- 论坛徽章:
- 1
|
回复 5# ssffzz1
不知道是不是iptables的bug
TRACE: raw:PREROUTING:policy:2 IN=vlan0357 OUT= MAC=02:00:20:ee:69:03:02:00:00:0f:00:02:08:00:45:28:00:3c SRC=39.128.0.2 DST=192.0.0.1 LEN=60 TOS=0x08 PREC=0x20 TTL=63 ID=60889 DF PROTO=TCP SPT=53015 DPT=3000 SEQ=3417509349 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A0072035A0000000001030309)
TRACE: raw:PREROUTING:policy:2 IN=vlan0357 OUT= MAC=02:00:20:ee:69:03:02:00:00:0f:00:02:08:00:45:28:00:3c SRC=39.128.0.2 DST=192.0.0.1 LEN=60 TOS=0x08 PREC=0x20 TTL=63 ID=60890 DF PROTO=TCP SPT=53015 DPT=3000 SEQ=3417509349 ACK=0 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A0072323A0000000001030309)
===========分割线,上面TCP不行,下面ICMP就可以================
TRACE: raw:PREROUTING:policy:2 IN=vlan0357 OUT= MAC=02:00:20:ee:69:03:02:00:00:0f:00:02:08:00:45:28:00:54 SRC=39.128.0.2 DST=192.0.0.1 LEN=84 TOS=0x08 PREC=0x20 TTL=63 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=45849 SEQ=1
TRACE: nat:PREROUTING:rule:1 IN=vlan0357 OUT= MAC=02:00:20:ee:69:03:02:00:00:0f:00:02:08:00:45:28:00:54 SRC=39.128.0.2 DST=192.0.0.1 LEN=84 TOS=0x08 PREC=0x20 TTL=63 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=45849 SEQ=1
# iptables -t raw -L
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
TRACE all -- anywhere 192.0.0.1
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
# iptables -t nat -L -v
Chain PREROUTING (policy ACCEPT 1620 packets, 115K bytes)
pkts bytes target prot opt in out source destination
2 168 DNAT all -- any any anywhere 192.0.0.1 to:11.0.7.1
Chain POSTROUTING (policy ACCEPT 1041 packets, 75357 bytes)
pkts bytes target prot opt in out source destination
0 0 SNAT all -- any any 11.0.7.1 anywhere to:192.0.0.1
Chain OUTPUT (policy ACCEPT 1041 packets, 75357 bytes)
pkts bytes target prot opt in out source destination
|
|