|
|
|
|
|
|
|
[Original]
[Print]
[Top]
|
system :fc3
eth0 :10.0.0.85 內網 IP
eth1:61.28.42.211 外網 IP
以下是我的iptables 設定:
用來做 NAT 通不過,請各位幫幫忙幫我check 一下有沒出錯:Thanks
*filter
##############################
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
##############################
-F
-Z
-X
#############################
-A INPUT -p tcp --dport 21 -j ACCEPT
-A OUTPUT -p tcp --sport 21 -j ACCEPT
-A INPUT -p tcp --dport 22 -j ACCEPT
-A OUTPUT -p tcp --sport 22 -j ACCEPT
-A INPUT -p tcp --dport 23 -j ACCEPT
-A OUTPUT -p tcp --sport 23 -j ACCEPT
-A INPUT -p tcp --dport 25 -j ACCEPT
-A OUTPUT -p tcp --sport 25 -j ACCEPT
-A INPUT -p tcp --dport 53 -j ACCEPT
-A OUTPUT -p tcp --sport 53 -j ACCEPT
-A INPUT -p tcp --dport 80 -j ACCEPT
-A OUTPUT -p tcp --sport 80 -j ACCEPT
-A INPUT -p tcp --dport 110 -j ACCEPT
-A OUTPUT -p tcp --sport 110 -j ACCEPT
-A INPUT -p tcp --dport 143 -j ACCEPT
-A OUTPUT -p tcp --sport 143 -j ACCEPT
-A INPUT -p tcp --dport 138 -j ACCEPT
-A OUTPUT -p tcp --sport 138 -j ACCEPT
-A INPUT -p tcp --dport 139 -j ACCEPT
-A OUTPUT -p tcp --sport 139 -j ACCEPT
-A INPUT -p tcp --dport 5800 -j ACCEPT
-A OUTPUT -p tcp --sport 5800 -j ACCEPT
-A INPUT -p tcp --dport 5900 -j ACCEPT-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A INPUT -i eth0 -j ACCEPT
-A OUTPUT -o eth0 -j ACCEPT
-A FORWARD -i eth0 -j ACCEPT
-A FORWARD -o eth0 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A OUTPUT -p icmp -j ACCEPT
-L -v
COMMIT
######################
*nat
#################################
:PREROUTING DROP [0:0]
:OUTPUT DROP [0:0]
:POSTROUTING DROP [0:0]
################################
-F
-Z
-X
###############################
#-A POSTROUTING -o eth0 -j MASQUERADE
-A PREROUTING -p tcp --dport 21 -j ACCEPT
-A PREROUTING -p tcp --dport 22 -j ACCEPT
-A PREROUTING -p tcp --dport 23 -j ACCEPT
-A PREROUTING -p tcp --dport 25 -j ACCEPT
-A PREROUTING -p tcp --dport 53 -j ACCEPT
-A PREROUTING -p tcp --dport 80 -j ACCEPT
-A PREROUTING -p tcp --dport 110 -j ACCEPT
-A PREROUTING -p tcp --dport 143 -j ACCEPT
-A PREROUTING -p tcp --dport 139 -j ACCEPT
-A PREROUTING -p tcp --dport 138 -j ACCEPT
-A PREROUTING -p tcp --dport 5800 -j ACCEPT
-A PREROUTING -p tcp --dport 5900 -j ACCEPT
-A PREROUTING -p icmp -j ACCEPT
-A POSTROUTING -p icmp -j ACCEPT
-A POSTROUTING -o eth1 -s 10.0.2.16 -j SNAT --to-source 61.28.42.211
-L -v
COMMIT
|
|
|
----
chen-shuilang
|
|
[Original]
[Print]
[Top]
|
|
|