- 论坛徽章:
- 1
|
iptables -A FORWARD -d www.sex.com -j DROP ??
原帖由 "platinum" 发表:
nslookup www.sex.com
iptables-save
看一些结果
[root@localhost yushin]# nslookup www.sex.com
Server: 202.96.134.133
Address: 202.96.134.133#53
Non-authoritative answer:
Name: www.sex.com
Address: 209.81.7.23
[root@localhost yushin]# iptables-save
# Generated by iptables-save v1.3.3 on Thu Oct 13 15:07:13 2005
*mangle
REROUTING ACCEPT [2037001]
:INPUT ACCEPT [310610]
:FORWARD ACCEPT [1726356]
:OUTPUT ACCEPT [323845]
OSTROUTING ACCEPT [2042795]
COMMIT
# Completed on Thu Oct 13 15:07:13 2005
# Generated by iptables-save v1.3.3 on Thu Oct 13 15:07:13 2005
*nat
REROUTING ACCEPT [104413]
OSTROUTING ACCEPT [20511]
:OUTPUT ACCEPT [20118]
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
COMMIT
# Completed on Thu Oct 13 15:07:13 2005
# Generated by iptables-save v1.3.3 on Thu Oct 13 15:07:13 2005
*filter
:INPUT DROP [9]
:FORWARD DROP [0]
:OUTPUT ACCEPT [324432]
:syn-flood - [0]
-A INPUT -s 192.168.0.50 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m multiport --dports 110,80,25 -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 139 -j ACCEPT
-A INPUT -i eth1 -p udp -m multiport --dports 53 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
-A INPUT -p gre -j ACCEPT
-A INPUT -s 192.186.0.0/255.255.255.0 -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
-A INPUT -s 192.186.0.0/255.255.255.0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
-A INPUT -p icmp -m limit --limit 3/sec -j LOG --log-prefix "ICMP packet IN: " --log-level 6
-A INPUT -p icmp -m limit --limit 6/min -j ACCEPT
-A INPUT -p icmp -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn-flood
-A FORWARD -s 192.168.0.50 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 64.20.41.169 -j DROP
-A FORWARD -d 209.81.7.23 -j DROP
-A FORWARD -d 64.20.39.53 -j DROP
-A FORWARD -d 219.133.41.213 -j DROP
-A FORWARD -m layer7 --l7proto qq -m time --timestart 08:15 --timestop 12:30 --days Mon,Tue,Wed,Thu,Fri,Sat -j DROP
-A FORWARD -m layer7 --l7proto qq -m time --timestart 13:30 --timestop 20:30 --days Mon,Tue,Wed,Thu,Fri,Sat -j DROP
-A FORWARD -m layer7 --l7proto msn-filetransfer -j DROP
-A FORWARD -p tcp -m tcp --dport 80 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 24 -j DROP
-A FORWARD -m ipp2p --kazaa --edk --bit -j DROP
-A FORWARD -p tcp -m ipp2p --ares -j DROP
-A FORWARD -p udp -m ipp2p --kazaa -j DROP
-A FORWARD -p tcp -m tcp --dport 4000 -j DROP
-A FORWARD -p tcp -m tcp --dport 2000 -j DROP
-A FORWARD -s 192.168.0.0/255.255.255.0 -p gre -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -p tcp -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -p udp -j ACCEPT
-A syn-flood -p tcp -m limit --limit 3/sec --limit-burst 6 -j RETURN
-A syn-flood -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Thu Oct 13 15:07:13 2005
[root@localhost yushin]# |
|