- 论坛徽章:
- 0
|
我用iptables做nat,,tcp协议可以连通,,但udp不能通的,,
流媒体那服务一直都处于buffering。。然后就停了。
RH AS3系统,
- iptables -nvL
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 255
- 0 0 ACCEPT esp -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT ah -- * * 0.0.0.0/0 0.0.0.0/0
- 132 9360 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1220
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:554
- 1 40 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1554
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:631
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1554
- 4 160 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 2270 443K REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy ACCEPT 1 packets, 48 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0
- 19 3105 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- Chain OUTPUT (policy ACCEPT 118 packets, 12236 bytes)
- pkts bytes target prot opt in out source destination
复制代码
iptables -t nat -nvL
- Chain PREROUTING (policy ACCEPT 4907 packets, 879K bytes)
- pkts bytes target prot opt in out source destination
- 1 48 DNAT tcp -- * * 0.0.0.0/0 10.200.50.90 tcp dpt:1554 to:10.200.50.83:554
- 0 0 DNAT udp -- * * 0.0.0.0/0 10.200.50.90 udp dpt:1554 to:10.200.50.83:554
- Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 9 592 MASQUERADE all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 8 packets, 544 bytes)
- pkts bytes target prot opt in out source destination
复制代码
iptables-save
- # Generated by iptables-save v1.2.11 on Fri Oct 21 09:38:10 2005
- *nat
- :PREROUTING ACCEPT [823:229647]
- :POSTROUTING ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A PREROUTING -d 10.200.50.90 -p tcp -m tcp --dport 1554 -j DNAT --to-destination 10.200.50.83:554
- -A PREROUTING -d 10.200.50.90 -p udp -m udp --dport 1554 -j DNAT --to-destination 10.200.50.83:554
- -A POSTROUTING -j MASQUERADE
- COMMIT
- # Completed on Fri Oct 21 09:38:10 2005
- # Generated by iptables-save v1.2.11 on Fri Oct 21 09:38:10 2005
- *filter
- :INPUT ACCEPT [2327:435284]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [299:26968]
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type any -j ACCEPT
- -A INPUT -p tcp --dport 22 -j ACCEPT
- -A INPUT -p tcp --dport 1220 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 554 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 1554 -j ACCEPT
- -A INPUT -p tcp --dport 80 -j ACCEPT
- -A INPUT -p udp -m udp --dport 631 -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -p udp -j ACCEPT
- -A INPUT -p udp -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
- COMMIT
- # Completed on Fri Oct 21 09:38:10 2005
复制代码
麻烦帮看看。。 |
|