- 论坛徽章:
- 0
|
原帖由 luojm_24680 于 2007-12-13 08:20 发表 ![]()
谢谢ShadowStar兄!
客户端通过iptables防火墙上网,上面列出的是iptables规则
eth0:连接客户端10.8.32.0/22
eth1:连接ISP:61.50.*。*
目的:限制客户端使用p2p软件,因为客户端疯狂使用这些软件,打开网页 ... - # Generated by iptables-save v1.3.8 on Tue Dec 11 12:33:51 2007
- *filter
- :INPUT DROP [1924:209294]
- :FORWARD ACCEPT [8:499]
- :OUTPUT ACCEPT [1042:79046]
- -A FORWARD -m ipp2p --ipp2p --xunlei --mute --waste --xdcc -j DROP
- -A FORWARD -m string --algo bm --string "sex.com" -j REJECT
- -A FORWARD -m string --algo bm --string "色情电影" -j REJECT
- -A FORWARD -m string --algo bm --string "激情图片" -j REJECT
- -A FORWARD -m string --algo bm --string "成人电影" -j REJECT
- -A FORWARD -m string --algo bm --string "电影" -j REJECT
- -A FORWARD -m layer7 --l7proto xunlei -j DROP
- -A FORWARD -m layer7 --l7proto bittorrent -j DROP
- -A FORWARD -m layer7 --l7proto chikka -j DROP
- -A FORWARD -m layer7 --l7proto edonkey -j DROP
- -A FORWARD -m layer7 --l7proto goboogy -j DROP
- -A FORWARD -m layer7 --l7proto h323 -j DROP
- -A FORWARD -m layer7 --l7proto kugoo -j DROP
- -A FORWARD -m layer7 --l7proto live365 -j DROP
- -A FORWARD -m layer7 --l7proto mohaa -j DROP
- -A FORWARD -m layer7 --l7proto poco -j DROP
- -A FORWARD -m layer7 --l7proto zmaap -j DROP
- -A FORWARD -m conntrack --ctstate INVALID -j DROP
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -p esp -j ACCEPT
- -A INPUT -p ah -j ACCEPT
- -A INPUT -p udp -m udp --dport 631 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 631 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 23 -j ACCEPT
- -A INPUT -p udp -m udp --dport 137 -j ACCEPT
- -A INPUT -p udp -m udp --dport 138 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 445 -j ACCEPT
- COMMIT
- # Completed on Tue Dec 11 12:33:51 2007
- # Generated by iptables-save v1.3.8 on Tue Dec 11 12:33:51 2007
- *nat
- REROUTING ACCEPT [124:20532]
- OSTROUTING ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A POSTROUTING -o eth1 -j SNAT --to-source 61.50.*.*
- COMMIT
- # Completed on Tue Dec 11 12:33:51 2007
复制代码 |
|