- 论坛徽章:
- 0
|
我使用了下面的规则,为什么flashget还能下载,我规则哪儿有问题
[root@sushe ~]# more /etc/sysconfig/iptables
# Generated by iptables-save v1.3.8 on Tue Dec 11 12:33:51 2007
*filter
:INPUT ACCEPT [1924:209294]
:FORWARD ACCEPT [8:499]
:OUTPUT ACCEPT [1042:79046]
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type any -j ACCEPT
-A INPUT -p esp -j ACCEPT
-A INPUT -p ah -j ACCEPT
-A INPUT -d 224.0.0.251 -p udp -m udp --dport 5353 -j ACCEPT
-A INPUT -p udp -m udp --dport 631 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 631 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 23 -j ACCEPT
-A INPUT -p udp -m state --state NEW -m udp --dport 137 -j ACCEPT
-A INPUT -p udp -m state --state NEW -m udp --dport 138 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 139 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 445 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A INPUT -s 10.8.32.0/255.255.252.0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -m layer7 --l7proto xunlei -j DROP
-A INPUT -m layer7 --l7proto bittorrent -j DROP
-A INPUT -m layer7 --l7proto chikka -j DROP
-A INPUT -m layer7 --l7proto edonkey -j DROP
-A INPUT -m layer7 --l7proto goboogy -j DROP
-A INPUT -m layer7 --l7proto h323 -j DROP
-A INPUT -m layer7 --l7proto kugoo -j DROP
-A INPUT -m layer7 --l7proto live365 -j DROP
-A INPUT -m layer7 --l7proto mohaa -j DROP
-A INPUT -m layer7 --l7proto poco -j DROP
-A INPUT -m layer7 --l7proto zmaap -j DROP
-A INPUT -m iprange --src-range 10.8.32.1-10.8.35.1 -m ipp2p --ipp2p -j DROP
-A INPUT -p tcp -m ipp2p --edk --soul -j DROP
-A INPUT -p tcp -m ipp2p --bit -j DROP
-A INPUT -p udp -m ipp2p --bit -j DROP
-A INPUT -m ipp2p --bit -j DROP
-A INPUT -p udp -m ipp2p --xunlei -j DROP
-A INPUT -p tcp -m ipp2p --xunlei -j DROP
-A INPUT -m ipp2p --xunlei -j DROP
-A INPUT -p udp -m ipp2p --pp -j DROP
-A INPUT -p tcp -m ipp2p --pp -j DROP
-A INPUT -m ipp2p --pp -j DROP
-A INPUT -m conntrack --ctstate INVALID -j DROP
-A INPUT -m ipp2p --ipp2p -j DROP
-A INPUT -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -p udp -m udp --sport 53 -j ACCEPT
-A INPUT -s 10.8.32.0/255.255.252.0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -m ipp2p --xunlei -j DROP
-A INPUT -m ipp2p --pp -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -m string --algo bm --string "sex.com" -j REJECT
-A INPUT -m string --algo bm --string "色情电影" -j REJECT
-A INPUT -m string --algo bm --string "激情图片" -j REJECT
-A INPUT -m string --algo bm --string "成人电影" -j REJECT
-A INPUT -m string --algo bm --string "电影" -j REJECT
-A INPUT -j DROP
COMMIT
# Completed on Tue Dec 11 12:33:51 2007
# Generated by iptables-save v1.3.8 on Tue Dec 11 12:33:51 2007
*nat
REROUTING ACCEPT [124:20532]
OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A POSTROUTING -o eth1 -j SNAT --to-source 61.50.*.*
COMMIT
# Completed on Tue Dec 11 12:33:51 2007
flashget 1.8版本
请ShadowStar精灵帮忙分析,谢谢!
[ 本帖最后由 luojm_24680 于 2007-12-12 11:35 编辑 ] |
|