot emphasize this enough:READ THE DOCUMENTATION and, if appropriate, CHECK YOUR LOGS before asking aquestion on the list.  LWQ, the qmail man pages, the web pages maintained byqmail's author at http://cr.yp.to, and especially the qmail mailing listarchives (http://www.ornl.gov/cts/archives/mailing-lists/qmail/) are allexcellent sources of information, and many list veterans consider all ofthese to be required reading.  Should you decide a question to the list isnecessary, list veteran Charles Cazabon has written "12 Steps to qmail ListBliss"(http://www.qcc.ca/~charlesc/writings/12-steps-to-qmail-list-bliss.html),detailing what every list veteran would like to see happen when somebody hasa question about qmail.

If you have a question or comment about this guide in particular, feel freeto email me at skunkworx@kingwoodcable.com.

Appendix A - The qmail Program Chain

This section briefly describes how the various qmail programs are set up, andhow they interact with one another to provide qmail's services.  Understandingthese interactions is essential if you plan on modifying your qmailinstallation to take advantage of additional features, such as those describedin appendix B.  This section does not go into much detail, and is also somewhatspecific to the way qmail is installed and configured on Gentoo systems.  For abetter and more general understanding of why and how these programs interactthe way they do, you are encouraged to read the referenced documentation.

The svscan init script (/etc/init.d/svscan) is used to start all of qmail'sservices.  First, an svscan (http://cr.yp.to/daemontools/svscan.html) processis created.  For every symbolic link created within the /service directory,svscan then creates and monitors two supervise(http://cr.yp.to/daemontools/supervise.html) processes.  The second superviseprocess creates and monitors a multilog(http://cr.yp.to/daemontools/multilog.html) process, which will feed the outputof the first supervise process into a log file.  The first supervise process'sactivity depends on the service.

For qmail-send, supervise executes and monitors the /var/qmail/rc script.  Bydefault, this script in turn executes qmail-start, which in turn creates allthe processes in charge of processing qmail's message queue.  These processesinclude qmail-send, qmail-clean, qmail-lspawn, and qmail-rspawn.  Man pages areavailable for these four programs, and for qmail-start.

For qmail-smtpd, supervise creates and monitors a softlimit(http://cr.yp.to/daemontools/softlimit.html) process, designed to limit theuse of system resources and prevent runaway processes.  softlimit in turncreates a tcpserver (http://cr.yp.to/ucspi-tcp/tcpserver.html) process,configured to listen for SMTP connections.  For every SMTP connectionreceived, tcpserver creates a qmail-smtpd process to handle that connection.A man page is available for qmail-smtpd.

For qmail-pop3d, supervise creates and monitors a softlimit process, which inturn creates a tcpserver process configured to listen for POP3 connections.For every POP3 connection received, tcpserver creates a qmail-popup process tohandle that connection.  qmail-popup displays to the connecting client a POP3greeting, then prompts for a login name and password.  qmail-popup thenexecutes a password checking program to verify the login name and password.If the login name and password are valid, the password checking program willthen create a qmail-pop3d process to further handle that connection;otherwise, the password checking program will exit, causing the connection tobe dropped.  Man pages are available for qmail-popup and qmail-pop3d.

(NOTE:  If you followed the instructions for adding svscanboot to /etc/inittab,svscanboot (http://cr.yp.to/daemontools/svscanboot.html) will be executedduring system boot, which in turn will create the svscan process.)

Appendix B.1 - qmail Network Service Configuration

This section explains the environment variables that can be defined in/var/qmail/control/conf-common, /var/qmail/control/conf-smtpd, and/var/qmail/control/conf-pop3d.  The values of these variables are in turn usedby /var/qmail/supervise/qmail-smtpd/run and/var/qmail/supervise/qmail-pop3d/run.

This section assumes an understanding of how the various programs interact toprovide qmail's services; see appendix A for an overview.

The configuration files provide default definitions for most of thesevariables.  The defaults will be enough for many qmail users' needs.Appendices B.2 through B.5 provide examples of how the configuration files canbe changed to enable certain features in qmail.  I *strongly* recommend leavingthese files alone until you are confident about what you are doing.

/var/qmail/control/conf-common provides definitions that affect all of qmail'snetwork services.  /var/qmail/control/conf-smtpd and/var/qmail/control/conf-pop3d provide definitions that will affect only SMTPand POP3 services, respectively.  Except where noted, these environmentvariables can be defined in conf-common or in a specific network service'sconfiguration file.  A definition in a specific network service's configurationfile will override any definition of that variable in conf-common, unless theprevious definition is incorporated into the new definition.

* MAXCONN

The maximum number of concurrent connections that tcpserver will allow.If unset, tcpserver will use its internal default of 40.  Normally, thisvalue is read from /var/qmail/control/concurrencyincoming.

* NOFILESGID

The GID of the system group that will run the tcpserver processes in chargeof providing qmail-related network services.

* QMAIL_CONTROLDIR

The directory for qmail's control files.  This will almost always be/var/qmail/control.  This variable is also defined in an /etc/env.dconfiguration file, so defining it again is really not necessary.

* QMAIL_POP3_CHECKPASSWORD

Specific to POP3.  This variable defines the program that will be executedto verify a POP3 login's name and password.  It is assumed that thisprogram provides the standard checkpassword interface, described athttp://cr.yp.to/checkpwd/interface.html, and further assumed that thisprogram can execute qmail-pop3d when a login name and password have beensuccessfully verified.

* QMAIL_POP3_POP3HOST

Specific to POP3.  This variable defines the name of the machine thatqmail's POP3 service will identify as its host.  By default, this is readfrom /var/qmail/control/me.

* QMAIL_POP3_POSTAUTH

Specific to POP3.  Normally, the password checking program defined byQMAIL_POP3_CHECKPASSWORD will execute qmail-pop3d when a login name andpassword have been successfully verified.  If this variable is defined, thepassword checking program will instead execute the program or string ofprograms given by this variable.  It is assumed that qmail-pop3d and itscommand-line arguments can be passed as the final command-line arguments ofthis program chain.

* QMAIL_POP3_PREAUTH

Specific to POP3.  After accepting a POP3 connection, tcpserver willnormally execute qmail-popup to provide the initial POP3 greeting andpassword prompt to the connecting client.  If this variable is defined,tcpserver will instead execute the program or string of programs given bythis variable.  It is assumed that qmail-popup and its command-linearguments can be passed as the final command-line arguments of this programchain.

* QMAIL_SMTP_POST

Specific to SMTP.  This variable provides command-line arguments to executeqmail-smtpd with.

* QMAIL_SMTP_PRE

Specific to SMTP.  After accepting an SMTP connection, tcpserver willnormally execute qmail-smtpd to provide SMTP service to the connectingclient.  If this variable is defined, tcpserver will instead execute theprogram or string of programs given by this variable.  It is assumed thatthat qmail-smtpd and its command-line arguments can be passed as the finalcommand-line arguments to this program chain.

* QMAIL_TCPSERVER_PRE

Normally, softlimit will execute tcpserver.  If this variable is defined,softlimit will instead execute the program or string of programs given bythis variable.  It is assumed that tcpserver and its command-line argumentscan be passed as the final command-line arguments to this program chain.

* QMAILDUID

The UID of the system user that will run the tcpserver processes in chargeof providing qmail-related network services.

* SOFTLIMIT_OPTS

Command-line arguments to execute softlimit with.  Seehttp://cr.yp.to/daemontools/softlimit.html for more information about theoptions available.

* TCPSERVER_HOST

The IP address tcpserver will listen for connections on.

* TCPSERVER_OPTS

Command-line arguments to execute tcpserver with, in addition to-x, -c, -u and -g.  See http://cr.yp.to/ucspi-tcp/tcpserver.html for moreinformation about the options available.

* TCPSERVER_PORT

The specific port of the IP address defined by TCPSERVER_HOST thattcpserver will listen for connections on.  This can be defined in theconfiguration file specific to each network service, however, conf-commonas installed by the qmail ebuild will set the value of this variable equalto that of the SERVICE environment variable.  SERVICE is defined by eachnetwork service's supervise script, "smtp" for SMTP, "pop3" for POP3, andso on.  For this to work, these services need to be defined with portnumbers in /etc/services.

* QMAILQUEUE

Normally, qmail pipes all messages through a program called "qmail-queue."qmail-queue's task is to place each message into qmail's message queue,where later it will be picked up by qmail-send for further processing anddelivery.  This environment variable, which by default is not set, allowsanother program to take the place of qmail-queue, providing the opportunityfor additional processing on each message before it is placed in the queue.See http://www.qmail.org/qqrbl for one example of a replacement qmail-queueprogram.  Note:  You better know what you are doing if you wish to takeadvantage of this feature.  If you do not replace qmail-queue with aprogram that provides at least the same functionality, you will break yourqmail installation!

Appendix B.2 - Authenticated SMTP

Gentoo's installation of qmail allows SMTP sessions to be authenticated withthe ESMTP AUTH command.  This permits you to restrict relaying priveleges topeople who have correct user names and passwords, instead of people who connectfrom certain IP addresses (the two methods can also be used together).  TheESMTP AUTH command was designed to support different methods of passwordverification, and this implementation provides the three most popular methods:PLAIN, LOGIN, and CRAM-MD5.  This makes qmail's authentication featurecompatible with most email clients currently available.

To enable authenticated SMTP, the QMAIL_SMTP_POST environment variable inthe conf-smtpd control file needs to be defined with three arguments.  The manpage for qmail-smtpd explains what these arguments should be: a hostname, apassword checking program, and an additional subprogram.  The hostname shouldbe the fully qualified domain name of your email server; it is used to generateCRAM-MD5 "challenges."  The password checking program must conform to thecheckpassword standard defined at http://cr.yp.to/checkpwd/interface.html, withone additional requirement:  If the password checking program is to supportCRAM-MD5, the program must be able to handle both unencrypted passwords andMD5-encrypted challenges and responses.  The subprogram is executed by thepassword checking program if password verification was successful; usually setto /bin/true, the subprogram must return "true" when exiting.

(NOTE:  checkpassword and other compatible programs are also used by qmail toauthenticate POP3 sessions, as explained earlier in this guide.  Whenauthenticating POP3 sessions, the subprogram argument is necessary because,after verifying a user's name and password, the password checking program isexpected to execute qmail-pop3d.  In the case of authenticated SMTP, thesubprogram really doesn't serve any purpose, which is why /bin/true isnormally used.)

The default conf-smtpd control file has configuration that, when uncommented,will enable authenticated SMTP, using cmd5checkpw as the passwordchecking program.  cmd5checkpw keeps a list of allowed user names andpasswords in /etc/poppasswd; see the cmd5checkpw man page for more details.If cmd5checkpw suits your needs, uncomment the four environment variabledefinitions in the "SMTP-AUTH" section of conf-smtpd.  Be sure to set up/etc/poppasswd as instructed by the cmd5checkpw man page for authentication towork properly.

Other password checking programs can be used.  For example, checkpassword uses/etc/passwd and/or /etc/shadow, enabling system users to use authenticatedSMTP.  To use checkpassword, edit conf-smtpd, uncommenting the four environmentvariable definitions mentioned in the above paragraph.  Then, change the linedefining QMAIL_SMTP_CHECKPASSWORD to look like this:

QMAIL_SMTP_CHECKPASSWORD="/bin/checkpassword"

Remember to restart qmail afterward.

One advantage of using checkpassword over cmd5checkpw is that passwords do nothave to be stored in an unencrypted format on the server.  This iscounterbalanced by the disadvantage of checkpassword not supporting CRAM-MD5;consequently, LOGIN or PLAIN must be used, which means passwords have to besent unencrypted across the network.

(NOTE:  You may need to change the permissions of checkpassword for it to workproperly in this case.  The program must be setuid root, otherwiseauthentication will fail.  Run "chmod 6755 /bin/checkpassword" to givecheckpassword the proper permissions.  Keep in mind that setting programs to besetuid root is generally a bad idea, and you may wish to look into otherpassword checking programs instead.)

(NOTE:  If you plan on providing POP3 and/or IMAP service, you may want to usethe same authentication data across all email services.  If you plan onproviding POP3 service using qmail's POP3 server, you can use the samepassword checking program for both POP3 and authenticated SMTP.  Have a lookat the conf-pop3d control file, and make sure the QMAIL_POP3_CHECKPASSWORDenvironment variable is set to your liking.)

For more information about authenticated SMTP and how it works, Erwin Hoffmanhas written a tutorial, available at http://www.fehcom.de/qmail/smtpauth.html.

Appendix B.3 - Outbound Authenticated SMTP

qmail can also be instructed to use authenticated SMTP when relaying email toother servers.  This is useful when you plan on routing all your email throughanother email server, such as the one provided by your Internet serviceprovider, and that server requires authentication.

If you have qmail configured to deliver all email to another server, then youshould have a single line in the smtproutes control file that looks similar tothis:

:mail.your-isp.com

To enable outbound authenticated SMTP, modify that line to include a usernameand password, both of which should be encoded in base64:

:mail.your-isp.com  

This feature was patched into qmail.  The patch's original author, JaySoffian, has documentation athttp://www.soffian.org/downloads/qmail/qmail-remote-auth-patch-doc.txt, whichincludes some Perl commands to help with base64 encodings.  There are alsoweb-based base64 encoders available.

For the security-conscious, keep in mind that base64 encoding is not the sameas encrypting, and anybody who can see your smtproutes control file can learnyour passwords.  Also, this feature uses LOGIN for authentication, which meansthe remote server must support LOGIN, and which also means your passwords willbe sent unencrypted across the network.

Appendix B.4 - POP-before-SMTP

An alternative to authenticated SMTP is POP-before-SMTP.  When aPOP-before-SMTP system is in place, any user that first checks his or herincoming email with POP3 is then permitted, for a period of time, to relayoutgoing email through the server.  POP-before-SMTP implementations accomplishthis by remembering POP3 clients' IP addresses, and looking for each SMTPclient's IP address in that list, granting relay permission if the address islisted.  The list is periodically cleaned of old IP addresses, ensuring relaypermission is not granted for longer than necessary.  While not as secure asauthenticated SMTP, POP-before-SMTP is a good solution that supports all emailclients, including those that cannot use authenticated SMTP.

POP-before-SMTP requires additional software, specifically, a program that willactually maintain the list of IP addresses permitted to relay.  Portage offersrelay-ctrl, written by Bruce Guenter, for this purpose.  Emerge this packagewith the following commands:

# emerge -p relay-ctrl

These are the packages that I would merge...

# emerge relay-ctrl

After emerge finishes, edit the conf-smtpd and conf-pop3d control files.  Thedefault installation already includes the necessary configuration in each ofthese files, commented out.  In conf-smtpd, uncomment the first two environmentvariable definitions in the section that begins with, "If you are interested inproviding POP or IMAP before SMTP..."  In conf-pop3d, uncomment the twoenvironment variable defitions in the section for POP3 before SMTP.  Aftersaving the changes, remember to restart qmail.  POP-before-SMTP should nowwork.

(NOTE:  This appendix assumes you are providing POP3 service, and that you areusing qmail-pop3d to do so.  With relay-ctrl, it is possible to use adifferent POP3 server and still provide POP-before-SMTP.  It is even possibleto provide "IMAP-before-SMTP" instead, using Courier IMAP.  These examples arebeyond the scope of this guide, however, there is documentation for relay-ctrlat http://untroubled.org/relay-ctrl/ and for Courier IMAP athttp://www.inter7.com/courierimap.html, as well as notes about enablingIMAP-before-SMTP in the default installation of conf-smtpd.)

Appendix B.5 - Encrypted SMTP

Ordinarily, SMTP communications are "in the clear," with no encryption.  Thismeans anybody who can eavesdrop on your network activity can monitor youremail traffic, snooping messages, sender and recipient addresses, and perhapseven SMTP authentication user names and passwords.  Consequently, an extentionto the SMTP protocol was drafted, providing email servers with the ability toencrypt SMTP sessions by using the ESMTP STARTTLS command.  Gentoo's qmailebuild allows encryption to be used on both incoming and outgoing SMTPconnections.

To enable encrypted SMTP, first make sure that you emerged qmail with the"ssl" USE flag enabled.  Next, you must have an SSL server certificate inplace.  If you ran the ebuild command for extra automatic configuration,described in Part Two above, then a self-signed certificate is already inplace.  If you did not run the ebuild command, you can generate aself-signed certificate by first editing /var/qmail/control/servercert.cnf,filling in information specific to your server, and then running/var/qmail/bin/mkservercert.  When the certificate generation processfinishes (using either command), three new files will appear in/var/qmail/control:  servercert.pem, the server's new self-signed certificate,used for incoming SMTP connections; clientcert.pem, which can be a separatecertificate used for outgoing SMTP connections, but which by default is thesame as servercert.pem; and rsa512.pem, the private code-key used to decryptincoming SMTP traffic.  Restart qmail after creating your certificate.

At this point, any client that supports the ESMTP STARTTLS command will beable to request an encrypted SMTP session; also, the server will automaticallyrequest an encrypted SMTP session when connecting to any remote host thatboasts ESMTP STARTTLS support.  The server is ready to go.  Furtherconfiguration is possible, providing, among other features, the ability torefuse outgoing email to remote hosts that do not support encryption, and theability to accept email from ecrypting clients that otherwise would have beenrejected.  For more information, visit the web page for Frederik Vermeulen'soriginal patch for qmail (http://inoa.net/qmail-tls/).

Note that self-signed certificates may be rejected by some servers as insecureor untrustworthy.  You may want to have a certificate signed by a mutuallytrusted Certificate Authority instead.

(NOTE:  The process of getting an SSL certificate issued by a CertificateAuthority is really beyond the scope of this guide, however, I plan to havemore information in a future revision.)

Also, be aware that encrypting your server's SMTP traffic does not guaranteethat your email is safe from prying eyes.  Email messages are sometimesrelayed through multiple servers, one or more of which may not supportencryption.  Also, email that has made it to its final destination is usuallystored unencrypted, making it possible for other users or administrators onthat server to read it.  For more complete email security, you may want toconsider using an email client that supports encrypting each email messagebefore it is sent.  Of course, this will require that the recipient be able todecrypt the message.  Further information would be beyond the scope of thisguide, but you can visit the web pages of email clients that support messageencryption, such as Mutt (http://www.mutt.org/), and the web pages ofgeneral-use encryption software, such as GnuPG (http://www.gnupg.org/).

Appendix C - Patches

Warning:  Lots of technical jargon ahead.  This section describes the patchesthat are applied to the qmail 1.03 source code by the qmail 1.03-r13 ebuild.  Ishould mention that many qmail veterans consider some of these patches to beunnecessary for general use, suggesting that one should use as pristine a copyof qmail as possible, applying only those patches that are known to be needed.If you are handy at writing and modifying ebuild scripts, you may want toconsider editing qmail's ebuild script to remove patches that do not apply toyou.  Of course, qmail has been found to run just fine with these patches, andthey do provide features many find useful, and fix bugs many find annoying orinconvenient.  Buyer beware, however:  The author of qmail makes no guaranteesabout its security beyond his original code.  Buyer beware again:  Removingpatches may result in unexpected behavior if the configuration files and scriptsare not modified appropriately.

* qregex-starttls-2way-auth (http://www.arda.homeunix.net/store/qmail/)

This patch combines several patches into one, providing several extentionsto qmail's functionality.

This patch provides the extra configuration file/var/qmail/control/badmailto, and enables the use of regular expressions tobe used in /var/qmail/control/badmailto and /var/qmail/control/badmailfrom.For more information, visit the original patch's web page(http://www.unixpimps.org/software/qregex/).

This patch also provides the ESMTP AUTH command, enabling qmail to requireauthorization before accepting messages for processing.  For moreinformation, visit the original patch's web page(http://members.elysium.pl/brush/qmail-smtpd-auth/).  See appendix B.2 fordetails on how to make use of this feature.

This patch also gives qmail the ability to use the ESMTP AUTH command whenconnecting to other SMTP servers.  See appendix B.3 for more details onoutbound authenticated SMTP.

Finally, this patch enables TLS/SSL support for encrypted SMTP sessions.See appendix B.5 for details on how to make use of this feature.

Patch written by Andrew St. Jean, based on the work of "unixpimps.org,"Krzysztof Dabrowski, "Mrs. Brisby," Frederik Vermeulen, and Neal Groothuis.

* smtp-auth-close3

According to the qmail 1.03-r13 ebuild, this patch "fixes a problem whenutilizing morercpthosts" together with ESMTP AUTH.

* qmailqueue (http://www.qmail.org/qmailqueue-patch)

This patch provides qmail with the ability to replace qmail-queue withother programs.  See appendix B.1 for more details.  Patch written by BruceGuenter.

* big-todo (http://qmail.null.dk/big-todo.103.patch)

qmail was designed to be able to handle large numbers of email messageswithout a significant slow-down.  One way it accomplishes this is bysplitting its queue into several different directories.  Many of thesedirectories are in turn split into subdirectories, ensuring that no singlefolder becomes unnecessarily large.

When a message is first accepted by qmail for processing, it is placed inthe "todo" directory.  Normally, this directory is not split intosubdirectories like certain queue directories are.  This means that if alarge number of messages enters the system before qmail has a chance toprocess them all, the todo directory could become quite large, introducing alag into the system.  This patch enables the todo directory to be split intosubdirectories, helping to prevent a sudden influx of email from being aproblem.  Patch written by Russel Nelson, with some modification by BruceGuenter.

* qmail-1.03-qmtpc (http://www.qmail.org/qmail-1.03-qmtpc.patch)

This patch allows qmail to send email to other servers using QMTP insteadof SMTP.  More information about QMTP will be in a future revision of thisguide.  Patch written by Russel Nelson.

* qmail-103 (http://www.ckdhr.com/ckd/qmail-103.patch)

Unpatched qmail will have trouble sending email to domains whose DNSservers send oversized answers to DNS queries.  This patch resolves thisissue.  Patch written by Christopher K. Davis.

* qmail-local-tabs

Unpatched qmail, when handling .qmail files whose first lines are nothing buttabs, has the potential to access an array out of range, an error morecommonly known as a memory or buffer overflow.  This bug is generallyconsidered to be minor, because qmail by this point is running as the ownerof the .qmail file and will never run as root, and also because qmail'sdocumentation states that a .qmail file should not start with an empty line.Nonetheless, this is a bug, and this patch fixes it.

* qmail-link-sync (http://www.jedi.claranet.fr/qmail-link-sync.patch)

qmail assumes that certain file commands are synchronous, that is, thecommands will not report a successful finish until the file has actuallybeen written to disk (as opposed to residing in a cache to be writtenlater).  While this assumption is true for some Unix-compatible operatingsystems and the file systems they use, it is not true for many flavors oflinux and its file systems.  The consequence is that a disruption of service,such as a power outage, could result in email being lost.  This patchworks around this issue by forcing file synchronization to take place afterthese commands.  Patch written by Frank Denis.

* big-concurrency

Unpatched qmail has an inherent maximum concurrency limit of 255.  In otherwords, the highest number of concurrent local deliveries and concurrentremote deliveries that can take place is 255 each.  This patch allows thoselimits to be as high as 65,000, though the qmail 1.03-r13 ebuild sets a newmaximum limit of 500 for each.  Patch written by Johannes Erdfelt.

* qmail-0.0.0.0

0.0.0.0 is considered to be a self-referencing IP address, similar to127.0.0.1 (though the semantics of each are not quite the same).Unpatched qmail does not treat 0.0.0.0 as a local IP address; this patchresolves that issue.  Patch written by Scott Gifford.

* errno

This patch fixes the code compatibility issue that prevents qmail 1.03 fromcompiling or running properly against versions of glibc 2.3.2 and newer.

* sendmail-flagf (http://david.acz.org/software/sendmail-flagf.patch)

qmail's sendmail wrapper does not support the "-f" option that the realsendmail does.  This patch provides that feature.  Patch written by DavidPhillips.

* qmail-maildir++ (http://www.shupp.org/patches/qmail-maildir++.patch)

Sam Varshavshik, the author of Courier and Courier IMAP, authored anextention to the maildir format called maildir++.  Among other things,maildir++ provides for multiple email subdirectories, and quota support.This patch enables qmail to make use of maildir++, allowing greatercompatibility between qmail and packages supporting maildir++, such asCourier IMAP and vpopmail.  Patch written by Bill Shupp.

* maildir-quota-fix

This patch fixes a typo in the above patch.

* qmail-date-localtime(ftp://ftp.nlc.net.au/pub/unix/mail/qmail/qmail-date-localtime.patch)

Whenever qmail needs to generate a timestamp, such as when adding a "Date:"header to an email message, it uses Greenwich Mean Time (GMT) timestamps.Most email clients know how to convert GMT into the local time zone, butsome do not.  This patch enables qmail to generate timestamps in the localtimezone instead.

* qmail-limit-bounce-size(http://www.qmail.org/www.jedi.claranet.fr/qmail-bounce.patch)

Normally, qmail will include a copy of the entire original message forthe original sender when generating a bounce message.  This patch allowsfor a new control file, "bouncemaxbytes", that states the maximum size abounce message can be.  Any bounce message that would go over this limitwill be truncated.

* qmail-smtpd-esmtp-size-gentoo

This patch provides support for the ESMTP SIZE command, allowing qmail toreject messages deemed too large before they are sent, instead of after.

* qmail-smtpd-relay-reject.gentoo

Some email servers allow their users to relay messages to non-localaddresses by creating a new email address that appears to be local.  Toillustrate, an email server local to example.com could be instructed todeliver a message to user@anotherexample.com by sending it a messageaddressed to user%anotherexample.com@example.com.  qmail by default doesNOT support this trick, as it can be easily abused by spammers who areaware of it.  However, according to some programs that test the integrity ofemail servers, qmail APPEARS to support this trick, because it does notreject up front any email messages addressed to local domains; instead, itlater bounces any messages that are not destined for valid addresses, such asthose with "%" or other extraneous characters.  Because these broken testingprograms do not check to see if their messages were actually delivered, manyqmail servers have unfortunately been incorrectly blacklisted.  This patchworks around this issue by enabling qmail to reject up front any recipientaddresses that use "%" and other such characters.

* qmail-gentoo-1.03-r12-badrcptto-morebadrcptto-accdias.diff

This patch provides for two new control files, "badrcptto" and"morebadrcptto".  They work similarly to badmailfrom, rejecting up frontany messages bound for addresses that appear in either of these files.Patch originally written by Ward Vandewege, later modified.

* qmail-popupnofd2close (http://www.dataloss.nl/software/patches/)

This patch allows checkpassword and similar programs to log error messagesto stderr.  Patch written by peter(at)dataloss.nl.

* qmail-1.03-reread-concurrency.2 (http://js.hu/package/qmail/)

This patch enables qmail to reread control files concurrencylocal andconcurrencyremote when the qmail-send process receives a HUP signal.Normally qmail has to be restarted for these files to be reread.  Patchwritten by Julian Severn-nek.

* 08-capa.diff (http://www.mcmilk.de/qmail/dl/djb-qmail/patches/)

This patch provides the POP3 CAPA command, allowing POP3 clients to get alist of all POP3 commands provided by qmail-pop3d.  Patch written by TinoReichardt.

Appendix D - Additional Software

This is a collection of additional software packages, many of which areavailable through Portage, that are useful for managing qmail and extendingits functionality.

* Courier IMAP (http://www.inter7.com/vpopmail) (ebuild available)

An IMAP server that supports the maildir format, and therefore integratesvery well with qmail.

* qlogtools (http://untroubled.org/qlogtools) (ebuild available)

A set of programs designed to analyze qmail's logs for monitoring andstatistics gathering.

* qmail-scanner (http://qmail-scanner.sourceforge.net/) (ebuild available)

A multi-purpose email scanner specifically designed to work with qmail,useful for combatting viruses, spam, and even unwanted file attachments.qmail-scanner can be configured with its own set of rules, and can also workwith other popular email tools such as SpamAssassin(http://spamassassin.org, ebuild available), F-Prot (http://www.f-prot.com,ebuild available), and many commercial virus scanners available for linux.

* qmailanalog (http://cr.yp.to/qmailanalog.html) (ebuild available)

Another set of tools for analyzing qmail's logs, written by the author ofqmail.

* vpopmail (http://www.inter7.com/vpopmail) (ebuild available)

A collection of programs designed to make the creation and management ofvirtual users and multiple email domains relatively fast and painless.

Acknowledgements

Thanks to Dave Sill for excellent qmail documentation in the form of "Lifewith qmail" and 'The qmail Handbook'.

Thanks to Charles Cazabon for invaluable help through the qmail mailing list.

Thanks to Daniel J. Bernstein for qmail itself.

Thanks to the authors and contributors of Gentoo for creating an excellentlinux distribution.

Guide Revision History

3/20/03 - First release.

3/21/03 - Corrected the statement about Gentoo's scripts not providing alimit on the number of simultaneous incoming SMTP connections.  There isalways a limit, even if it is not explicitly set.  Thanks to Dave Sill forpointing out this typo.

4/17/03 - Added a note about the incompatibility between qmail 1.03 and glibc2.3.2, and also fixed some grammatical and formatting mistakes.  glibc 2.3.1must be used to compile qmail and related packages.

5/13/03 - Added comments about the qmail ebuild's option for extra automaticconfiguration, and cleaned up some wording here and there.

5/15/03 - Added comments about the qmail-sumo and qmail-pop3d ebuilds.  Thanksto Tridib Biswas for pointing these out to me.

7/20/03 - Updated the guide to reflect recent releases of qmail and relatedebuilds for Gentoo.

11/30/03 - Rewrote several sections in part one to more accurately explainPortage's system of virtual packages and package blocking; added appendices,which will be further fleshed out in the next update; cleaned up some wordinghere and there.  This update is incomplete, pending a new version of the guideto be based on qmail ebuild 1.03-r13.

12/29/03 - Updated the guide to reflect qmail ebuild 1.03-r13.  Reorganizedthe appendices.  This update is also incomplete, as many sections in theappendices still need to be written.

12/30/03 - Corrected a statement concerning the Gentoo ebuild's initialconfiguration of qmail.  By default, qmail will accept SMTP connections fromanywhere, not just from local IP addresses.

2/8/04 - Removed information about the qmail-sumo ebuild, which is no longerin Portage.  Updated information about "Life with qmail," which is now basedon netqmail 1.05.  Updated information about glibc; the latest stable ebuildis now 2.3.2-r9.  Added a note about making sure the correct system users andgroups are in place before emerging qmail.  Added information about theqmail-control script installed by the qmail ebuild.  Reorganized the appendicesagain, and wrote sections concerning authenticated SMTP, outbound authenticatedSMTP, POP-before-SMTP, and additional qmail-related software.  The section onencrypted SMTP still needs to be written.  Cleaned up wording and formattingin various places.

2/20/04 - Wrote the section on encrypted SMTP.  Cleaned up wording in variousplaces.

2/22/04 - Fixed a typo in the section for encrypted SMTP.  "servercert.pem"was mentioned where "servercert.cnf" should have been named.

6/5/05 - Added the note that I am no longer actively maintaining this guide.</pre>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/32/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/32/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/32/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/32/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/32/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=32&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/running-qmail-under-gentoo-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title></title>
		<link>http://sddlzz.wordpress.com/2005/12/24/3com-superstack3-switch4200%e7%b3%bb%e5%88%97%e4%ba%a4%e6%8d%a2%e6%9c%ba%e4%b8%ad%e6%96%87%e7%94%b5%e5%ad%90%e6%89%8b%e6%8a%84%e6%9c%ac/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/3com-superstack3-switch4200%e7%b3%bb%e5%88%97%e4%ba%a4%e6%8d%a2%e6%9c%ba%e4%b8%ad%e6%96%87%e7%94%b5%e5%ad%90%e6%89%8b%e6%8a%84%e6%9c%ac/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 15:29:27 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/3com-superstack3-switch4200%e7%b3%bb%e5%88%97%e4%ba%a4%e6%8d%a2%e6%9c%ba%e4%b8%ad%e6%96%87%e7%94%b5%e5%ad%90%e6%89%8b%e6%8a%84%e6%9c%ac/</guid>
		<description><![CDATA[3Com SuperStack3 Switch4200ç³»åˆ—äº¤æ?¢æœºä¸­æ–‡ç”µå­?æ‰‹æŠ„æœ¬ ä½œè€…ï¼šä¸?ç¥¥ æ–‡ç« æ?¥æº?ï¼šInternet ç‚¹å‡»æ•°ï¼š226 æ›´æ–°æ—¶é—´ï¼š2005-4-7 ç‰ˆæœ¬ä¿¡æ?¯ Version 1.00 2004-05-31 Version 1.01 2004-06-01 ç‰ˆæœ¬è¯´æ˜Žï¼š 1ï¼Žä¿®æ”¹äº†VLANè®¾ç½®ä¸­æ³¨æ„?äº‹é¡¹ä¸‰çš„é”™è¯¯è¯´æ³• 2ï¼Žå¢žåŠ äº†STP/RSTPä¸­äº¤æ?¢æœºPriorityå?Šç«¯å?£costçš„è®¾ç½®è¯´æ˜Ž 3ï¼Žå¢žåŠ äº†Securityä¸­æœ‰å…³ç«¯å?£å®‰å…¨çš„å†…å®¹ ã€?æ–‡æ¡£è¯´æ˜Žã€‘ 1. æœ¬æ–‡æ¡£ä¸ºå…?è´¹æ–‡æ¡£ï¼Œè¯·å‹¿ç”¨ä½œå•†ä¸šç”¨é€”ã€‚ 2. è™½ç„¶ä½œè€…ä¼?å›¾é?¿å…?é”™è¯¯çš„å?‘ç”Ÿï¼Œä½†ç”±äºŽæ°´å¹³å?Šç?†è§£èƒ½åŠ›çš„å½±å“?ï¼Œæ–‡æ¡£ä¸­è¿˜æ˜¯å?¯èƒ½å­˜åœ¨é”™è¯¯ã€‚å¦‚æžœå?‘çŽ°æ–‡æ¡£ä¸­çš„é”™è¯¯ï¼Œè¯·å?‘é‚®ä»¶é€šçŸ¥ä½œè€…ï¼Œä½œè€…çš„é‚®ç®±åœ°å?€ä¸º: Aaron_Zhao@Huawei-3Com.com å…ˆåœ¨æ­¤å?‘å?‘çŽ°é—®é¢˜å¹¶é€šçŸ¥ä½œè€…çš„å?Œä»?è¡¨ç¤ºä¸¥é‡?æ„Ÿè°¢ï¼Œå¸Œæœ›å¤§å®¶å¤šäº¤æµ?ã€‚ 3. æ¬¢è¿Žå¤§å®¶å°†æ­¤æ–‡æ¡£å?‘å¤–å?‘é€?ï¼Œå?‘é€?æ—¶è¯·å‹¿å¯¹æ–‡æ¡£å†…å®¹è¿›è¡Œä¿®æ”¹ã€‚ 4. å¯¹äºŽä½¿ç”¨æœ¬æ–‡æ¡£ä¸­çš„å†…å®¹ï¼Œå¯¹äº¤æ?¢æœºè¿›è¡Œé…?ç½®æ—¶å?¯èƒ½å¼•èµ·çš„æ•…éšœå?Šé”™è¯¯ï¼Œä½œè€…æœ¬äººä¸?è´Ÿä»»ä½•è´£ä»»ã€‚ 5. ä»¥ä¸Šè¯´æ˜Žæ?¡æ¬¾ä¸?å…·æœ‰å¼ºåˆ¶æ€§ï¼Œç›®çš„æ˜¯ä¸ºäº†å¤§å®¶å¾—åˆ°æ›´å¥½å¸®åŠ©ä¿¡æ?¯ã€‚å¯¹äºŽä¸?é?µå®ˆä»¥ä¸Šæ?¡æ¬¾çš„äººï¼Œä½œè€…æ¯?æ—¥å°†é„™è§†ä¹‹ä¸€è‡³ä¸¤æ¬¡æˆ–æ›´å¤šã€‚ã€‚ã€‚ [å?‚è€ƒä¿¡æ?¯] 1ï¼Ž3Comäº¤æ?¢æœºè½¯ä»¶å?Šæ–‡æ¡£é¡µé?¢ http://www.3com.com/products/en_US/downloadsindex.jsp?home1=supportdownload 2ï¼Ž3Com Knowledgebaseä¸»é¡µ http://3kb.3com.com 3ï¼Žå?Žä¸º3Comçƒ­çº¿ç”µè¯? 800-810-0504 4ï¼Ž3ComæŠ€æœ¯æ”¯æŒ?ç”µè¯? 800-810-3033 SS3 4200äº¤æ?¢æœºä»‹ç»? SS3 4200ç³»åˆ—äº¤æ?¢æœºæ˜¯3Comç”Ÿäº§çš„ä¸€æ¬¾å?¯ç®¡ç?†çš„äºŒå±‚äº¤æ?¢æœºï¼Œè¯¥ç³»åˆ—äº¤æ?¢æœºç›®å‰?åŒ…æ‹¬ä¸‰ä¸ªåž‹å?·ï¼Œåˆ†åˆ«æ˜¯4226T(3C17300)ã€?4250T(3C17302)å?Š4228G(3C17304)ã€‚å…¶ä¸­ï¼š l 4226T åŒ…æ‹¬24ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£ l 4250T åŒ…æ‹¬48ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£ l 4228G åŒ…æ‹¬24ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£ï¼Œ2ä¸ªGBIC å?£ã€‚GBICå?£å?¯ä»¥é€‰é…?3Comçš„GBICæ¨¡å?—ï¼ŒåŒ…æ‹¬1000Base-SX(3CGBIC91)ã€?1000Base-LX(3CGBIC92)ã€? [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=29&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div> 3Com SuperStack3 Switch4200ç³»åˆ—äº¤æ?¢æœºä¸­æ–‡ç”µå­?æ‰‹æŠ„æœ¬</p>
<p>ä½œè€…ï¼šä¸?ç¥¥    æ–‡ç« æ?¥æº?ï¼šInternet    ç‚¹å‡»æ•°ï¼š226    æ›´æ–°æ—¶é—´ï¼š2005-4-7</p>
<p>ç‰ˆæœ¬ä¿¡æ?¯</p>
<p>Version 1.00</p>
<p>2004-05-31</p>
<p>Version 1.01</p>
<p>2004-06-01    ç‰ˆæœ¬è¯´æ˜Žï¼š</p>
<p>1ï¼Žä¿®æ”¹äº†VLANè®¾ç½®ä¸­æ³¨æ„?äº‹é¡¹ä¸‰çš„é”™è¯¯è¯´æ³•</p>
<p>2ï¼Žå¢žåŠ äº†STP/RSTPä¸­äº¤æ?¢æœºPriorityå?Šç«¯å?£costçš„è®¾ç½®è¯´æ˜Ž</p>
<p>3ï¼Žå¢žåŠ äº†Securityä¸­æœ‰å…³ç«¯å?£å®‰å…¨çš„å†…å®¹</p>
<p>ã€?æ–‡æ¡£è¯´æ˜Žã€‘</p>
<p>1.          æœ¬æ–‡æ¡£ä¸ºå…?è´¹æ–‡æ¡£ï¼Œè¯·å‹¿ç”¨ä½œå•†ä¸šç”¨é€”ã€‚</p>
<p>2.          è™½ç„¶ä½œè€…ä¼?å›¾é?¿å…?é”™è¯¯çš„å?‘ç”Ÿï¼Œä½†ç”±äºŽæ°´å¹³å?Šç?†è§£èƒ½åŠ›çš„å½±å“?ï¼Œæ–‡æ¡£ä¸­è¿˜æ˜¯å?¯èƒ½å­˜åœ¨é”™è¯¯ã€‚å¦‚æžœå?‘çŽ°æ–‡æ¡£ä¸­çš„é”™è¯¯ï¼Œè¯·å?‘é‚®ä»¶é€šçŸ¥ä½œè€…ï¼Œä½œè€…çš„é‚®ç®±åœ°å?€ä¸º: Aaron_Zhao@Huawei-3Com.com</p>
<p>å…ˆåœ¨æ­¤å?‘å?‘çŽ°é—®é¢˜å¹¶é€šçŸ¥ä½œè€…çš„å?Œä»?è¡¨ç¤ºä¸¥é‡?æ„Ÿè°¢ï¼Œå¸Œæœ›å¤§å®¶å¤šäº¤æµ?ã€‚</p>
<p>3.          æ¬¢è¿Žå¤§å®¶å°†æ­¤æ–‡æ¡£å?‘å¤–å?‘é€?ï¼Œå?‘é€?æ—¶è¯·å‹¿å¯¹æ–‡æ¡£å†…å®¹è¿›è¡Œä¿®æ”¹ã€‚</p>
<p>4.          å¯¹äºŽä½¿ç”¨æœ¬æ–‡æ¡£ä¸­çš„å†…å®¹ï¼Œå¯¹äº¤æ?¢æœºè¿›è¡Œé…?ç½®æ—¶å?¯èƒ½å¼•èµ·çš„æ•…éšœå?Šé”™è¯¯ï¼Œä½œè€…æœ¬äººä¸?è´Ÿä»»ä½•è´£ä»»ã€‚</p>
<p>5.          ä»¥ä¸Šè¯´æ˜Žæ?¡æ¬¾ä¸?å…·æœ‰å¼ºåˆ¶æ€§ï¼Œç›®çš„æ˜¯ä¸ºäº†å¤§å®¶å¾—åˆ°æ›´å¥½å¸®åŠ©ä¿¡æ?¯ã€‚å¯¹äºŽä¸?é?µå®ˆä»¥ä¸Šæ?¡æ¬¾çš„äººï¼Œä½œè€…æ¯?æ—¥å°†é„™è§†ä¹‹ä¸€è‡³ä¸¤æ¬¡æˆ–æ›´å¤šã€‚ã€‚ã€‚</p>
<p>[å?‚è€ƒä¿¡æ?¯]</p>
<p>1ï¼Ž3Comäº¤æ?¢æœºè½¯ä»¶å?Šæ–‡æ¡£é¡µé?¢</p>
<p>http://www.3com.com/products/en_US/downloadsindex.jsp?home1=supportdownload</p>
<p>2ï¼Ž3Com Knowledgebaseä¸»é¡µ</p>
<p>http://3kb.3com.com</p>
<p>3ï¼Žå?Žä¸º3Comçƒ­çº¿ç”µè¯? 800-810-0504</p>
<p>4ï¼Ž3ComæŠ€æœ¯æ”¯æŒ?ç”µè¯? 800-810-3033</p>
<p>SS3 4200äº¤æ?¢æœºä»‹ç»?</p>
<p>SS3 4200ç³»åˆ—äº¤æ?¢æœºæ˜¯3Comç”Ÿäº§çš„ä¸€æ¬¾å?¯ç®¡ç?†çš„äºŒå±‚äº¤æ?¢æœºï¼Œè¯¥ç³»åˆ—äº¤æ?¢æœºç›®å‰?åŒ…æ‹¬ä¸‰ä¸ªåž‹å?·ï¼Œåˆ†åˆ«æ˜¯4226T(3C17300)ã€?4250T(3C17302)å?Š4228G(3C17304)ã€‚å…¶ä¸­ï¼š</p>
<p>l         4226T åŒ…æ‹¬24ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£</p>
<p>l         4250T åŒ…æ‹¬48ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£</p>
<p>l         4228G åŒ…æ‹¬24ä¸ª10Base-T/100Base-Txè‡ªé€‚åº”å?£ï¼Œ2ä¸ª10Base-T/100Base-Tx/1000Base-Tè‡ªé€‚åº”å?£ï¼Œ2ä¸ªGBIC å?£ã€‚GBICå?£å?¯ä»¥é€‰é…?3Comçš„GBICæ¨¡å?—ï¼ŒåŒ…æ‹¬1000Base-SX(3CGBIC91)ã€?1000Base-LX(3CGBIC92)ã€? 1000Base-T(3CGBIC93)å?Š1000Base-LH70(3CGBIC97) GBIC</p>
<p>4200ç³»åˆ—äº¤æ?¢æœºçš„ç«¯å?£éƒ½æ˜¯å›ºå®šçš„ï¼Œæ²¡æœ‰æ‰©å±•æ§½ä½?ï¼Œä¸?èƒ½å¢žåŠ æ¨¡å?—ã€‚å?ªæœ‰4228Gäº¤æ?¢æœºæœ‰2ä¸ªGBICå?£ï¼Œå?¯ä»¥æ?’3Comçš„GBICå?ƒå…†æ¨¡å?—ã€‚</p>
<p>ä½œä¸ºä¸€æ¬¾äºŒå±‚äº¤æ?¢æœºï¼Œ4200çš„å®šä½?æ˜¯è¾¹ç¼˜æŽ¥å…¥å?Šæ¡Œé?¢äº¤æ?¢æœºã€‚ç›¸å¯¹å?Œæ ·å®šä½?çš„4400ç³»åˆ—äº¤æ?¢æœºæ?¥è®²ï¼Œ4200ç³»åˆ—çš„äº¤æ?¢æœºä»·æ ¼æ¯”è¾ƒä½Žï¼Œç›¸å¯¹åŠŸèƒ½ä¹Ÿæ¯”4400ç³»åˆ—è¦?å°‘ï¼Œå› æ­¤é€‚ç”¨äºŽè¿½æ±‚ç«¯å?£å¯†åº¦ï¼Œä½†å¯¹è¾¹ç¼˜äº¤æ?¢æœºåŠŸèƒ½è¦?æ±‚ä¸€èˆ¬çš„ç”¨æˆ·çŽ¯å¢ƒã€‚</p>
<p>ä»ŽåŠŸèƒ½å’Œæ€§èƒ½ä¸Šè®²ï¼Œ4200å…·æœ‰ä»¥ä¸‹ç‰¹ç‚¹ï¼š</p>
<p>l         å?¯å †å? ã€‚è¯¦ç»†æƒ…å†µå?Žé?¢ç« èŠ‚ä»‹ç»?</p>
<p>l         é™¤é€šè¿‡Consoleå?£è¿›è¡Œç®¡ç?†å¤–ï¼Œè¿˜å?¯ä»¥é…?ç½®ç®¡ç?†åœ°å?€ï¼Œè¿œç¨‹é€šè¿‡Telnetæ–¹å¼?å?ŠWebæ–¹å¼?æ?¥è¿›è¡Œç®¡ç?†ã€‚ä½†æ˜¯ï¼Œå¼ºçƒˆå»ºè®®ç”¨æˆ·å?Šä»£ç?†å•†ä¸?è¦?ä½¿ç”¨Webæ–¹å¼?(å› ä¸ºæ˜¾å¾—å¤ªä¸?ä¸“ä¸šäº†)ã€‚æ”¯æŒ?åŸºäºŽSNMPçš„ç½‘ç®¡</p>
<p>l         åŸºæœ¬çš„äºŒå±‚äº¤æ?¢åŠŸèƒ½ï¼Œå…¶æ€§èƒ½ä¸ºï¼š4226Täº¤æ?¢å®¹é‡?8.8Gbpsï¼ŒåŒ…è½¬å?‘çŽ‡6.6MPPSï¼›4228Gäº¤æ?¢å®¹é‡?12.8Gbpsï¼ŒåŒ…è½¬å?‘çŽ‡9.5MPPSï¼›4226Täº¤æ?¢å®¹é‡?13.6Gbpsï¼ŒåŒ…è½¬å?‘çŽ‡10.1MPPS</p>
<p>l         æ‰€æœ‰ç«¯å?£æ”¯æŒ?è‡ªå??å•†Auto-Negotiationå?ŠMDI/MDIXè‡ªé€‚åº”</p>
<p>l         æ”¯æŒ?VLANã€?STPã€?Multicast Filterã€?BroadcastControlç­‰åŠŸèƒ½ï¼Œè¯¦ç»†é…?ç½®æƒ…å†µï¼Œå?Žé?¢ç« èŠ‚å…·ä½“ä»‹ç»?</p>
<p>SS3 4200äº¤æ?¢æœºå…¸åž‹é…?ç½®</p>
<p>ã€?ç®¡ç?†æ–¹å¼?ã€‘</p>
<p>4200äº¤æ?¢æœºæ”¯æŒ?é€šè¿‡Consoleå?£(ä¸²å?£)ç®¡ç?†ã€?é…?ç½®ç®¡ç?†IPå?Žç”¨Telnet/Webæ–¹å¼?ç®¡ç?†ï¼Œä»¥å?Šé€šè¿‡æ ‡å‡†çš„SNMPç½‘ç®¡ç³»ç»Ÿè¿›è¡Œç®¡ç?†ã€‚</p>
<p>å»ºè®®ç”¨æˆ·å°½é‡?ä½¿ç”¨å‘½ä»¤è¡Œæ–¹å¼?(CLI-Command Line Interface)å¯¹äº¤æ?¢æœºè¿›è¡Œé…?ç½®ç®¡ç?†ï¼ŒåŒ…æ‹¬Consoleå?£å?ŠTelnetæ–¹å¼?ã€‚å¯¹äºŽWebæ–¹å¼?å?Šç½‘ç®¡ç³»ç»Ÿï¼Œç”¨æ?¥è§‚å¯Ÿç›‘æŽ§äº¤æ?¢æœºçš„è¿?è¡Œæƒ…å†µå?¯ä»¥ï¼Œç”¨æ?¥ä½œä¸ºé…?ç½®çš„æ‰‹æ®µï¼Œä¸?å»ºè®®ä½¿ç”¨ã€‚</p>
<p>ä¸€ã€?Consoleå?£ç®¡ç?†æ–¹å¼?</p>
<p>é€šè¿‡Consoleå?£å¯¹äº¤æ?¢æœºè¿›è¡Œç®¡ç?†æ˜¯æœ€åŸºæœ¬çš„ä¸€ç§?æ–¹å¼?ï¼Œä¹Ÿæ˜¯æœ€å?Žä¸€ç§?ç®¡ç?†æ–¹å¼?ï¼Œå½“å…¶ä»–ç®¡ç?†æ–¹å¼?éƒ½ä¸?èƒ½è¿›å…¥äº¤æ?¢æœºæ—¶ï¼Œç”¨Consoleçº¿è¿žåˆ°äº¤æ?¢æœºçš„ç®¡ç?†ç«¯å?£è¯•ä¸€è¯•ã€‚å¦‚æžœé€šè¿‡Consoleå?£éƒ½ä¸?èƒ½è¿›å…¥äº¤æ?¢æœºï¼Œé‚£è¯´æ˜Žäº¤æ?¢æœºé—®é¢˜æ¯”è¾ƒä¸¥é‡?ï¼Œæœ‰å?¯èƒ½éœ€è¦?è¿›è¡Œç¡¬ä»¶è¿”ä¿®ã€‚</p>
<p>Console å?£ï¼Œä¹Ÿå?¯ä»¥å?«ç®¡ç?†å?£ï¼Œåœ¨4200äº¤æ?¢æœºçš„æœºç®±å?Žé?¢ï¼Œæ˜¯ä¸€ä¸ª9é’ˆçš„ä¸²å?£ã€‚ä¸€èˆ¬é€šè¿‡ä¸“ç”¨çš„Consoleçº¿ä¸Žè®¡ç®—æœºçš„ä¸²å?£(COM1æˆ–COM2)ç›¸è¿žï¼Œåœ¨è®¡ç®—æœºä¸Šç”¨è¶…çº§ç»ˆç«¯(HyperTerminal)ä½œä¸ºå·¥å…·ï¼Œå?³å?¯å®žçŽ°å¯¹äº¤æ?¢æœºçš„ç®¡ç?†ã€‚è¶…çº§ç»ˆç«¯çš„ä¸²å?£é€ŸçŽ‡è®¾ç½®ä¸ºï¼šç«¯å?£é€ŸçŽ‡9600/æ•°æ?®ä½?8/å?œæ­¢ä½?1/å¥‡å?¶æ ¡éªŒæ— /æµ?æŽ§æ— ã€‚è¿žæŽ¥è®¡ç®—æœºä¸Žäº¤æ?¢æœºçš„æŽ§åˆ¶çº¿å?ˆå?«ç©ºModemçº¿(Null Modem)ï¼Œå…¶çº¿åº?å¦‚ä¸‹æ‰€ç¤ºã€‚</p>
<p>äºŒã€?é€šè¿‡è®¾ç½®ç®¡ç?†IPæ–¹å¼?æ?¥ç®¡ç?†</p>
<p>ç»™4200äº¤æ?¢æœºè®¾ç½®ä¸€ä¸ªç®¡ç?†IPå?Žï¼Œå°±å?¯ä»¥é€šè¿‡ç½‘ç»œè¿›è¡Œè¿œç¨‹ç®¡ç?†ã€‚ç®¡ç?†çš„æ–¹å¼?åŒ…æ‹¬Telnetå’ŒWebæ–¹å¼?ã€‚</p>
<p>è®¾ç½®4200ç®¡ç?†IPçš„å‘½ä»¤å¦‚ä¸‹æ‰€ç¤ºã€‚</p>
<p>Select menu option: pro ip basic</p>
<p>Enter configuration method (auto,manual,none)[auto]: manual</p>
<p>Enter IP address           [0.0.0.0        ]: 10.10.10.3</p>
<p>Enter subnet mask          [0.0.0.0        ]: 255.255.255.0</p>
<p>Enter gateway IP address   [0.0.0.0        ]: 10.10.10.1</p>
<p>IP address:                      10.10.10.3</p>
<p>Subnet mask:                  255.255.255.0</p>
<p>Gateway IP address:     10.10.10.1</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>1ï¼Ž   é»‘ä½“å­—ä¸ºè¾“å…¥çš„å‘½ä»¤å?Šå?‚æ•°</p>
<p>2ï¼Ž    4200çš„ç®¡ç?†åœ°å?€æœ‰æ‰‹å·¥æ–¹å¼?(manual)å?Šè‡ªåŠ¨æ–¹å¼?ä¸¤ç§?ã€‚å¦‚æžœæ˜¯è®¾ç½®æˆ?è‡ªåŠ¨æ–¹å¼?ï¼Œåˆ™ç”¨æˆ·çš„ç½‘ç»œä¸­éœ€è¦?æœ‰ä¸€ä¸ªDHCP Serverï¼Œ4200å¼€æœºå?Žä¼šè‡ªåŠ¨åŽ»ç”³è¯·ä¸€ä¸ªIPåœ°å?€ã€‚è¿™ç§?è‡ªåŠ¨æ–¹å¼?ä¸?å»ºè®®ç”¨æˆ·ä½¿ç”¨ï¼Œå»ºè®®ç”¨æˆ·æ‰‹å·¥è®¾å®šç®¡ç?†åœ°å?€ã€‚ä¸Šé?¢ä¾‹å­?ä¸­æ˜¯ç”¨manualæ–¹å¼?æ‰‹å·¥è®¾ç½®ä¸€ä¸ªç®¡ç?†IPï¼Œåœ°å?€ä¸º10.10.10.3/24ï¼Œå…¶é»˜è®¤ç½‘å…³ä¸º10.10.10.1</p>
<p>3ï¼Ž   4200çš„ç®¡ç?†åœ°å?€æ˜¯è®¾åœ¨VLAN 1ä¸Šçš„ï¼Œè¿™ç‚¹ä¸?èƒ½æ”¹å?˜ã€‚æ‰€ä»¥è¿žåˆ°4200äº¤æ?¢æœºVLAN 1ä¸Šçš„è®¡ç®—æœºå?¯ç›´æŽ¥å¯¹4200è¿›è¡Œç®¡ç?†ã€‚å±žäºŽ4200å…¶ä»–VLANçš„è®¡ç®—æœºéœ€è¦?é€šè¿‡ä¸‰å±‚è·¯ç”±æ‰?èƒ½è®¿é—®4200çš„ç®¡ç?†IPï¼Œå?³ä½¿è¯¥è®¡ç®—æœºç›´æŽ¥è¿žæŽ¥åˆ°4200ä¸Š</p>
<p>4ï¼Ž   4200æ˜¯äºŒå±‚äº¤æ?¢æœºï¼Œç®¡ç?†IPçš„è®¾ç½®æ–¹å¼?ä¸Ž3Comä¸‰å±‚äº¤æ?¢æœºè®¾ç½®VLAN Interfaceçš„æ–¹å¼?å®Œå…¨ç›¸å?Œï¼Œä½†ä¸€å®šè¦?æ³¨æ„?ï¼Œ4200ä¸Šçš„ç®¡ç?†IPå?ªèƒ½ç”¨ä½œç½‘ç®¡ï¼Œä¸?æ˜¯ä½œä¸‰å±‚è½¬å?‘çš„ã€‚</p>
<p>ä¸‰ã€?4200äº¤æ?¢æœºç½‘ç®¡çš„è®¾ç½®</p>
<p>4200 äº¤æ?¢æœºè®¾ç½®ç®¡ç?†IPå?Žï¼Œè¿˜å?¯ä»¥é€šè¿‡ç½‘ç®¡ç³»ç»Ÿè¿›è¡Œç®¡ç?†ï¼Œå¦‚3Comçš„å…?è´¹ç½‘ç®¡è½¯ä»¶3Com Network Supervisorã€‚ä¸€èˆ¬æƒ…å†µä¸‹ç”¨4200é»˜è®¤çš„é…?ç½®å°±å?¯ä»¥ï¼Œæ ¹æ?®æƒ…å†µä¹Ÿå?¯ä»¥è¿›è¡Œä¿®æ”¹ã€‚ä¸»è¦?çš„åŒ…æ‹¬è®¾ç½®ç½‘ç®¡è½¯ä»¶å¯¹äº¤æ?¢æœºè¿›è¡Œè¯»/å†™çš„Community å­—ä¸²ï¼Œä»¥å?Šäº¤æ?¢æœºå?‘ç½‘ç®¡è½¯ä»¶å?‘é€?Trapçš„ç›®çš„åœ°å?€ï¼Œå¦‚ä¸‹æ‰€ç¤ºã€‚</p>
<p>Select menu option: sys man snmp comm</p>
<p>Enter new community for user &#8216;admin&#8217; [private]: write001</p>
<p>Enter new community for user &#8216;manager&#8217; [manager]: write000</p>
<p>Enter new community for user &#8216;monitor&#8217; [public]: read001</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ä»¥ä¸Šè®¾ç½®å°†ç½‘ç®¡ç³»ç»Ÿè¯»çš„Communityå­—ä¸²è®¾ä¸ºread001ï¼Œå°†æ”¹é…?ç½®å’Œä¿®æ”¹ç³»ç»Ÿå?‚æ•°çš„Communityå­—ä¸²è®¾ä¸ºwrite001å?Šwrite000</p>
<p>Select menu option: sys man snmp trap create</p>
<p>Enter the trap community string [monitor]:</p>
<p>Enter the trap destination address: 10.10.10.8</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ä»¥ä¸Šè®¾ç½®ä½¿äº¤æ?¢æœºå°†monitorçš„trapä¿¡æ?¯å?‘åˆ°åœ°å?€ä¸º10.10.10.8çš„ç½‘ç®¡ç³»ç»Ÿæˆ–å…¶ä»–å?¯æŽ¥æ”¶trapçš„ç³»ç»Ÿã€‚</p>
<p>å?¯ä»¥è®¾ç½®å¤šä¸ªç›®çš„åœ°å?€</p>
<p>ã€?4200ç³»ç»Ÿä¿¡æ?¯ã€‘</p>
<p>Select menu option: sys summ</p>
<p>3Com SuperStack 3</p>
<p>System Name             : Office Test</p>
<p>Location                : Huawei-3Com, BeiJing</p>
<p>Contact                 : Aaron Zhao</p>
<p>Time Since Reset        : 1 Hrs 9 Mins 16 Seconds</p>
<p>Operational Version     : 02.03p14</p>
<p>Hardware Version        : 01.01.00</p>
<p>Boot Version            : 1.00</p>
<p>MAC Address             : 00-0a-04-64-38-80</p>
<p>Product Number          : 3C17302</p>
<p>Serial Number           : 7Y3V1D7643880</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ç”±ä»¥ä¸Šå‘½ä»¤å?¯ä»¥å¾—åˆ°è¯¥4200äº¤æ?¢æœºçš„ç³»ç»Ÿä¿¡æ?¯ï¼ŒæŒ‰é‡?è¦?ç¨‹åº¦ï¼Œè¯´æ˜Žå¦‚ä¸‹ï¼š</p>
<p>1ï¼Ž   ç‰ˆæœ¬ä¿¡æ?¯ï¼ŒåŒ…æ‹¬Operationç‰ˆæœ¬ï¼ŒHardwareç‰ˆæœ¬å?ŠBootç‰ˆæœ¬ã€‚æˆ‘ä»¬è¦?çš„æ˜¯Operationç‰ˆæœ¬ä¿¡æ?¯ï¼Œ3Comåœ¨ç½‘ç«™ä¸Šå?‘å¸ƒçš„ç‰ˆæœ¬ã€?æˆ‘ä»¬è¦?å?‡çº§çš„ç‰ˆæœ¬ä¹Ÿéƒ½æ˜¯Operationç‰ˆæœ¬ã€‚å…¶ä»–ä¸¤ä¸ªç‰ˆæœ¬ä¿¡æ?¯ä¸?ç»?å¸¸ç”¨åˆ°ã€‚</p>
<p>2ï¼Ž   ç³»ç»Ÿè¿?è¡Œæ—¶é—´-Time Since Resetï¼Œä»Žè¿™é‡Œå?¯ä»¥çœ‹åˆ°ç³»ç»Ÿåˆ°ç›®å‰?å·²ç»?è¿?è¡Œäº†å¤šå¸¸æ—¶é—´ã€‚</p>
<p>3ï¼Ž   äº§å“?åº?åˆ—å?·-Serial Numberï¼Œè¿™ä¸ªåº?åˆ—å?·æ˜¯å”¯ä¸€çš„ï¼Œæ¯?å?°4200è®¾å¤‡éƒ½ä¸?ç›¸å?Œã€‚ç”¨æˆ·åœ¨3Comç½‘ç«™ä¸Šæ³¨å†Œè¯¥äº§å“?æ—¶éœ€è¦?è¾“å…¥è¿™ä¸ªåº?åˆ—å?·ï¼Œäº§å“?æœ‰ç¡¬ä»¶æ•…éšœéœ€è¦?æ›´æ?¢æ—¶ä¹Ÿè¦?å?‘3Comæ??ä¾›è¿™ä¸ªåº?åˆ—å?·ã€‚è¯¥åº?åˆ—å?·åœ¨æœºç®±åº•é?¢çš„æ ‡ç­¾å¤„ä¹Ÿå?¯ä»¥æŸ¥åˆ°ã€‚</p>
<p>ç³»ç»Ÿä¿¡æ?¯ä¸­çš„System Nameã€?Locationå?ŠContactå?¯ä»¥ç”±ç”¨æˆ·è‡ªè¡Œè®¾ç½®ï¼Œå‘½ä»¤å¦‚ä¸‹ï¼š</p>
<p>Select menu option: system management name</p>
<p>Select menu option: system management location</p>
<p>Select menu option: system management contact</p>
<p>ã€?æ?‚é¡¹åŠŸèƒ½ã€‘</p>
<p>ä¸‹é?¢åˆ—å‡ºçš„æ˜¯ä¸€äº›å¤§å®¶ç»?å¸¸ç”¨åˆ°çš„æ?‚é¡¹åŠŸèƒ½ã€‚</p>
<p>4200äº¤æ?¢æœºçš„é»˜è®¤ç”¨æˆ·å??æ˜¯ adminï¼Œå¯†ç ?æ²¡æœ‰</p>
<p>Login: admin</p>
<p>Password:</p>
<p>Menu options: &#8212;&#8212;&#8212;&#8212;&#8211;3Com SuperStack 3 Switch 4200&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p> bridge             &#8211; Administer bridge-wide parameters</p>
<p> gettingStarted     &#8211; Basic device configuration</p>
<p> logout             &#8211; Logout of the Command Line Interface</p>
<p> physicalInterface  &#8211; Administer physical interfaces</p>
<p> protocol           &#8211; Administer protocols</p>
<p> security           &#8211; Administer security</p>
<p> system             &#8211; Administer system-level functions</p>
<p> trafficManagement  &#8211; Administer traffic management</p>
<p>Type  ? for help</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option:</p>
<p>å°†é…?ç½®æ¸…ç©ºä¸ºå‡ºåŽ‚å€¼</p>
<p>Select menu option: system control init</p>
<p>WARNING: This command initializes the system to factory defaults</p>
<p>         (excluding Management IP configuration) and causes a reset.</p>
<p>Do you wish to continue (yes,no)[no]: y</p>
<p>Login:</p>
<p>[è¯´æ˜Ž]</p>
<p>1ï¼Ž   ç®¡ç?†IPä¸?ä¼šæ¸…ç©ºæˆ?å‡ºåŽ‚å€¼ï¼Œéœ€è¦?åˆ°è®¾ç½®ç®¡ç?†IPçš„è?œå?•ä¸‹å?•ç‹¬è®¾ç½®</p>
<p>2ï¼Ž   é…?ç½®æ¸…ç©ºå?Žï¼Œæœºå™¨ä¼šé‡?å?¯åŠ¨</p>
<p>3ï¼Ž   3Comäº¤æ?¢æœºçš„é…?ç½®ä¸?éœ€è¦?saveã€?writeç­‰å‘½ä»¤è¿›è¡Œä¿?å­˜ï¼Œè®¾ç½®å?Žç³»ç»Ÿè‡ªåŠ¨ä¿?å­˜ï¼Œé‡?æ–°å¼€æœºå?Žé…?ç½®ä¸?ä¼šä¸¢å¤±</p>
<p>4ï¼Ž   å»ºè®®æ‹¿åˆ°ä¸€å?°äº¤æ?¢æœºå?Žï¼Œå¼€å§‹é…?ç½®å‰?ï¼Œå…ˆå°†å…¶é…?ç½®æ¸…ç©ºä¸ºå‡ºåŽ‚å€¼</p>
<p>å¯†ç ?ä¸¢å¤±</p>
<p>Login: recover</p>
<p>Password:</p>
<p>*** Password Recovery Mode ***</p>
<p>The administrative password will be cleared if a hard reset operation is</p>
<p>carried out on the device within 30 seconds.</p>
<p>If a hard reset operation is not carried out during this period, the device</p>
<p>will return to the CLI login prompt</p>
<p>countdown =  30 29 28 27 26</p>
<p>*** Password Recovery Mode ***</p>
<p>Enter the new password for the admin user:</p>
<p>Re-enter the new password:</p>
<p>The Password Recovery feature is enabled.</p>
<p>Enter new value (enable,disable)[enable]:</p>
<p>Menu options: &#8212;&#8212;&#8212;&#8212;&#8211;3Com SuperStack 3 Switch 4200&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p> bridge             &#8211; Administer bridge-wide parameters</p>
<p> gettingStarted     &#8211; Basic device configuration</p>
<p> logout             &#8211; Logout of the Command Line Interface</p>
<p> physicalInterface  &#8211; Administer physical interfaces</p>
<p> protocol           &#8211; Administer protocols</p>
<p> security           &#8211; Administer security</p>
<p> system             &#8211; Administer system-level functions</p>
<p> trafficManagement  &#8211; Administer traffic management</p>
<p>Type  ? for help</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1) &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>1ï¼Ž   åœ¨ç™»å½•æ??ç¤ºæ—¶è¾“å…¥ç”¨æˆ·å??recoverï¼Œå¯†ç ?ä¹Ÿæ˜¯recover</p>
<p>2ï¼Ž   åœ¨ç³»ç»Ÿæ??ç¤ºçš„æ—¶é—´å†…(30ç§’)ï¼Œå¯¹äº¤æ?¢æœºæ–­ç”µï¼Œå†?åŠ ç”µ</p>
<p>3ï¼Ž   ç³»ç»Ÿé‡?æ–°å?¯åŠ¨å?Žï¼Œä¼šæ??ç¤ºä½ è¾“å…¥æ–°çš„adminç”¨æˆ·çš„å¯†ç ?</p>
<p>4ï¼Ž   ç³»ç»Ÿè¿˜ä¼šæ??ç¤ºæ˜¯å?¦å°†æ­¤å¯†ç ?æ?¢å¤?çš„åŠŸèƒ½å¼€å?¯è¿˜æ˜¯å…³é—­ï¼Œé»˜è®¤æ˜¯å¼€å?¯çŠ¶æ€?</p>
<p>ä¿®æ”¹ç™»å½•å¯†ç ?</p>
<p>Select menu option: sys mana password</p>
<p>Old password:</p>
<p>Enter new password:</p>
<p>Retype password:</p>
<p>The command line interface password has been successfully changed.</p>
<p>Select menu option:</p>
<p>ã€?åŸºæœ¬çš„äºŒå±‚äº¤æ?¢åŠŸèƒ½ã€‘</p>
<p>4200çš„åŸºæœ¬æ•°æ?®äº¤æ?¢åŠŸèƒ½ä¸?éœ€è¦?å?šä»»ä½•è®¾ç½®ã€‚è¿™ä¸€éƒ¨åˆ†å¯¹æˆ‘ä»¬æœ‰ç”¨çš„ä¿¡æ?¯æ˜¯MACåœ°å?€ï¼?ç«¯å?£å¯¹ç…§è¡¨ï¼Œé€šè¿‡ä»¥ä¸‹å‘½ä»¤å?¯ä»¥çœ‹åˆ°ã€‚</p>
<p>Select menu option: bri add summ</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,all,?): all</p>
<p>Location             Address                VLAN ID     Permanent</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Unit 1 Port 3        00-10-4b-a0-91-64      1           No</p>
<p>Unit 1 Port 11       00-09-6b-7a-6a-c6      1           No</p>
<p>Unit 1 Port 13       00-10-4b-a0-91-64      2           No</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ç”±ä¸Šé?¢å?¯ä»¥çœ‹åˆ°å?„ä¸ªç«¯å?£æ‰€è¿žè®¾å¤‡çš„MACåœ°å?€ï¼Œä»¥å?Šç›¸å…³çš„VLANä¿¡æ?¯ã€‚å¦‚æžœä¸€ä¸ªç«¯å?£ä¸‹é?¢è¿žçš„æ˜¯äº¤æ?¢æœºæˆ–è€…é›†çº¿å™¨ï¼Œé‚£ä¹ˆè¿™ä¸ªç«¯å?£ä¸Šä¼šå¯¹åº”å¤šä¸ªMACåœ°å?€ã€‚</p>
<p>ä¸Šé?¢ä¾‹å­?ä¸­æœ€å?Žä¸€é¡¹æ˜¯Permanentï¼Œæ‰€åˆ—çš„åœ°å?€éƒ½æ˜¯Noï¼Œè¯´æ˜Žè¿™å‡ ä¸ªåœ°å?€éƒ½æ˜¯äº¤æ?¢æœºå­¦ä¹ è€Œæ?¥çš„ï¼Œå½“è¿™ä¸ªç«¯å?£æ‰€è¿žæœºå™¨æ–­å¼€å?Žï¼Œè¿™ä¸ªåœ°å?€é¡¹åœ¨ä¸€æ®µæ—¶é—´å?Žä¼šè‡ªåŠ¨ä»Žè¡¨ä¸­æ¸…é™¤ã€‚</p>
<p>å?¯ä»¥æ‰‹å·¥æŠŠæŸ?ä¸ªæœºå™¨(å®žé™…æ˜¯è¯¥æœºå™¨çš„ç½‘å?¡)çš„MACåœ°å?€åŠ åˆ°è¡¨ä¸­ï¼Œå¦‚ä¸‹æ‰€ç¤ºï¼š</p>
<p>Select menu option: bri address add</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge port (AL1-AL4,unit:port,?): 1:8</p>
<p>Enter address: 00-10-4b-a0-91-64</p>
<p>Enter VLAN ID (1-2)[1]: 1</p>
<p>Select menu option: bri address summ</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,all,?): all</p>
<p>Location             Address                VLAN ID     Permanent</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Unit 1 Port 8        00-10-4b-a0-91-64      1           Yes</p>
<p>Unit 1 Port 11       00-09-6b-7a-6a-c6      1           No</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ä»¥ä¸Šä¾‹å­?æŠŠMACåœ°å?€00-10-4b-a0-91-64åŠ åˆ°Unit 1çš„ç«¯å?£8ä¸Šï¼Œæ‰€å±žçš„VLANæ˜¯1ã€‚æ­¤æ—¶ï¼ŒMACåœ°å?€ä¸º00-10-4b-a0-91-64çš„è®¡ç®—æœºå?ªæœ‰è¿žåˆ°Unit 1çš„ç«¯å?£8ä¸Šæ‰?èƒ½é€šï¼Œè¿žåˆ°å…¶ä»–ç«¯å?£ä¸?èƒ½é€šã€‚</p>
<p>æ³¨æ„?ï¼š</p>
<p>1.        å…¶ä»–MACåœ°å?€çš„è®¡ç®—æœºè¿žæŽ¥åˆ°ç«¯å?£8ä¸Šï¼Œé€šä¿¡å®Œå…¨æ­£å¸¸ã€‚</p>
<p>2.        å?¯ä»¥å°†å¤šä¸ªMACåœ°å?€æ‰‹å·¥å†™åˆ°å?Œä¸€ä¸ªç«¯å?£ä¸Šã€‚</p>
<p>å¦‚ä¸‹æ‰€ç¤ºï¼š</p>
<p>Select menu option (bridge/addressDatabase): summ</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,all,?): all</p>
<p>Location             Address                VLAN ID     Permanent</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Unit 1 Port 8        00-09-6b-7a-6a-c6      1           No</p>
<p>Unit 1 Port 8        00-10-4b-a0-91-24      1           Yes</p>
<p>Unit 1 Port 8        00-10-4b-a0-91-64      1           Yes</p>
<p>Select menu option (bridge/addressDatabase):</p>
<p>ã€?VLANåŠŸèƒ½ã€‘</p>
<p>é™¤äº†åŸºæœ¬çš„æ•°æ?®äº¤æ?¢åŠŸèƒ½ï¼ŒVLANæ˜¯æˆ‘ä»¬åœ¨é…?ç½®äº¤æ?¢æœºä¸­ç¢°åˆ°æœ€å¤šçš„äº†ã€‚ä¸‹é?¢ä¸¾ä¸¤ä¸ªä¾‹å­?æ?¥è¯´æ˜Žå¦‚ä½•é…?ç½®ã€‚</p>
<p>æ¡ˆä¾‹1ï¼š</p>
<p>åœ¨ä¸€å?°4200äº¤æ?¢æœºè¦?åˆ›å»º3ä¸ªVLANï¼Œåˆ†åˆ«ä¸ºå·¥ç¨‹å¸ˆã€?è´¢åŠ¡ã€?äººäº‹éƒ¨é—¨ä½¿ç”¨ï¼Œé»˜è®¤VLAN1ä¸?åŠ¨ï¼Œä½œä¸ºç®¡ç?†VLANï¼Œé…?ç½®å¦‚ä¸‹ï¼š</p>
<p>[åˆ›å»ºVLAN]</p>
<p>Select menu option: bri vlan create</p>
<p>Select VLAN ID (2-4094)[2]: 2</p>
<p>Enter VLAN Name [VLAN 2]: engineer</p>
<p>Select menu option: bri vlan create 3 finance</p>
<p>Select menu option: bri vlan create 4 hr</p>
<p>Select menu option: bri vlan summ all</p>
<p>VLAN ID   Name</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>1         Default VLAN</p>
<p>2         engineer</p>
<p>3         finance</p>
<p>4         hr</p>
<p>Select menu option:</p>
<p>[å?‘å?„ä¸ªVLANé‡ŒåŠ ç«¯å?£]</p>
<p>elect menu option: bri vlan modi add</p>
<p>Select VLAN ID (1-4)[1]: 2</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,?): 1:1-1:9</p>
<p>Enter tag type (untagged,tagged): un</p>
<p>Select menu option: bri vlan modi add 3 1:10-1:19 un</p>
<p>Select menu option: bri vlan modi add 4 1:20-1:29 un</p>
<p>Select menu option:</p>
<p>ç»?è¿‡ä»¥ä¸Šé…?ç½®ï¼Œç«¯å?£1åˆ°9åˆ’åˆ°VLAN2é‡Œï¼Œç«¯å?£10åˆ°19åˆ’åˆ°VLAN3é‡Œï¼Œç«¯å?£20åˆ°29åˆ’åˆ†åˆ°VLAN3ä¸­ï¼Œå…¶ä»–ç«¯å?£ä¿?ç•™åœ¨VLAN1ä¸­ã€‚</p>
<p>åœ¨å?Œä¸€VLANå†…çš„è®¡ç®—æœºå?¯ä»¥äº’ç›¸é€šä¿¡ï¼Œä¸?å?ŒVLANä¹‹é—´ä¸?èƒ½é€šä¿¡ã€‚</p>
<p>æ¡ˆä¾‹2ï¼š</p>
<p>ç»§ç»­æ¡ˆä¾‹1ã€‚æ¡ˆä¾‹1ä¸­çš„4200æ”¾åœ¨å…¬å?¸çš„2æ¥¼ï¼Œç»§ç»­å?‘å·¥ç¨‹å¸ˆã€?è´¢åŠ¡å?Šäººäº‹éƒ¨é—¨æ??ä¾›æŽ¥å…¥ç«¯å?£ã€‚çŽ°åœ¨åœ¨3æ¥¼å?ˆæ·»åŠ äº†ä¸€å?°4200ï¼Œä½†ä¸‰æ¥¼æœ‰å·¥ç¨‹å¸ˆå?Šè´¢åŠ¡éƒ¨é—¨ï¼Œæ²¡æœ‰äººäº‹éƒ¨é—¨ï¼Œè€Œä¸”å¤šäº†å¸‚åœºéƒ¨é—¨ã€‚ä¸¤å?°äº¤æ?¢æœºé€šè¿‡å?ƒå…†ç«¯å?£50(4250Täº¤æ?¢æœº)äº’è?”ã€‚è¦?æ±‚2æ¥¼å’Œ3æ¥¼çš„å·¥ç¨‹å¸ˆéƒ¨é—¨å’Œè´¢åŠ¡éƒ¨å†…éƒ¨èƒ½äº’é€šï¼Œéƒ¨é—¨ä¹‹é—´è¿˜æ˜¯ä¿?æŒ?ä¸?é€š(æ²¡æœ‰ä¸‰å±‚è®¾å¤‡ï¼Œç›¸é€šä¹Ÿæ²¡é—¨å„¿)ã€‚</p>
<p>[2æ¥¼4200æ·»åŠ å¦‚ä¸‹é…?ç½®]</p>
<p>Select menu option: bri vlan modi remove 1 1:50</p>
<p>WARNING: Ports 1:50 are no longer members of any VLANs.</p>
<p>ï¼›å°†50ç«¯å?£ä»ŽVLAN1ä¸­é™¤åŽ»ï¼Œå› ä¸ºæ­¤æ—¶50ç«¯å?£æ˜¯untagç«¯å?£ã€‚</p>
<p>Select menu option: bri vlan modi add 1 1:50 tag</p>
<p>ï¼›å°†50ç«¯å?£é‡?æ–°åŠ å…¥VLAN1(ç®¡ç?†VLAN)ï¼Œæ‰“ä¸Štagã€‚</p>
<p>Select menu option: bri vlan modi add 2 1:50 tag</p>
<p>ï¼›å°†50ç«¯å?£åŠ å…¥VLAN2(å·¥ç¨‹å¸ˆVLAN)ï¼Œæ‰“ä¸Štagã€‚</p>
<p>Select menu option: bri vlan modi add 3 1:50 tag</p>
<p>ï¼›å°†50ç«¯å?£åŠ å…¥VLAN3(è´¢åŠ¡VLAN)ï¼Œæ‰“ä¸Štagã€‚</p>
<p>[3æ¥¼4200é…?ç½®]</p>
<p>åˆ›å»ºVLAN</p>
<p>Select menu option: bri vlan create 2 engineer</p>
<p>Select menu option: bri vlan create 3 finance</p>
<p>Select menu option: bri vlan create 5 marketing</p>
<p>å?‘å?„ä¸ªVLANä¸­åŠ ç«¯å?£</p>
<p>Select menu option: bri vlan modi add 5 1:1-1:9 un</p>
<p>Select menu option: bri vlan modi add 2 1:10-1:19 un</p>
<p>Select menu option: bri vlan modi add 3 1:20-1:29 un</p>
<p>å°†ç«¯å?£50åˆ’åˆ°VLAN1ï¼Œ2ï¼Œ3ä¸­</p>
<p>Select menu option: bri vlan modi remove 1 1:50</p>
<p>Select menu option: bri vlan modi add 1 1:50 tag</p>
<p>Select menu option: bri vlan modi add 2 1:50 tag</p>
<p>Select menu option: bri vlan modi add 3 1:50 tag</p>
<p>ç»?è¿‡ä»¥ä¸Šé…?ç½®ï¼Œä¸¤å?°4200é€šè¿‡ç«¯å?£50ï¼Œå?¯ä»¥ä½¿VLAN1(ç®¡ç?†VLAN)ã€?VLAN2(å·¥ç¨‹å¸ˆVLAN)å?ŠVLAN3(è´¢åŠ¡VLAN)å†…éƒ¨å?¯ä»¥äº’é€šï¼Œå·¥ç¨‹å¸ˆéƒ¨é—¨å’Œè´¢åŠ¡éƒ¨é—¨çš„è®¡ç®—æœºå?³ä½¿ä¸?åœ¨ä¸€ä¸ªä¸€å±‚æ¥¼ï¼Œä¹Ÿèƒ½äº’ç›¸é€šä¿¡ã€‚ä¸ºäº†æ–¹ä¾¿ç®¡ç?†ï¼Œè®©ç®¡ç?†VLANï¼Œå?³VLAN1ä¹Ÿèƒ½å¤Ÿäº’é€šã€‚ä¸?å?ŒVLANä¹‹é—´è¿˜æ˜¯ä¿?æŒ?ä¸?é€šã€‚</p>
<p>ä¸¥é‡?æ??é†’ï¼š3Comäº¤æ?¢æœºVLANé…?ç½®ä¸­æœ‰å…³ç«¯å?£æ‰“Tag(ä»¥å‰?å?«802.1Q)çš„ä¸‰åŽŸåˆ™</p>
<p>1ï¼Ž  äº¤æ?¢æœºä¸Šçš„æŸ?ä¸ªç«¯å?£è¦?å±žäºŽå¤šä¸ªVLANï¼Œåˆ™è¯¥ç«¯å?£ä¸€å®šè¦?æ‰“tag</p>
<p>2ï¼Ž  äº¤æ?¢æœºçš„æŸ?ä¸ªç«¯å?£æ‰“äº†tagï¼Œä¸Žå®ƒç›¸è¿žçš„å¯¹ç«¯çš„äº¤æ?¢æœºç«¯å?£ (æˆ–ç½‘å?¡)ä¹Ÿè¦?æ‰“tag</p>
<p>3ï¼Ž  æŸ?ä¸ªç«¯å?£å?¯ä»¥åœ¨ä¸€ä¸ªVLANä¸­æ˜¯untagæ–¹å¼?(æ”¶å?‘ä¸?å¸¦802.1Qçš„æ•°æ?®åŒ…)ï¼Œåœ¨å…¶ä»–å¤šä¸ªVLANä¸­æ˜¯tagæ–¹å¼?(æ”¶å?‘å¸¦802.1Qçš„æ•°æ?®åŒ…)ã€‚è¿™æ—¶å¦‚æžœä¸¤ç«¯è®¾ç½®ä¸?å½“ï¼Œä¼šä½¿ä¸?å?ŒVLANäº’é€šï¼Œå› æ­¤éœ€æ³¨æ„?ã€‚</p>
<p>[æ³¨ï¼šæœ‰å…³VLANï¼ŒçŒ«è…»çš„ä¸œè¥¿è¿˜æ˜¯æŒºå¤šçš„ï¼Œå¦‚4200æ”¯æŒ?çš„æ˜¯Open VLANæ–¹å¼?ï¼Œé‚£ä½?å¤§å“¥é—²ç?€æ²¡äº‹å¹²ï¼Œå?¯ä»¥ç?¢ç£¨ç?¢ç£¨]</p>
<p>ã€?ç«¯å?£è®¾ç½®ã€‘</p>
<p>å¯¹4200äº¤æ?¢æœºç«¯å?£çš„è®¾ç½®åŒ…æ‹¬å°†ç«¯å?£blockï¼Œè§£é™¤blockï¼Œæ”¹å?˜ç«¯å?£çš„å·¥ä½œçŠ¶æ€?ç­‰ã€‚å‘½ä»¤åœ¨Select menu option (physicalInterface/ethernet): å­?è?œå?•ä¸‹ã€‚ä¸‹é?¢ä¸¾ä¾‹åˆ—å‡ºä¸€äº›å?¯èƒ½ç”¨åˆ°çš„è®¾ç½®</p>
<p>å°†ç«¯å?£1åˆ°10é˜»å¡žï¼Œblockå?Žï¼Œç«¯å?£çš„çŠ¶æ€?ç?¯ä¼šåœ¨ç»¿/é»„ä¹‹é—´äº¤äº’é—ªçƒ?</p>
<p>Select menu option (physicalInterface/ethernet): portstate</p>
<p>This operation may take a number of seconds</p>
<p>Select Ethernet ports (unit:port&#8230;,?): 1:1-1:10</p>
<p>Enter new value (enable,disable)[enable]: dis</p>
<p>æ”¹å?˜ç«¯å?£2åˆ°5çš„è‡ªå??å•†æ–¹å¼?</p>
<p>Select menu option (physicalInterface/ethernet): portmode</p>
<p>This operation may take a number of seconds</p>
<p>Select Ethernet ports (unit:port&#8230;,?): 1:2-1:5</p>
<p>Enter auto-negotiation mode (enable,disable)[disable]: en</p>
<p>Enter fallback port mode (10half,10full,100half,100full)[10half]: 10full</p>
<p>[è¯´æ˜Ž]</p>
<p>ç«¯å?£é»˜è®¤æƒ…å†µä¸‹auto-negotiationæ–¹å¼?æ˜¯enableçš„ã€‚Fallback port modeæ˜¯æŒ‡å½“ç«¯å?£è‡ªå??å•†æ–¹å¼?å¤±è´¥æ—¶ï¼Œæœ€å?Žåˆ°é‚£ä¸ªå·¥ä½œé€ŸçŽ‡</p>
<p>å¦‚æžœè¦?æŒ‡å®šç«¯å?£çš„å·¥ä½œé€ŸçŽ‡å?Šå…¨å?Œå·¥æ¨¡å¼?ï¼Œéœ€è¦?å°†auto-negotiationå…³é—­ï¼Œå†?è®¾ç½®é€ŸçŽ‡å?Šå?Œå·¥æ¨¡å¼?</p>
<p>smartAutosenseçš„è®¾ç½®</p>
<p>Select menu option (physicalInterface/ethernet): smartau</p>
<p>Enter new value (enable,disable)[enable]: en</p>
<p>Select menu option (physicalInterface/ethernet):</p>
<p>[è¯´æ˜Ž]</p>
<p>smartAutosenseæ˜¯ä¸€ä¸ªå¯¹äº¤æ?¢æœºçš„è®¾ç½®ï¼Œä¸?èƒ½æŒ‡å®šå…·ä½“ç«¯å?£è¿›è¡Œè®¾ç½®ã€‚</p>
<p>å½“smartAutosense è®¾ç½®ä¸ºenableæ—¶ï¼Œå¯¹äºŽåœ¨auto-negotiationçŠ¶æ€?çš„ç«¯å?£ï¼Œäº¤æ?¢æœºä¼šæ ¹æ?®è¯¥ç«¯å?£ç»Ÿè®¡çš„é”™è¯¯åŒ…æ•°æ?¥è°ƒæ•´ç«¯å?£é€ŸçŽ‡ã€‚ä¾‹å¦‚ï¼Œç«¯å?£5çš„auto- negotiationä¸ºenableï¼Œå½“å‰?å·¥ä½œæ–¹å¼?ä¸º100fullï¼Œå¦‚æžœè¯¥ç«¯å?£åœ¨æŸ?ä¸€æ—¶é—´æ®µå†…æ”¶åˆ°çš„é”™è¯¯åŒ…æ•°è¶…è¿‡äº†ä¸€å®šæ•°é‡?ï¼Œåˆ™äº¤æ?¢æœºè‡ªåŠ¨å°†è¯¥ç«¯å?£çš„å·¥ä½œæ¨¡å¼?å?‘ä¸‹é™?ã€‚</p>
<p>ã€?å †å? ã€‘</p>
<p>4200äº¤æ?¢æœºåœ¨v2.0ç‰ˆæœ¬ä»¥å?Žï¼Œæ”¯æŒ?å †å? åŠŸèƒ½ã€‚å †å? ä»¥å?Žçš„äº¤æ?¢æœºå?¯ä»¥ä½œä¸ºä¸€ä¸ªæ•´ä½“æ?¥ç®¡ç?†ï¼Œå¦‚ä¸‹å›¾æ‰€ç¤ºï¼š</p>
<p>æ³¨æ„?ç‚¹å¦‚ä¸‹ï¼š</p>
<p>1.          4200çš„å †å? ä¸?éœ€è¦?å?¦å¤–é…?ç½®æ¨¡å?—(ä½ æƒ³é…?ä¹Ÿæ²¡åœ°æ–¹æ?’å•Š)ã€‚å?ªéœ€è¦?ç”¨è¶…5ç±»çš„ç½‘çº¿å°†äº¤æ?¢æœºçš„UPã€?DOWNç«¯å?£å¦‚ä¸Šå›¾æ‰€ç¤ºè¿žæŽ¥èµ·æ?¥å?³å®Œæˆ?ï¼Œä¸?éœ€è¦?åœ¨äº¤æ?¢æœºé‡Œä½œä»»ä½•é…?ç½®ã€‚</p>
<p>2.          ä¸€ä¸ªå †å? æœ€å¤šå?ªèƒ½æœ‰4å?°äº¤æ?¢æœºï¼Œäº¤æ?¢æœºåž‹å?·å?¯ä»¥ä¸?å?Œï¼Œä½†å¼ºçƒˆå»ºè®®å…¶è½¯ä»¶ç‰ˆæœ¬ä¸€è‡´ã€‚æœ€å¥½åœ¨å †å? å‰?å¯¹å…¶è½¯ä»¶ç‰ˆæœ¬è¿›è¡Œæ£€æŸ¥ï¼Œå¹¶å°†æ²¡å?°è®¾å¤‡çš„é…?ç½®æ¸…ç©ºåˆ°å‡ºåŽ‚å€¼å?Žå†?å †å? ã€‚</p>
<p>3.          UPã€?DOWNç«¯å?£åœ¨ä¸?å †å? æ—¶ï¼Œå?¯ä»¥ä½œä¸ºæ™®é€šçš„10/100/1000Base-Tç«¯å?£æ?¥ç”¨ã€‚åœ¨å †å? æ—¶ï¼Œå¿…é¡»æ˜¯UP-DOWNç›¸è¿žï¼Œä¸?èƒ½UP-UPæˆ– DOWN-DOWNç›¸è¿žã€‚ä¹Ÿä¸?å…?è®¸å°†æœ€ä¸Šé?¢äº¤æ?¢æœºçš„UPå?£ä¸Žæœ€ä¸‹é?¢äº¤æ?¢æœºçš„DOWNç«¯å?£ç›¸è¿žï¼Œå?³ä¸?å…?è®¸å½¢æˆ?çŽ¯ã€‚</p>
<p>4.          å‰?é?¢åœ¨å¾ˆå¤šåœ°æ–¹æ??åˆ°è¿‡Unitï¼ŒUnitå°±æ˜¯æŒ‡åœ¨ä¸€ä¸ªå †å? ä¸­çš„è®¡ç®—æœºã€‚å¦‚æžœ1å?°è®¡ç®—æœºæ²¡æœ‰å †å? ï¼Œåˆ™å®ƒå?ªæ˜¯Unit 1ã€‚å¦‚æžœ1ä¸ªå †å? ä¸­æœ‰3å?°è®¡ç®—æœºï¼Œåˆ™åº”è¯¥åˆ†åˆ«æ˜¯Unit 1ã€?2ã€?3ã€‚å…·ä½“çš„Unitå?·åœ¨äº¤æ?¢æœºå‰?é?¢æ?¿ä¸Šæœ‰æŒ‡ç¤ºç?¯æ˜¾ç¤ºã€‚</p>
<p>5.          å½“ç™»å½•åˆ°äº¤æ?¢æœºä¸Šå¯¹äº¤æ?¢æœºè¿›è¡Œé…?ç½®æ—¶ï¼Œæ¯?æ¬¡ä½ è¾“å…¥å‘½ä»¤å‰?ï¼Œéƒ½æœ‰ä¸€è¡Œè™šçº¿çš„æŒ‡ç¤ºè¡Œã€‚è¯¥è¡Œæ‹¬å?·ä¸­çš„æ•°å­—å?³æ˜¯ä½ æ‰€é…?ç½®çš„äº¤æ?¢æœºåœ¨å †å? ä¸­çš„Unitå?·ã€‚å¦‚ä¸‹é?¢å°±åœ¨é…?ç½®Unit 2ã€‚</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (2)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option:</p>
<p>6.          åœ¨å?Œä¸€ä¸ªå †å? é‡Œï¼Œå¦‚æžœä½ è¦?ä»Žä¸€ä¸ªUnitè½¬åˆ°å?¦ä¸€ä¸ªUnitï¼Œåœ¨ä»¥ä¸‹è?œå?•ä¸­é€‰æ‹©å?³å?¯(æœ¬ä¾‹å­?ä¸­å?ªæœ‰ä¸€å?°è®¾å¤‡ï¼Œæ‰€ä»¥å?ªæœ‰ä¸€ä¸ªé€‰æ‹©)ï¼š</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option: sys unit select</p>
<p>Select unit (1):</p>
<p>7.          å½“ä½ è¿›è¡Œè®¾ç½®æ—¶ï¼Œé…?ç½®ä¼šåœ¨æ•´ä¸ªå †å? å†…ç”Ÿæ•ˆï¼Œå¦‚åˆ›å»ºçš„VLANã€‚åœ¨å?‘VLANé‡ŒåŠ ç«¯å?£æ—¶ï¼Œä¹Ÿå?¯ä»¥é€šè¿‡æŒ‡å®šä¸?å?Œçš„Unitå?·å°†ä¸?å?ŒUnitä¸Šçš„ç«¯å?£åˆ’åˆ°å?Œä¸€ä¸ªVLANä¸­ã€‚</p>
<p>ã€?ç”Ÿæˆ?æ ‘-Spanning Tree Protocolã€‘</p>
<p>4200æ”¯æŒ?ç”Ÿæˆ?æ ‘STPå’Œå¿«é€Ÿç”Ÿæˆ?æ ‘RSTPå??è®®ã€‚RSTPæ˜¯STPçš„æ”¹è¿›ç‰ˆæœ¬ï¼Œå¹¶ä¸”å?‘ä¸‹å…¼å®¹ï¼Œå?³å¦‚ä¸‹æƒ…å†µï¼Œå½“4200äº¤æ?¢æœºä¸Šå?¯åŠ¨RSTPï¼Œå½“ç«¯å?£æ£€æµ‹åˆ°è¯¥ç«¯å?£æ‰€è¿žè®¾å¤‡å?ªæ”¯æŒ?STPæ—¶ï¼Œè¯¥ç«¯å?£ä¼šè‡ªåŠ¨é™?åˆ°æ”¯æŒ?STPã€‚</p>
<p>STP/RSTPå¸¸ç”¨çš„è®¾ç½®æœ‰å¦‚ä¸‹ä¸€äº›ï¼š</p>
<p>Select menu option: bri spann stpver</p>
<p>Enter Spanning Tree version &#8211; 0=STP, or 2=RSTP (0,2)[2]: 2</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>å?¯ä»¥è®¾ç½®ä¿®æ”¹4200æ”¯æŒ?RSTPè¿˜æ˜¯STPï¼Œé»˜è®¤æ˜¯RSTPã€‚</p>
<p>Select menu option: bri spann stpstate</p>
<p>Enter new value (enable,disable)[enable]: dis</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>å°†RSTP/STPåŠŸèƒ½æ¿€æ´»æˆ–è€…å…³é—­ï¼Œå¯¹æ•´ä¸ªäº¤æ?¢æœºæœ‰æ•ˆã€‚äº¤æ?¢æœºé»˜è®¤æ—¶æœ‰æ•ˆã€‚</p>
<p>Select menu option: bri spann stppri</p>
<p>Select stp priority (?)[32768]: ?</p>
<p>One of the following items may be selected at this prompt:</p>
<p>0,4096,8192,12288,16384,20480,24576,28672,32768,36864,40960,45056,49152,53248,57</p>
<p>344,61440</p>
<p>Select stp priority (?)[32768]: 8192</p>
<p>[è¯´æ˜Ž]</p>
<p>è®¾ç½®äº¤æ?¢æœºåœ¨é€‰æ‹©ç”Ÿæˆ?æ ‘æ ¹æ—¶çš„ä¼˜å…ˆå€¼ï¼Œè¯¥å€¼è¶Šå°?è¡¨ç¤ºä¼˜å…ˆå€¼è¶Šé«˜ã€‚å¦‚æžœæ‰€æœ‰äº¤æ?¢æœºçš„ä¼˜å…ˆå€¼ä¸€æ ·ï¼Œç”Ÿæˆ?æ ‘ä¼šé€‰æ‹©MACå°?çš„äº¤æ?¢æœºä½œä¸ºç”Ÿæˆ?æ ‘çš„æ ¹(ä¼˜å…ˆå€¼+MAC)ã€‚</p>
<p>Select menu option: bri port stpfa</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,?): 1:9</p>
<p>Enter new value (enable,disable)[enable]: dis</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>ä»¥ä¸Šå‘½ä»¤å?¯ä»¥å¯¹äº¤æ?¢æœºæ¯?ä¸ªç«¯å?£çš„StpFastStartè¿›è¡Œè®¾ç½®ã€‚è¿™ä¸ªå?‚æ•°å?ªæœ‰å½“STP/RSTPåŠŸèƒ½å?¯åŠ¨æ—¶æ‰?èµ·ä½œç”¨ã€‚</p>
<p>Select menu option: bri port stpcost</p>
<p>This operation may take a number of seconds</p>
<p>Select bridge ports (AL1-AL4,unit:port&#8230;,?): 1:3</p>
<p>Enter new value (1-200000000,auto)[19]: 10</p>
<p>Select menu option:</p>
<p>[è¯´æ˜Ž]</p>
<p>å¯¹ç«¯å?£çš„costå€¼è¿›è¡Œè®¾ç½®ï¼Œè¿™æ ·å?¯ä»¥æ‰‹å·¥æ”¹å?˜ç«¯å?£åœ¨STP/RSTPé€‰æ‹©ä¸­çš„ä¼˜å…ˆé¡ºåº?ã€‚Costå€¼è¶Šä½Žï¼Œè¢«é€‰ä¸­ä½œä¸ºforwardingç«¯å?£çš„ä¼˜å…ˆçº§è¶Šé«˜ã€‚</p>
<p>å¦‚ä¸Šé?¢ä¾‹å­?ä¸­æ‰€ç¤ºï¼Œå°†ç«¯å?£3çš„costå€¼è®¾ä¸º10ï¼Œå…¶ä»–ç«¯å?£çš„é»˜è®¤å€¼19ä¸?å?˜ã€‚åˆ™å½“ç«¯å?£3å?‚åŠ STP/RSTPé€‰æ‹©forwardingç«¯å?£æ—¶ï¼Œä¼šåˆ«ä¼˜å…ˆé€‰ä¸­ä¸ºforwardingï¼Œå…¶ä»–å?‚åŠ é€‰æ‹©çš„ç«¯å?£ä¸ºblockçŠ¶æ€?ã€‚</p>
<p>ã€?ç«¯å?£å®‰å…¨PortSecurityã€‘</p>
<p>å‰?é?¢åœ¨åŸºæœ¬çš„äºŒå±‚äº¤æ?¢åŠŸèƒ½ä¸­ä»‹ç»?è¿‡ï¼Œå?¯ä»¥æŠŠæŸ?å?°è®¾å¤‡çš„MACåœ°å?€æ‰‹å·¥å†™åˆ°4200çš„æŸ?ä¸ªç«¯å?£ä¸Šï¼Œè¿™æ ·ï¼Œè¿™ä¸ªè®¾å¤‡å?ªèƒ½è¿žåˆ°è¯¥ç«¯å?£ï¼Œå¦‚æžœè¿žåˆ°å…¶ä»–ç«¯å?£ï¼Œåˆ™ä¸?é€šã€‚</p>
<p>ç”¨æˆ·åœ¨ä½¿ç”¨ä¸­ç»?å¸¸æœ‰ä¸Žå…¶ç›¸å??çš„åº”ç”¨ï¼Œå?³æŸ?ä¸ªç«¯å?£å?ªå…?è®¸æŸ?ä¸€å?°æˆ–å‡ å?°è®¾å¤‡æŽ¥å…¥ï¼Œè€Œä¸?å…?è®¸å…¶ä»–è®¾å¤‡æŽ¥å…¥ï¼Œè¿™æ—¶å€™å?¯ä»¥åˆ©ç”¨4200äº¤æ?¢æœºçš„PortSecurityåŠŸèƒ½ã€‚</p>
<p>Select menu option: secu net acc</p>
<p>Menu options: &#8212;&#8212;&#8212;&#8212;&#8211;3Com SuperStack 3 Switch 4200&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p> portSecurity       &#8211; Configure port security</p>
<p>Type \&#8221;quit\&#8221; to return to the previous menu or  ? for help</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option (security/network/access): ports</p>
<p>Select user ports (unit:port&#8230;,?): 1:3</p>
<p>Enter mode of operation (?)[noSecurity]: ?</p>
<p>One of the following items may be selected at this prompt:</p>
<p>noSecurity,continuallyLearn,autoLearn</p>
<p>Enter mode of operation (?)[noSecurity]: autol</p>
<p>Enter the number of authorized addresses (0-79)[1]: 5</p>
<p>Enter Disconnect Unauthorized Device mode (?)[noAction]: ?</p>
<p>One of the following items may be selected at this prompt:</p>
<p>noAction,permanentlyDisable,temporaryDisable</p>
<p>Enter Disconnect Unauthorized Device mode (?)[noAction]: noac</p>
<p>Select menu option (security/network/access):</p>
<p>[è¯´æ˜Ž]</p>
<p>ä¸Šé?¢ä¾‹å­?ä¸­ï¼Œç«¯å?£3è®¾ç½®ä¸ºautolearnæ–¹å¼?ï¼Œå…?è®¸çš„åœ°å?€ä¸ªæ•°ä¸º5ä¸ª(è¯¥ç«¯å?£æ‰€å­¦åˆ°çš„å‰?5ä¸ªåœ°å?€)ï¼Œå¯¹äºŽ5ä¸ªä»¥å?Žçš„MACåœ°å?€ï¼Œè®¾å¤‡å?³ä½¿è¿žåˆ°ç«¯å?£3ä¸Šï¼Œä¹Ÿä¸?èƒ½é€šä¿¡ã€‚</p>
<p>ä¸‹é?¢æ˜¯ä¸€äº›ç®€å?•çš„å?‚æ•°è¯´æ˜Žï¼Œmode of operationæœ‰3ä¸ªå?‚æ•°ï¼ŒnoSecurityï¼ŒcontinuallyLearnå?ŠautoLearnã€‚å¦‚æžœé’ˆå¯¹ä¸€ä¸ªç«¯å?£è®¾ç½®ï¼Œé€‰æ‹©autoLearnã€‚</p>
<p>DUD-Disconnect Unauthorized Deviceæ¨¡å¼?æœ‰ä¸‰ä¸ªï¼ŒnoActionï¼ŒpermanentlyDisableï¼ŒtemporaryDisableã€‚å¦‚æžœé€‰æ‹©å?Žä¸¤ä¸ªï¼Œå½“ç«¯å?£ä¸Šæ‰€å­¦åˆ°çš„MACåœ°å?€è¶…è¿‡å…?è®¸çš„ä¸ªæ•°æ—¶ï¼Œè¯¥ç«¯å?£ä¼šè‡ªåŠ¨downæŽ‰ï¼›å¦‚æžœé€‰æ‹©noActionï¼Œç«¯å?£ä¸?ä¼šé—­å¡žï¼Œä½†å?Žé?¢è¿žä¸Šæ?¥çš„è®¾å¤‡ä¸?èƒ½é€šä¿¡ï¼Œè¿™æ˜¯å¤§éƒ¨åˆ†æƒ…å†µä¸‹æˆ‘ä»¬å¸Œæœ›çš„ã€‚</p>
<p>ã€?ç»„æ’­è¿‡è™‘-Multicast Filterã€‘</p>
<p>4200æ”¯æŒ?ç»„æ’­è¿‡è™‘åŠŸèƒ½ã€‚å?¯ä»¥é€šè¿‡è®¾ç½®IGMPçš„Snoopingå’ŒQueryingæ?¥å®žçŽ°ã€‚å…¶å‘½ä»¤è¡Œæ–¹å¼?å¦‚ä¸‹ï¼š</p>
<p>Select menu option: bri multi igmp</p>
<p>Menu options: &#8212;&#8212;&#8212;&#8212;&#8211;3Com SuperStack 3 Switch 4200&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p> queryMode          &#8211; Enable/disable IGMP querying</p>
<p> snoopMode          &#8211; Enable/disable IGMP Multicast learning</p>
<p>Type \&#8221;quit\&#8221; to return to the previous menu or  ? for help</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option (bridge/multicastFilter/igmp): query</p>
<p>Enter new value (enable,disable)[disable]: en</p>
<p>Select menu option (bridge/multicastFilter/igmp): snoopmo</p>
<p>Enter new value (enable,disable)[enable]: en</p>
<p>[è¯´æ˜Ž]</p>
<p>å½“snoopmodeä¸ºdisableæ—¶ï¼Œäº¤æ?¢æœºä¼šæŠŠç»„æ’­æ•°æ?®åŒ…å½“ä½œå¹¿æ’­æ?¥å¤„ç?†ï¼Œå?³å?‘æ‰€æœ‰ç«¯å?£è½¬å?‘ã€‚æ­¤æ—¶ç½‘ç»œçŽ¯å¢ƒä¸­å¦‚æžœæœ‰ç»„æ’­åº”ç”¨ï¼Œä¸€å®šä¼šé€šï¼Œä½†æµªè´¹å¸¦å®½ï¼Œä¸§å¤±äº†ç»„æ’­çš„ä¼˜åŠ¿ã€‚</p>
<p>å½“snoopmodeä¸ºenableæ—¶ï¼Œ4200äº¤æ?¢æœºä¼šå¯¹ç»„æ’­æ•°æ?®è¿›è¡Œè¿‡è™‘ï¼Œç«¯å?£æ‰€è¿žè®¾å¤‡è¦?æŽ¥å?—ç»„æ’­æ•°æ?®ï¼Œå°±å?‘è¯¥ç«¯å?£è½¬å?‘ï¼Œå?¦åˆ™ï¼Œå°±ä¸?å?‘è¯¥ç«¯å?£è½¬å?‘ã€‚</p>
<p>æ³¨æ„?å½“snoopmodeä¸ºenableæ—¶ï¼Œæœ¬ç½‘æ®µä¸­å¿…é¡»æœ‰ä¸€å?°è®¾å¤‡çš„querymodeè®¾ç½®ä¸ºenableï¼Œè¿™æ ·ï¼Œæ‰?èƒ½çŸ¥é?“ç½‘ç»œä¸­é‚£äº›è®¡ç®—æœºè¦?æŽ¥å?—ç»„æ’­ã€‚</p>
<p>ã€?è½¯ä»¶å?‡çº§ã€‘</p>
<p>4200çš„è½¯ä»¶å?¯ä»¥åœ¨3Comçš„è‹±æ–‡ç½‘ç«™å…?è´¹èŽ·å¾—ï¼Œä½†éœ€è¦?ç”¨æˆ·å…ˆæ³¨å†Œï¼Œå¹¶å°†4200äº§å“?è¿›è¡Œæ³¨å†Œï¼Œå½“ç„¶ï¼Œäº§å“?æ¯?ç§?å?ªæ³¨å†Œä¸€å?°å?³å?¯ã€‚</p>
<p>å»ºè®®ç”¨TFTPæ–¹å¼?å¯¹4200äº¤æ?¢æœºè¿›è¡Œå?‡çº§ï¼Œå?‡çº§æ—¶ï¼Œ4200ä½œä¸ºClientç«¯ï¼Œå­˜æœ‰4200è½¯ä»¶çš„è®¡ç®—æœºä½œä¸ºTFTPçš„Server ç«¯ã€‚TFTPçš„è½¯ä»¶åœ¨3Comçš„ç½‘ç«™ä¸Šå?¯ä»¥å…?è´¹ä¸‹è½½ï¼Œåœ¨éš?æœºçš„å…‰ç›˜ä¸­ä¹Ÿæœ‰ã€‚</p>
<p>å?‡çº§è¿‡ç¨‹åœ¨æ¯?ä¸ªç‰ˆæœ¬çš„ReleaseNoteä¸­æœ‰è¯¦ç»†ä»‹ç»?ï¼Œä¸€èˆ¬åœ¨æ–‡æ¡£çš„æœ€å?Žã€‚</p>
<p>Select menu option: sys con</p>
<p>Menu options: &#8212;&#8212;&#8212;&#8212;&#8211;3Com SuperStack 3 Switch 4200&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p> initialize         &#8211; Reset to factory defaults</p>
<p> reboot             &#8211; Perform system reboot</p>
<p> softwareUpgrade    &#8211; Perform agent software upgrade</p>
<p>Type \&#8221;quit\&#8221; to return to the previous menu or  ? for help</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; (1)&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Select menu option (system/control): soft</p>
<p>TFTP Server Address [0.0.0.0]:10.10.10.8</p>
<p>File Name           []:s4202_03.bin</p>
<p>[è¯´æ˜Ž]</p>
<p>ä»¥ä¸Š10.10.10.8æ˜¯ä¸Ž4200æ‰€è¿žçš„TFTP Serverçš„åœ°å?€ã€‚</p>
<p>S4202_03.bin æ˜¯ä»Ž3Comç½‘ç«™ä¸Šä¸‹è½½çš„4200çš„è½¯ä»¶ï¼Œåº”è¯¥ä¿?å­˜åœ¨TFTP Serverçš„é»˜è®¤ç›®å½•ä¸‹ã€‚ä»Ž3Comç½‘ç«™ä¸Šä¸‹è½½çš„æ˜¯.exeæ–‡ä»¶ï¼Œè¿?è¡Œå?Žé‡Šæ”¾å‡ºå?‡çº§è½¯ä»¶å?Šè¯¥è½¯ä»¶ç‰ˆæœ¬çš„ReleaseNotesï¼Œè¦?æ±‚ç”¨æˆ·åœ¨å?‡çº§å‰?ä¸€å®šè¦?è¯»ä¸€é??ReleaseNotesã€‚</p></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/29/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/29/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=29&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/3com-superstack3-switch4200%e7%b3%bb%e5%88%97%e4%ba%a4%e6%8d%a2%e6%9c%ba%e4%b8%ad%e6%96%87%e7%94%b5%e5%ad%90%e6%89%8b%e6%8a%84%e6%9c%ac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>Squid</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/squid/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/squid/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 15:26:40 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/squid/</guid>
		<description><![CDATA[ä½¿ç”¨Squidå?šä»£ç?†æœ?åŠ¡å™¨ http://www.sina.com.cn 2001/10/31 17:03 èµ›è¿ªç½‘-ä¸­å›½è®¡ç®—æœºæŠ¥ æ–‡/æ?¨é¹? è¯´åˆ°ä»£ç?†æœ?åŠ¡å™¨ï¼Œæˆ‘ä»¬æœ€å…ˆæƒ³åˆ°çš„å?¯èƒ½æ˜¯ä¸€äº›ä¸“é—¨çš„ä»£ç?†æœ?åŠ¡å™¨ç½‘ç«™ï¼ŒæŸ?äº›æƒ…å†µä¸‹ï¼Œé€šè¿‡å®ƒä»¬èƒ½åŠ å¿«è®¿é—®äº’è?”ç½‘çš„é€Ÿåº¦ã€‚å…¶å®žï¼Œåœ¨éœ€è¦?è®¿é—®å¤–éƒ¨çš„å±€åŸŸç½‘ä¸­ï¼Œæˆ‘ä»¬è‡ªå·±å°±èƒ½è®¾ç½®ä»£ç?†ï¼ŒæŠŠè®¿é—®æ¬¡æ•°è¾ƒå¤šçš„ç½‘é¡µä¿?å­˜åœ¨ç¼“å­˜ä¸­ï¼Œä»Žè€Œâ€œæ??é«˜â€?ç½‘ç»œé€Ÿåº¦ã€‚æ›´é‡?è¦?çš„æ˜¯ï¼Œæˆ‘ä»¬èƒ½é€šè¿‡ä»£ç?†æœ?åŠ¡å™¨ï¼Œè¾¾åˆ°æŽ§åˆ¶è®¿é—®æ?ƒé™?çš„ç›®çš„ã€‚åœ¨Windowsä¸­ï¼Œæœ‰å¾ˆå¤šè¿™æ ·çš„è½¯ä»¶ï¼Œå¦‚ï¼šWinGateã€?SyGateç­‰ï¼Œä¸?è¿‡ï¼Œæœ¬æ–‡è¦?è®¨è®ºçš„ï¼Œæ˜¯èƒ½ç»™ä½ å……åˆ†è‡ªç”±çš„Linuxä¸‹çš„Squidã€‚ Linuxä¸‹çš„ä»£ç?†æœ?åŠ¡å™¨è½¯ä»¶ä¹Ÿä¸?æ˜¯å?ªæœ‰Squidï¼Œä¸?è¿‡åœ¨å¤§éƒ¨åˆ†Linuxç‰ˆæœ¬ä¸­éƒ½å¸¦æœ‰å®ƒã€‚ èµ°è¿›â€œä»£ç?†â€? é¦–å…ˆï¼Œæˆ‘ä»¬æ?¥äº†è§£ä¸€ä¸‹ä»£ç?†æœ?åŠ¡å™¨çš„å·¥ä½œåŽŸç?†ã€‚ä»£ç?†æœ?åŠ¡å™¨å…¶å®žå°±æ˜¯åŸºäºŽTCP/IPçš„ä¸€ç§?è½¯ä»¶ï¼Œå®ƒåœ¨TCPçš„æŸ?ä¸ªç«¯å?£ä¸Šè¿›è¡Œç›‘å?¬ï¼Œä¾‹å¦‚ï¼š4444ï¼Œå…¶ä»–å®¢æˆ·æœº(å°±æ˜¯æƒ³é€šè¿‡ä»£ç?†ä¸Šç½‘çš„é‚£äº›Windowsç³»ç»Ÿ)é…?ç½®å¥½åº”ç”¨è½¯ä»¶ï¼Œå¦‚ï¼šIEã€‚å…¶ä¸­éœ€è¦?å¡«ä¸Šä»£ç?†æœ?åŠ¡å™¨çš„ç«¯å?£ï¼Œå?³å‰?ä¾‹ä¸­çš„4444ï¼Œè¿™æ ·ä»£ç?†æœ?åŠ¡å™¨æ‰?çŸ¥é?“ä½ è¦?è®¿é—®çš„åœ°å?€ã€‚å¦‚æžœä½ æ˜¯å?ˆæ³•ç”¨æˆ·çš„è¯?ï¼Œå®ƒå°±å?–å¾—ä½ æƒ³è¦?çš„ç½‘é¡µï¼Œç„¶å?Žå†?é€šè¿‡4444è¿™ä¸ªç«¯å?£ä¼ é€’ç»™ä½ ï¼Œä¸Šç½‘æ—¶ä½ ä¸?ä¼šæ„Ÿè§‰åˆ°ä»£ç?†æœ?åŠ¡å™¨çš„å­˜åœ¨ã€‚ è€Œä»£ç?†æœ?åŠ¡å™¨çš„çœŸæ­£æ„?ä¹‰åœ¨äºŽï¼šä¸€ã€?ç”±äºŽå®ƒæ˜¯å…ˆå°†ç½‘é¡µä¸‹è½½åˆ°æœ¬åœ°ä½¿ç”¨ï¼Œå› æ­¤è®¿é—®é¢‘çŽ‡è¶Šé«˜çš„ç«™ç‚¹é€Ÿåº¦å°±ä¼šè¶Šå¿«ï¼›äºŒã€?å¦‚æžœä½ æ²¡æœ‰è®¿é—®æŸ?ä¸ªç«™ç‚¹çš„æ?ƒé™?è€Œå®ƒæœ‰ï¼Œä½ å°±èƒ½é€šè¿‡å®ƒè®¿é—®åˆ°è¯¥ç«™ç‚¹ï¼›ä¸‰ã€?å®ƒå?¯ä»¥æŽ§åˆ¶ä½ çš„è®¿é—®ã€‚ å½“ä»Šï¼Œé€šè¿‡çª„å¸¦è?”å…¥Internetçš„æ??æ€•ä»?ç„¶å? å¤§å¤šæ•°ï¼Œä»£ç?†æœ?åŠ¡å™¨çš„æ??é€Ÿä½œç”¨ä¹Ÿå°±å??åˆ†æ˜Žæ˜¾äº†ã€‚ ç†Ÿæ‚‰Linuxçš„æœ‹å?‹å?¯èƒ½çŸ¥é?“ï¼Œåœ¨Linuxä¸‹æœ‰Ipchainså?¯ä»¥å?šè·¯ç”±å™¨ï¼Œä¸€æ ·å?¯ä»¥æŽ§åˆ¶è®¿é—®æ?ƒé™?ï¼Œä½†Ipchainsçš„ç¼ºç‚¹æ˜¯ä¸?æ”¯æŒ? DNSè§£æž?ï¼Œå¦‚æžœä½ æƒ³é€šè¿‡å®ƒæŽ§åˆ¶å®¢æˆ·æœºçš„è®¿é—®ï¼Œå°±å¿…é¡»ä¸€ä¸€æŒ‡å®šç›®çš„åœ°çš„IPï¼Œå¦‚æžœæœ‰è°?æŠŠIpchainsç”¨åœ¨è®¿é—®Internetä¸Šï¼Œé‚£ä»–ä¸€å®šæ˜¯ç–¯äº†ï¼Œå› ä¸ºInternetä¸Šçš„IPåœ°å?€ä¸?ä½†å¤šå¾—åƒ?å¤©ä¸Šçš„æ˜Ÿæ˜Ÿï¼Œè€Œä¸”å’Œæ˜Ÿæ˜Ÿä¸€æ ·éš?æ—¶éƒ½åœ¨å?˜åŒ–ã€‚Squidå°±ä¸?å?Œï¼Œå®ƒå?¯ä»¥æŒ‡å®šå“ªäº›åŸŸå?Žç¼€ä¸?èƒ½è®¿é—®ï¼Œå¦‚ï¼š.twã€?. netç­‰ï¼Œè¿™æ ·å°±æŠŠåŸŸå??å¯¹IPçš„æ˜ å°„äº¤ç»™ISPåŽ»å?šäº†ã€‚ é…?ç½®ä¸¾ä¾‹ åœ¨è¿™ä¸ªä¾‹å­?ä¸­ï¼Œæˆ‘ä»¬ä½¿ç”¨çš„æ˜¯ä¸€å?°æ™®é€šå“?ç‰Œæœºå?šä»£ç?†æœ?åŠ¡å™¨ï¼Œå†…è£…ä¸¤å?—ç½‘å?¡ï¼Œç¬¬ä¸€å?—eth0æŽ¥çš„æ˜¯æœ¬å?•ä½?çš„å±€åŸŸç½‘ï¼Œç¬¬äºŒå?—eth1æŽ¥çš„æ˜¯ä¸€å?°ç®€å?•çš„Internetå…±äº«å™¨ï¼Œæ“?ä½œç³»ç»Ÿæ˜¯RedHat Linux 6.1ï¼ŒIpchainså’ŒSquidéƒ½æ˜¯ç³»ç»Ÿè‡ªå¸¦çš„ã€‚ åƒ?å¤§å¤šæ•°Linuxè½¯ä»¶ä¸€æ ·ï¼ŒSquidæ˜¯é€šè¿‡é…?ç½®æ–‡ä»¶å·¥ä½œçš„ï¼Œå®ƒçš„é»˜è®¤é…?ç½®æ–‡ä»¶æ˜¯/etc/squid/squid.confï¼ŒåŽŸå§‹æ–‡ä»¶é•¿è¾¾æ•°å??é¡µï¼Œç»™å‡ºäº†è¯¦ç»†çš„é…?ç½®è¯´æ˜Žï¼Œå…¶ä¸­çœŸæ­£ç”¨å¾—ä¸Šçš„ï¼Œå?¯èƒ½å?ªæ˜¯å¾ˆå°?çš„ä¸€éƒ¨åˆ†ã€‚çœ‹çœ‹ä¸‹é?¢è¿™ä¸ªé…?ç½®æ–‡ä»¶ï¼Œå…¶å®žå¾ˆå¤šé€‰é¡¹éƒ½æ˜¯ä¸€ç›®äº†ç„¶çš„ï¼š http_port 4444 #ä»£ç?†æœ?åŠ¡å™¨ç›‘å?¬çš„ç«¯å?£ cache_dir /var/cache/squid 100 16 32 #ç¼“å­˜ç›®å½• å¤§å°?(å…†) ç¬¬ä¸€çº§å­?ç›®å½•ä¸ªæ•° ç¬¬äºŒçº§å­?ç›®å½•ä¸ªæ•° cache_access_log /var/log/squid/access.log cache_log /var/log/squid/cache.log acl all src 0.0.0.0/0.0.0.0 acl head src 192.168.0.2/255.255.255. 255 192.168.0.3/255.255.255.255 acl normal src 192.168.0.21-192.168. 0.99/255.255.255.255 acl denysite dstdomain tw [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=28&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>
<div>
<table border="0" cellpadding="0" cellspacing="0" width="750">
<tbody>
<tr>
<td height="15">     </td>
<p></tr>
<p></tbody>
<p></table>
<table border="0" cellpadding="0" cellspacing="0" width="560">
<tbody>
<tr>
<th>       <font color="#05006c">ä½¿ç”¨Squidå?šä»£ç?†æœ?åŠ¡å™¨</font>     </th>
<p></tr>
<p>
<tr>
<td>
<hr size="1" />     </td>
<p></tr>
<p>
<tr>
<td align="middle" height="20">       http://www.sina.com.cn 2001/10/31 17:03       <font color="#a20010">èµ›è¿ªç½‘-ä¸­å›½è®¡ç®—æœºæŠ¥</font>     </td>
<p></tr>
<p>
<tr>
<td height="15">     </td>
<p></tr>
<p>
<tr>
<td>
<p>         æ–‡/æ?¨é¹?       </p>
<p>         è¯´åˆ°<a href="http://tech.sina.com.cn//soft/nettools_proxy.shtml" target="_blank">ä»£ç?†æœ?åŠ¡å™¨</a>ï¼Œæˆ‘ä»¬æœ€å…ˆæƒ³åˆ°çš„å?¯èƒ½æ˜¯ä¸€äº›ä¸“é—¨çš„ä»£ç?†æœ?åŠ¡å™¨ç½‘ç«™ï¼ŒæŸ?äº›æƒ…å†µä¸‹ï¼Œé€šè¿‡å®ƒä»¬èƒ½åŠ å¿«è®¿é—®äº’è?”ç½‘çš„é€Ÿåº¦ã€‚å…¶å®žï¼Œåœ¨éœ€è¦?è®¿é—®å¤–éƒ¨çš„å±€åŸŸç½‘ä¸­ï¼Œæˆ‘ä»¬è‡ªå·±å°±èƒ½è®¾ç½®ä»£ç?†ï¼ŒæŠŠè®¿é—®æ¬¡æ•°è¾ƒå¤šçš„ç½‘é¡µä¿?å­˜åœ¨ç¼“å­˜ä¸­ï¼Œä»Žè€Œâ€œæ??é«˜â€?ç½‘ç»œé€Ÿåº¦ã€‚æ›´é‡?è¦?çš„æ˜¯ï¼Œæˆ‘ä»¬èƒ½é€šè¿‡ä»£ç?†æœ?åŠ¡å™¨ï¼Œè¾¾åˆ°æŽ§åˆ¶è®¿é—®æ?ƒé™?çš„ç›®çš„ã€‚åœ¨Windowsä¸­ï¼Œæœ‰å¾ˆå¤šè¿™æ ·çš„è½¯ä»¶ï¼Œå¦‚ï¼šWinGateã€?SyGateç­‰ï¼Œä¸?è¿‡ï¼Œæœ¬æ–‡è¦?è®¨è®ºçš„ï¼Œæ˜¯èƒ½ç»™ä½ å……åˆ†è‡ªç”±çš„<a href="http://tech.sina.com.cn/introduction/focus/linux.shtml" target="_blank">Linux</a>ä¸‹çš„Squidã€‚       </p>
<table align="right" border="0" cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td><a href="http://ad.doubleclick.net/jump/minisite.sina.com.cn/tech;sz=1x1;num=28729036424615452?"><br /><img border="0" src="http://ad.doubleclick.net/ad/minisite.sina.com.cn/tech;sz=1x1;num=28729036424615452?" /><br /></a></p>
<p>           </td>
<p></tr>
<p></tbody>
<p></table>
<p>         Linuxä¸‹çš„ä»£ç?†æœ?åŠ¡å™¨è½¯ä»¶ä¹Ÿä¸?æ˜¯å?ªæœ‰Squidï¼Œä¸?è¿‡åœ¨å¤§éƒ¨åˆ†Linuxç‰ˆæœ¬ä¸­éƒ½å¸¦æœ‰å®ƒã€‚       </p>
<p>         èµ°è¿›â€œä»£ç?†â€?       </p>
<p>         é¦–å…ˆï¼Œæˆ‘ä»¬æ?¥äº†è§£ä¸€ä¸‹ä»£ç?†æœ?åŠ¡å™¨çš„å·¥ä½œåŽŸç?†ã€‚ä»£ç?†æœ?åŠ¡å™¨å…¶å®žå°±æ˜¯åŸºäºŽTCP/IPçš„ä¸€ç§?è½¯ä»¶ï¼Œå®ƒåœ¨TCPçš„æŸ?ä¸ªç«¯å?£ä¸Šè¿›è¡Œç›‘å?¬ï¼Œä¾‹å¦‚ï¼š4444ï¼Œå…¶ä»–å®¢æˆ·æœº(å°±æ˜¯æƒ³é€šè¿‡ä»£ç?†ä¸Šç½‘çš„é‚£äº›Windowsç³»ç»Ÿ)é…?ç½®å¥½åº”ç”¨è½¯ä»¶ï¼Œå¦‚ï¼š<a href="http://tech.sina.com.cn/introduction/focus/msie.shtml" target="_blank">IE</a>ã€‚å…¶ä¸­éœ€è¦?å¡«ä¸Šä»£ç?†æœ?åŠ¡å™¨çš„ç«¯å?£ï¼Œå?³å‰?ä¾‹ä¸­çš„4444ï¼Œè¿™æ ·ä»£ç?†æœ?åŠ¡å™¨æ‰?çŸ¥é?“ä½ è¦?è®¿é—®çš„åœ°å?€ã€‚å¦‚æžœä½ æ˜¯å?ˆæ³•ç”¨æˆ·çš„è¯?ï¼Œå®ƒå°±å?–å¾—ä½ æƒ³è¦?çš„ç½‘é¡µï¼Œç„¶å?Žå†?é€šè¿‡4444è¿™ä¸ªç«¯å?£ä¼ é€’ç»™ä½ ï¼Œä¸Šç½‘æ—¶ä½ ä¸?ä¼šæ„Ÿè§‰åˆ°ä»£ç?†æœ?åŠ¡å™¨çš„å­˜åœ¨ã€‚       </p>
<p>         è€Œä»£ç?†æœ?åŠ¡å™¨çš„çœŸæ­£æ„?ä¹‰åœ¨äºŽï¼šä¸€ã€?ç”±äºŽå®ƒæ˜¯å…ˆå°†ç½‘é¡µä¸‹è½½åˆ°æœ¬åœ°ä½¿ç”¨ï¼Œå› æ­¤è®¿é—®é¢‘çŽ‡è¶Šé«˜çš„ç«™ç‚¹é€Ÿåº¦å°±ä¼šè¶Šå¿«ï¼›äºŒã€?å¦‚æžœä½ æ²¡æœ‰è®¿é—®æŸ?ä¸ªç«™ç‚¹çš„æ?ƒé™?è€Œå®ƒæœ‰ï¼Œä½ å°±èƒ½é€šè¿‡å®ƒè®¿é—®åˆ°è¯¥ç«™ç‚¹ï¼›ä¸‰ã€?å®ƒå?¯ä»¥æŽ§åˆ¶ä½ çš„è®¿é—®ã€‚       </p>
<p>         å½“ä»Šï¼Œé€šè¿‡çª„å¸¦è?”å…¥Internetçš„æ??æ€•ä»?ç„¶å? å¤§å¤šæ•°ï¼Œä»£ç?†æœ?åŠ¡å™¨çš„æ??é€Ÿä½œç”¨ä¹Ÿå°±å??åˆ†æ˜Žæ˜¾äº†ã€‚       </p>
<p>         ç†Ÿæ‚‰Linuxçš„æœ‹å?‹å?¯èƒ½çŸ¥é?“ï¼Œåœ¨Linuxä¸‹æœ‰Ipchainså?¯ä»¥å?šè·¯ç”±å™¨ï¼Œä¸€æ ·å?¯ä»¥æŽ§åˆ¶è®¿é—®æ?ƒé™?ï¼Œä½†Ipchainsçš„ç¼ºç‚¹æ˜¯ä¸?æ”¯æŒ?         DNSè§£æž?ï¼Œå¦‚æžœä½ æƒ³é€šè¿‡å®ƒæŽ§åˆ¶å®¢æˆ·æœºçš„è®¿é—®ï¼Œå°±å¿…é¡»ä¸€ä¸€æŒ‡å®šç›®çš„åœ°çš„IPï¼Œå¦‚æžœæœ‰è°?æŠŠIpchainsç”¨åœ¨è®¿é—®Internetä¸Šï¼Œé‚£ä»–ä¸€å®šæ˜¯ç–¯äº†ï¼Œå› ä¸ºInternetä¸Šçš„IPåœ°å?€ä¸?ä½†å¤šå¾—åƒ?å¤©ä¸Šçš„æ˜Ÿæ˜Ÿï¼Œè€Œä¸”å’Œæ˜Ÿæ˜Ÿä¸€æ ·éš?æ—¶éƒ½åœ¨å?˜åŒ–ã€‚Squidå°±ä¸?å?Œï¼Œå®ƒå?¯ä»¥æŒ‡å®šå“ªäº›åŸŸå?Žç¼€ä¸?èƒ½è®¿é—®ï¼Œå¦‚ï¼š.twã€?.         netç­‰ï¼Œè¿™æ ·å°±æŠŠåŸŸå??å¯¹IPçš„æ˜ å°„äº¤ç»™ISPåŽ»å?šäº†ã€‚       </p>
<p>         é…?ç½®ä¸¾ä¾‹       </p>
<p>         åœ¨è¿™ä¸ªä¾‹å­?ä¸­ï¼Œæˆ‘ä»¬ä½¿ç”¨çš„æ˜¯ä¸€å?°æ™®é€šå“?ç‰Œæœºå?šä»£ç?†æœ?åŠ¡å™¨ï¼Œå†…è£…ä¸¤å?—ç½‘å?¡ï¼Œç¬¬ä¸€å?—eth0æŽ¥çš„æ˜¯æœ¬å?•ä½?çš„å±€åŸŸç½‘ï¼Œç¬¬äºŒå?—eth1æŽ¥çš„æ˜¯ä¸€å?°ç®€å?•çš„Internetå…±äº«å™¨ï¼Œæ“?ä½œç³»ç»Ÿæ˜¯RedHat         Linux 6.1ï¼ŒIpchainså’ŒSquidéƒ½æ˜¯ç³»ç»Ÿè‡ªå¸¦çš„ã€‚       </p>
<p>         åƒ?å¤§å¤šæ•°Linuxè½¯ä»¶ä¸€æ ·ï¼ŒSquidæ˜¯é€šè¿‡é…?ç½®æ–‡ä»¶å·¥ä½œçš„ï¼Œå®ƒçš„é»˜è®¤é…?ç½®æ–‡ä»¶æ˜¯/etc/squid/squid.confï¼ŒåŽŸå§‹æ–‡ä»¶é•¿è¾¾æ•°å??é¡µï¼Œç»™å‡ºäº†è¯¦ç»†çš„é…?ç½®è¯´æ˜Žï¼Œå…¶ä¸­çœŸæ­£ç”¨å¾—ä¸Šçš„ï¼Œå?¯èƒ½å?ªæ˜¯å¾ˆå°?çš„ä¸€éƒ¨åˆ†ã€‚çœ‹çœ‹ä¸‹é?¢è¿™ä¸ªé…?ç½®æ–‡ä»¶ï¼Œå…¶å®žå¾ˆå¤šé€‰é¡¹éƒ½æ˜¯ä¸€ç›®äº†ç„¶çš„ï¼š       </p>
<p>         http_port 4444       </p>
<p>         #ä»£ç?†æœ?åŠ¡å™¨ç›‘å?¬çš„ç«¯å?£       </p>
<p>         cache_dir /var/cache/squid 100 16 32       </p>
<p>         #ç¼“å­˜ç›®å½• å¤§å°?(å…†) ç¬¬ä¸€çº§å­?ç›®å½•ä¸ªæ•° ç¬¬äºŒçº§å­?ç›®å½•ä¸ªæ•°       </p>
<p>         cache_access_log /var/log/squid/access.log       </p>
<p>         cache_log /var/log/squid/cache.log       </p>
<p>         acl all src 0.0.0.0/0.0.0.0       </p>
<p>         acl head src 192.168.0.2/255.255.255. 255 192.168.0.3/255.255.255.255       </p>
<p>         acl normal src 192.168.0.21-192.168. 0.99/255.255.255.255       </p>
<p>         acl denysite dstdomain tw net       </p>
<p>         acl denyip dst 61.136.135.04/255.255. 255.255       </p>
<p>         acl dnsport port 53       </p>
<p>         http_access allow head       </p>
<p>         http_access deny denysite       </p>
<p>         http_access deny denyip       </p>
<p>         http_access allow normal       </p>
<p>         http_access deny dnsport       </p>
<p>         å®žä¾‹åˆ†æž?       </p>
<p>         ä¸Šé?¢çš„å†…å®¹ï¼Œå°±æ˜¯ä¸€ä¸ªåŸºæœ¬Squidæ‰€éœ€è¦?çš„å…¨éƒ¨é…?ç½®ï¼Œæ˜¯ä¸?æ˜¯å¾ˆç®€å?•ï¼Ÿï¼?       </p>
<p>         ä»Žä¸Šé?¢æˆ‘ä»¬å?¯ä»¥çœ‹åˆ°ï¼Œä»£ç?†æœ?åŠ¡å™¨ä½¿ç”¨4444è¿™ä¸ªç«¯å?£è¿›è¡Œç›‘å?¬ï¼Œç¼“å­˜ç›®å½•ä¸º100MBï¼ŒIPåœ°å?€ä¸º192.168.0.2å’Œ         192.168.0.3çš„ç”¨æˆ·å?¯è®¿é—®æ‰€æœ‰ç«™ç‚¹ï¼Œè€ŒIPåœ°å?€ä¸º192.168.0.21ï½ž99çš„ç”¨æˆ·ä¸?èƒ½è®¿é—®å?Žç¼€ä¸ºtwå’Œnetçš„ç«™ç‚¹ï¼Œä¹Ÿä¸?èƒ½è®¿é—®IPåœ°å?€ä¸º61.136.135.04çš„ç«™ç‚¹(å¦‚æžœdst         61.136.135.04/255.255.255.255å?˜æˆ?dst         61.136.135.04/255.255.255.0ï¼ŒæŒ‡çš„æ˜¯61.136.135.0è¿™ä¸ªç½‘ç»œ)ã€‚       </p>
<p>         å¾ˆæ˜Žæ˜¾ï¼ŒSquidä½¿ç”¨aclæ?¥å®šä¹‰ç”¨æˆ·ç»„ï¼Œå¹¶ä½¿ç”¨http_accessæ?¥æŽ§åˆ¶ç”¨æˆ·ç»„çš„æ?ƒé™?ã€‚aclå?Žé?¢å?¯ä»¥æ˜¯src(æº?åœ°å?€)ã€?dst(ç›®æ ‡åœ°å?€)ã€?proto(å??è®®)ã€?port(ç«¯å?£)ã€?         srcdomain(æº?åŸŸ)ã€?dstdomain(ç›®æ ‡åŸŸ)ç­‰ï¼ŒSquidçš„æŽ§åˆ¶åŠŸèƒ½å??åˆ†å¼ºå¤§ï¼Œä½ ç”šè‡³å?¯ä»¥ç”¨acl aclname         timeæŒ‡å®šç”¨æˆ·ç»„ç”Ÿæ•ˆçš„æ—¶é—´ï¼Œä¸?è¿‡è¦?æ³¨æ„?ï¼Œç”¨http_accessè®¾ç½®ä¸?å?Œç”¨æˆ·ç»„çš„æ?ƒé™?æ—¶ï¼ŒSquidæ˜¯æŒ‰ä»Žä¸Šåˆ°ä¸‹çš„é¡ºåº?æ‰§è¡Œçš„ï¼Œå¦‚æžœä½ æƒ³å…³é—­ä¸€ä¸ªç»„è®¿é—®æŸ?äº›ç«™ç‚¹çš„æ?ƒé™?ï¼Œå°±å¿…é¡»æŠŠdenyçš„ç›¸åº”å?¥å­?æ”¾åœ¨è¿™ä¸ªç»„çš„å‰?é?¢ã€‚       </p>
<p>         å?¦å¤–ï¼ŒSquidæ–‡æ¡£ä¸­ç‰¹åˆ«æŒ‡å‡ºï¼Œå¦‚æžœæ²¡æœ‰ç›¸åº”çš„accessè®¾ç½®ï¼Œé‚£ä¹ˆé»˜è®¤çš„æ?ƒé™?ä¸Žæœ€å?Žä¸€è¡Œç›¸å??ï¼Œåœ¨ä¸Šä¾‹ä¸­ï¼Œä¸€ä¸ªIPä¸º192.168.0.5çš„å®¢æˆ·æœªè¢«å®šä¹‰å?´èƒ½è®¿é—®å¤–éƒ¨ç½‘ç»œï¼Œå› æ­¤ï¼Œåœ¨æœ€å?Žä¸€è¡Œè®¾ç½®http_access         deny allæ˜¯å¾ˆæœ‰å¿…è¦?çš„ã€‚       </p>
<p>         è®¾ç½®å®Œæˆ?å?Žï¼Œå°±å?¯ä»¥ç›´æŽ¥è¿?è¡ŒSquidæ?¥å?¯åŠ¨å®ƒï¼Œå¦‚æžœé…?ç½®æ–‡ä»¶æœ‰è¯¯ï¼ŒSquidä¼šç»™å‡ºç›¸åº”çš„æ??ç¤ºã€‚ç„¶å?Žå†?ä½¿ç”¨Ipchainsè®¾ç½®åŒ…çš„è½¬å?‘è§„åˆ™ï¼Œå¦‚å?ªå…?è®¸å®¢æˆ·æœºä½¿ç”¨POP3(110)ã€?SMTP(25)ã€?DNS(53)è¿™å‡ ä¸ªç«¯å?£æ”¶å?‘ä¿¡ä»¶ï¼Œæµ?è§ˆç½‘é¡µå?ªèƒ½ä½¿ç”¨ä»£ç?†ï¼Œè¿™æ ·ç½‘ç»œå°±å®‰å…¨å¾—å¤šäº†ã€‚       </p>
</td>
<p></tr>
<p></tbody>
<p></table>
<p></div>
<p></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/28/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/28/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=28&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/squid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>

		<media:content url="http://ad.doubleclick.net/ad/minisite.sina.com.cn/tech;sz=1x1;num=28729036424615452?" medium="image" />
	</item>
		<item>
		<title>Ten Rules For Web Startups</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/ten-rules-for-web-startups/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/ten-rules-for-web-startups/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 15:26:20 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/ten-rules-for-web-startups/</guid>
		<description><![CDATA[Ten Rules for Web Startups #1: Be Narrow Focus on the smallest possible problem you could solve that would potentially be useful. Most companies start out trying to do too many things, which makes life difficult and turns you into a me-too. Focusing on a small niche has so many advantages: With much less work, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=27&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3>    		  	 			Ten Rules for Web Startups</h3>
<p>#1: Be Narrow<br />
Focus on the smallest possible problem you could solve that would<br />
potentially be useful. Most companies start out trying to do too many<br />
things, which makes life difficult and turns you into a me-too.<br />
Focusing on a small niche has so many advantages: With much less work,<br />
you can be the best at what you do. Small things, like a microscopic<br />
world, almost always turn out to be bigger than you think when you zoom<br />
in. You can much more easily position and market yourself when more<br />
focused. And when it comes to partnering, or being acquired,<br />
thereâ€™s less chance for conflict. This is all so logical and,<br />
yet, thereâ€™s a resistance to focusing. I think it comes from a<br />
fear of being trivial. Just remember: If you get to be #1 in your<br />
category, but your category is too small, then you can broaden your<br />
scopeâ€”and you can do so with leverage.</p>
<p>#2: Be Different<br />
Ideas are in the air. There are lots of people thinking aboutâ€”and<br />
probably working onâ€”the same thing you are. And one of them is<br />
Google. Deal with it. How? First of all, realize that no sufficiently<br />
interesting space will be limited to one player. In a sense,<br />
competition actually is goodâ€”especially to legitimize new<br />
markets. Second, see #1â€”the specialist will almost always kick<br />
the generalistâ€™s ass. Third, consider doing something<br />
thatâ€™s not so cutting edge. Many highly successful<br />
companiesâ€”the aforementioned big G being oneâ€”have thrived<br />
by taking on areas that everyone thought were done and redoing them<br />
right. Also? Get a good, non-generic name. Easier said than done,<br />
granted. But the most common mistake in naming is trying to be too<br />
descriptive, which leads to lots of hard-to-distinguish names. How many<br />
blogging companies have â€œblogâ€? in their name, RSS companies<br />
â€œfeed,â€? or podcasting companies â€œpodâ€? or<br />
â€œcastâ€?? Rarely are they the ones that stand out.</p>
<p>#3: Be Casual<br />
Weâ€™re moving into what I call the era of the â€œCasual Webâ€? (and <a href="http://odeo.com/blog/2005/10/podcasting-for-regular-people.html">casual content creation</a>).<br />
This is much bigger than the hobbyist web or the professional web. Why?<br />
Because people have lives. And now, people with lives also have<br />
broadband. If you want to hit the really big home runs, create services<br />
that fit in withâ€”and, indeed, helpâ€”peopleâ€™s everyday<br />
lives without requiring lots of commitment or identity change. <a href="http://flickr.com/">Flickr</a><br />
enables personal publishing among millions of folks who would never<br />
consider themselves personal publishersâ€”theyâ€™re just<br />
sharing pictures with friends and family, a casual activity. <a href="http://www.thehollywoodreporter.com/thr/columns/tech_reporter_display.jsp?vnu_content_id=1000535245">Casual games are huge</a>. Skype enables casual conversations.</p>
<p>#4: Be Picky<br />
Another perennial business rule, and it applies to everything you do:<br />
features, employees, investors, partners, press opportunities. Startups<br />
are often too eager to accept people or ideas into their world. You can<br />
almost always afford to wait if something doesnâ€™t feel just<br />
right, and false negatives are usually better than false positives. One<br />
of Googleâ€™s biggest strengthsâ€”and sources of frustration<br />
for outsidersâ€”was their willingness to say no to opportunities,<br />
easy money, potential employees, and deals.</p>
<p>#5: Be User-Centric<br />
User experience is everything. It always has been, but itâ€™s still<br />
undervalued and under-invested in. If you donâ€™t know<br />
user-centered design, study it. Hire people who know it. Obsess over<br />
it. Live and breathe it. Get your whole company on board. Better to<br />
iterate a hundred times to get the right feature right than to add a<br />
hundred more. The point of Ajax is that it can make a site more<br />
responsive, not that itâ€™s sexy. Tags can make things easier to<br />
find and classify, but maybe not in your application. The point of an<br />
API is so developers can add value for users, not to impress the geeks.<br />
Donâ€™t get sidetracked by technologies or the blog-worthiness of<br />
your next feature. Always focus on the user and all will be well.</p>
<p>#6: Be Self-Centered<br />
Great products almost always come from someone scratching their own<br />
itch. Create something you want to exist in the world. Be a user of<br />
your own product. Hire people who are users of your product. Make it<br />
better based on your own desires. (But donâ€™t trick yourself into<br />
thinking you are your user, when it comes to usability.) Another aspect<br />
of this is to not get seduced into doing deals with big companies at<br />
the expense or your users or at the expense of making your product<br />
better. When youâ€™re small and theyâ€™re big, itâ€™s hard<br />
to say no, but see #4.</p>
<p>#7: Be Greedy<br />
Itâ€™s always good to have options. One of the best ways to do that<br />
is to have income. While itâ€™s true that traffic is now again<br />
actually worth something, the<br />
give-everything-away-and-make-it-up-on-volume strategy stamps an<br />
expiration date on your companyâ€™s ass. In other words, design<br />
something to charge for into your product and start taking money within<br />
6 months (and do it with PayPal). Done right, charging money can<br />
actually accelerate growth, not impede it, because then you have<br />
something to fuel marketing costs with. More importantly, having money<br />
coming in the door puts you in a much more powerful position when it<br />
comes to your next round of funding or acquisition talks. In fact,<br />
consider whether you need to have a free version at all. The <a href="http://www.typepad.com/">TypePad</a><br />
approachâ€”taking the high-end position in the marketâ€”makes<br />
for a great business model in the right market. Less support. Less<br />
scalability concerns. Less abuse. And much higher margins.</p>
<p>#8: Be Tiny<br />
Itâ€™s standard web startup wisdom by now that with the substantially <a href="http://bnoopy.typepad.com/bnoopy/2005/06/its_a_great_tim.html">lower costs to starting something</a> on the web, the <a href="http://www.paulgraham.com/vcsqueeze.html">difficulty of IPOs</a>,<br />
and the willingness of the big guys to shell out for small teams doing<br />
innovative stuff, the most likely end game if youâ€™re successful<br />
is acquisition. Acquisitions are much easier if theyâ€™re small.<br />
And small acquisitions are possible if valuations are kept low from the<br />
get go. And keeping valuations low is possible because it doesnâ€™t<br />
cost much to start something anymore (especially if you keep the scope<br />
narrow). Besides the obvious techniques, one way to do this is to use<br />
turnkey services to lower your overheadâ€”<a href="http://www.administaff.com/">Administaff</a>, <a href="http://www.serverbeach.com/">ServerBeach</a>, <a href="http://www.evhead.com/2005/04/running-your-company-on-web-apps.asp">web apps</a>, maybe even <a href="http://andrej.mobileduo.com/archives/2005/03/etech_bloglines.html">Elance</a>.</p>
<p>#9: Be Agile<br />
You know that old saw about a plane flying from California to Hawaii<br />
being off course 99% of the timeâ€”but constantly correcting? The<br />
same is true of successful startupsâ€”except they may start out<br />
heading toward Alaska. Many dot-com bubble companies that died could<br />
have eventually been successful had they been able to adjust and change<br />
their plans instead of running as fast as they could until they burned<br />
out, based on their initial assumptions. Pyra was started to build a<br />
project-management app, not Blogger. Flickrâ€™s company was<br />
building a game. Ebay was going to sell auction software. Initial<br />
assumptions are almost always wrong. Thatâ€™s why the waterfall<br />
approach to building software is obsolete in favor <a href="http://en.wikipedia.org/wiki/Agile_software_development">agile techniques</a>. The same philosophy should be applied to building a company.</p>
<p>#10: Be Balanced<br />
What is a startup without bleary-eyed, junk-food-fueled,<br />
balls-to-the-wall days and sleepless, caffeine-fueled,<br />
relationship-stressing nights? Answer?: A lot more enjoyable place to<br />
work. Yes, high levels of commitment are crucial. And yes, crunch times<br />
come and sometimes require an inordinate, painful, apologies-to-the-SO<br />
amount of work. But it canâ€™t be all the time. Nature requires<br />
balance for healthâ€”as do the bodies and minds who work for you<br />
and, without which, your company will be worthless. There is no better<br />
way to maintain balance and lower your stress that Iâ€™ve found<br />
than <a href="http://www.43folders.com/2004/09/08/getting-started-with-getting-things-done/">David Allenâ€™s GTD process</a>. Learn it. Live it. Make it a part of your company, and youâ€™ll have a secret weapon.</p>
<p>#11 (bonus!): Be Wary<br />
Overgeneralized lists of business â€œrulesâ€? are not to be taken too literally. There are exceptions to everything.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=27&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/ten-rules-for-web-startups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>aptå‘½ä»¤</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/apt%e5%91%bd%e4%bb%a4/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/apt%e5%91%bd%e4%bb%a4/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 15:25:05 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/apt%e5%91%bd%e4%bb%a4/</guid>
		<description><![CDATA[APT &#160;&#160;&#160; apt-get update ä»Ž /etc/apt/source.list ä¸­æº?çš„æ›´æ–°è½¯ä»¶åŒ…åˆ—è¡¨, å½“æº?çš„å†…å®¹æ”¹å?˜æˆ–ä¸?èƒ½ç¡®å®šæ—¶,è¿?è¡Œ apt-cache search search-string æŸ¥æ‰¾æ??è¿°å¦‚ search-string çš„è½¯ä»¶åŒ… apt-cache policy package-name æ˜¾ç¤ºè½¯ä»¶åŒ…çš„ç‰ˆæœ¬å’Œä¼˜å…ˆçº§ apt-cache show package-name æ˜¾ç¤ºæ–‡ä»¶çš„æ??è¿°ä¿¡æ?¯ apt-cache showpkg package-name æ˜¾ç¤ºè½¯ä»¶åŒ…çš„ä¾?èµ–å…³ç³» apt-get install package-name ä»Žæº?å®‰è£…è½¯ä»¶åŒ…å?Šå…¶æ‰€æœ‰ä¾?èµ–åŒ… apt-get upgrade å°†å½“å‰?å®‰è£…çš„è½¯ä»¶åŒ…æ›´æ–°åˆ°æœ€æ–° apt-get dist-upgrade å¦‚ apt-get upgrade, ä½†æ˜¯è‡ªåŠ¨è§£å†³å†²çª? apt-get remove package-names åˆ é™¤è½¯ä»¶åŒ…, å?Šå…¶æ‰€æœ‰ä¾?èµ–å®ƒçš„åŒ… apt-cache depends package-names åˆ—å‡ºæŒ‡å®šåŒ…çš„æ‰€æœ‰ä¾?èµ–åŒ… apt-cache rdepends package-names åˆ—å‡ºä¾?èµ–äºŽç»™å®šåŒ…çš„æ‰€æœ‰è½¯ä»¶åŒ… apt-file upgrade ä»Žæº?æ›´æ–°å†…å®¹åˆ—è¡¨, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=26&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<ul>
<li> APT     </li>
</ul>
<p>&nbsp;&nbsp;&nbsp; apt-get update<br />
ä»Ž /etc/apt/source.list ä¸­æº?çš„æ›´æ–°è½¯ä»¶åŒ…åˆ—è¡¨, å½“æº?çš„å†…å®¹æ”¹å?˜æˆ–ä¸?èƒ½ç¡®å®šæ—¶,è¿?è¡Œ</p>
<p>apt-cache search search-string<br />
æŸ¥æ‰¾æ??è¿°å¦‚ search-string çš„è½¯ä»¶åŒ…</p>
<p>apt-cache policy package-name<br />
æ˜¾ç¤ºè½¯ä»¶åŒ…çš„ç‰ˆæœ¬å’Œä¼˜å…ˆçº§</p>
<p>apt-cache show package-name<br />
æ˜¾ç¤ºæ–‡ä»¶çš„æ??è¿°ä¿¡æ?¯</p>
<p>apt-cache showpkg package-name<br />
æ˜¾ç¤ºè½¯ä»¶åŒ…çš„ä¾?èµ–å…³ç³»</p>
<p>apt-get install package-name<br />
ä»Žæº?å®‰è£…è½¯ä»¶åŒ…å?Šå…¶æ‰€æœ‰ä¾?èµ–åŒ…</p>
<p>apt-get upgrade<br />
å°†å½“å‰?å®‰è£…çš„è½¯ä»¶åŒ…æ›´æ–°åˆ°æœ€æ–°</p>
<p>apt-get dist-upgrade<br />
å¦‚ apt-get upgrade, ä½†æ˜¯è‡ªåŠ¨è§£å†³å†²çª?</p>
<p>apt-get remove package-names<br />
åˆ é™¤è½¯ä»¶åŒ…, å?Šå…¶æ‰€æœ‰ä¾?èµ–å®ƒçš„åŒ…</p>
<p>apt-cache depends package-names<br />
åˆ—å‡ºæŒ‡å®šåŒ…çš„æ‰€æœ‰ä¾?èµ–åŒ…</p>
<p>apt-cache rdepends package-names<br />
åˆ—å‡ºä¾?èµ–äºŽç»™å®šåŒ…çš„æ‰€æœ‰è½¯ä»¶åŒ…</p>
<p>apt-file upgrade<br />
ä»Žæº?æ›´æ–°å†…å®¹åˆ—è¡¨, è¯¦è§? apt-get upgrade</p>
<p>apt-file search file-name<br />
æŸ¥æ‰¾åŒ…å?«æ–‡ä»¶çš„è½¯ä»¶åŒ…</p>
<p>apt-file search package-name<br />
åˆ—å‡ºè½¯ä»¶åŒ…çš„å†…å®¹</p>
<p>auto-apt<br />
å¦‚æžœéœ€è¦?å?¯ä»¥è‡ªåŠ¨å®‰è£…è½¯ä»¶åŒ…, å?¯ä»¥æ›¿ä»£ apt-file, éœ€è¦?å®‰è£… auto-apt.</p>
<p>aptitude<br />
APT çš„æŽ§åˆ¶å?°æŽ¥å?£, éœ€è¦?å®‰è£… aptitude</p>
<p>synaptic<br />
APTçš„GUIæŽ¥å?£, éœ€è¦?å®‰è£…synaptic</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/26/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/26/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=26&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/apt%e5%91%bd%e4%bb%a4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
		<item>
		<title>Mysqlä¼˜åŒ–</title>
		<link>http://sddlzz.wordpress.com/2005/12/24/mysql%e4%bc%98%e5%8c%96/</link>
		<comments>http://sddlzz.wordpress.com/2005/12/24/mysql%e4%bc%98%e5%8c%96/#comments</comments>
		<pubDate>Sat, 24 Dec 2005 15:24:02 +0000</pubDate>
		<dc:creator>sddlzz</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sddlzz.wordpress.com/2005/12/24/mysql%e4%bc%98%e5%8c%96/</guid>
		<description><![CDATA[(1)ã€?back_logï¼š è¦?æ±‚ MySQL èƒ½æœ‰çš„è¿žæŽ¥æ•°é‡?ã€‚å½“ä¸»è¦?MySQLçº¿ç¨‹åœ¨ä¸€ä¸ªå¾ˆçŸ­æ—¶é—´å†…å¾—åˆ°é?žå¸¸å¤šçš„è¿žæŽ¥è¯·æ±‚ï¼Œè¿™å°±èµ·ä½œç”¨ï¼Œç„¶å?Žä¸»çº¿ç¨‹èŠ±äº›æ—¶é—´(å°½ç®¡å¾ˆçŸ­)æ£€æŸ¥è¿žæŽ¥å¹¶ä¸”å?¯åŠ¨ä¸€ä¸ªæ–°çº¿ç¨‹ã€‚ back_logå€¼æŒ‡å‡ºåœ¨MySQLæš‚æ—¶å?œæ­¢å›žç­”æ–°è¯·æ±‚ä¹‹å‰?çš„çŸ­æ—¶é—´å†…å¤šå°‘ä¸ªè¯·æ±‚å?¯ä»¥è¢«å­˜åœ¨å †æ ˆä¸­ã€‚å?ªæœ‰å¦‚æžœæœŸæœ›åœ¨ä¸€ä¸ªçŸ­æ—¶é—´å†…æœ‰å¾ˆå¤šè¿žæŽ¥ï¼Œä½ éœ€è¦?å¢žåŠ  å®ƒï¼Œæ?¢å?¥è¯?è¯´ï¼Œè¿™å€¼å¯¹åˆ°æ?¥çš„TCP/IPè¿žæŽ¥çš„ä¾¦å?¬é˜Ÿåˆ—çš„å¤§å°?ã€‚ä½ çš„æ“?ä½œç³»ç»Ÿåœ¨è¿™ä¸ªé˜Ÿåˆ—å¤§å°?ä¸Šæœ‰å®ƒè‡ªå·±çš„é™?åˆ¶ã€‚ è¯•å›¾è®¾å®šback_logé«˜äºŽä½ çš„æ“?ä½œç³»ç»Ÿçš„é™?åˆ¶å°†æ˜¯æ— æ•ˆçš„ã€‚ å½“ä½ è§‚å¯Ÿä½ çš„ä¸»æœºè¿›ç¨‹åˆ—è¡¨ï¼Œå?‘çŽ°å¤§é‡? 264084 &#124; unauthenticated user &#124; xxx.xxx.xxx.xxx &#124; NULL &#124; Connect &#124; NULL &#124; login &#124; NULL çš„å¾…è¿žæŽ¥è¿›ç¨‹æ—¶ï¼Œå°±è¦?åŠ å¤§ back_log çš„å€¼äº†ã€‚é»˜è®¤æ•°å€¼æ˜¯50ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º500ã€‚ (2)ã€?interactive_timeoutï¼š æœ?åŠ¡å™¨åœ¨å…³é—­å®ƒå‰?åœ¨ä¸€ä¸ªäº¤äº’è¿žæŽ¥ä¸Šç­‰å¾…è¡ŒåŠ¨çš„ç§’æ•°ã€‚ä¸€ä¸ªäº¤äº’çš„å®¢æˆ·è¢«å®šä¹‰ä¸ºå¯¹ mysql_real_connect()ä½¿ç”¨ CLIENT_INTERACTIVE é€‰é¡¹çš„å®¢æˆ·ã€‚ é»˜è®¤æ•°å€¼æ˜¯28800ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º7200ã€‚ (3)ã€?key_buffer_sizeï¼š ç´¢å¼•å?—æ˜¯ç¼“å†²çš„å¹¶ä¸”è¢«æ‰€æœ‰çš„çº¿ç¨‹å…±äº«ã€‚key_buffer_sizeæ˜¯ç”¨äºŽç´¢å¼•å?—çš„ç¼“å†²åŒºå¤§å°?ï¼Œå¢žåŠ å®ƒå?¯å¾—åˆ°æ›´å¥½å¤„ç?†çš„ç´¢å¼•(å¯¹æ‰€æœ‰è¯»å’Œå¤šé‡?å†™)ï¼Œåˆ°ä½  èƒ½è´Ÿæ‹…å¾—èµ·é‚£æ ·å¤šã€‚å¦‚æžœä½ ä½¿å®ƒå¤ªå¤§ï¼Œç³»ç»Ÿå°†å¼€å§‹æ?¢é¡µå¹¶ä¸”çœŸçš„å?˜æ…¢äº†ã€‚é»˜è®¤æ•°å€¼æ˜¯8388600(8M)ï¼Œæˆ‘çš„MySQLä¸»æœºæœ‰2GBå†…å­˜ï¼Œæ‰€ä»¥æˆ‘æŠŠå®ƒæ”¹ä¸º 402649088(400MB)ã€‚ (4)ã€?max_connectionsï¼š å…?è®¸çš„å?Œæ—¶å®¢æˆ·çš„æ•°é‡?ã€‚å¢žåŠ è¯¥å€¼å¢žåŠ  mysqld è¦?æ±‚çš„æ–‡ä»¶æ??è¿°ç¬¦çš„æ•°é‡?ã€‚è¿™ä¸ªæ•°å­—åº”è¯¥å¢žåŠ ï¼Œå?¦åˆ™ï¼Œä½ å°†ç»?å¸¸çœ‹åˆ° Too many connections é”™è¯¯ã€‚ é»˜è®¤æ•°å€¼æ˜¯100ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º1024 ã€‚ (5)ã€?record_bufferï¼š æ¯?ä¸ªè¿›è¡Œä¸€ä¸ªé¡ºåº?æ‰«æ??çš„çº¿ç¨‹ä¸ºå…¶æ‰«æ??çš„æ¯?å¼ è¡¨åˆ†é…?è¿™ä¸ªå¤§å°?çš„ä¸€ä¸ªç¼“å†²åŒºã€‚å¦‚æžœä½ å?šå¾ˆå¤šé¡ºåº?æ‰«æ??ï¼Œä½ å?¯èƒ½æƒ³è¦?å¢žåŠ è¯¥å€¼ã€‚é»˜è®¤æ•°å€¼æ˜¯131072(128K)ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º16773120 (16M) (6)ã€?sort_bufferï¼š æ¯?ä¸ªéœ€è¦?è¿›è¡ŒæŽ’åº?çš„çº¿ç¨‹åˆ†é…?è¯¥å¤§å°?çš„ä¸€ä¸ªç¼“å†²åŒºã€‚å¢žåŠ è¿™å€¼åŠ é€ŸORDER BYæˆ–GROUP BYæ“?ä½œã€‚é»˜è®¤æ•°å€¼æ˜¯2097144(2M)ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º 16777208 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=24&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>
<p>(1)ã€?back_logï¼š<br />
è¦?æ±‚ MySQL èƒ½æœ‰çš„è¿žæŽ¥æ•°é‡?ã€‚å½“ä¸»è¦?MySQLçº¿ç¨‹åœ¨ä¸€ä¸ªå¾ˆçŸ­æ—¶é—´å†…å¾—åˆ°é?žå¸¸å¤šçš„è¿žæŽ¥è¯·æ±‚ï¼Œè¿™å°±èµ·ä½œç”¨ï¼Œç„¶å?Žä¸»çº¿ç¨‹èŠ±äº›æ—¶é—´(å°½ç®¡å¾ˆçŸ­)æ£€æŸ¥è¿žæŽ¥å¹¶ä¸”å?¯åŠ¨ä¸€ä¸ªæ–°çº¿ç¨‹ã€‚<br />
back_logå€¼æŒ‡å‡ºåœ¨MySQLæš‚æ—¶å?œæ­¢å›žç­”æ–°è¯·æ±‚ä¹‹å‰?çš„çŸ­æ—¶é—´å†…å¤šå°‘ä¸ªè¯·æ±‚å?¯ä»¥è¢«å­˜åœ¨å †æ ˆä¸­ã€‚å?ªæœ‰å¦‚æžœæœŸæœ›åœ¨ä¸€ä¸ªçŸ­æ—¶é—´å†…æœ‰å¾ˆå¤šè¿žæŽ¥ï¼Œä½ éœ€è¦?å¢žåŠ <br />
å®ƒï¼Œæ?¢å?¥è¯?è¯´ï¼Œè¿™å€¼å¯¹åˆ°æ?¥çš„TCP/IPè¿žæŽ¥çš„ä¾¦å?¬é˜Ÿåˆ—çš„å¤§å°?ã€‚ä½ çš„æ“?ä½œç³»ç»Ÿåœ¨è¿™ä¸ªé˜Ÿåˆ—å¤§å°?ä¸Šæœ‰å®ƒè‡ªå·±çš„é™?åˆ¶ã€‚<br />
è¯•å›¾è®¾å®šback_logé«˜äºŽä½ çš„æ“?ä½œç³»ç»Ÿçš„é™?åˆ¶å°†æ˜¯æ— æ•ˆçš„ã€‚<br />
å½“ä½ è§‚å¯Ÿä½ çš„ä¸»æœºè¿›ç¨‹åˆ—è¡¨ï¼Œå?‘çŽ°å¤§é‡? 264084 | unauthenticated user | xxx.xxx.xxx.xxx |<br />
NULL | Connect | NULL | login | NULL çš„å¾…è¿žæŽ¥è¿›ç¨‹æ—¶ï¼Œå°±è¦?åŠ å¤§ back_log<br />
çš„å€¼äº†ã€‚é»˜è®¤æ•°å€¼æ˜¯50ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º500ã€‚</p>
<p>(2)ã€?interactive_timeoutï¼š<br />
æœ?åŠ¡å™¨åœ¨å…³é—­å®ƒå‰?åœ¨ä¸€ä¸ªäº¤äº’è¿žæŽ¥ä¸Šç­‰å¾…è¡ŒåŠ¨çš„ç§’æ•°ã€‚ä¸€ä¸ªäº¤äº’çš„å®¢æˆ·è¢«å®šä¹‰ä¸ºå¯¹ mysql_real_connect()ä½¿ç”¨ CLIENT_INTERACTIVE é€‰é¡¹çš„å®¢æˆ·ã€‚ é»˜è®¤æ•°å€¼æ˜¯28800ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º7200ã€‚</p>
<p>(3)ã€?key_buffer_sizeï¼š<br />
ç´¢å¼•å?—æ˜¯ç¼“å†²çš„å¹¶ä¸”è¢«æ‰€æœ‰çš„çº¿ç¨‹å…±äº«ã€‚key_buffer_sizeæ˜¯ç”¨äºŽç´¢å¼•å?—çš„ç¼“å†²åŒºå¤§å°?ï¼Œå¢žåŠ å®ƒå?¯å¾—åˆ°æ›´å¥½å¤„ç?†çš„ç´¢å¼•(å¯¹æ‰€æœ‰è¯»å’Œå¤šé‡?å†™)ï¼Œåˆ°ä½ <br />
èƒ½è´Ÿæ‹…å¾—èµ·é‚£æ ·å¤šã€‚å¦‚æžœä½ ä½¿å®ƒå¤ªå¤§ï¼Œç³»ç»Ÿå°†å¼€å§‹æ?¢é¡µå¹¶ä¸”çœŸçš„å?˜æ…¢äº†ã€‚é»˜è®¤æ•°å€¼æ˜¯8388600(8M)ï¼Œæˆ‘çš„MySQLä¸»æœºæœ‰2GBå†…å­˜ï¼Œæ‰€ä»¥æˆ‘æŠŠå®ƒæ”¹ä¸º<br />
402649088(400MB)ã€‚</p>
<p>(4)ã€?max_connectionsï¼š<br />
å…?è®¸çš„å?Œæ—¶å®¢æˆ·çš„æ•°é‡?ã€‚å¢žåŠ è¯¥å€¼å¢žåŠ  mysqld è¦?æ±‚çš„æ–‡ä»¶æ??è¿°ç¬¦çš„æ•°é‡?ã€‚è¿™ä¸ªæ•°å­—åº”è¯¥å¢žåŠ ï¼Œå?¦åˆ™ï¼Œä½ å°†ç»?å¸¸çœ‹åˆ° Too many connections é”™è¯¯ã€‚ é»˜è®¤æ•°å€¼æ˜¯100ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º1024 ã€‚</p>
<p>(5)ã€?record_bufferï¼š<br />
æ¯?ä¸ªè¿›è¡Œä¸€ä¸ªé¡ºåº?æ‰«æ??çš„çº¿ç¨‹ä¸ºå…¶æ‰«æ??çš„æ¯?å¼ è¡¨åˆ†é…?è¿™ä¸ªå¤§å°?çš„ä¸€ä¸ªç¼“å†²åŒºã€‚å¦‚æžœä½ å?šå¾ˆå¤šé¡ºåº?æ‰«æ??ï¼Œä½ å?¯èƒ½æƒ³è¦?å¢žåŠ è¯¥å€¼ã€‚é»˜è®¤æ•°å€¼æ˜¯131072(128K)ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º16773120 (16M)</p>
<p>(6)ã€?sort_bufferï¼š<br />
æ¯?ä¸ªéœ€è¦?è¿›è¡ŒæŽ’åº?çš„çº¿ç¨‹åˆ†é…?è¯¥å¤§å°?çš„ä¸€ä¸ªç¼“å†²åŒºã€‚å¢žåŠ è¿™å€¼åŠ é€ŸORDER BYæˆ–GROUP BYæ“?ä½œã€‚é»˜è®¤æ•°å€¼æ˜¯2097144(2M)ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º 16777208 (16M)ã€‚</p>
<p>(7)ã€?table_cacheï¼š<br />
ä¸ºæ‰€æœ‰çº¿ç¨‹æ‰“å¼€è¡¨çš„æ•°é‡?ã€‚å¢žåŠ è¯¥å€¼èƒ½å¢žåŠ mysqldè¦?æ±‚çš„æ–‡ä»¶æ??è¿°ç¬¦çš„æ•°é‡?ã€‚MySQLå¯¹æ¯?ä¸ªå”¯ä¸€æ‰“å¼€çš„è¡¨éœ€è¦?2ä¸ªæ–‡ä»¶æ??è¿°ç¬¦ã€‚é»˜è®¤æ•°å€¼æ˜¯64ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º512ã€‚</p>
<p>(8)ã€?thread_cache_sizeï¼š<br />
å?¯ä»¥å¤?ç”¨çš„ä¿?å­˜åœ¨ä¸­çš„çº¿ç¨‹çš„æ•°é‡?ã€‚å¦‚æžœæœ‰ï¼Œæ–°çš„çº¿ç¨‹ä»Žç¼“å­˜ä¸­å?–å¾—ï¼Œå½“æ–­å¼€è¿žæŽ¥çš„æ—¶å€™å¦‚æžœæœ‰ç©ºé—´ï¼Œå®¢æˆ·çš„çº¿ç½®åœ¨ç¼“å­˜ä¸­ã€‚å¦‚æžœæœ‰å¾ˆå¤šæ–°çš„çº¿ç¨‹ï¼Œä¸ºäº†æ??é«˜æ€§èƒ½å?¯<br />
ä»¥è¿™ä¸ªå?˜é‡?å€¼ã€‚é€šè¿‡æ¯”è¾ƒ Connections å’Œ Threads_created çŠ¶æ€?çš„å?˜é‡?ï¼Œå?¯ä»¥çœ‹åˆ°è¿™ä¸ªå?˜é‡?çš„ä½œç”¨ã€‚æˆ‘æŠŠå®ƒè®¾ç½®ä¸º 80ã€‚</p>
<p>(10)ã€?wait_timeoutï¼š<br />
æœ?åŠ¡å™¨åœ¨å…³é—­å®ƒä¹‹å‰?åœ¨ä¸€ä¸ªè¿žæŽ¥ä¸Šç­‰å¾…è¡ŒåŠ¨çš„ç§’æ•°ã€‚ é»˜è®¤æ•°å€¼æ˜¯28800ï¼Œæˆ‘æŠŠå®ƒæ”¹ä¸º7200ã€‚</p>
<p>æ³¨ï¼šå?‚æ•°çš„è°ƒæ•´å?¯ä»¥é€šè¿‡ä¿®æ”¹ /etc/my.cnf æ–‡ä»¶å¹¶é‡?å?¯ MySQL å®žçŽ°ã€‚è¿™æ˜¯ä¸€ä¸ªæ¯”è¾ƒè°¨æ…Žçš„å·¥ä½œï¼Œä¸Šé?¢çš„ç»“æžœä¹Ÿä»…ä»…æ˜¯æˆ‘çš„ä¸€äº›çœ‹æ³•ï¼Œä½ å?¯ä»¥æ ¹æ?®ä½ è‡ªå·±ä¸»æœºçš„ç¡¬ä»¶æƒ…å†µï¼ˆç‰¹åˆ«æ˜¯å†…å­˜å¤§å°?ï¼‰è¿›ä¸€æ­¥ä¿®æ”¹ã€‚
</p>
</p></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sddlzz.wordpress.com/24/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sddlzz.wordpress.com/24/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sddlzz.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sddlzz.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sddlzz.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sddlzz.wordpress.com&amp;blog=4503&amp;post=24&amp;subd=sddlzz&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://sddlzz.wordpress.com/2005/12/24/mysql%e4%bc%98%e5%8c%96/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d9658d623af2690c6ae7e842c2d1b301?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sddlzz</media:title>
		</media:content>
	</item>
	</channel>
</rss>
