Portál AbcLinuxu, 5. května 2025 16:36
# Generated by iptables-save v1.4.21 on Sat May 19 16:18:11 2018 *nat :PREROUTING ACCEPT [14:1309] :INPUT ACCEPT [11:1153] :OUTPUT ACCEPT [8:480] :POSTROUTING ACCEPT [8:480] -A PREROUTING -d XXX.YYY.UUU.ZZZ/32 -p tcp -m tcp --dport 8100 -j DNAT --to-destination 192.168.42.10:8100 -A POSTROUTING -s 192.168.42.0/24 -o eth0 -j MASQUERADE -A POSTROUTING -s 192.168.43.0/24 -o eth0 -m policy --dir out --pol none -j MASQUERADE -A POSTROUTING -d 192.168.42.10/32 -p tcp -m tcp --dport 8100 -j SNAT --to-source 192.168.42.1 COMMIT # Completed on Sat May 19 16:18:11 2018 # Generated by iptables-save v1.4.21 on Sat May 19 16:18:11 2018 *filter :INPUT ACCEPT [1211:101883] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [12168:2311930] :f2b-SSH - [0:0] -A INPUT -p tcp -m tcp --dport 22 -j f2b-SSH -A INPUT -p udp -m udp --dport 1701 -m policy --dir in --pol none -j DROP -A INPUT -m conntrack --ctstate INVALID -j DROP -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A INPUT -p udp -m multiport --dports 500,4500 -j ACCEPT -A INPUT -p udp -m udp --dport 1701 -m policy --dir in --pol ipsec -j ACCEPT -A INPUT -p udp -m udp --dport 1701 -j DROP -A FORWARD -m conntrack --ctstate INVALID -j DROP -A FORWARD -i eth0 -o ppp+ -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i ppp+ -o eth0 -j ACCEPT -A FORWARD -s 192.168.42.0/24 -d 192.168.42.0/24 -i ppp+ -o ppp+ -j ACCEPT -A FORWARD -d 192.168.43.0/24 -i eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -s 192.168.43.0/24 -o eth0 -j ACCEPT -A FORWARD -j DROP -A f2b-SSH -j RETURN COMMIT
-A FORWARD -j DROP
-A POSTROUTING -s 192.168.42.0/24 -o eth0 -j MASQUERADEDoporucuji pouzit klasicke nastroje jako ping,telnet a tcpdump.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.