- 论坛徽章:
- 0
|
今天服务器挂了n次。。,看iptables被更改.请版主等高手们帮忙
-A PREROUTING -s 192.168.0.0/255.255.255.0 -p udp -m udp --dport 443 -j DROP
-A PREROUTING -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 443 -j DROP
-A PREROUTING -s 192.168.0.0/255.255.255.0 -p udp -m udp --dport 443 -j DROP
-A PREROUTING -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 443 -j DROP
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.20 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.20 -o ppp0 -j MASQUERADE
晕,这么多重复的,而且怎么还有 UDP/443
-A INPUT -i eth1 -p tcp -m multiport --dports 135,136,netbios-ns,netbios-dgm,netbios-ssn,microsoft-ds,http,ftp,domain,pop3,smtp -j ACCEPT
-A INPUT -i eth1 -p udp -m multiport --dports 135,136,netbios-ns,netbios-dgm,netbios-ssn,microsoft-ds,ftp,domain -j ACCEPT
思维混乱,没有搞懂什么服务用什么协议跑在什么端口上,建议你 netstat -lnp 看看再决定开哪个端口
:RH-Lokkit-0-50-INPUT - [0]
这个链没用到,可用 iptables -X 删之 |
|