Mac OS X Server ネットワークサービスの管理

Similar documents
Mac OS X Server Windows NTからの移行

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

AirMac ネットワーク構成の手引き

AirMac ネットワーク for Windows

Mac OS X Server メールサービスの管理(バージョン 10.3 以降用)

Mac OS X Server ファイルサービスの管理

Mac OS X Server 高可用性の管理

Mac OS X Server QuickTime Streaming Server 5.5 の管理

Mac OS X Server メールサービスの管理

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

IP IP DHCP..

1 Linux UNIX-PC LAN. UNIX. LAN. UNIX. 1.1 UNIX LAN. 1.2 Linux PC Linux. 1.3 studenta odd kumabari studentb even kumabari studentc odd kumabari student

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi

DNS DNS(Domain Name System) named(bind), tinydns(djbdns), MicrosoftDNS(Windows), etc 3 2 (1) ( ) IP IP DNS 4

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

Vol. 9 No. 2 DNS. DNS IP.... leopard.loc. DNS. Mac OS X Server. Web Mac OS X Server Mac OS X Server.. DNS DNS DNS example.com DNS

橡sirahasi.PDF

設定例集_Rev.8.03, Rev.9.00, Rev.10.01対応

rzakg.ps

DNSを「きちんと」設定しよう

BIG‑IP Access Policy Manager | F5 Datasheet

2008, 2009 TOSHIBA TEC CORPORATION All rights reserved

Si-R30取扱説明書

2 1: OSI OSI,,,,,,,,, 4 TCP/IP TCP/IP, TCP, IP 2,, IP, IP. IP, ICMP, TCP, UDP, TELNET, FTP, HTTP TCP IP

ヤマハ ルーター ファイアウォール機能~説明資料~

FileMaker Server Getting Started Guide

集中講義 インターネットテクノロジー 第5回

SRT/RTX/RT設定例集

CPE9V1.0&AP615V2.0-C01说明书-电子档

NATディスクリプタ機能

Logitec NAS シリーズ ソフトウェアマニュアル

Logitec NAS シリーズ ソフトウェアマニュアル

Packet Tracer: 拡張 ACL の設定 : シナリオ 1 トポロジ アドレステーブル R1 デバイスインターフェイス IP アドレスサブネットマスクデフォルトゲートウェイ G0/ N/A G0/

LAN

YMS-VPN1_User_Manual

LHD-LAN_E_G_PDF.}.j...A...p65

2011 TOSHIBA TEC CORPORATION All rights reserved

AirMac Extreme Technology Overview

WP_8021X Authentication_21MAY2012

wp_integrating_active_directory_ml

BIND 9 BIND 9 IPv6 BIND 9 view lwres

tcp/ip.key

(O) (N) (V) (N) kuins-pptp (N) 2

IP.dvi

GA-1190J

RouteMagic Controller RMC-MP200 / MP Version

FileMaker Server 9 Getting Started Guide

Soliton Net’Attest EPS + AR router series L2TP+IPsec RADIUS 設定例

FileMaker Server Getting Started Guide

perimeter gateway

SRX300 Line of Services Gateways for the Branch

ict2-.key

A/B WWW MTA/MSP sendmail POP/IMAP apache WWW 1 1 sendmail uw imap apache WWW host host subnet1: /24 IF1: router & server mail and

図解でわかるVoIPのすべて - IP電話の技術から構築まで -

iPhone Configuration Utility

Cisco Configuration Professional(CCP)Express 3.3 による Cisco 841M J シリーズ初期設定ガイド

untitled

FileMaker Server Getting Started Guide

ScreenOS 5.0 ScreenOS 5.0 Deep Inspection VLAN NetScreen-25/-50/-204/-208 HA NetScreen-25 HA Lite NetScreen-25 NetScreen-50) ALG(Application Layer Gat

RouteMagic Controller( RMC ) 3.6 RMC RouteMagic RouteMagic Controller RouteMagic Controller MP1200 / MP200 Version 3.6 RouteMagic Controller Version 3

1 IPv6 WG OS SWG PCOSIPv6 Windows Vista 2 3 KAMEUSAGIMacOSX IPv6 2

Microsoft Windows, Windows CE, Microsoft Corporation Citrix ICA Citrix Presentation Server Citrix Systems, Inc IBM IBM Corporation

お客様システムにおけるセキュリティ施策

RouteMagic Controller RMC-MP200 / MP Version

TechnicalBrief_Infoblox_jp.indd


FileMaker Server 8 Advanced Web Publishing Installation Guide

ヤマハ ルーター ファイアウォール機能~説明資料~

LSM-L3-24設定ガイド(初版)

アライドテレシス ディストリビューション・スイッチ AT-x600シリーズで実現するMicrosoft® NAP

LHD-LAN ...[.U.[.Y.}.j...A.. V05.p65

$ cal ) ( cal $ cal cal cal 1. () ( clear) 2. ( cal) 3. ( man) \() ( ) --() +()

Dynamic VPN Dynamic VPN IPSec VPN PC SRX IPSec VPN SRX PC IPSec 2 Copyright 2010 Juniper Networks, Inc.

設定例集

Transcription:

Mac OS X Server 10.4

apple Apple Computer, Inc. 2005 Apple Computer, Inc. All rights reserved. Mac OS X Server Apple 1 Infinite Loop Cupertino CA 95014-2084 U.S.A. www.apple.com 163-1480 3 20 2 www.apple.com/jp Apple Apple Computer, Inc. Apple Apple AppleScript AppleShare AppleTalk Mac Mac OS Macintosh Power Mac Power Macintosh QuickTime Sherlock WebObjects Apple Computer, Inc. AirMac Apple Computer, Inc. Java Java Sun Microsystems, Inc. UNIX X/Open Company, Ltd. Apple Computer, Inc. J019-0165/3-24-05

1 9 9 10.4 9 10 10 11 Mac OS X Server 12 12 1 15 15 16 16 17 LAN 18 LAN 19 LAN 2 23 DHCP 23 DHCP 24 24 IP 24 IP 25 DHCP 25 DHCP 25 DHCP 25 IP 25 DHCP 26 DHCP 26 DHCP 26 DHCP 27 DHCP 27 DHCP 28 DHCP 28 3

28 IP 29 DHCP DNS 29 LDAP 30 WINS 30 DHCP IP 31 31 DHCP 31 DHCP 32 DHCP 32 DHCP 32 DHCP 33 DHCP 36 3 37 DNS 38 DNS 38 DNS BIND 38 38 DNS 41 DNS 41 DNS 41 42 42 DNS 43 44 44 45 45 45 46 DNS 47 DNS 48 DNS 48 DNS 49 DNS 49 DNS 49 DNS 49 DNS 50 DNS 50 DNS 50 DNS 51 52 DNS 4

52 DoS 52 53 DNS 53 MX 55 NAT 56 56 TCP/IP 57 1 IP 58 58 4 59 IP 60 61 62 62 64 64 64 IP 65 66 66 Tiger Server 10.4 Panther Server 10.3 66 67 67 68 68 69 70 70 IP 71 IP 72 IP 72 72 73 73 73 74 74 74 75 76 76 IP 5

77 77 IP NAT 77 Web 78 79 79 Apple 80 80 DoS 81 81 82 86 5 87 NAT 87 NAT 88 NAT LAN 89 NAT 89 NAT 90 NAT 90 91 93 NAT 93 NAT 93 NAT 93 1 IP LAN 95 LAN 95 97 6 99 VPN 99 VPN 99 100 101 VPN 101 VPN 102 VPN 102 VPN 102 L2TP 102 PPTP 103 VPN 103 VPN 105 VPN 106 IP VPN 6

107 109 VPN 109 VPN 109 VPN 109 VPN 110 VPN 110 VPN 110 112 112 116 7 117 NTP 117 NTP 118 NTP 118 NTP 119 NTP 119 8 121 VLAN 121 VLAN 121 VLAN 122 9 123 IPv6 124 IPv6 124 IPv6 124 IPv6 124 125 IPv6 125 IPv6 125 IPv6 126 127 139 7

Mac OS X Server 10.4 Mac OS X Server 10.4 10.3 DNS DHCP IP VPN NAT VLAN 9 15 1 23 2 DHCP DHCP IP 37 3 DNS Mac OS X Server 59 4 IP 87 5 NAT NAT 1 IP 99 6 VPN LAN VPN 117 7 NTP 9

121 8 VLAN VLAN 123 9 IPv6 IPv6 IPv6 127 Web Mac OS X Server www.apple.com/jp/server/documentation Finder Mac OS X Mac OS X Server 10

Mac OS X Server Mac OS X Server PDF www.apple.com/jp/server/documentation/ Mac OS X Server Mac OS X AFP NFS FTP SMB/CIFS NetBoot Macintosh WebDAV WebMail Web Web DHCP DNS VPN NTP IP NAT QuickTime PDC BDC Windows Windows NT Mac OS X Server Mac OS X Server JBoss UNIX 11

Mac OS X Server IP Xgrid Xserve Mac OS X Server PDF Mac OS X Server Web www.apple.com/jp/server/documentation www.apple.com/jp/server/macosx/ www.apple.com/jp/support/ www.apple.com/jp/training/ 12

discussions.info.apple.com/jp www.lists.apple.com 13

1 1 Mac OS X Server 10.4 IP 192.168.x.1 x x 0 2 x 1 DHCP DHCP 192.168.x.x DHCP VPN 192.168.x.2 192.168.x.254 VPN VPN L2TP 192.168.x.x VPN VPN DHCP IP VPN 192.168.x.128 192.168.x.254 VPN 15

IP DHCP NAT NAT IP DNS DNS 2 / / / IP ISP XServe G5 2 Ethernet Ethernet 1 en0 Ethernet 2 en1 LAN IP LAN IP 192.168.x.x 16 1

LAN LAN LAN Ethernet LAN IP DHCP VPN DNS DNS LAN 1 XServe Ethernet 1 en0 2 LAN XServe Ethernet 2 en1 3 / / / 4 Ethernet 1 WAN 5 Ethernet 2 LAN LAN LAN WAN Ethernet 2 Ethernet 3 6 LAN VPN VPN VPN VPN 99 6 VPN 7 1 17

IP DHCP 2 DHCP IP LAN IP UNIX LAN LAN LAN LAN Ethernet LAN AirMac LAN AirMac LAN AirMac IP DHCP VPN DNS DNS LAN 1 XServe Ethernet 1 en0 2 LAN XServe Ethernet 2 en1 3 AirMac 2 WAN 4 AirMac AirMac Ethernet DHCP 5 IP 6 18 1

7 / / / 8 Ethernet 1 WAN 9 Ethernet 2 LAN LAN LAN WAN Ethernet 2 Ethernet 3 10 LAN VPN VPN VPN VPN 99 6 VPN 11 IP DHCP 2 DHCP IP LAN IP NAT LAN LAN Mac OS X Server IP DHCP IP DNS LAN VPN AirMac Mac OS X Server 1 19

AirMac AirMac IP DHCP VPN DNS DNS LAN 1 XServe Ethernet 1 en0 2 AirMac 2 WAN XServe Ethernet 2 en1 3 AirMac AirMac Ethernet DHCP 4 IP 5 6 / / / 7 Ethernet 1 WAN 8 Ethernet 2 LAN LAN LAN WAN Ethernet 2 Ethernet 3 9 LAN VPN VPN VPN VPN 99 6 VPN 20 1

10 IP DHCP 2 DHCP IP LAN IP NAT LAN 1 21

2 DHCP 2 DHCP Dynamic Host Configuration Protocol IP DHCP IP DHCP DHCP DHCP IP DHCP IP IP IP DHCP DHCP DNS LDAP WINS DHCP IP DHCP IP IP IP IP IP DNS LDAP Lightweight Directory Access Protocol DHCP DHCP DHCP IP IP 23

IP IP IP IP IP DHCP IP VPN DHCP DHCP VPN DHCP VPN VPN 99 6 VPN IP IP Web IP IP IP IP DHCP DHCP DHCP IP DHCP DHCP IP DHCP DHCP 30 DHCP IP 24 2 DHCP

DHCP DHCP DHCP DHCP BootP DHCP BootP DHCP DHCP AirMac DHCP DHCP IP Mac OS X Server DHCP DHCP LDAP AirMac LDAP Ethernet AirMac Mac OS X Server DHCP AirMac DHCP AirMac DHCP LDAP DHCP DHCP IP IP IP ISP DHCP DHCP Mac OS X Server bootpd DHCP bootpd bootpd man bootpd 2 DHCP 25

DHCP Mac OS X Server DHCP DHCP 26 DHCP 1 IP 1 DHCP 27 DHCP 2 DHCP DHCP DHCP DHCP DHCP 32 DHCP 3 DHCP 26 DHCP DHCP Mac OS X Server DHCP LDAP DNS DHCP DHCP 1 DHCP 1 DHCP 2 1 3 26 2 DHCP

DHCP 2 1 IP 1 DHCP 2 3 4 5 6 7 IP IP 8 9 10 IP LAN IP 11 12 DNS LDAP WINS 29 DHCP DNS 29 LDAP 30 WINS 13 DHCP DHCP IP 1 DHCP 2 3 4 5 / 6 2 DHCP 27

DNS LDAP WINS DHCP 7 DHCP IP 1 DHCP 2 3 4 5 IP 1 DHCP 2 3 4 IP IP 1 DHCP 2 3 4 / 5 6 7 8 28 2 DHCP

DHCP DNS DNS DHCP DNS 1 DHCP 2 3 4 / 5 DNS 6 7 DHCP IP 8 LDAP LDAP DHCP LDAP LDAP Mac OS X Server LDAP LDAP LDAP LDAP IP LDAP LDAP 1 DHCP 2 3 4 / 5 LDAP 6 LDAP IP 7 LDAP 8 LDAP 9 SSL LDAP 10 2 DHCP 29

WINS Windows DHCP Windows Windows Windows WINS/NBNS IP DHCP IP NBT broadcast NBDD NetBIOS ID Windows Windows WINS 1 DHCP 2 3 4 / 5 WINS 6 WINS/NBNS IP 7 NBDD IP 8 NBT 9 NetBIOS ID 10 DHCP IP DHCP IP Ethernet MAC Ethernet 2 Ethernet 1 1 30 2 DHCP

IP 1 DHCP 2 3 4 5 Ethernet 6 IP 7 8 OK 9 1 DHCP 2 3 4 5 / 6 OK 7 DHCP DHCP DHCP 2 1 2 DHCP DHCP DHCP IP 1 DHCP 2 2 DHCP 31

DHCP DHCP DHCP quiet -q bootpd DHCP bootpd DHCP verbose -v bootpd 1 DHCP 2 3 4 5 DHCP DHCP DHCP bootpd system.log DHCP 1 DHCP 2 DHCP DHCP IP 24 DHCP ID Ethernet ID DHCP 1 DHCP 2 32 2 DHCP

DHCP DHCP IANA Internet Assigned Numbers Authority IP IP 10.0.0.0 10.255.255.255 10/8 172.16.0.0 172.31.255.255 172.16/12 192.168.0.0 192.168.255.255 192.168/16 DHCP NAT IP DHCP NAT IP NAT DHCP IP 93 1 IP LAN DHCP IP DHCP LDAP IP 4 IP LDAP Mac OS X Server 10.4 Mac OS X Server 10.4 DHCP IP IP DHCP IP DHCP 24 IP Mac OS X Server IP Ethernet IP 30 DHCP IP 2 DHCP 33

DHCP DHCP LDAP 29 LDAP Mac OS X IPv4 DHCP LDAP DHCP IP IP DHCP Netboot Netboot DHCP Netboot 33 NetBoot Netboot NetBoot NetBoot LDAP DHCP 34 2 DHCP

Web DNS LAN DHCP Web DNS DHCP IP 4 IP DHCP DHCP DHCP LDAP DHCP Windows 30 WINS DHCP 27 DHCP 27 DHCP DHCP 2 DHCP 35

RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html DHCP RFC 2131 bootpd bootpd man bootpd 36 2 DHCP

3 DNS 3 Web IP 192.168.12.12 www.example.com DNS Domain Name System IP DNS IP IP DNS IP IP IP DNS ISP DNS ISP ISP IP DNS ISP DNS ISP DNS ISP ISP Mac OS X Server BIND Berkeley Internet Name Domain 9.2.2 DNS BIND 37

DNS DNS DNS DNS DNS hostmaster DNS DNS DNS DNS BIND DNS DNS DNS Paul Albitz Cricket Liu O Reilly and Associates 2001 1 IP DNS TTL IP TTL DNS DNS IP DNS 1 IANA Internet Assigned Numbers Authority IANA www.iana.org 38 3 DNS

IP DNS example.com host1.example.com mail.example.com www.example.com primary.www.example.com backup.www.example.com example.com DNS IP ISP DNS ISP IP ISP 2 DNS DNS Mac OS X Server BIND 58 DNS Domain Name System DNS ISP DNS DNS 2 3 DNS DNS Web Mac OS X Server DNS 2 1 DNS 41 DNS 2 BIND BIND DNS Mac OS X Server 1 BIND 3 DNS 39

/etc/named.conf example.com /var/named/example.com.zone named.conf BIND controls inet DNS inet controls { inet 127.0.0.1 port 54 allow {any;} keys { "rndc-key"; }; }; 3 DNS 41 DNS 4 DNS DNS 42 DNS Source of Authority SOA NS Mac OS X Server IP IP 5 DNS IP DNS DNS 46 DNS 6 MX Mail Exchange MX 53 MX 7 IP DNS IP 4 IP 40 3 DNS

8 DNS Mac OS X Server DNS 41 DNS DNS Mac OS X Server DNS DNS BIND DNS DNS DNS DNS DNS 1 DNS 2 1 3 DNS DNS DNS DNS. 1 DNS 2 3 4 3 DNS 41

IP DNS DNS DNS DNS DNS 1 DNS 2 3 4 IP LAN IP BIND named.conf BIND DNS DNS 3 1 DNS 42 3 DNS

BIND BIND DNS DNS DNS DNS BIND BIND Source of Authority SOA NS 1 DNS 2 3 4 5 6 SOA ns.example.com. 7 IP 8 9 TTL Time to Live DNS 10 3 DNS 43

1 DNS 2 3 4 5 6 7 IP 8 OK 9 LAN 1 DNS 2 3 4 5 6 44 3 DNS

1 DNS 2 3 4 / 5 42 DNS 6 OK 1 DNS 2 3 4 5 6 DNS BIND Mac OS X Server BIND /etc/named.conf /var/named/ BIND 9 DNS 3 DNS 45

1 BIND /etc/named.conf named.conf /var/named/ db.xyz.com xyz.com zone "xyz.com" IN { // Forward lookup zone for xyz.com type master; // It s a primary zone file "db.xyz.com"; // Zone info stored in /var/named/db.xyz.com allow-update { none; }; }; 2 /var/named/ 3 DNS DNS www.example.com IP Web DNS IP mail.apple.com MailSrv473.apple.com IP DNS BIND BIND Mac OS X Server Mac OS X Server 46 3 DNS

DNS DNS IP IP IP 1 DNS 1 DNS 2 3 4 5 / 6 7 8 IP 9 A 10 CNAME 11 MX 53 MX 12 HINFO 13 3 DNS 47

TXT 7 ASCII ASCII 255 2 B John 14 OK DNS DNS DNS 1 DNS 2 3 4 5 / 6 7 8 / 9 10 OK DNS 1 DNS 2 3 4 5 / 6 48 3 DNS

7 8 9 DNS DNS DNS DNS DNS DNS DNS BIND DNS DNS 1 DNS 2 DNS DNS DNS named.log DNS 1 DNS 2 3 DNS DNS 1 DNS 2 3 3 DNS 49

4 DNS DNS 1 DNS 2 3 4 DNS / /Logs/named.log DNS DNS DNS DNS DNS DNS DoS DNS DNS DNS IP A IP Web 50 3 DNS

DNS DNS DNS BIND Mac OS X Server DNS IP IP TCP 53 DNS m IP IP TCP 53 4 IP IP 53 TCP IP DNS IP IP DNS IP 3 DNS 51

DNS DNS BIND BIND BIND BIND BIND 1 vi emacs pico 2 named.conf 3 version "[your text, maybe we're not telling! ]"; 4 DoS DNS IP 70 IP ISP DNS ISP DNS DNS DNS DNS DNS LAN LAN 42 52 3 DNS

IP BIND named.conf named.conf options {... allow-recursion{ 127.0.0.0/8; [your internal IP range of addresses, like 192.168.1.0/27]; }; }; BIND DNS DNS MX DNS reliable example.com MX user-name@reliable.example.com MX 3 DNS 53

MX example.com 10 reliable.example.com 20 our-backup.example.com 30 last-resort.example.com MX MX MX DNS MX DNS DNS DNS MX Mail Exchange ISP DNS ISP MX DNS MX MX 1 DNS 2 3 4 5 / 6 7 8 IP 54 3 DNS

9 CNAME A 10 A 11 MX 12 13 HINFO 14 TXT 2 B John 15 OK 16 7 15 17 NAT NAT Network Address Translation NAT IP NAT NAT 87 5 NAT 3 DNS 55

DNS NAT IP NAT IP DNS DNS NAT NAT DNS 93 1 IP LAN NAT NAT NAT DNS NAT NAT NAT 90 Mac OS X DNS DNS.local DNS DNS BIND IP BIND IP 3 Web IP 192.168.12.12 192.168.12.13 192.168.12.14 3 IP 3 1 DNS A B C B C A C A B Time-to-Live TCP/IP IP IP ISP 56 3 DNS

TCP/IP TCP/IP IANA Internet Assigned Numbers Authority IP IP 10.0.0.0 10.255.255.255 10/8 172.16.0.0 172.31.255.255 172.16/12 192.168.0.0 192.168.255.255 192.168/16 IP TCP/IP DNS TCP/IP DNS Web 1 IP 1 Web 1 IP 1 www.example.com ftp.example.com mail.example.com IP 1 IP 1 DNS DNS DNS mail.example.com www.example.com Web Finder Apple afp.example.com ftp.example.com ftp DNS 3 DNS 57

1 Web www.example.com www.example.org IP 1 IP 1 DNS DNS DNS Web DNS BIND Paul Albitz Cricket Liu O Reilly and Associates 2001 International Software Consortium Web www.isc.org www.isc.org/products/bind/ DNS Resources Directory www.dns.net/dnsrd/ Request For Comments RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html A PTR CNAME MX RFC 1035 AAAA RFC 1886 58 3 DNS

4 IP 4 Mac OS X Server IP IP IP IP 10.221.41.33 80 80 IP 10.221.41.33 10.221.41.33 Web FTP TCP Transmission Control Protocol UDP User Datagram Protocol 59

TCP UDP ICMP Internet Control Message Protocol IGMP Internet Group Management Protocol Secure Shell 22 IP Mac OS X Server 3 IP IP IP IP 60 4 IP

Web ipfw sysctl sysctl IPFilter /etc/hostconfig IPFILTER sysctl sysctl -w net.inet.ip.fw.enable=1 sysctl -w net.inet.ip.fw.enable=0 IPFilter Mac OS X Server 10.4 4 IP 61

IP IP IP 66 IP IP IP IP IP IP 0 255 8 4 192.168.12.12 IP IP CIDR Classless Inter Domain Routing IP / 1 32 IP IP 192.168.2.1 /16 16 2 192.168 16 2 2 IP : 0 255 4 CIDR 10 62 4 IP

CIDR CIDR /1 128.0.0.0 4.29 10 9 /2 192.0.0.0 2.14 10 9 /3 224.0.0.0 1.07 10 9 /4 240.0.0.0 5.36 10 8 /5 248.0.0.0 1.34 10 8 /6 252.0.0.0 6.71 10 7 /7 254.0.0.0 3.35 10 7 /8 255.0.0.0 1.67 10 7 /9 255.128.0.0 8.38 10 6 /10 255.192.0.0 4.19 10 6 /11 255.224.0.0 2.09 10 6 /12 255.240.0.0 1.04 10 6 /13 255.248.0.0 5.24 10 5 /14 255.252.0.0 2.62 10 5 /15 255.254.0.0 1.31 10 5 /16 255.255.0.0 65536 /17 255.255.128.0 32768 /18 255.255.192.0 16384 /19 255.255.224.0 8192 /20 255.255.240.0 4096 /21 255.255.248.0 2048 /22 255.255.252.0 1024 /23 255.255.254.0 512 /24 255.255.255.0 256 /25 255.255.255.128 128 /26 255.255.255.192 64 /27 255.255.255.224 32 /28 255.255.255.240 16 /29 255.255.255.248 8 /30 255.255.255.252 4 /31 255.255.255.254 2 /32 255.255.255.255 1 4 IP 63

IP 3 192.168.2.1 CIDR 192.168.2.1/24 192.168.2.1:255.255.255.0 1 IP IP 10.221.41.33 10.221.41.33 10.221.41.33/32 10.221.41.33 1 4 3 4 10.221.41.33 10.221.41.33/24 10.221.41.0 10.221.41.255 10.221.41.33 10.221.41.33/22 10.221.40.0 10.221.43.255 IP IP IP 1 IP IP IP 64 4 IP

66 1 IP Mac OS X Server BIND 62 IP Web FTP IP IP 2 FTP FTP 3 IP IP IP 67 4 IP 68 5 IP 62 4 IP 65

UDP UDP UDP UDP UDP UDP 70 IP 6 FTP FTP 1 1 Tiger Server 10.4 Panther Server 10.3 Panther Server 10.3 Tiger Server 10.4 Panther10.3 Panther 10.3 TCP UDP IP FTP FTP 66 4 IP

1 2 IP 2 IP 10-net 192.168-net 192.168.2.2 IP CIDR 192.168.2.0/24 IP 192.168.2.0:255.255.255.0 1 2 3 4 5 6 IP any 7 OK 8 IP 192.168.2.2 CIDR 192.168.2.0/24 1 2 3 4 4 IP 67

5 / 6 OK 7 1 2 3 4 5 TCP UDP IP SSH Web Apple Windows FTP DNS/ DNS ICMP Echo Reply ping IGMP Internet Gateway Multicast Protocol PPTP VPN L2TP VPN QTSS itunes 68 4 IP

FTP FTP 1 2 3 4 5 6 70 IP 7 IP 1 2 3 4 5 6 22 650 750 7 TCP UDP 8 OK 9 4 IP 69

1 2 3 4 5 / 6 OK 7 IP IP IP IP IP IP IP 192.168.2.2 IP CIDR 192.168.2.0/24 IP 1 2 3 4 5 6 icmp esp ipencap 7 8 70 4 IP

9 IP CIDR 10 11 IP CIDR 12 13 WAN LAN en0 en1 fw1 14 OK 15 IP IP Web Web IP 1 2 3 4 5 / 6 OK 7 4 IP 71

IP IP m 1 2 3 4 TCP UDP 5 1 2 3 /etc/ipfilter/ip_address_groups.conf 4 ipfw /etc/ipfilter/ipfw.conf 5 ipfw -f flush 6 /etc/hostconfig IPFILTER=-YES- 72 4 IP

7 Mac OS X Server exit 8 9 ipfw(1) keep-state 1 2 4 IP 73

ipfw 1 2 1 2 3 4 5 1 IP /var/log/ipfw.log 74 4 IP

1 2 3 1 Dec 12 13:08:16 ballch5 mach_kernel: ipfw: 65000 Unreach TCP 10.221.41.33:2190 192.168.12.12:80 in via en0 65000 10.221.41.33:2190 Ethernet 0 Web 80 192.168.12.12 2 Dec 12 13:20:15 mayalu6 mach_kernel: ipfw: 100 Accept TCP 10.221.41.33:721 192.168.12.12:515 in via en0 100 10.221.41.33:721 Ethernet 0 LPR 515 192.168.12.12 3 Dec 12 13:33:15 smithy2 mach_kernel: ipfw: 10 Accept TCP 192.168.12.12:49152 192.168.12.12:660 out via lo0 NAT NAT 660 1 2 3 4 5 6 unreach 4 IP 75

1 2 3 4 71 IP 5 6 Accept IP ipfw 1 2 3 4 /etc/ipfilter/ipfw.conf.apple 5 /etc/ipfilter/ipfw.conf.apple ipfw 76 4 IP

IP IP NAT NAT Network Address Translation IP NAT Tiger Server NAT NAT NAT NAT NAT IP IP NAT NAT LAN LAN IP NAT IP NAT LAN NAT IP NAT LAN 93 1 IP LAN Web Web 10.0.1.1 10.0.1.254 IP Web en2 10.0.2.1 4 IP 77

1 LAN 10.0.1.1/24 10.0.1.x 67 2 TCP Web LAN 10.0.2.1 en2 70 IP 1 Web 10.0.2.1 67 2 3 4 Web 5 Web Web Web 6 LAN Web 10.0.1.1 10.0.1.254 IP 1 2 3 4 Web Web Web 5 78 4 IP

6 7 IP 17.128.100.0 SMTP 25 1 2 3 4 5 SMTP 6 7 8 9 17.128.100.0 10 OK 11 12 SMTP 13 Apple IP 10.221.41.33 Apple 1 2 3 4 5 Apple 6 4 IP 79

7 8 9 10.221.41.33 10 OK 11 12 13 Apple 14 DoS TCP IP TCP Dinial of Service Attacks ping 1 2 3 4 5 ICMP Echo Reply (incoming pings) 6 ICMP ping 80 4 IP

P2P P2P P2P P2P P2P Mac OS X Server P2P IP LAN P2P WAN 70 IP Mac OS X Server IP LAN WAN 70 IP LAN WAN 70 IP 4 IP 81

Mac OS X Mac OS X Server TCP UDP RFC Web www.faqs.org/rfcs TCP 7 echo RFC 792 20 FTP RFC 959 21 FTP RFC 959 22 SSH Secure Shell 23 Telnet RFC 854 25 SMTP RFC 821 53 DNS RFC 1034 79 Finger RFC 1288 80 HTTP Web RFC 2068 88 Kerberos V5 KDC RFC 1510 106 3659 110 POP3 RFC 1081 111 RPC RFC 1057 113 AUTH RFC 931 115 sftp 119 NNTP RFC 977 123 Network Time Server NTP RFC 1305 137 Windows 138 Windows 139 Windows RFC 100 SMB/CIFS 143 IMAP RFC 2060 201-208 AppleTalk 311 SSL AppleShare IP Web servermgrd DirectoryService 389 LDAP RFC 2251 Sherlock 2 LDAP 82 4 IP

TCP 407 Timbuktu 427 SLP 443 SSL HTTPS 445 Microsoft 497 Dantz Retrospect 514 syslog 515 LPR RFC 1179 532 netnews 548 AFP Apple 554 Real Time Streaming Protocol QTSS 591 FileMaker Web 600 1023 Mac OS X RPC NetInfo 625 626 IMAP Mac OS X AppleShare IP 6.x 631 IPP 636 LDAP SSL 660 687 AppleShare IP servermgrd 749 kadmind Kerberos changepw 985 NetInfo 993 SSL IMAP 995 SSL POP3 1085 Web Objects 1099 8043 JBoss RMI RMI/IIOP 1220 QTSS Admin 1694 IP RFC 2326 1723 PPTP VPN RFC 2637 2049 NFS 2236 Macintosh 2399 FileMaker 4 IP 83

TCP 3004 isync 3031 AppleEvent 3283 ARD 2.0 3306 MySQL 3632 XCode 3659 106 3689 itunes 4111 XGrid 5003 FileMaker 5100 5190 ichat ichat 5222 ichat 5223 ichat SSL 5269 ichat 5298 ichat 5432 ARD 2.0 5900 ARD 2.0 VNC 7070 Real Time Streaming Protocol QTSS 7777 ichat 8000 8999 Web 8000-8001 QTSS MP3 8005 Tomcat 8043 1099 JBoss RMI RMI/IIOP 8080 8443 9006 Tomcat JBoss 8080 Web Apache 2 9007 AIP Web 16080 Web 42000-42999 itunes Radio 84 4 IP

UDP 7 echo 53 DNS 67 DHCP BootP NetBoot 68 DHCP 69 TFTP Trivial File Transfer Protocol 111 RPC 123 Network Time Protocol RFC 1305 137 WINS Windows 138 Windows NETBIOS 161 SNMP Simple Network Management Protocol 192 AirMac 427 SLP 497 Retrospect 500 VPN ISAKMP/IKE 513 who 514 Syslog 554 Real Time Streaming Protocol QTSS 600 1023 Mac OS X RPC NetInfo 626 985 NetInfo NetInfo 1701 VPN L2TP 3283 ARD 1.2 5353 DNS mdnsresponder 2049 Network File System NFS 3031 3283 Apple Apple Remote Desktop 4500 IKE NAT Traversal 5060 ichat 5297 5678 ichat 4 IP 85

UDP 5353 DNS mdnsresponder 6970-6999 QTSS RTP 7070 Real-Time Streaming Protocol QTSS 16384-16403 ichat RTP RTCP ipfw IP ipfw man man ipfw Request For Comments RFC Request for Comments RFC RFC Web RFC RFC www.ietf.org/rfc.html IANA Internet Assigned Number Authority TCP UDP Web www.iana.org/assignments/port-numbers Assigned Numbers RFC RFC 1700 86 4 IP

5 NAT 5 NAT Network Address Translation IP NAT IP 1 NAT NAT NAT NAT NAT NAT NAT Mac OS X Server DHCP DHCP DHCP 23 2 DHCP NAT Mac OS X Server NAT NAT NAT NAT NAT NAT IP 87

NAT LAN NAT LAN NAT 93 1 IP LAN 1 NAT Mac OS X Server 2 WAN LAN 2 NAT LAN IP LAN IP Mac OS X Server DHCP 3 IP WAN LAN 4 NAT 89 NAT 5 90 6 NAT 89 NAT 7 NAT NAT 66 8 DHCP DHCP 2 DHCP 88 5 NAT

NAT NAT NAT NAT DHCP LAN NAT NAT LAN NAT 1 NAT 2 NAT NAT NAT LAN NAT 1 NAT 2 3 IP 4 5 5 NAT 89

NAT IP IP Mac OS X Server NAT IP NAT IP Mac OS X Server LAN IP IP NAT LAN NAT 1 NAT 2 3 IP 4 NAT NAT IP Web NAT 80 TCP Web sudo plist plist /etc/nat/natd.conf.apple NAT NAT /etc/nat/natd.conf.apple plist 90 5 NAT

1 /etc/natd.plist NAT plist sudo cp /etc/nat/natd.plist.default /etc/natd.plist 2 /etc/natd.plist 2 </dict> </plist> XML <key>redirect_port</key> <array> <dict> <key>proto</key> <string>tcp UDP</string> <key>targetip</key> <string>lan_ip</string> <key>targetportrange</key> <string>lan_ip_range</string> <key>aliasip</key> <string>wan_ip</string> <key>aliasportrange</key> <string>wan_port_range</string> </dict> </array> 3 serveradmin 4 NAT 89 NAT 5 1 IP WAN LAN WAN 10 LAN 10 5 NAT 91

WAN 17.128.128.128 TCP 80 Web LAN 192.168.1.1 TCP 80 Web /etc/natd.plist <key>redirect_port</key> <array> <dict> <key>proto</key> <string>tcp</string> <key>targetip</key> <string>192.168.1.1</string> <key>targetportrange</key> <string>80</string> <key>aliasip</key> <string>17.128.128.128</string> <key>aliasportrange</key> <string>80</string> </dict> </array> WAN 17.128.128.128 TCP UDP 600 1023 NetInfo LAN 192.168.1.1 /etc/natd.plist <key>redirect_port</key> <array> <dict> <key>proto</key> <string>tcp</string> <key>targetip</key> <string>192.168.1.1</string> <key>targetportrange</key> <string>600-1023</string> <key>aliasip</key> <string>17.128.128.128</string> <key>aliasportrange</key> <string>600-1023</string> </dict> </array> <array> <dict> <key>proto</key> <string>udp</string> <key>targetip</key> <string>192.168.1.1</string> <key>targetportrange</key> <string>600-1023</string> <key>aliasip</key> <string>17.128.128.128</string> 92 5 NAT

<key>aliasportrange</key> <string>60-1023</string> </dict> </array> NAT NAT NAT NAT NAT NAT 1 NAT 2 NAT NAT 1 IP LAN NAT LAN IP NAT LAN 15 NAT IP 2 Mac OS X Server Ethernet PCI Ethernet 1 17.254.0.3 IP ISP 17.254.1.6 IP ISP ) 192.168.0.2 192.168.0.254 192.168.0.0/24 192.168.0.0:255.255.255.0 192.168.0.1 5 NAT 93

DHCP IPv4 NAT DHCP IP NAT LAN 1 2 Ethernet WAN 3 Ethernet IP ISP IP 17.254.0.3 255.255.252.0 DNS 17.254.1.6 4 PCI Ethernet 1 IP IP 192.168.0.1 255.255.255.0 DNS 17.254.1.6 5 6 7 DHCP 8 LAN < > IP 192.168.0.2 IP 192.168.0.254 255.255.255.0 en1 192.168.0.1 < > DNS 17.254.1.6 DHCP 24 9 DHCP 10 NAT 11 NAT Ethernet 12 94 5 NAT

13 NAT 14 15 16 192.168.0.0/24 LAN IP 67 17 LAN LAN Web SSH 68 18 LAN Web SSH 68 19 LAN LAN 1 IP LAN LAN LAN LAN DHCP NAT Web 80 10.0.0.5 80 SSH 22 10.0.0.15 22 17.100.0.1 domain.example.com NAT Web NAT 10.0.0.5 Web 1 NAT LAN NAT DNS IP 3 5 NAT 95

NAT DNS IP NAT LAN NAT 2 Ethernet PCI Ethernet 1 17.100.0.1 IP ISP 192.168.0.0 192.168.0.255 192.168.0.0/24 192.168.0.0:255.255.255.0 192.168.0.1 192.168.0.2 192.168.0.3 DHCP IPv4 NAT DHCP IP 1 2 DHCP 3 LAN < > IP 192.168.0.2 IP 192.168.0.254 255.255.255.0 en1 192.168.0.1 < > DNS <ISP > Web 192.168.0.2 <Web Ethernet > 192.168.0.3 < Ethernet > DHCP 24 30 DHCP IP 4 DHCP 5 NAT 6 NAT Ethernet 96 5 NAT

TCP 80 Web 192.168.0.2 TCP 25 192.168.0.3 7 8 NAT 9 10 11 67 12 LAN 2 Web SMTP 68 13 14 DNS 2 DNS ISP IP 17.100.0.1 www.example.com A IP mail.example.com MX A CNAME www.example.com Web 192.168.0.2 mail.example.com 192.168.0.3 NAT DHCP IP Ethernet Web IP natd NAT natd man man natd 5 NAT 97

Request For Comments RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html NAT RFC 1631 RFC 3022 98 5 NAT

6 VPN 6 VPN Virtual Private Network 2 LAN VPN LAN LAN VPN VPN VPN WAN VPN ISP VPN LAN VPN VPN VPN VPN VPN VPN ID 99

L2TP/IPSec Layer Two Tunnelling Protocol, Secure Internet Protocol L2TP/IPSec IPSec Cisco L2F IPSec Verisign L2TP Kerberos Mac OS X Server VPN PPTP Point to Point Tunneling Protocol PPTP VPN Windows VPN PPTP 128 VPN 40 PPTP Windows Mac OS X 10.2.x Mac OS X Server L2TP VPN Kerberos v5 Microsoft Challenge Handshake Authentication Protocol version 2 MS-CHAPv2 Mac OS X Server PPTP VPN MS-CHAPv2 Kerberos Kerberos Key Distribution Server MS-CHAPv2 Kerberos VPN Windows Mac OS X Server PPTP VPN PPTP RSA Security SecurID VPN / /Preferences/SystemConfiguration/com.apple.RemoteAccessServers.plist 107 VPN SecurID 100 6 VPN

VPN VPN Virtual Private Network L2TP/IPSec PPTP Mac OS X 10.4 10.3.x X X Mac OS X 10.2.x X Windows X Windows XP X Linux Unix X X L2TP 8 12 PPTP 128 PPTP 40 VPN Mac OS X Server VPN DHCP DHCP VPN IP DHCP DHCP 23 2 DHCP VPN IP IP LAN VPN IP ISP VPN IP VPN 6 VPN 101

VPN VPN VPN VPN VPN 1 VPN 2 1 3 L2TP L2TP IPSec IP VPN L2TP PPTP L2TP 1 VPN 2 3 L2TP 4 L2TP over IPsec 5 IP 6 IP 7 PPP Kerberos Kerberos MS-CHAPv2 8 9 PPTP PPTP 128 40 IP VPN L2TP PPTP 102 6 VPN

PPTP 1 VPN 2 3 PPTP 4 PPTP 5 128 40 128 40 40 VPN 6 IP 7 VPN VPN IP DHCP DNS 1 VPN 2 3 4 DNS IP 5 6 VPN VPN VPN ISP VPN LAN IP VPN LAN VPN 6 VPN 103

VPN VPN VPN VPN DNS VPN LAN IP 17.x.x.x VPN Web URL LPR VPN 17.x.x.x LAN LAN Web 17.x.x.x 17.x.x.x 17.0.0.0 255.0.0.0 Private LAN VPN 17.x.x.x IP VPN 17.x.x.x LAN 17.100.100.x 17.100.100.0 255.255.255.0 Public 17.x.x.x 17.100.100.x VPN Private VPN Public VPN VPN 104 6 VPN

1 VPN 2 3 4 5 a 192.168.0.0 b 255.255.0.0 6 a VPN b 7 OK 8 VPN VPN VPN VPN VPN Mac OS X Server ACL ACL ACL VPN 1 VPN VPN 2 3 4 5 6 7 6 VPN 105

IP VPN IP VPN VPN IP VPN Mac OS X Server IP IP VPN 1 2 3 4 5 6 VPN L2TP UDP VPN PPTP TCP 7 VPN L2TP PPTP 8 9 VPN IP CIDR VPN IP 10 VPN IP CIDR 11 WAN 12 OK 13 106 6 VPN

LDAP VPN-PPTP Mac OS X 10.4 LDAP PPTP-VPN PPTP Mac OS X Server VPN Mac OS X Server 10.3 10.4 1 /usr/sbin/vpnaddkeyagentuser LDAP VPN LDAP sudo /usr/sbin/vpnaddkeyagentuser /LDAPv3/127.0.0.1 VPN LDAP LDAP LDAP IP LDAP 17.221.67.87 sudo /usr/sbin/vpnaddkeyagentuser /LDAPv3/17.221.67.87 2 a VPN LDAP b LDAP LDAP LDAP LDAP VPN PPTP 3 VPN PPTP 4 VPN VPN SecurID RSA Security SecurID L2TP PPTP Web www.rsasecurity.com 6 VPN 107

Mac OS X Server VPN SecurID VPN RSA Security SecurID VPN SecurID 1 RSA Security SecurID sdconf.rec SecurID Mac OS X Server /var/ace 1 a / / / b sudo mkdir /var/ace Return c Return d Dock Finder e f /var/ace g h sdconf.rec SecurID ace i ace 2 Mac OS X Server VPN EAP-SecurID PPTP 2 1 # sudo serveradmin settings vpn:servers:com.apple.ppp.pptp:ppp:authenticatoreapplugins:_array_index : 0 = "EAP-RSA" # sudo serveradmin settings vpn:servers:com.apple.ppp.pptp:ppp:authenticatorprotocol:_array_index:0 = "EAP" L2TP 2 # sudo serveradmin settings vpn:servers:com.apple.ppp.l2tp:ppp:authenticatoreapplugins:_array_index : 0 = "EAP-RSA" # sudo serveradmin settings vpn:servers:com.apple.ppp.l2tp:ppp:authenticatorprotocol:_array_index:0 = "EAP" SecurID Mac OS X Server VPN 108 6 VPN

VPN VPN VPN VPN VPN L2TP PPTP 1 VPN 2 VPN VPN VPN VPN VPN 1 VPN 2 3 4 5 VPN VPN VPN /var/log/ppp/ vpnd.log 1 VPN 2 6 VPN 109

VPN VPN IP IP 1 VPN 2 VPN VPN VPN LAN L2TP prdwkj49fd!254 gateway.example.com 192.168.0.0 192.168.0.255 192.168.0.0/24 192.168.0.0:255.255.255.0 192.168.0.3 192.168.0.127 192.168.0.2 VPN L2TP LAN 1 VPN 1 VPN 2 3 4 L2TP 5 prdwkj49fd!254 IPSec 110 6 VPN

6 VPN IP DHCP 192.168.0.128 7 VPN IP DHCP 192.168.0.255 8 VPN 9 10 11 LAN DNS IP 192.168.0.2 12 VPN 13 14 VPN 2 1 VPN 67 2 L2TP VPN 68 3 VPN 4 3 Mac OS X 1 2 VPN 3 L2TP over IPSec 4 5 a gateway.example.com b < > c < > d prdwkj49fd!254 6 OK 6 VPN 111

VPN LAN 1 VPN LAN 110 192.168.0.15 Apple 110 m 1 12 IP 192.168.0.15 255.255.255.255 m 2 3 Apple VPN DNS VPN VPN VPN 2 2 LAN VPN LAN LAN Mac OS X Server s2svpnadmin site-to-site VPN admin s2svpnadmin sudo s2svpnadmin man s2svpnadmin LAN LAN s2svpnadmin s2svpnadmin VPN L2TP/IPSec VPN PPTP 2 112 6 VPN

L2TP prdwkj49fd!254 A.B.C.D W.X.Y.Z 192.168.0.1 192.168.20.1 192.168.0.0 192.168.0.255 192.168.0.0/24 192.168.0.0:255.255.0.0 192.168.20.0 192.168.20.255 192.168.20.0/16 192.168.0.0:255.255.0.0 192.168.0.2 LAN L2TP LAN 1 s2svpnadmin 1 s2svpnadmin sudo s2svpnadmin 2 Configure a new site-to-site server 3 1 site_1 4 IP 1 A.B.C.D 2 W.X.Y.Z 5 IP 1 W.X.Y.Z 2 A.B.C.D 6 s prdwkj49fd!254 c 7 1 8 1 192.168.0.0 2 192.168.20.0 9 CIDR CIDR 1 192.168.2.0/16 16 6 VPN 113

10 1 192.168.20.0 2 192.168.0.0 11 CIDR CIDR 1 192.168.2.0/16 16 12 Return LAN LAN 13 y site_1 14 s2svpnadmin 2 1 LAN IP 1 A.B.C.D/32 2 W.X.Y.Z/32 67 2 L2TP VPN 68 3 IP 1 UDP A.B.C.D W.X.Y.Z isakmp 2 UDP W.X.Y.Z A.B.C.D isakmp 114 6 VPN

3 esp A.B.C.D W.X.Y.Z 4 esp W.X.Y.Z A.B.C.D 5 ipencap A.B.C.D W.X.Y.Z 6 ipencap W.X.Y.Z A.B.C.D 70 IP 4 5 3 VPN 1 VPN VPN s2svpnadmin 2 LAN LAN ping 6 VPN 115

L2TP/IPSec IETF Internet Engineering Task Force L2TP/IPSec Web www.ietf.org/ids.by.wg/ipsec.html Request For Comments RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html L2TP RFC 2661 PPTP RFC 2637 Kerberos 5 RFC 1510 116 6 VPN

7 NTP 7 NTP Network Time Protocol NTP Cookie Web NTP NTP UTC Universal Time Coordinated UTC UTC NTP UTC Stratum 1 Stratum 2 3 Stratum 3 NTP UTC 117

NTP Mac OS X Server NTP NTP NTP Stratum 2 time.apple.com NTP UDP 123 59 4 IP NTP 1 2 3 4 5 6 NTP 7 118 7 NTP

NTP NTP 1 2 3 4 5 time.example.com IP 6 NTP NTP Web www.ntp.org NTP Web www.eecis.udel.edu/~mills/ntp/servers.html Request For Comments RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html NTP 3 RFC 1305 7 NTP 119

8 VLAN 8 VLAN Mac OS X Server Xserve Ethernet PCI Ethernet 802.1q VLAN Virtual Local Area Network VLAN LAN LAN Xserve G5 VLAN IEEE 802.1q VLAN VLAN VLAN VLAN 802.1Q Ethernet 802.1Q Ethernet VLAN Xserve G5 VLAN 1 2 3 4 VLAN 5 VLAN Ethernet 6 VLAN 121

7 VLAN 1 4094 OK VLAN VLAN ID VID VID VID 8 VLAN VLAN VLAN www.ieee.org VLAN IEEE standards.ieee.org/getieee802/download/802.1q-1998.pdf 122 8 VLAN

9 IPv6 9 IPv6 Internet Protocol Version 6 IPv6 Internet Protocol IP Version 4 IPv4 IP Internet Protocol IPv4 IP IPv4 32 43 IPv4 IPv4 NAT Network Address Translation NAT 2 IPv6 3 10 38 NAT IPv6 IPv4 Mac OS X Server IPv6 IPv6 IPv6 123

IPv6 Mac OS X Server IPv6 DNS BIND IP POP/IMAP/SMTP SMB/CIFS Web Apache 2 Mac OS X Server IPv6 ping6 traceroute6 IPv6 IPv6 IPv6 IPv6 IPv6 IPv4 IPv4 4 10 IPv6 16 IPv6 xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx IPv6 : 16 E3C5:0000:0000:0000:0000:4AC8:C0A8:6420 E3C5:0:0:0:0:4AC8:C0A8:6420 IPv6 0 0 E3C5::4AC8:C0A8:6420 124 9 IPv6

IPv4 IPv6 IPv4 IPv6 4 2 IPv4 E3C5:4AC8:192.168.100.32 IPv6 IPv6 2 0:0:0:0:0:0:0:0 0:0:0:0:0:0:0:1 IPv4 127.0.0.1 IPv6 IPv6 Ethernet 1 IPv6 1 IPv6 IPv6 IPv6 IPv4 IPv6 IPv6 3 IP 1 1 1 IPv6 IPv6 IPv4 IPv6 FF 255 1 9 IPv6 125

Internet Protocol Version 6 Web www.ipv6.org IPv6 Web IPv6 www.ipv6forum.com/navbar/links/v6apps.htm Request For Comments RFC Request for Comments RFC RFC RFC Web www.ietf.org/rfc.html 29 IPv6 RFC Web www.ipv6.org/specs.html 126 9 IPv6

Mac OS X Server 10.4 ACL Access Control List 1 Challenge Handshake Authentication Protocol CHAP Challenge Handshake Authentication Protocol DHCP Dynamic Host Configuration Protocol IP DHCP DHCP DHCP IP DHCP IP DHCP DNS Domain Name System IP DNS IP DNS Domain Name System IP DNS Domain Name System IP Domain Name System Dynamic Host Configuration Protocol EAP Extensible Authentication Protocol 1 127

Ethernet 1 TCP/IP Ethernet ID FTP File Transfer Protocol FTP FTP FTP GB 1,073,741,824 2 30 HTTP Hypertext Transfer Protocol World Wide Web Web HTTP Web HTML Hypertext Transfer Protocol IANA Internet Assigned Numbers Authority IP ICMP Internet Control Message Protocol ICMP 2 IEEE Institute of Electrical and Electronics Engineers, Inc. IGMP Internet Group Management Protocol QuickTime Streaming Server QTSS SLP Service Location Protocol Internet Assigned Numbers Authority Internet Control Message Protocol Internet Group Management Protocol Internet Message Access Protocol Internet Protocol IP Internet Protocol IPv4 TCP Transmission Control Protocol IP TCP 128

IPSec IP L2TP VPN IPSec IPSec IP IPv4 IPv6 Internet Protocol 6 IP IPv4 IPv6 IP IP IP ISP Internet service provider Web KB 1,024 2 10 L2TP Layer Two Tunnelling Protocol VPN Cisco L2F PPTP L2TP IPSec LAN WAN LDAP Lightweight Directory Access Protocol Lightweight Directory Access Protocol Mac OS X Mac OS X Macintosh UNIX Mac OS X Server Mac Windows UNIX Linux MAC Media Access Control AirMac MAC AirMac ID Media Access Control Microsoft Challenge Handshake Authentication Protocol 129

MS-CHAP Microsoft Challenge Handshake Authentication Protocol Windows VPN MS-CHAP Windows CHAP MX DNS 1 MX MX NAT Network Address Translation 1 IP IP 1 IP IP NetInfo 1 Network Address Translation NTP Network Time Protocol 1 NTP Point to Point Tunneling Protocol Post Office Protocol PPTP Point to Point Tunneling Protocol VPN Windows VPN PTR IP IPv4 DNS DNS QTSS QuickTime Streaming Server QuickTime Streaming Server Secure Sockets Layer SLP DA Service Location Protocol Directory Agent SLP SLP/DA 130

SMTP Simple Mail Transfer Protocol POP IMAP SPAM SSL Secure Sockets Layer SSL TLS Transport Level Security SSL Secure Sockets Layer SSL TLS Transport Level Security Stratum 1 Network Time Protocol NTP UTC Stratum 2 Stratum 3 TCP Transmission Control Protocol IP Internet Protocol IP TCP Time-To-Live Transmission Control Protocol TTL Time-To-Live DNS IP TTL DNS TXT DNS 1 DNS UCE UDP User Datagram Protocol 1 Internet Protocol IP TCP UDP User Datagram Protocol UTC UTC UTC Virtual Private Network 131

VPN Virtual Private Network VPN WAN LAN WAN Windows Internet Naming Service WINS Windows Internet Naming Service Windows IP WINS WLAN permissions 4 privileges TCP/IP 132

LDAP NetInfo Active Directory BSD L2TP VPN LAN WAN Mac OS X SLP SMB/CIFS Finder SLP Windows Finder < > Bluetooth Apple Remote Desktop 133

Web denial of service attack DoS attack 1 ping IP DNS IP DNS DNS DNS.com.net.us.uk TLD www.example.com www example com 2 IP IP 1 QuickTime Player QTSS SDP ID Mac OS X Server x.509 CA 1 134

mail.apple.com MailSrv473.apple.com IP IP DNS DNS 1 IP IP IP Ethernet AirMac FireWire Xsan 1 8 2 QTSS TCP UDP IP 135

1 0 1 Mac OS X Server IP IP IP IP IP DNS DNS 1 Ethernet 2 IP QuickTime Streaming Server 1 Web 2 TCP UDP 136

UNIX Mac OS X Server NFS /etc/hostconfig HOSTNAME=some-host-name DHCP BootP IP DNS IP localhost DNS DNS DNS QuickTime 1 DNS IP ZeroConf www.apple.com/jp www.zeroconf.org Mac OS X Server Mac OS X 1 RSTP IP IP DHCP IP 137

QuickTime Streaming Server 1 SMTP SMTP SMTP DNS IP.local billscomputer.local DNS 1 IP 138

A AirMac DHCP 25 B BIND 37, 38 56 C CIDR 62, 64 D DHCP 25 25 25 DHCP 23 36 AirMac 25 DHCP DNS 29 23 26 DNS 29 LDAP 25 26 26 31 32 32 24 IP 28 LDAP 29 WINS 30, 31 27 28 27 28 27 26 23 25 23 36 32 DNS 37 58 DHCP 29 37 41 41 42 38 38 38 41 38 38 38 41 37 58 41 56 53 DoS 80 Dynamic Host Configuration Protocol DHCP I IANA 38 Internet Gateway Multicast Protocol IGMP Internet Protocol Version 6 IPv6 IPv6 124 124 125 124 126 124 IP DHCP 23 DHCP 28 DHCP 23 IPv6 124 24 24 24 64 64 64 25 25 139

IP 31 IP 59 61, 66 59 66 72 65 DoS 80 65 66, 68 80 86 62 60 77 79 69, 70 65 71 IP 64 82 86 60 74 74 75 M Mac OS X Server 82 86 Mac OS X 82 86 Mail Exchange MX MX Mail Exchange 40, 54 MX 53 N NAT 89 87 93 93 89 NetBoot 32 NTP 117 119 118 119 117 S Stratum 117 T TCP/IP 56 57 TCP 82 84 U UDP 85 UTC Universal Time Coordinated 117 V VPN 110 109 105 109 109 27, 32, 78, 79, 94, 95, 96, 97 38 11 24 24, 27 62 IP 24 Stratum 117 IP 24 38, 39 38 TCP/IP 56 57 56 57 62 64 62 64 71 77 79, IP 62 65 56 Mac OS X 82 86 TCP 82 83 UDP 85 140

11 53 53 53 DNS 53 56 DHCP 32 DNS 49 IP 74 76 DHCP 26 141