- 论坛徽章:
- 0
|
回复 #2 ssffzz1 的帖子
[root@gateway sysconfig]# iptables-save \r\n# Generated by iptables-save v1.2.8 on Fri Jul 11 13:09:46 2008\r\n*filter\r\n:INPUT DROP [0:0]\r\n:FORWARD DROP [0:0]\r\n:OUTPUT ACCEPT [415117:218454503]\r\n:allow - [0:0]\r\n-A INPUT -j allow \r\n-A FORWARD -j allow \r\n-A allow -i lo -j ACCEPT \r\n-A allow -p icmp -m icmp --icmp-type 255 -j ACCEPT \r\n-A allow -p esp -j ACCEPT \r\n-A allow -p ah -j ACCEPT \r\n-A allow -m state --state RELATED,ESTABLISHED -j ACCEPT \r\n-A allow -s 192.168.0.0/255.255.255.0 -d 172.31.168.0/255.255.255.224 -i eth1 -p tcp -m multiport --dports 20,21,25,110,80 -j ACCEPT \r\n-A allow -s 192.168.0.6 -i eth1 -j ACCEPT \r\n-A allow -s 192.168.1.0/255.255.255.0 -d 192.168.0.11 -j ACCEPT \r\n-A allow -s 192.168.0.179 -i eth1 -m mac --mac-source 00:11:25:70:B3:31 -j ACCEPT \r\n-A allow -s 192.168.0.69 -i eth1 -m mac --mac-source 00:11:43:4F:26:BE -j ACCEPT \r\n-A allow -s 192.168.0.0/255.255.255.0 -i eth1 -j DROP \r\n-A allow -j REJECT --reject-with icmp-host-prohibited \r\nCOMMIT\r\n# Completed on Fri Jul 11 13:09:46 2008\r\n# Generated by iptables-save v1.2.8 on Fri Jul 11 13:09:46 2008\r\n*nat\r\n:PREROUTING ACCEPT [50175:3017466]\r\n:POSTROUTING ACCEPT [8442:841575]\r\n:OUTPUT ACCEPT [8439:841431]\r\n-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.31.168.13 \r\n-A PREROUTING -d 201.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 25:110 -j DNAT --to-destination 172.31.168.13 \r\n-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 21 -j DNAT --to-destination 172.31.168.4 \r\n-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 20 -j DNAT --to-destination 172.31.168.4 \r\n-A PREROUTING -d 202.XXX.XXX.XXX -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.31.168.5 \r\n-A PREROUTING -s 192.168.0.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 \r\n-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE \r\nCOMMIT\r\n# Completed on Fri Jul 11 13:09:46 2008\n\n[ 本帖最后由 mdiane 于 2008-7-11 13:16 编辑 ] |
|