想請問呢類經中轉連線方法有無咩特別叫法, 想知多少少
hhmmss2016 發表於 2020-12-10 03:20 PM


https://en.wikipedia.org/wiki/Hole_punching_(networking)

Hole punching (or sometimes punch-through) is a technique in computer networking for establishing a direct connection between two parties in which one or both are behind firewalls or behind routers that use network address translation (NAT). To punch a hole, each client connects to an unrestricted third-party server that temporarily stores external and internal address and port information for each client. The server then relays each client's information to the other, and using that information each client tries to establish direct connection; as a result of the connections using valid port numbers, restrictive firewalls or routers accept and forward the incoming packets on each side.

TOP

回覆 5# javacomhk
唔完全相同
冇vpn情況下,外部 Internet 想連 router LAN client 要做port forwarding / UPnP (都係做緊port forwarding 只係自動咁解)
有vpn情況下就唔需要做port forwarding

TOP

回覆 4# hhmmss2016
睇你隻router用乜做upnp
如果router行liunx類os一般都係用miniupnpd,睇log

TOP

回覆  javacomhk
唔完全相同
冇vpn情況下,外部 Internet 想連 router LAN client 要做port forwarding /  ...
Rolf 發表於 2020-12-10 17:30



    你想大開中門咪用UPnP 囉,但係有的 service 係出唔到router 架嘛,你估開哂的port 就變直線咩。

TOP

回覆 14# javacomhk
其實UPnP可以set allowed internal port range
亦需要該service有UPnP support才有效果
例如就算你enable UPnP,都唔會自動forward port 22,想由外部ssh去 LAN只能自己手動set port forwarding rules,開UPnP唔等於可以隨意連LAN client所有port

我又真係想知有咩service唔可以靠 set port forwarding rules 出 router

TOP

UPnP仲要諗一個問題
如果屋企兩部機, 兩部都會用相同既service
第一部機用過之後自動開左port
第二部機想再用時, 之前既記錄未必會清左, 有機會因為咁先失敗, 開唔到port
結果都係要手動走入去做port forwarding

TOP

回覆  javacomhk
其實UPnP可以set allowed internal port range
亦需要該service有UPnP support才有效果
...
Rolf 發表於 2020-12-10 18:34



    你試下響 Internet mount 個 nfs server 比我睇下?

TOP

回覆 17# javacomhk
直接forward :892 :2049 可以呀,但考慮到security一般唔會咁做
冇vpn的做法係只 forward 22
再用ssh tunnel :892 :2049 去local port mount
你以為一定要VPN?

TOP

回覆 16# KinChungE
UPnP protocol 已經有考慮呢個問題,唔洗擔心
始終ip得一個,同時用就唔可能

TOP

回覆  javacomhk
直接forward :892 :2049 可以呀,但考慮到security一般唔會咁做
冇vpn的做法係只 forward ...
Rolf 發表於 2020-12-10 21:13



   Port forward 到唔代表mount 到, nfs 用 rpc protocol 低過 router, 你真係唔用 bridged network 都 mount 到個drive 先講啦。

TOP