- 论坛徽章:
- 0
|
谢谢楼上的。
$ uname -a
Linux COLO 2.4.21-27.EL #1 Wed Dec 1 22:08:15 EST 2004 i686 i686 i386 GNU/Linux
应该是说是RedHat企业版吧。
我先排查之后贴出结果。
SSH设置一切正常
我的IP是 192.168.0.12
iptables-save如下:
-------------------------------------------------------------------
# Generated by iptables-save v1.2.8 on Fri Nov 3 10:17:20 2006
*mangle
:PREROUTING ACCEPT [653855:299257822]
:INPUT ACCEPT [18258:1955737]
:FORWARD ACCEPT [634450:297155557]
:OUTPUT ACCEPT [16926:2439687]
:POSTROUTING ACCEPT [650866:299491053]
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
-A PREROUTING -s 192.168.0.168 -p tcp -j MARK --set-mark 0x1
COMMIT
# Completed on Fri Nov 3 10:17:20 2006
# Generated by iptables-save v1.2.8 on Fri Nov 3 10:17:20 2006
*filter
:INPUT ACCEPT [18259:1955777]
:FORWARD ACCEPT [336870:249242819]
:OUTPUT ACCEPT [16910:2437678]
-A FORWARD -d 198.168.0.0/255.255.255.0 -i eth0 -p tcp -m tcp --sport 20 -j ACCEPT
-A FORWARD -d 192.168.0.0/255.255.255.0 -i eth0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A FORWARD -d 192.168.0.0/255.255.255.0 -i eth0 -p udp -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -i eth1 -j ACCEPT
-A FORWARD -f -m limit --limit 100/sec --limit-burst 100 -j ACCEPT
-A FORWARD -p icmp -m limit --limit 3/sec --limit-burst 10 -j ACCEPT
COMMIT
# Completed on Fri Nov 3 10:17:20 2006
# Generated by iptables-save v1.2.8 on Fri Nov 3 10:17:20 2006
*nat
:PREROUTING ACCEPT [31635:2320615]
:POSTROUTING ACCEPT [189:16737]
:OUTPUT ACCEPT [811:39610]
-A POSTROUTING -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.168 -o eth0 -j SNAT --to-source XXX.XXX.XXX.XXX(colo007编辑,保密)
COMMIT
# Completed on Fri Nov 3 10:17:20 2006
~
[[i] 本帖最后由 colo007 于 2006-11-3 11:20 编辑 [/i]] |
|