免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1510 | 回复: 0
打印 上一主题 下一主题

内网用户通过域名访问内网服务器 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2009-02-05 11:02 |只看该作者 |倒序浏览
[root@router sysconfig]# iptables-save
# Generated by iptables-save v1.2.11 on Thu Feb  5 10:57:35 2009
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1891:283703]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 47 -j ACCEPT
-A INPUT -p gre -j ACCEPT
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i ppp0 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp1 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp2 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp3 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp4 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp5 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp6 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp7 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp8 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp9 -j ACCEPT
-A RH-Firewall-1-INPUT -i ppp10 -j ACCEPT
-A RH-Firewall-1-INPUT -i eth1 -j ACCEPT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp -m icmp --icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p ipv6-crypt -j ACCEPT
-A RH-Firewall-1-INPUT -p ipv6-auth -j ACCEPT
-A RH-Firewall-1-INPUT -d 224.0.0.251 -p udp -m udp --dport 5353 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 8088 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 7000 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Thu Feb  5 10:57:35 2009
# Generated by iptables-save v1.2.11 on Thu Feb  5 10:57:35 2009
*nat
:PREROUTING ACCEPT [5466:394183]
:POSTROUTING ACCEPT [6:380]
:OUTPUT ACCEPT [1:76]
-A PREROUTING -d 218.80.193.59 -i eth0 -p udp -m udp --dport 5060 -j DNAT --to-destination 192.168.1.192
-A PREROUTING -d 218.80.193.59 -i eth0 -p udp -m udp --dport 15000:50000 -j DNAT --to-destination 192.168.1.192
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 2222 -j DNAT --to-destination 192.168.1.168:22
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 8822 -j DNAT --to-destination 192.168.1.18:22
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 8088 -j DNAT --to-destination 192.168.1.172:8088
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 7000 -j DNAT --to-destination 192.168.1.168:7000
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.168:8080
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.1.18:25
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 110 -j DNAT --to-destination 192.168.1.18:110
-A PREROUTING -d 218.80.193.59 -i eth0 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.18:80
-A PREROUTING -d 218.80.193.59 -i eth1 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.168:8080
-A PREROUTING -d 218.80.193.59 -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.18:80
-A PREROUTING -d 218.80.193.59 -i eth1 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.1.18:25
-A PREROUTING -d 218.80.193.59 -i eth1 -p tcp -m tcp --dport 110 -j DNAT --to-destination 192.168.1.18:110
-A POSTROUTING -s 192.168.0.0/255.255.0.0 -j SNAT --to-source 218.80.193.59
COMMIT
# Completed on Thu Feb  5 10:57:35 2009

本文来自ChinaUnix博客,如果查看原文请点:http://blog.chinaunix.net/u1/35016/showart_1813927.html
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP