- 论坛徽章:
- 0
|
另#ftp,telnet
iptables -t nat -A PREROUTING -d 202.96.186.240 -p tcp --dport 21 -j DNAT --to 192.168.100.4
iptables -A FORWARD -o eth0 -d 192.168.100.4 -p tcp --dport 21 -j ACCEPT
iptables -A FORWARD -i eth0 -s 192.168.100.4 -p tcp --sport 21 -m state --state ESTABLISHED -j ACCEPT
iptables -A FORWARD -i eth0 -s 192.168.100.4 -p tcp --sport 20 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -o eth0 -d 192.168.100.4 -p tcp --dport 20 -m state --state ESTABLISHED -j ACCEPT
iptables -t nat -A PREROUTING -d 202.96.186.240 -p tcp --dport 23 -j DNAT --to 192.168.100.4
iptables -A FORWARD -o eth0 -d 192.168.100.4 -p tcp --dport 23 -j ACCEPT
iptables -A FORWARD -i eth0 -s 192.168.100.4 -p tcp --sport 23 -m state --state ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -d 192.168.100.4 -p tcp --dport 23 -j SNAT --to 192.168.100.1
iptables -t nat -A POSTROUTING -d 192.168.100.4 -p tcp --dport 21 -j SNAT --to 192.168.100.1
这个端口影射在之前有这一句iptables -P FORWARD DROP
时无效。 |
|