- 论坛徽章:
- 0
|
运行了新的规则,经测试,还是无法限制flashget、超级旋风等p2p软件,规则如下,请帮忙分析:
[root@sushe ~]# iptables-save -L
iptables-save: invalid option -- L
# Generated by iptables-save v1.3.8 on Sat Dec 15 21:29:35 2007
*nat
REROUTING ACCEPT [4808941:293006417]
OSTROUTING ACCEPT [253:36240]
:OUTPUT ACCEPT [13:1056]
-A POSTROUTING -o eth1 -j SNAT --to-source 61.50.139.251
COMMIT
# Completed on Sat Dec 15 21:29:35 2007
# Generated by iptables-save v1.3.8 on Sat Dec 15 21:29:35 2007
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [58772897:27650870129]
:OUTPUT ACCEPT [23641:9384127]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -p esp -j ACCEPT
-A INPUT -p ah -j ACCEPT
-A INPUT -p udp -m udp --dport 631 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 631 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 23 -j ACCEPT
-A INPUT -p udp -m udp --dport 137 -j ACCEPT
-A INPUT -p udp -m udp --dport 138 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
% |
|