免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 5805 | 回复: 1
打印 上一主题 下一主题

[vpn] 能够连接 无法上网 PPTP iptables需要允许那些? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2011-03-21 17:28 |只看该作者 |倒序浏览
这个是小弟的 Iptables 能连接 不能上网的 配置
  1. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  2. *nat
  3. :PREROUTING ACCEPT [67:7044]
  4. :POSTROUTING ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. -A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
  7. COMMIT
  8. # Completed on Mon Mar 21 12:11:04 2011
  9. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  10. *filter
  11. :INPUT ACCEPT [0:0]
  12. :FORWARD ACCEPT [0:0]
  13. :OUTPUT ACCEPT [95:8972]
  14. :RH-Firewall-1 - [0:0]
  15. -A INPUT -j RH-Firewall-1
  16. -A FORWARD -j RH-Firewall-1
  17. -A RH-Firewall-1 -i lo -j ACCEPT
  18. -A RH-Firewall-1 -p icmp -m icmp --icmp-type any -j ACCEPT
  19. -A RH-Firewall-1 -m state --state RELATED,ESTABLISHED -j ACCEPT
  20. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 22 -j ACCEPT
  21. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 443 -j ACCEPT
  22. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 80 -j ACCEPT
  23. -A RH-Firewall-1 -p tcp -m tcp --dport 1723 -j ACCEPT
  24. -A RH-Firewall-1 -j REJECT --reject-with icmp-host-prohibited
  25. COMMIT
  26. # Completed on Mon Mar 21 12:11:04 2011
复制代码
能连接 也能上网的 配置
  1. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  2. *nat
  3. :PREROUTING ACCEPT [67:7044]
  4. :POSTROUTING ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. -A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
  7. COMMIT
  8. # Completed on Mon Mar 21 12:11:04 2011
  9. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  10. *filter
  11. :INPUT ACCEPT [0:0]
  12. :FORWARD ACCEPT [0:0]
  13. :OUTPUT ACCEPT [95:8972]
  14. :RH-Firewall-1 - [0:0]
  15. -A INPUT -j RH-Firewall-1
  16. -A FORWARD -j RH-Firewall-1
  17. -A RH-Firewall-1 -i lo -j ACCEPT
  18. -A RH-Firewall-1 -p icmp -m icmp --icmp-type any -j ACCEPT
  19. -A RH-Firewall-1 -m state --state RELATED,ESTABLISHED -j ACCEPT
  20. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 22 -j ACCEPT
  21. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 443 -j ACCEPT
  22. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 80 -j ACCEPT
  23. -A RH-Firewall-1 -p tcp -m tcp --dport 1723 -j ACCEPT
  24. COMMIT
  25. # Completed on Mon Mar 21 12:11:04 2011
复制代码
删掉 -A RH-Firewall-1 -j REJECT --reject-with icmp-host-prohibited 就能上网了
估计是 还是配置问题 求高手帮助~

论坛徽章:
0
2 [报告]
发表于 2011-03-21 22:22 |只看该作者
还是自己搞定了 自己动手 丰衣足食 = -
查看日记 发现 53 和 137 这两个端口 的一直很不口耐 所以打开就好了~
  1. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  2. *nat
  3. :PREROUTING ACCEPT [67:7044]
  4. :POSTROUTING ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. -A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
  7. COMMIT
  8. # Completed on Mon Mar 21 12:11:04 2011
  9. # Generated by iptables-save v1.3.5 on Mon Mar 21 12:11:04 2011
  10. *filter
  11. :INPUT ACCEPT [0:0]
  12. :FORWARD ACCEPT [0:0]
  13. :OUTPUT ACCEPT [95:8972]
  14. :RH-Firewall-1 - [0:0]
  15. -A INPUT -j RH-Firewall-1
  16. -A FORWARD -j RH-Firewall-1
  17. -A RH-Firewall-1 -i lo -j ACCEPT
  18. -A RH-Firewall-1 -p icmp -m icmp --icmp-type any -j ACCEPT
  19. -A RH-Firewall-1 -m state --state RELATED,ESTABLISHED -j ACCEPT
  20. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 22 -j ACCEPT
  21. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 443 -j ACCEPT
  22. -A RH-Firewall-1 -p tcp -m state --state NEW,RELATED -m tcp --dport 80 -j ACCEPT
  23. -A RH-Firewall-1 -p udp -m state --state NEW,RELATED -m udp --dport 53 -j ACCEPT
  24. -A RH-Firewall-1 -p udp -m state --state NEW,RELATED -m udp --dport 137 -j ACCEPT
  25. -A RH-Firewall-1 -p tcp -m tcp --dport 1723 -j ACCEPT
  26. -A RH-Firewall-1 -j REJECT --reject-with icmp-host-prohibited
  27. COMMIT
  28. # Completed on Mon Mar 21 12:11:04 2011
复制代码
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP