- 论坛徽章:
- 0
|
我的规则:
Chain FORWARD (policy DROP)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 ipp2p v0.8.1_rc1 --bit
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
先是用iptables -P FORWARD DROP
测试后发现内网机器啥都访问不了,比如WEB,PING,但我加了
iptables -A FORWARD -p icmp -j ACCEPT后,可以PING外网,奇怪的是我加上上面的规则后用IE无法打开网页,DNS没问题
加上规则后:
Chain FORWARD (policy DROP)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 ipp2p v0.8.1_rc1 --bit
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
[root@RHEL4 soft]# iptables -nL -t nat
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
MASQUERADE all -- 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT)
target prot opt source destination |
|