- 论坛徽章:
- 0
|
网关上iptables -L的输入:
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- 192.168.100.0/23 anywhere
ACCEPT all -- proxym anywhere
ACCEPT all -- 192.168.100.4 anywhere
ACCEPT all -- 61.237.*.* anywhere
ACCEPT udp -- anywhere anywhere udp spt:bootpc dpt:bootps
ACCEPT all -- anywhere 61.237.*.* state RELATED,ESTABLISHED
tcp_packets tcp -- anywhere anywhere
udp_packets udp -- anywhere anywhere
icmp_packets icmp -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:22222
ACCEPT udp -- 192.168.100.0/23 192.168.100.1 udp dpt:domain
Chain FORWARD (policy DROP)
target prot opt source destination
REJECT tcp -- anywhere anywhere #conn/32 > 80 reject-with icmp-port-unreachable
bad_tcp_packets tcp -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
DROP all -- anywhere anywhere domain --name "btchina.net"
Chain OUTPUT (policy DROP)
target prot opt source destination
bad_tcp_packets tcp -- anywhere anywhere
ACCEPT all -- proxym anywhere
ACCEPT all -- 192.168.100.4 anywhere
ACCEPT all -- 61.237.*.* anywhere
Chain allowed (4 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere state RELATED,ESTABLISHED
DROP tcp -- anywhere anywhere
Chain bad_tcp_packets (2 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere tcp flags:SYN,ACK/SYN,ACK state NEW reject-with tcp-reset
DROP tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN state NEW
Chain icmp_packets (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
Chain tcp_packets (1 references)
target prot opt source destination
allowed tcp -- anywhere anywhere tcp dpt:ftp
allowed tcp -- anywhere anywhere tcp dpt:ssh
allowed tcp -- anywhere anywhere tcp dpt:http
allowed tcp -- anywhere anywhere tcp dpt:auth
Chain udp_packets (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain |
|