- 论坛徽章:
- 0
|
ip_conntrack问题
ip route内容如下
166.111.x.0/24 dev eth1 scope link
172.16.0.0/16 dev eth0 scope link
169.254.0.0/16 dev eth1 scope link
127.0.0.0/8 dev lo scope link
default via 166.111.x.x dev eth1
iptables -t nat -vnL内容如下
Chain PREROUTING (policy ACCEPT 5610K packets, 2265M bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 1 packets, 72 bytes)
pkts bytes target prot opt in out source destination
15246 6158K MASQUERADE all -- * eth1 172.16.0.0/16 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 1 packets, 72 bytes)
pkts bytes target prot opt in out source destination
iptables -vnL内容如下
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
15442 1185K RH-Lokkit-0-50-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:135
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:138
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:445
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:135
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:139
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:445
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:593
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:4444
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:69
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:707
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:707
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
46017 19M RH-Lokkit-0-50-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 2707 packets, 141K bytes)
pkts bytes target prot opt in out source destination
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:135
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:138
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:445
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:135
2 80 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:139
8 320 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:445
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:593
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:4444
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:69
0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:707
0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:707
Chain RH-Lokkit-0-50-INPUT (2 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT udp -- * * 166.111.8.28 0.0.0.0/0 udp spt:53 dpts:1025:65535
2 295 ACCEPT udp -- * * 211.152.8.137 0.0.0.0/0 udp spt:53 dpts:1025:65535
2 96 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 flags:0x16/0x02
3 144 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 flags:0x16/0x02
2 264 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
13641 974K ACCEPT all -- eth1 * 0.0.0.0/0 0.0.0.0/0
47809 19M ACCEPT all -- eth0 * 0.0.0.0/0 0.0.0.0/0
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:0:1023 flags:0x16/0x02 reject-with icmp-port-unreachable
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2049 flags:0x16/0x02 reject-with icmp-port-unreachable
0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:0:1023 reject-with icmp-port-unreachable
0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:2049 reject-with icmp-port-unreachable
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:6000:6009 flags:0x16/0x02 reject-with icmp-port-unreachable
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7100 flags:0x16/0x02 reject-with icmp-port-unreachable |
|