ÈçºÎÈ·±£ÎҵĴ«ÆæÒýÇæ·þÎñÆ÷ÔÚIPv6»·¾³Ïµİ²È«ÐÔ£¿

À´Ô´£º ×÷Õߣº µã»÷£º
ÔÚʹÓô«ÆæÒýÇæ·þÎñÆ÷²¢²¿ÊðÔÚIPv6»·¾³ÏÂʱ£¬È·±£°²È«ÐÔÊÇÖÁ¹ØÖØÒªµÄ¡£ÒÔÏÂÊÇһЩ¹Ø¼ü´ëÊ©£¬¿ÉÒÔ°ïÖúÄãÌá¸ß·þÎñÆ÷µÄ°²È«ÐÔ£º

¸üкͲ¹¶¡¹ÜÀí£ºÈ·±£ÄãµÄ·þÎñÆ÷Èí¼þºÍ²Ù×÷ϵͳ¶¼°²×°ÁË×îÐµİ²È«²¹¶¡¡£Õâ°üÀ¨´«ÆæÒýÇæ±¾ÉíÒÔ¼°·þÎñÆ÷ÉÏÔËÐеÄËùÓÐÆäËûÈí¼þ¡£

·À»ðǽÅäÖãºÕýÈ·ÅäÖ÷À»ðǽ£¬ÒÔÏÞÖÆ²»±ØÒªµÄÈëÕ¾ºÍ³öÕ¾Á÷Á¿¡£È·±£·À»ðǽ¹æÔòÔÊÐíºÏ·¨µÄIPv6Á÷Á¿£¬Í¬Ê±×èֹδ¾­ÊÚȨµÄ·ÃÎÊ¡£

·ÃÎÊ¿ØÖÆ£ºÊµÊ©ÑϸñµÄ·ÃÎÊ¿ØÖƲßÂÔ£¬È·±£Ö»ÓÐÊÚȨµÄÓû§ºÍ·þÎñÄܹ»·ÃÎÊ·þÎñÆ÷¡£Õâ°üÀ¨Ê¹ÓÃÇ¿ÃÜÂë¡¢¶àÒòËØÈÏÖ¤ºÍ×îСȨÏÞÔ­Ôò¡£

¼à¿ØºÍÈÕÖ¾¼Ç¼£ºÊµÊ©ÊµÊ±¼à¿ØºÍÈÕÖ¾¼Ç¼»úÖÆ£¬ÒÔ±ãÄܹ»¼°Ê±·¢ÏÖºÍÏìÓ¦ÈκοÉÒɻ¡£È·±£ÈÕÖ¾°üº¬ÁË×ã¹»µÄÐÅÏ¢£¬Èçʱ¼ä´Á¡¢Ô´IPµØÖ·ºÍÖ´ÐеIJÙ×÷¡£

°²È«É󼯣º¶¨ÆÚ½øÐа²È«É󼯣¬ÒÔʶ±ðºÍÐÞ¸´Ç±Ôڵݲȫ©¶´¡£Õâ°üÀ¨¶Ô·þÎñÆ÷ÅäÖá¢Ó¦ÓóÌÐò´úÂëºÍÍøÂç»ù´¡ÉèÊ©µÄÉ󼯡£

ʹÓð²È«µÄ±à³Ìʵ¼ù£ºÈç¹ûÄãµÄ·þÎñÆ÷ÔËÐÐ×Ô¶¨Òå´úÂ룬ȷ±£×ñÑ­°²È«µÄ±à³Ìʵ¼ù£¬ÒÔ·ÀÖ¹°²È«Â©¶´£¬ÈçSQL×¢Èë¡¢¿çÕ¾½Å±¾¹¥»÷µÈ¡£

DDoS·À»¤£ºÓÉÓÚIPv6µØÖ·¿Õ¼äµÄ¹ãÀ«£¬DDoS¹¥»÷¿ÉÄܸü¼ÓÄÑÒÔ·ÀÓù¡£Ê¹ÓÃרҵµÄDDoS·À»¤·þÎñ¿ÉÒÔ°ïÖú¼õÇáÕâÀ๥»÷µÄÓ°Ïì¡£

IPv6ÌØ¶¨°²È«´ëÊ©£ºÓÉÓÚIPv6µÄÒ»Ð©ÌØÐÔ£¬Èç×Ô¶¯ÅäÖõØÖ·£¨SLAAC£©ºÍÁÚ¾Ó·¢ÏÖЭÒ飬¿ÉÄÜ»áÒýÈëÐµİ²È«·çÏÕ¡£È·±£ÄãµÄÍøÂçºÍ·þÎñÆ÷ÅäÖÿ¼Âǵ½ÁËÕâЩIPv6ÌØÓеݲȫÎÊÌâ¡£

½ÌÓýºÍÅàѵ£ºÈ·±£ÄãµÄÍŶÓÁ˽âIPv6µÄ°²È«×î¼Ñʵ¼ù£¬²¢Äܹ»Ê¶±ðºÍÓ¦¶ÔÏà¹ØµÄ°²È«Íþв¡£

Ó¦¼±ÏìÓ¦¼Æ»®£ºÖƶ¨²¢²âÊÔÓ¦¼±ÏìÓ¦¼Æ»®£¬ÒÔ±ãÔÚ·¢Éú°²È«Ê¼þʱÄܹ»Ñ¸ËÙ²ÉÈ¡Ðж¯£¬¼õÉÙDZÔÚµÄË𺦡£

ͨ¹ýʵʩÕâЩ´ëÊ©£¬Äã¿ÉÒÔÌá¸ß´«ÆæÒýÇæ·þÎñÆ÷ÔÚIPv6»·¾³Ïµİ²È«ÐÔ£¬±£»¤ÄãµÄ·þÎñÆ÷ºÍÓû§ÃâÊÜÍøÂç¹¥»÷µÄÍþв¡£

ÔÚ IPv6 »·¾³ÏÂÈ·±£´«ÆæÒýÇæ·þÎñÆ÷µÄ°²È«ÐÔ£¬¿ÉÒÔ²ÉÈ¡ÒÔÏ´ëÊ©£º
Ê×ÏÈ£¬ÔÚ Nginx ÖпªÆô IPv6 Ö§³Ö·Ç³£ÖØÒª¡£ÒªÈ·±£ Nginx ±»±àÒëʱ£¬Ê¹ÓÃÁËÕýÈ·µÄ IPv6 Ñ¡ÏÈç --with-ipv6 Ñ¡ÏîÒÔÆôÓà IPv6 Ö§³Ö¡£ÅäÖà IPv6 µØÖ·Ê±£¬ÒªÊ¹Óà IPv6 µØÖ·À´¶¨Òå Nginx µÄ¼àÌý¶Ë¿ÚºÍ·þÎñÆ÷Ãû³Æ£¬IPv6 µØÖ·Ê¹ÓÃðºÅ×÷Ϊ·Ö¸ô·û£¬ÐèÒªÓ÷½À¨ºÅ½«·þÎñÆ÷Ãû³ÆÀ¨ÆðÀ´¡£
ͬʱ£¬ÒªÊ¹Óà IPv6 ·À»ðǽ£¬¿ØÖƽøÈëºÍÀë¿ªÍøÂçµÄ IPv6 Á÷Á¿£¬×èֹδÊÚȨµÄ·ÃÎʺͷÀÖ¹ÍøÂçÖеĹ¥»÷¡£²ÉÓà IPsec ЭÒ飬Ϊ IPv6 Á÷Á¿Ìṩ¼ÓÃܺÍÉí·ÝÑéÖ¤µÈ°²È«·þÎñ£¬±£Ö¤Êý¾ÝÔÚ´«Êä¹ý³ÌÖеݲȫÐÔºÍÍêÕûÐÔ¡£
´ËÍ⣬½ûÓà IPv6 ²»±ØÒªµÄ¹¦ÄÜ£¬Èç IPv6 ¹ý³ÌÄÚ·ÓÉЭÒ飨RIPng£©ºÍ IPv6 ËíµÀЭÒ飬ÒÔÌá¸ß°²È«ÐÔ¡£¶¨ÆÚ¸üÐÂÈí¼þ£¬ÐÞ¸´¿ÉÄÜ´æÔڵĩ¶´ºÍ´íÎó¡£ÕýÈ·ÅäÖà IPv6 µØÖ·£¬ÀýÈçʹÓÃΨһ±¾µØµØÖ·£¨ULA£©À´±ÜÃâÍøÂçµØÖ·µÄ¹«¿ª±©Â¶¡£ÔöÇ¿·ÃÎÊ¿ØÖÆ£¬²ÉȡһЩ´ëÊ©À´ÔöÇ¿·ÃÎÊ¿ØÖÆ£¬±£ÕÏ·þÎñÆ÷°²È«¡£
IPv6 ÓµÓо޴óµÄµØÖ·¿Õ¼äºÍ²ã´Î»¯µÄµØÖ·½á¹¹£¬Ö§³Ö¸ü¶à¼¶±ðµÄµØÖ·²ã´Î£¬ÓÐÀûÓڹǸÉÍøÂ·ÓÉÆ÷¶ÔÊý¾Ý°üµÄ¿ìËÙת·¢¡£IPv6 ÔÚЭÒé²ãÃæÌṩÁËԴ·Óɼì²é¹¦ÄÜ£¬¿É¸ù¾ÝÐèÒª¿ªÆô·´Ïò·Óɼì²â¹¦ÄÜ£¬·ÀֹԴ·Óɴ۸ĺͶÔÓ¦¹¥»÷¡£IPv6 Êý¾Ý°üÍ·ÓÉ»ù±¾Í·ºÍ²»Í¬ÀàÐ͵ÄÀ©Õ¹±¨Í·×é³É£¬¹¦ÄÜÃ÷È·£¬¹Ì¶¨³¤¶È£¬²»ÔÊÐí·ÖƬ£¬½â¾öÁË IPv4 ÏÂÕë¶Ô°üÍ·µÄË鯬¹¥»÷¡£
×ÜÖ®£¬Í¨¹ýÒÔÉ϶àÖÖ´ëÊ©µÄ×ÛºÏÔËÓ㬿ÉÒÔÓÐЧÌá¸ß´«ÆæÒýÇæ·þÎñÆ÷ÔÚ IPv6 »·¾³Ïµİ²È«ÐÔ¡£
ÔÚ Nginx ÖпªÆô IPv6 Ö§³ÖµÄÒªµã
ÔÚ Nginx ÖпªÆô IPv6 Ö§³ÖÊÇÈ·±£·þÎñÆ÷°²È«ÐÔµÄÖØÒª»·½ÚÖ®Ò»¡£Ê×ÏÈ£¬ÔÚ±àÒë Nginx ʱ£¬±ØÐëʹÓÃÕýÈ·µÄÑ¡ÏîÀ´ÆôÓà IPv6 Ö§³Ö£¬¼´È·±£Ê¹ÓÃÁË --with-ipv6 ²ÎÊý¡£±àÒëÍê³Éºó£¬¿ÉÒÔͨ¹ýÌØ¶¨µÄÃüÁîÀ´¼ì²é IPv6 ÊÇ·ñÕý³£¹¤×÷£¬±ÈÈçʹÓÃcurl -g -6 http: //(::1)/ -IÃüÁÈç¹ûÄÜÕý³£»ñÈ¡µ½Êä³öÐÅÏ¢£¬¾Í±íÃ÷ IPv6 Ö§³ÖÕý³£¡£ÔÚÅäÖà IPv6 µØÖ·Ê±£¬Òª×¢ÒâÆäÓë IPv4 µØÖ·µÄÇø±ð£¬IPv6 µØÖ·Ê¹ÓÃðºÅ×÷Ϊ·Ö¸ô·û£¬ÐèÒªÓ÷½À¨ºÅ½«·þÎñÆ÷Ãû³ÆÀ¨ÆðÀ´£¬ÀýÈçlisten (::):80; server_name (::):example.com;¡£´ËÍ⣬»¹ÐèÒª×Ðϸ¼ì²éÅäÖÃÎļþ£¬È·±£Ã»ÓÐÈκÎì¶Ü»ò´íÎ󣬿Éͨ¹ýsudo nginx -tÃüÁîÀ´¼ì²é¡£
ΪÁË·ÀÖ¹ DoS ¹¥»÷µÈ¶ñÒâÐÐΪ£¬»¹ÐèÒª¶Ô Nginx µÄÏà¹Ø²ÎÊý½øÐкÏÀíÅäÖ㬱ÈÈçÏÞÖÆÁ¬½ÓÊý¡¢ÇëÇóËÙÂʵȡ£Í¬Ê±£¬Òª¼°Ê±¸üРNginx µ½×îа汾£¬ÒÔÐÞ¸´¿ÉÄÜ´æÔڵݲȫ©¶´¡£
IPv6 ·À»ðǽµÄʹÓÃÒªµã
IPv6 ·À»ðǽÔÚ±£ÕÏ·þÎñÆ÷°²È«·½ÃæÆð׏ؼü×÷Óá£Ëü¿ÉÒÔ¿ØÖƽøÈëºÍÀë¿ªÍøÂçµÄ IPv6 Á÷Á¿£¬×èֹδÊÚȨµÄ·ÃÎʺͷÀÖ¹ÍøÂçÖеĹ¥»÷¡£ÀýÈ磬ʹÓà iptables µÈ·À»ðǽÈí¼þ¿ÉÒÔÉèÖà IPv6 ·À»ðǽ¹æÔò¡£Ä¬ÈÏÇé¿öÏ£¬Ó¦¾Ü¾øËùÓÐÊäÈëºÍת·¢Á÷Á¿£¬Ö»ÔÊÐíÏà¹ØÁ¬½Ó¡¢IPv6 ¿ØÖÆÏûÏ¢ºÍ±¾µØÁ¬½Ó¡£Í¬Ê±£¬»¹¿ÉÒÔ¸ù¾Ýʵ¼ÊÐèÇó£¬ÔÊÐíÌØ¶¨µÄ SSH¡¢HTTP ºÍ HTTPS Á÷Á¿µÈ¡£
ÔÚÅäÖà IPv6 ·À»ðǽʱ£¬Òª³ä·ÖÁ˽â·þÎñÆ÷µÄÓ¦Óó¡¾°ºÍ·ÃÎÊÐèÇ󣬾«È·µØÉèÖùæÔò¡£¶ÔÓÚһЩÃô¸Ð·þÎñ»ò¶Ë¿Ú£¬Òª½øÐÐÑϸñµÄ·ÃÎÊ¿ØÖÆ¡£´ËÍ⣬Ҫ¶¨ÆÚ¼ì²é·À»ðǽ¹æÔòµÄÓÐЧÐÔ£¬È·±£ÆäÄܹ»Ó¦¶Ô²»¶Ï±ä»¯µÄ°²È«Íþв¡£
½ûÓà IPv6 ²»±ØÒª¹¦Äܵķ½·¨
½ûÓà IPv6 µÄ²»±ØÒª¹¦ÄÜ¿ÉÒÔÌá¸ßϵͳµÄ°²È«ÐÔºÍÐÔÄÜ¡£Ò»ÖÖ³£¼ûµÄ·½·¨ÊÇͨ¹ýϵͳÅäÖÃÎļþ/etc/sysctl.conf£¬ÔÚÆäÖÐÌí¼ÓÏàÓ¦µÄÐÐÀ´½ûÓÃÕû¸öϵͳËùÓÐ½Ó¿ÚµÄ IPv6£¬ÀýÈçnet.ipv6.conf.all.disable_ipv6 = 1¡£Ò²¿ÉÒÔÕë¶Ôijһ¸öÖ¸¶¨½Ó¿Ú½øÐнûÓã¬Èçnet.ipv6.conf.eth0.disable_ipv6 = 1¡£Ê¹ÕâЩ¸ü¸ÄÉúЧ£¬¿ÉÒÔÔËÐÐsudo sysctl -p /etc/sysctl.confÃüÁî¡£
ÁíÍ⣬»¹¿ÉÒÔÔÚÄÚºËÆô¶¯Ê±´«µÝÄں˲ÎÊýÀ´½ûÓà IPv6 ²»±ØÒªµÄ¹¦ÄÜ¡£ÓÃÎı¾±à¼­Æ÷´ò¿ª/etc/default/grub²¢¸øGRUBCMDLINELINUX±äÁ¿Ìí¼Óipv6.disable=1¡£
ÔÚ½ûÓà IPv6 ²»±ØÒª¹¦ÄÜ֮ǰ£¬ÐèÒª×ÐϸÆÀ¹ÀÆä¶ÔϵͳºÍÓ¦ÓõÄÓ°Ï죬ȷ±£²»»áÓ°Ïìµ½¹Ø¼ü·þÎñµÄÕý³£ÔËÐС£
IPv6 µØÖ·µÄÕýÈ·ÅäÖÃ
IPv6 µØÖ·µÄÕýÈ·ÅäÖöÔÓÚ·þÎñÆ÷ÔÚ IPv6 »·¾³ÏµÄÕý³£ÔËÐÐÖÁ¹ØÖØÒª¡£IPv6 Ö§³Ö¶àÖÖµØÖ·ÅäÖ÷½Ê½£¬°üÀ¨ÊÖ¶¯ÅäÖᢻùÓÚ ICMPv6 NDP ЭÒéµÄ×Ô¶¯ÅäÖúͻùÓÚ DHCPv6 ЭÒéµÄ×Ô¶¯ÅäÖá£
ÔÚÊÖ¶¯ÅäÖÃʱ£¬ÐèҪ׼ȷÊäÈëÍêÕûµÄ IPv6 µØÖ·¡£¶ø»ùÓÚ ICMPv6 NDP ЭÒéµÄ×Ô¶¯ÅäÖã¬ÏµÍ³»á×Ô¶¯Éú³ÉÁ´Â·±¾µØµØÖ·£¬²¢½øÐÐÖØ¸´µØÖ·¼ì²âºÍÁÚ¾Ó·¢ÏÖ£¨µØÖ·½âÎö£©¡£¶ÔÓÚ»ùÓÚ DHCPv6 ЭÒéµÄ×Ô¶¯ÅäÖã¬ÐèҪȷ±£ DHCPv6 ·þÎñÆ÷Õý³£ÔËÐУ¬²¢ÕýÈ··ÖÅ䵨ַ¡£
ÔÚÅäÖà IPv6 µØÖ·Ê±£¬»¹Òª¿¼ÂǵØÖ·µÄΨһÐԺͿÉ·ÓÉÐÔ£¬±ÜÃâµØÖ·³åÍ»¡£Í¬Ê±£¬Òª¸ù¾Ý·þÎñÆ÷ËùÔÚµÄÍøÂç»·¾³ºÍÐèÇó£¬Ñ¡ÔñºÏÊʵĵØÖ·ÅäÖ÷½Ê½¡£
ÔöÇ¿ IPv6 ·ÃÎÊ¿ØÖƵĴëÊ©
ÔöÇ¿ IPv6 ·ÃÎÊ¿ØÖÆÊDZ£ÕÏ·þÎñÆ÷°²È«µÄÖØÒªÊֶΡ£¿ÉÒÔ²ÉÈ¡¶àÖÖ´ëÊ©£¬ÀýÈçÅäÖÃÇ¿ÃÜÂ룬±ÜÃâʹÓüòµ¥ÒײµÄÃÜÂ룬Ôö¼ÓÃÜÂëµÄ¸´ÔÓÐԺͳ¤¶È¡£Ê¹Ó÷ÃÎÊ¿ØÖÆÁÐ±í£¨ACL£©À´ÏÞÖÆ·ÃÎÊÍøÂçµÄÓû§ºÍÉ豸£¬Ã÷È·¹æ¶¨ÄÄЩÓû§ºÍÉ豸¿ÉÒÔ·ÃÎÊ·þÎñÆ÷£¬ÄÄЩ²»¿ÉÒÔ¡£
»¹¿ÉÒÔÏÞÖÆ·ÃÎÊÍøÂçµÄʱ¼ä¶Î£¬ÀýÈçÖ»ÔÚ¹¤×÷ʱ¼äÔÊÐíÌØ¶¨Óû§·ÃÎÊ¡£¶ÔÓÚÃô¸ÐÊý¾ÝºÍ·þÎñ£¬¿ÉÒÔ²ÉÓÃË«ÖØÉí·ÝÑéÖ¤µÈ¸üÑϸñµÄÑéÖ¤·½Ê½¡£Í¬Ê±£¬Òª¶¨ÆÚÉó²éºÍ¸üзÃÎÊ¿ØÖƲßÂÔ£¬ÒÔÊÊÓ¦²»¶Ï±ä»¯µÄ°²È«ÐèÇó¡£