- 论坛徽章:
- 0
|
问题解决了,现在的策略如下,请问下面那个策略有用哪些策略没用呢?
# Generated by iptables-save v1.4.7 on Thu May 4 13:30:13 2017
*filter
:INPUT ACCEPT [74:8590]
:FORWARD ACCEPT [4237:691352]
:OUTPUT ACCEPT [22718:1253894]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 7222 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3128 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 3128 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 3128 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 3128 -j ACCEPT
COMMIT
# Completed on Thu May 4 13:30:13 2017
# Generated by iptables-save v1.4.7 on Thu May 4 13:30:13 2017
*nat
REROUTING ACCEPT [1048:78853]
OSTROUTING ACCEPT [58:4465]
:OUTPUT ACCEPT [58:4465]
-A PREROUTING -d 10.255.10.4/32 -p tcp -m tcp --dport 7222 -j DNAT --to-destination 192.168.100.2:22
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 10.255.10.1
-A PREROUTING -s 192.168.100.0/24 -p tcp -m multiport --dports 80,443 -j REDIRECT --to-ports 3128
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 223.5.5.5
-A POSTROUTING -d 192.168.100.2/32 -p tcp -m tcp --dport 22 -j SNAT --to-source 192.168.100.1
COMMIT
# Completed on Thu May 4 13:30:13 2017
还有个问题,我去掉的这两个策略是什么意思呢?
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited |
|