/
PC๊ฐ€ ์ธํ„ฐ๋„ท ๊ณต์œ ๊ธฐ๋‚˜ ์‚ฌ์„ค๋ง(Private Network)๊ณผ ๊ฐ™์€ NAT ์‹œ์Šคํ…œ ๋‚ด๋ถ€์— ์žˆ์„ ๋•Œ Xmanager๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

PC๊ฐ€ ์ธํ„ฐ๋„ท ๊ณต์œ ๊ธฐ๋‚˜ ์‚ฌ์„ค๋ง(Private Network)๊ณผ ๊ฐ™์€ NAT ์‹œ์Šคํ…œ ๋‚ด๋ถ€์— ์žˆ์„ ๋•Œ Xmanager๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

PC๊ฐ€ ๋ฐฉํ™”๋ฒฝ(Firewall)์ด๋‚˜ NAT ์‹œ์Šคํ…œ ๋‚ด๋ถ€์— ์žˆ๊ณ  UNIX/Linux๊ฐ€ ๊ทธ ์™ธ๋ถ€์— ์žˆ๋‹ค๋ฉด X์‘์šฉํ”„๋กœ๊ทธ๋žจ์€ Xmanager๊ฐ€ ๊ตฌ๋™ ์ค‘์ธ PC์— ์ ‘์†ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. 


  • Xmanager์™€ Unix/Linux๊ฐ€ ๋™์ผ ๋„คํŠธ์›Œํฌ์— ์žˆ๋Š” ๊ฒฝ์šฐ => ์ ‘์† ์„ฑ๊ณต



  • Xmanager๊ฐ€ NAT๋กœ ๊ตฌ์„ฑ๋œ ์‚ฌ์„ค๋ง ์•ˆ์— ์žˆ๋Š” ๊ฒฝ์šฐ =>์ ‘์† ์‹คํŒจ


์œ„์™€ ๊ฐ™์ด Xmanager๊ฐ€ ๋ฐฉํ™”๋ฒฝ์ด๋‚˜ ์‚ฌ์„ค๋ง ์•ˆ์— ๋†“์ธ ๊ฒฝ์šฐ ๋‹ค์Œ ๋‘ ๊ฐ€์ง€ ํ•ด๊ฒฐ์ฑ…์„ ์ƒ๊ฐํ•ด๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Xstart ์ ‘์† ์‹œ SSH ํ”„๋กœํ† ์ฝœ ์‚ฌ์šฉ
  • NAT ์„œ๋ฒ„(๊ณต์œ ๊ธฐ, IP Masquerading ์„œ๋ฒ„ ๋“ฑ)์˜ ํฌํŠธํฌ์›Œ๋”ฉ ์„ค์ •


Xstart ์ ‘์† ์‹œ SSH ํ”„๋กœํ† ์ฝœ ์‚ฌ์šฉ

SSH ์—ฐ๊ฒฐ์„ ์ด์šฉํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ํฌํŠธํฌ์›Œ๋”ฉ ์„ค์ • ๋“ฑ์˜ ๋ณต์žกํ•œ ๊ณผ์ •์ด ํ•„์š”์—†์Šต๋‹ˆ๋‹ค.

SSH ์—ฐ๊ฒฐ์€ PC์™€ Linux/Unix ์‚ฌ์ด์— ์•”ํ˜ธํ™” ํ„ฐ๋„์„ ์ƒ์„ฑํ•˜๊ณ  ์ด ํ„ฐ๋„์„ ํ†ตํ•ด์„œ ๋ชจ๋“  X์‘์šฉํ”„๋กœ๊ทธ๋žจ๋“ค์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. ์ ‘์†ํ•˜๊ณ ์ž ํ•˜๋Š” UNIX/Linux ์žฅ๋น„์— SSH ์„œ๋ฒ„๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ๋‹ค๋ฉด SSH ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋Š” ์ด ๋ฐฉ๋ฒ•์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

Secure XDMCP๋Š” ์›๊ฒฉ ํ˜ธ์ŠคํŠธ์— ์ ‘์†ํ•˜๋Š” ์ƒˆ๋กœ์šด ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค. PC๊ฐ€ ์‚ฌ์„ค๋ง(NAT, ๊ณต์œ ๊ธฐ ํ™˜๊ฒฝ)์ด๋‚˜ ๋ฐฉํ™”๋ฒฝ ์•ˆ์— ์žˆ๊ณ , ์ ‘์†ํ•˜๊ณ ์ž ํ•˜๋Š” ์œ ๋‹‰์Šค/๋ฆฌ๋ˆ…์Šค๊ฐ€ ๊ทธ ์™ธ๋ถ€์— ์žˆ๋Š” ๊ฒฝ์šฐ, ํ•ด๋‹น ์œ ๋‹‰์Šค/๋ฆฌ๋ˆ…์Šค ์žฅ๋น„์— SSH ์„œ๋ฒ„๊ฐ€ ๊ตฌ๋™ ์ค‘์ด๋ฉด Secure XDMCP ์ ‘์†์œผ๋กœ XDMCP ํ™˜๊ฒฝ์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Xstart์—์„œ SSH ์ ‘์†ํ•˜๊ธฐ

SSH ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด SSH ์„œ๋ฒ„๊ฐ€ X11 ํฌ์›Œ๋”ฉ์„ ์ง€์›ํ•ด์•ผ ํ•˜๋ฉฐ ์„œ๋ฒ„๋ณ„ ์„ค์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

OpenSSH ์„œ๋ฒ„์ธ ๊ฒฝ์šฐ ์„ค์ • ํŒŒ์ผ (/etc/ssh/sshd_config)์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

X11Forwarding yes 

Secure Shell Communications Security ์„œ๋ฒ„์ธ ๊ฒฝ์šฐ ์„ค์ • ํŒŒ์ผ (/etc/ssh2/sshd2_config)์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค. 

AllowX11Forwarding yes

์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•œ ํ›„ Xstart๋ฅผ ์ด์šฉํ•˜์—ฌ X ํ”„๋กœ๊ทธ๋žจ์„ ์‹คํ–‰ํ•˜์‹ญ์‹œ์˜ค.

  1. Xmanager ํด๋”(๊ทธ๋ฃน)์— ์žˆ๋Š” Xstart๋ฅผ ์‹คํ–‰
  2. [ํ”„๋กœํ† ์ฝœ]์„ SSH๋กœ ์„ ํƒ
  3. [์‹คํ–‰๋ช…๋ น] ์ž…๋ ฅ๋ž€์— ๋‹ค์Œ์˜ ์˜ˆ์™€ ๊ฐ™์ด xterm ๋“ฑ์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์„ ์ž…๋ ฅ
    usr/bin/X11/xterm -ls
    *SSH ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” SSH ์„œ๋ฒ„๊ฐ€ ์ ์ ˆํ•œ DISPLAY ๊ฐ’์„ ๋ถ€์—ฌํ•˜๋ฏ€๋กœ -display ์˜ต์…˜์ด ํ•„์š” ์—†์Šต๋‹ˆ๋‹ค.


  4. [์‹คํ–‰] ๋ฒ„ํŠผ์„ ๋ˆ„๋ฆ…๋‹ˆ๋‹ค. Xstart๋Š” Xmanager๋ฅผ ์ž๋™์œผ๋กœ ์‹คํ–‰ํ•œ ํ›„ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  5. KDE, Gnome ๋˜๋Š” CDE ์„ธ์…˜์„ ์–ป๊ธฐ ์œ„ํ•ด์„œ ๊ฐ๊ฐ ๋‹ค์Œ์„ ์‹คํ–‰์‹œํ‚ค์‹ญ์‹œ์˜ค. ์‹คํ–‰ ๊ฒฝ๋กœ๋Š” ์‹œ์Šคํ…œ๋งˆ๋‹ค ๋‹ค๋ฅผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๊ฒฝ๋กœ๋Š” ์•„๋ž˜ FAQ๋ฅผ ์ฐธ๊ณ ํ•˜์‹ญ์‹œ์˜ค.

NAT ์„œ๋ฒ„์˜ ํฌํŠธํฌ์›Œ๋”ฉ ์„ค์ •

ํฌํŠธํฌ์›Œ๋”ฉ์€ NAT ์„œ๋ฒ„์˜ TCP 6000๋ฒˆ ํฌํŠธ๋กœ ๋“ค์–ด์˜ค๋Š” ์ ‘์†์„ PC์˜ TCP 6000๋ฒˆ ํฌํŠธ๋กœ ์ „ํ™˜ํ•˜๋Š” ํ˜•์‹์œผ๋กœ ์ด๋ฃจ์–ด์ง‘๋‹ˆ๋‹ค. NAT ์‹œ์Šคํ…œ ์•ˆ์˜ Xmanager ์‚ฌ์šฉ์ž๊ฐ€ ์—ฌ๋Ÿฌ ๋ช…์ผ ๋•Œ์—๋Š” ์ด๋Ÿฐ ํฌํŠธํฌ์›Œ๋”ฉ์„ ๊ฐ ์‚ฌ์šฉ์ž๋งˆ๋‹ค ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.


(NAT, 6001)    ->    (PC1, 6000)
(NAT, 6002)    ->    (PC2, 6000)
. . .
(NAT, 6009)    ->    (PC9, 6000)

        โ–ผ                          โ–ผ

์—ฐ๊ฒฐ ์ฃผ์†Œ ๋ถ€๋ถ„    Xmanager ๋””์Šคํ”Œ๋ ˆ์ด ๋ถ€๋ถ„

โ€ป์œ„์˜ ์ „๋‹ฌ๋  PC๋“ค์˜ ํฌํŠธ๋Š” 6000~6255 ์‚ฌ์ด ์ž„์˜์˜ ๊ฐ’์œผ๋กœ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์œผ๋‚˜ Xmanager์—์„œ๋Š” ๋ฐ˜๋“œ์‹œ ์ด ๊ฐ’์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.


XDMCP ์ ‘์†์„ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์—ฐ๊ฒฐ ์ฃผ์†Œ๋ฅผ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.(PC1์˜ ์˜ˆ)

  1. Xbrowser์—์„œ XDMCP ์„ธ์…˜์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

  2. ์œ„์—์„œ ์ƒ์„ฑํ•œ ์„ธ์…˜์˜ ๋“ฑ๋ก์ •๋ณด์˜ ์—ฐ๊ฒฐ ์ฃผ์†Œ์—์„œ '์‚ฌ์šฉ์ž ์ •์˜'๋กœ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  3. [IP ์ฃผ์†Œ] ๋ถ€๋ถ„์— NAT ์„œ๋ฒ„์˜ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

  4. [ํฌํŠธ ๋ฒˆํ˜ธ]์—๋Š” ์œ„ NAT ์„œ๋ฒ„์—์„œ ์ •ํ•œ PC1์— ํ•ด๋‹นํ•˜๋Š” 6001๋ฒˆ์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

  5. [X ์„œ๋ฒ„] ํƒญ์˜ [๋””์Šคํ”Œ๋ ˆ์ด ๋ฒˆํ˜ธ]์—์„œ '๋””์Šคํ”Œ๋ ˆ์ด ๋ฒˆํ˜ธ๋ฅผ ์ž๋™์œผ๋กœ ํ• ๋‹นํ•ฉ๋‹ˆ๋‹ค.'๋ฅผ ํ•ด์ œํ•˜๊ณ  ๋ฐ˜๋“œ์‹œ NAT ์„œ๋ฒ„์—์„œ ์ •ํ•œ ํฌํŠธ๋ฒˆํ˜ธ(PC1์˜ ๊ฒฝ์šฐ 6000)์—์„œ 6000์„ ๋บ€ ๊ฐ’(0)์„ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.(๋””์Šคํ”Œ๋ ˆ์ด ๋ฒˆํ˜ธ 0์€ TCP ํฌํŠธ 6000๋ฒˆ์„, 1์€ 6001๋ฒˆ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค)


Xstart๋ฅผ ์ด์šฉํ•œ ์ ‘์†์„ ์œ„ํ•ด์„œ๋Š” ๊ฐ ์‚ฌ์šฉ์ž๋Š” "-display" ์˜ต์…˜์„ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํ•ฉ๋‹ˆ๋‹ค.

  • PC1:/usr/bin/X11/xterm -ls -display$NATsystem:1

  • PC2:/usr/bin/X11/xterm -ls -display$NATsystem:2

  • . . .

  • PC9:/usr/bin/X11/xterm -ls -display$NATsystem:9

IP Masquerading์„ ํ•˜๋Š” ์‹œ์Šคํ…œ ๋‚ด๋ถ€์— ์žˆ์„ ๊ฒฝ์šฐ์˜ ์‹ค์ œ ์˜ˆ (kernel 2.2)

Masquerading server์˜ TCP 6001๋ฒˆ ํฌํŠธ๋ฅผ PC์˜ TCP 6000๋ฒˆ ํฌํŠธ๋กœ ํฌ์›Œ๋”ฉํ•ฉ๋‹ˆ๋‹ค.
  # ipmasqadm portfw -a -P tcp -L FIREWALL_ADDRESS 6001 -R PC_ADDRESS 6000
Xstart ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‹คํ–‰๋ช…๋ น๋ž€์— ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ž…๋ ฅํ•˜๊ณ  ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  /usr/bin/X11/xterm -ls -display FIREWALL_ADDRESS:1.0
FIREWALL_ADDRESS์—๋Š” Masquerading server์˜ IP ์ฃผ์†Œ, PC_ADDRESS์—๋Š” PC์˜ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค. ipmasqadm ํˆด์ด ์—†์œผ๋ฉด ๋‹ค์Œ ์‚ฌ์ดํŠธ์—์„œ ๋ฐ›์œผ์„ธ์š”.
http://www.e-infomax.com/ipmasq/juanjox/



Related content