- 论坛徽章:
- 0
|
本帖最后由 hamgl 于 2015-01-31 10:00 编辑
我看了一下,路由器里的iptables规则如下,192.168.1.100 是DMZ主机,10.88.84.25是WAN口地址,eth1是WAN接口。在这种配置规则下,路由器是不是应该收不到icmp replay才对?
Chain PREROUTING (policy ACCEPT 76 packets, 4194 bytes)
pkts bytes target prot opt in out source destination
0 0 WANPREROUTING all -- * * 0.0.0.0/0 10.88.84.25
0 0 DROP all -- eth1 * 0.0.0.0/0 192.168.1.0/24
Chain POSTROUTING (policy ACCEPT 1 packets, 56 bytes)
pkts bytes target prot opt in out source destination
11 840 MASQUERADE all -- * eth1 0.0.0.0/0 0.0.0.0/0
0 0 SNAT all -- * br0 192.168.1.0/24 192.168.1.0/24 to:192.168.1.1
Chain OUTPUT (policy ACCEPT 6 packets, 476 bytes)
pkts bytes target prot opt in out source destination
Chain WANPREROUTING (1 references)
pkts bytes target prot opt in out source destination
0 0 DNAT all -- * * 0.0.0.0/0 0.0.0.0/0 to:192.168.1.100 |
|