Portál AbcLinuxu, 10. května 2025 23:04
# Generated by iptables-save v1.4.4 on Wed Dec 9 19:23:08 2009 *nat :PREROUTING ACCEPT [46:5742] :POSTROUTING ACCEPT [0:0] :OUTPUT ACCEPT [9:771] -A POSTROUTING -o eth0 -j MASQUERADE COMMIT # Completed on Wed Dec 9 19:23:08 2009 # Generated by iptables-save v1.4.4 on Wed Dec 9 19:23:08 2009 *filter :INPUT ACCEPT [60286:13916970] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [42362:4213667] -A FORWARD -i eth0 -o eth1 -j ACCEPT -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT COMMIT # Completed on Wed Dec 9 19:23:08 2009výpis iptables -L
pou@server:~$ sudo iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED Chain FORWARD (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED Chain OUTPUT (policy ACCEPT) target prot opt sourcea vypis iptables -t nat -L
pou@server:~$ sudo iptables -t nat -L Chain PREROUTING (policy ACCEPT) target prot opt source destination Chain POSTROUTING (policy ACCEPT) target prot opt source destination MASQUERADE all -- anywhere anywhere MASQUERADE all -- anywhere anywhere MASQUERADE all -- anywhere anywhere MASQUERADE all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destinationje zvlastní kdyz na PC zadam ping seznam.cz tak vse funguje a nevypadne žádny paket... Prosím o radu, děkuji
ip route
?
iptables -P FORWARD DROP; iptables -A FORWARD -i eth1 -o eth0 -s (zdrojová IP) -j ACCEPT; iptables -A FORWARD -i eth0 -o eth1 -s ! (zdrojová IP) -m state --state ESTABLISHED -j ACCEPT ; iptables -A POSTROUTING -t nat -o eth0 -s (zdrojová IP) -j MASQUERADE;Toto je len čásť ktorá riadi prechod z jedného do druhého interface. Ohladom DNS ak nemáš nejaké špecialne požiadavky, tak vlož priamo do DNS alebo klientského PC vonkajšie DNS. Tým znížiš pravdepodnosť prieniku do routra a zvýšiš dostupnosť. V prípade,že by vybavoval DNS router by si mal SPOF (Single Point of Failure).
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.