DNAT與restrict FORWARD - Linux
By Skylar Davis
at 2013-03-26T18:47
at 2013-03-26T18:47
Table of Contents
目的是只想讓172.16.1.237與172.16.8.15可以走ppp0做SNAT訪問對外網路,其餘IP無法聯外
且172.16.8.15有提供ftp,http與https的服務,需在ppp0做DNAT
請參考目前的設定連結
http://goo.gl/WbeqM
按照目前的設定,可以讓外部的三個服務順利導向172.16.8.15
但是無法做到限制FORWARD
如果把26行改為
iptables -P FORWARD DROP
可以做到限制FORWARD,但是服務沒有辦法使用
不確定是有正確導入但回應轉錯地方,或是根本無法導入
區網為172.16.0.0/20
請問是否有衝突的規則存在裡面造成設定失敗?
謝謝
---
感謝asadfish指正
並非開放INPUT
而是開放FORWARD
iptables -A FORWARD -d 172.16.8.15 -p tcp --dport 80 -j ACCEPT
--
且172.16.8.15有提供ftp,http與https的服務,需在ppp0做DNAT
請參考目前的設定連結
http://goo.gl/WbeqM
按照目前的設定,可以讓外部的三個服務順利導向172.16.8.15
但是無法做到限制FORWARD
如果把26行改為
iptables -P FORWARD DROP
可以做到限制FORWARD,但是服務沒有辦法使用
不確定是有正確導入但回應轉錯地方,或是根本無法導入
區網為172.16.0.0/20
請問是否有衝突的規則存在裡面造成設定失敗?
謝謝
---
感謝asadfish指正
並非開放INPUT
而是開放FORWARD
iptables -A FORWARD -d 172.16.8.15 -p tcp --dport 80 -j ACCEPT
--
Tags:
Linux
All Comments
By Donna
at 2013-03-31T01:01
at 2013-03-31T01:01
By Irma
at 2013-03-31T18:45
at 2013-03-31T18:45
By Tracy
at 2013-04-03T05:18
at 2013-04-03T05:18
By Wallis
at 2013-04-06T09:37
at 2013-04-06T09:37
By Catherine
at 2013-04-07T05:01
at 2013-04-07T05:01
By Odelette
at 2013-04-09T16:37
at 2013-04-09T16:37
By Eden
at 2013-04-10T05:31
at 2013-04-10T05:31
By Puput
at 2013-04-11T15:13
at 2013-04-11T15:13
By Hardy
at 2013-04-12T20:57
at 2013-04-12T20:57
By Ethan
at 2013-04-15T00:48
at 2013-04-15T00:48
By Xanthe
at 2013-04-16T10:06
at 2013-04-16T10:06
By Candice
at 2013-04-18T13:03
at 2013-04-18T13:03
By Lily
at 2013-04-21T13:40
at 2013-04-21T13:40
Related Posts
音量控制的熱鍵設定
By Dora
at 2013-03-26T08:42
at 2013-03-26T08:42
Mint Debian 201303 Ver. Release
By Regina
at 2013-03-26T05:31
at 2013-03-26T05:31
Mint Debian 201303 Ver. Release
By Valerie
at 2013-03-26T03:56
at 2013-03-26T03:56
GenTwoo: Social Compiling
By Joe
at 2013-03-25T20:00
at 2013-03-25T20:00
不小刪除etc/init.d
By George
at 2013-03-25T16:05
at 2013-03-25T16:05