- 论坛徽章:
- 0
|
版主教育的是。
这是我的iptables-save结果:
- iptables-save
- # Generated by iptables-save v1.2.7a on Wed May 31 16:42:37 2006
- *nat
- :PREROUTING ACCEPT [21195:1141849]
- :POSTROUTING ACCEPT [7694:728967]
- :OUTPUT ACCEPT [7695:729027]
- -A PREROUTING -i eth0 -p tcp -m tcp --dport 81 -j DNAT --to-destination a.b.c.e:80
- -A POSTROUTING -d a.b.c.e -o eth0 -p tcp -m tcp --dport 80 -j MASQUERADE
- COMMIT
- # Completed on Wed May 31 16:42:37 2006
- # Generated by iptables-save v1.2.7a on Wed May 31 16:42:37 2006
- *filter
- :INPUT DROP [3335:697389]
- :FORWARD ACCEPT [38993:27857805]
- :OUTPUT ACCEPT [1134028:778542141]
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 81 -j ACCEPT
- -A INPUT -i eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- COMMIT
- # Completed on Wed May 31 16:42:37 2006
复制代码
在一楼的描述中,我把INPUT的策略说错了,应该是DROP。
这个机器是单独的网卡,希望实现访问a.b.c.d的81端口时候可以转到a.b.c.e的80端口。
下面是telnet的结果
- telnet a.b.c.d 81
- Trying a.b.c.d...
- telnet: connect to address a.b.c.d: Connection refused
复制代码 |
|