Portál AbcLinuxu, 19. dubna 2024 18:41
Sep 26 19:00:53 localhost kernel:Nevite co s tim je a jak to popripade povolit ?
IN=eth0 OUT= MAC=00:02:44:5a:78:32:00:90:d0:89:71:88:08:00
SRC=212.67.79.50 DST=10.0.0.1
LEN=52 TOS=0x00 PREC=0x00 TTL=54 ID=58302 DF PROTO=TCP
SPT=80 DPT=32911 WINDOW=49232 RES=0x00 ACK FIN URGP=0
Tabulka: nat Chain PREROUTING (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere 192.168.0.0/24 Chain POSTROUTING (policy ACCEPT) target prot opt source destination MASQUERADE all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination Tabulka: filter Chain INPUT (policy ACCEPT) target prot opt source destination tcp_segmenty tcp -- anywhere anywhere ACCEPT icmp -- anywhere anywhere icmp echo-reply ACCEPT icmp -- anywhere anywhere icmp destination-unreachable ACCEPT icmp -- anywhere anywhere icmp echo-request ACCEPT icmp -- anywhere anywhere icmp time-exceeded ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere LOG all -- anywhere anywhere LOG level warning udp_pakety udp -- anywhere anywhere Chain FORWARD (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT tcp -- anywhere home tcp dpt:http ACCEPT all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination ACCEPT all -- localhost.localdomain anywhere ACCEPT all -- home anywhere ACCEPT all -- borec anywhere ACCEPT all -- 10.0.0.1 anywhere ACCEPT all -- 195.70.144.166 anywhere LOG all -- anywhere anywhere LOG level warning Chain RH-Firewall-1-INPUT (0 references) target prot opt source destination Chain tcp_segmenty (1 references) target prot opt source destination ACCEPT tcp -- anywhere anywhere tcp dpt:http ACCEPT tcp -- anywhere anywhere tcp dpt:smtp ACCEPT tcp -- anywhere anywhere tcp dpt:ssh ACCEPT tcp -- anywhere anywhere tcp dpt:domain ACCEPT tcp -- anywhere anywhere tcp dpt:pop3 ACCEPT tcp -- anywhere anywhere tcp dpt:telnet Chain udp_pakety (1 references) target prot opt source destination ACCEPT udp -- anywhere anywhere udp dpt:domainbtw nejak mi nefunguje maskarada ...
ACCEPT all -- anywhere anywherekde nejsou vidět interfacy ani případné detailní optiony, takže lze jen tipovat, co to dělá. Vezmi raději iptables -L -v -n pro každou tabulku a dej to někam na web.
Tiskni Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.