Portál AbcLinuxu, 10. května 2025 06:14
eth0 -> ADSL router eth1 -> lan1 eth2 -> lan2ADSL router pracuje v bridge rezimu, takze provoz ven jde pres ppp0. Chci, aby obe lokalni site mohly pristupovat ven, ale nedokazaly komunikovat mezi sebou. Prikladam cast konfigurace firewallu (ufw v Ubuntu):
-A POSTROUTING -s 192.168.0.0/24 -o ppp0 -j MASQUERADE (lan1) -A POSTROUTING -s 192.168.1.0/24 -o ppp0 -j MASQUERADE (lan2) Chain FORWARD (policy ACCEPT) -A ufw-before-forward -i !ppp0 -o eth1 -j REJECT -A ufw-before-forward -i !ppp0 -o eth2 -j REJECTProblem je v tom, ze mi porad funguje ping mezi sitema lan1 a lan2.
Řešení dotazu:
-I ufw-before-forward -i !ppp0 -o eth1 -j REJECT -I ufw-before-forward -i !ppp0 -o eth2 -j REJECT
Chain FORWARD (policy ACCEPT 3 packets, 670 bytes) pkts bytes target prot opt in out source destination 0 0 REJECT all -- !ppp0 eth1 anywhere anywhere reject-with icmp-port-unreachable 0 0 REJECT all -- !ppp0 eth2 anywhere anywhere reject-with icmp-port-unreachable 324K 308M ufw-before-logging-forward all -- any any anywhere anywhere 324K 308M ufw-before-forward all -- any any anywhere anywhere 324K 308M ufw-after-forward all -- any any anywhere anywhere 324K 308M ufw-after-logging-forward all -- any any anywhere anywhere 324K 308M ufw-reject-forward all -- any any anywhere anywhere
-I ufw-before-forward -i eth2 -o eth1 -j REJECT -I ufw-before-forward -i eth1 -o eth2 -j REJECTnešlo by zkusit rovnou tohle?
# pakety navázaných spojení -m state --state ESTABLISHED,RELATED -j ACCEPT # pakety z eth0 -i eth0 -o ppp0 -j ACCEPT # pakety z eth1 -i eth1 -o ppp0 -j ACCEPT # ostatní odmítnout -j REJECT
-A ufw-before-forward ! -i ppp0 -o eth2 -j REJECTNakonec jsem ale jako FORWARD politiku nastavil REJECT a povolil jen provoz ven.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.