免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1369 | 回复: 1
打印 上一主题 下一主题

仔细参考精华后设置IPF+NAT,还是有点问题,请帮忙 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2005-09-09 20:12 |只看该作者 |倒序浏览
碰到的问题:设置好后我在主机上运行ipnat -l看到如下提示
ipnat -l
List of active MAP/Redirect filters:
MAP 192.168.1.85        1397 <- ->;192.168.0.222 22581 [61.13.177.198 53]
MAP 192.168.1.85        1397 <- ->;192.168.0.222 22581 [61.13.177.197 53]
MAP 192.168.1.85        1396 <- ->;192.168.0.222 22580 [61.13.177.198 53]
MAP 192.168.1.85        137 <- ->;192.168.0.222 22581 [192.168.1.87 137]
而192.168.1.85这台机开网页没反映,ping也ping不到,但是主机上确实显示了,不知道哪里有问题,具体情况如下

NAT情况:主机外网网卡为dc0,IP=192.168.0.222(局域网给的地址) netmask=255.255.255.0  ,内网网卡为dc1,IP=192.168.1.1 netmask=255.255.255.252  ,client机只有一台(做实验,可以的话就让这台机器带整个网),IP=192.168.1.85 netmask=255.255.255.252,目标是让主机带动client透明代理,能上qq和玩各种网络游戏

配置情况:
www# cat /etc/ipnat.conf
map dc0 192.168.0.0/16 ->; 0.0.0.0/32 proxy port ftp ftp/tcp
map dc0 192.168.1.0/24 ->; 0.0.0.0/32 portmap tcp/udp auto
map dc0 192.168.1.0/24 ->; 0.0.0.0/32

www# cat /etc/ipf.conf
block in all
block out all

# Possibly dangerous: packets with ip-options, short and fragmented packets
block in log quick on dc0 proto icmp from any to any
block in log quick all with short
block in log quick all with ipopts
block in log quick all with frag
block in log quick all with opt lsrr
block in log quick all with opt ssrr

# Local network traffic is allowed
pass out quick on lo0 all
pass in quick on lo0 all
pass out on dc1 all
pass in on dc1 all

# The pass rules to enable Services
pass in on dc0 proto tcp from any to any port = 20 flags S keep state
pass in on dc0 proto tcp from any to any port = 21 flags S keep state
pass in on dc0 proto tcp from any to any port = 22 flags S keep state
pass in on dc0 proto tcp from any to any port = 25 flags S keep state
pass in on dc0 proto tcp from any to any port = 80 flags S keep state
pass in on dc0 proto tcp from any to any port = 110 flags S keep state
pass in on dc0 proto tcp from any to any port = 443 flags S keep state
pass in on dc0 proto tcp from any to any port 55000 >;< 56000 flags S keep state

# The general pass rules.
pass out quick on dc0 proto tcp from any to any flags S/SAFR keep state keep frags
pass out quick on dc0 proto udp from any to any keep state keep frags
pass out quick on dc0 proto icmp from any to any keep state keep frags

论坛徽章:
2
丑牛
日期:2013-09-29 09:47:222015七夕节徽章
日期:2015-08-21 11:06:17
2 [报告]
发表于 2005-09-10 08:20 |只看该作者

仔细参考精华后设置IPF+NAT,还是有点问题,请帮忙

www# cat /etc/ipnat.conf
map dc0 192.168.0.0/16 ->; 0.0.0.0/32 proxy port ftp ftp/tcp
map dc0 192.168.1.0/24 ->; 0.0.0.0/32 portmap tcp/udp auto
map dc0 192.168.1.0/24 ->; 0.0.0.0/32

换成:
www# cat /etc/ipnat.conf
map dc0 192.168.1.0/24 ->; 192.168.0.222/32 portmap tcp/udp auto
map dc0 192.168.1.0/24 ->; 192.168.0.222/32
map dc0 192.168.0.0/16 ->; 192.168.0.222/32 proxy port ftp ftp/tcp

试试。
另外可以把ipf.conf先写成
pass in all
pass out all
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP