- 论坛徽章:
- 0
|
各位大侠
请教问题
我搭建一个centos 双网卡的pptp服务器,配置如下
eth0 外网网卡:174.168.100.20 gw 174.168.100.1
eth1 内网网卡: 192.168.200.20
pptp 从外网拨入:分配 localip 192.168.0.1 remoteip 192.168.0.100-120,192.168.0.123
sysctl.conf已经开启默认路由
现在是pptp拨入后无法访问eth1里的192.168.200.254的服务器,但是ping eth1的192.168.200.20可以ping通
iptables 配置如下
*nat
REROUTING ACCEPT [37:3212]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
OSTROUTING ACCEPT [0:0]
COMMIT
# Completed on Wed Jun 15 08:48:19 2016
# Generated by iptables-save v1.4.21 on Wed Jun 15 08:48:19 2016
*filter
:INPUT DROP [185:24742]
:FORWARD DROP [1:60]
:OUTPUT ACCEPT [2564:407978]
:syn-flood - [0:0]
-A INPUT -p tcp -m tcp --dport 47 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
-A INPUT -p udp -m udp --dport 4500 -j ACCEPT
-A INPUT -p udp -m udp --dport 500 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -i tun+ -j ACCEPT
nat 那里我尝试几种方式:
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o eth0 -j SNAT --to 192.168.200.254
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -j SNAT --to-source 192.168.200.20
可还是不行,
请教各位大侠,我市哪里做错啦呢???
|
|