- 论坛徽章:
- 3
|
回复 1# energywu
不知道你说的什么意思。但是iptable可以添加一个规则,就是-j reject --reject-with ,你说的有点类似这种情况,看看你的iptable里面有没有这样的规则
--reject-with type
The type given can be icmp-net-unreachable, icmp-host-unreach-
able, icmp-port-unreachable, icmp-proto-unreachable,
icmp-net-prohibited, icmp-host-prohibited or icmp-admin-prohib-
ited (*) which return the appropriate ICMP error message
(port-unreachable is the default). The option tcp-reset can be
used on rules which only match the TCP protocol: this causes a
TCP RST packet to be sent back. This is mainly useful for
blocking ident (113/tcp) probes which frequently occur when
sending mail to broken mail hosts (which won’t accept your mail
otherwise).
(*) Using icmp-admin-prohibited with kernels that do not support it
will result in a plain DROP instead of REJECT
|
|