- 论坛徽章:
- 0
|
回复 #2 ssffzz1 的帖子
[root@gateway sysconfig]# iptables-save
# Generated by iptables-save v1.2.8 on Fri Jul 11 13:09:46 2008
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [415117:218454503]
:allow - [0:0]
-A INPUT -j allow
-A FORWARD -j allow
-A allow -i lo -j ACCEPT
-A allow -p icmp -m icmp --icmp-type 255 -j ACCEPT
-A allow -p esp -j ACCEPT
-A allow -p ah -j ACCEPT
-A allow -m state --state RELATED,ESTABLISHED -j ACCEPT
-A allow -s 192.168.0.0/255.255.255.0 -d 172.31.168.0/255.255.255.224 -i eth1 -p tcp -m multiport --dports 20,21,25,110,80 -j ACCEPT
-A allow -s 192.168.0.6 -i eth1 -j ACCEPT
-A allow -s 192.168.1.0/255.255.255.0 -d 192.168.0.11 -j ACCEPT
-A allow -s 192.168.0.179 -i eth1 -m mac --mac-source 00:11:25:70:B3:31 -j ACCEPT
-A allow -s 192.168.0.69 -i eth1 -m mac --mac-source 00:11:43:4F:26:BE -j ACCEPT
-A allow -s 192.168.0.0/255.255.255.0 -i eth1 -j DROP
-A allow -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Fri Jul 11 13:09:46 2008
# Generated by iptables-save v1.2.8 on Fri Jul 11 13:09:46 2008
*nat
:PREROUTING ACCEPT [50175:3017466]
:POSTROUTING ACCEPT [8442:841575]
:OUTPUT ACCEPT [8439:841431]
-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.31.168.13
-A PREROUTING -d 201.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 25:110 -j DNAT --to-destination 172.31.168.13
-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 21 -j DNAT --to-destination 172.31.168.4
-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 20 -j DNAT --to-destination 172.31.168.4
-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.31.168.5
-A PREROUTING -s 192.168.0.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
COMMIT
# Completed on Fri Jul 11 13:09:46 2008
[ 本帖最后由 mdiane 于 2008-7-11 13:16 编辑 ] |
|