- 论坛徽章:
- 0
|
我用RAHHAT9作了一台NAT代理服务器,假设外部ip:61.133.15.160,内部的ip为192.168.0.254,我的2K服务器放在内部,地址为192.168.0.10并安装了RADMIN远程控制软件端口默认是4899,我想在外部通过防火墙外部地址的4899端口,用RADMIN客户端来访问内部的WIN2K服务器可总是不成功,命令如下:
iptables -t nat -A PREROUTING -d 66.133.15.160 -p tcp -m tcp --dport 4899 -j DNAT --to-destination 192.168.0.10:4899
iptables -t nat -A POSTROUTING -d 192.168.0.10 -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 4899 -j SNAT --to 192.168.0.254
代理服务器端TCP检测如下:
[root@forwawd root]# tcpdump tcp port 4899
tcpdump: listening on eth0
22:46:05.188558 221.0.159.17.1224 > 61.133.15.160.4899: S 1544508777:1544508777(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
22:46:05.188692 61.133.15.160.4899 > 221.0.159.17.1224: R 0:0(0) ack 1544508778 win 0 (DF)
22:46:05.745958 221.0.159.17.1224 > 61.133.15.160.4899: S 1544508777:1544508777(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
22:46:05.746051 61.133.15.160.4899 > 221.0.159.17.1224: R 0:0(0) ack 1 win 0 (DF)
22:46:06.351823 221.0.159.17.1224 > 61.133.15.160.4899: S 1544508777:1544508777(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
22:46:06.351900 61.133.15.160.4899 > 221.0.159.17.1224: R 0:0(0) ack 1 win 0 (DF)
以上命令用3389端口也全部失败,请大家帮忙指正错误!谢谢
以上已经打开了echo 1 〉/proc/sys/net/ipv4/ip_forward
[ 本帖最后由 nisshinzgz 于 2005-11-17 23:20 编辑 ] |
|