- 论坛徽章:
- 0
|
iptables规则如下:实在看不出有什么异常啊(安全起见,IP做过替换了抱歉) 主要是我没有开启邮件服务怎么端口会打开了?
server02 ~]$ sudo cat /etc/sysconfig/iptables
# Generated by iptables-save v1.4.7 on Thu Jul 14 10:41:20 2016
*nat
REROUTING ACCEPT [28987546:2340137209]
OSTROUTING ACCEPT [3324161:199788327]
:OUTPUT ACCEPT [498934:30296675]
-A PREROUTING -d 218.69.98.130/32 -p tcp -m tcp --dport 14050 -j DNAT --to-destination 172.18.69.105:10050
-A PREROUTING -d 218.69.98.130/32 -i em1 -p tcp -m tcp --dport 11050 -j DNAT --to-destination 172.18.69.103:10050
-A PREROUTING -d 218.69.98.130/32 -i em1 -p tcp -m tcp --dport 12050 -j DNAT --to-destination 172.18.69.104:10050
-A PREROUTING -d 218.69.98.130/32 -i em1 -p tcp -m tcp --dport 33075 -j DNAT --to-destination 172.18.69.104:3306
-A PREROUTING -d 218.69.98.130/32 -i em1 -p tcp -m tcp --dport 33077 -j DNAT --to-destination 172.18.69.105:33076
-A POSTROUTING -s 172.18.69.104/32 -o em1 -p tcp -m tcp --dport 10051 -j SNAT --to-source 218.69.98.130:12051
-A POSTROUTING -s 172.18.69.103/32 -o em1 -p tcp -m tcp --dport 10051 -j SNAT --to-source 218.69.98.130:11051
-A POSTROUTING -s 172.18.69.103/32 -o em1 -p tcp -m tcp --dport 8081:8083 -j SNAT --to-source 218.69.98.130:443
-A POSTROUTING -s 172.18.69.0/24 -o em1 -j SNAT --to-source 218.69.98.130
COMMIT
# Completed on Thu Jul 14 10:41:20 2016
# Generated by iptables-save v1.4.7 on Thu Jul 14 10:41:20 2016
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [113919:20368810]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -d 224.0.0.18/32 -i em1 -j ACCEPT
-A INPUT -s 218.69.98.132/32 -p tcp -m tcp --dport 10050 -j ACCEPT
-A INPUT -s 218.69.98.137/32 -p tcp -m tcp --dport 10050 -j ACCEPT
-A INPUT -s 172.18.69.0/24 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 6379 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 33075 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 33077 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 33020 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -s 218.69.98.132/32 -p tcp -m tcp --dport 10050 -j ACCEPT
-A FORWARD -d 218.69.98.132/32 -j ACCEPT
-A FORWARD -d 172.18.69.0/24 -o em2 -j ACCEPT
-A FORWARD -s 172.18.69.0/24 -i em2 -j ACCEPT
-A FORWARD -j DROP
COMMIT
# Completed on Thu Jul 14 10:41:20 2016
|
|