iptables問題 - Linux

Ingrid avatar
By Ingrid
at 2012-12-05T17:47

Table of Contents

我ping外網ping不同,但是能上網,在iptables -F或者iptable -X過後不能上網。
我的firestarter運行時候會出現,
Error reading /proc/net/ip_conntrack: 沒有那個文件或目錄
顯示不了聯網的程序。
而且在ubuntu12.10下不能關閉iptables,service iptables stop找不到iptables這個
服務,而且chkconfig | grep iptables也找不到。

以下是我的iptables -L輸出。

Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- ns.group.yfc anywhere tcpflags:!
FIN,SYN,RST,ACK/SYN
ACCEPT udp -- ns.group.yfc anywhere
ACCEPT tcp -- ns.wuhan.net.cn anywhere tcpflags:!
FIN,SYN,RST,ACK/SYN
ACCEPT udp -- ns.wuhan.net.cn anywhere
ACCEPT all -- anywhere anywhere
LSI udp -- anywhere anywhere udp dpt:33434
LSI icmp -- anywhere anywhere
DROP all -- anywhere 255.255.255.255
DROP all -- anywhere 192.168.1.255
DROP all -- base-address.mcast.net/8 anywhere
DROP all -- anywhere base-address.mcast.net/8
DROP all -- 255.255.255.255 anywhere
DROP all -- anywhere 0.0.0.0
DROP all -- anywhere anywhere state INVALID
LSI all -f anywhere anywhere limit: avg
10/min burst 5
INBOUND all -- anywhere anywhere
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info
prefix "Unknown Input"

Chain FORWARD (policy DROP)
target prot opt source destination
LSI udp -- anywhere anywhere udp dpt:33434
LSI icmp -- anywhere anywhere
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info
prefix "Unknown Forward"

Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- 192.168.1.100 ns.group.yfc tcp dpt:domain
ACCEPT udp -- 192.168.1.100 ns.group.yfc udp dpt:domain
ACCEPT tcp -- 192.168.1.100 ns.wuhan.net.cn tcp dpt:domain
ACCEPT udp -- 192.168.1.100 ns.wuhan.net.cn udp dpt:domain
ACCEPT all -- anywhere anywhere
DROP all -- base-address.mcast.net/8 anywhere
DROP all -- anywhere base-address.mcast.net/8
DROP all -- 255.255.255.255 anywhere
DROP all -- anywhere 0.0.0.0
DROP all -- anywhere anywhere state INVALID
OUTBOUND all -- anywhere anywhere
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level info
prefix "Unknown Output"

Chain INBOUND (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere state
RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state
RELATED,ESTABLISHED
LSI all -- anywhere anywhere

Chain LOG_FILTER (5 references)
target prot opt source destination

Chain LSI (6 references)
target prot opt source destination
LOG_FILTER all -- anywhere anywhere
LOG tcp -- anywhere anywhere tcpflags:
FIN,SYN,RST,ACK/SYN limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP tcp -- anywhere anywhere tcpflags:
FIN,SYN,RST,ACK/SYN
LOG tcp -- anywhere anywhere tcpflags:
FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP tcp -- anywhere anywhere tcpflags:
FIN,SYN,RST,ACK/RST
LOG icmp -- anywhere anywhere icmp
echo-request limit: avg 1/sec burst 5 LOG level info prefix "Inbound "
DROP icmp -- anywhere anywhere icmp
echo-request
LOG all -- anywhere anywhere limit: avg
5/sec burst 5 LOG level info prefix "Inbound "
DROP all -- anywhere anywhere

Chain LSO (1 references)
target prot opt source destination
LOG_FILTER all -- anywhere anywhere
LOG all -- anywhere anywhere limit: avg
5/sec burst 5 LOG level info prefix "Outbound "
REJECT all -- anywhere anywhere reject-with
icmp-port-unreachable

Chain OUTBOUND (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere state
RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state
RELATED,ESTABLISHED
LSO all -- anywhere anywhere

--
橫看成嶺側成峰,遠近高低各不同。

--
Tags: Linux

All Comments

Megan avatar
By Megan
at 2012-12-08T14:58
請問這台是直接連外或是?
Iris avatar
By Iris
at 2012-12-12T00:21
妳預設的input output 都是DROP,所以妳iptables -F -X之後
不能上網是正常的
Jacky avatar
By Jacky
at 2012-12-13T03:30
我現在iptables -F過後又能上網了,不知道怎麼回事
我是連在路由器上連上外網的
William avatar
By William
at 2012-12-15T05:39
我該怎麼辦呢?》
Genevieve avatar
By Genevieve
at 2012-12-16T04:10
我第二個推文有誤...一般來說output預設ACCEPT,input設DROP
Cara avatar
By Cara
at 2012-12-18T16:31
恩,感謝推文!現在沒事了我就可以實驗用iptables了。

網站特定的code被替換(求救)??

Adele avatar
By Adele
at 2012-12-05T17:24
我的網站主要使用php5.3+mysql5.1+centos5.8,現在發生使用iframe iframe裡面特定的code替換成下面的code andlt;htmlandgt;andlt;body style=and#34;background-color:transparentand#34;andgt;a ...

關於make的新手問題

Xanthe avatar
By Xanthe
at 2012-12-05T15:14
想請教各位先進這問題是出在哪裡~ 小弟用的是raspberry pi 系統是raspbian正在make一個driver 以下是我執行的指令 ============================================================================ roota ...

Mageia套件庫沒有收錄Wine?

Linda avatar
By Linda
at 2012-12-05T11:40
各位好,我是Linux的新手,最近剛接觸Mageia發現一些小問題 我想用Wine來跑一些Windows的小程式,於是到套件管理的地方搜尋 wine,但居然找不到這個東西? 是因為Mageia沒有收錄嗎?我已增加 了所有的更新來源了。   而我怕到Wine官網下載rpm安裝時,又會出現一堆套間相依性 ...

用awk拆解config file

Isla avatar
By Isla
at 2012-12-04T15:43
$ cat test.config andlt;videoin_c0_textandgt; Dog andlt;videoin_c0_colorandgt; 1 andlt;videoin_c0_s0_resolutionandgt; 320x240 andlt;videoin_c0_imprinttimes ...

用awk拆解config file

Carol avatar
By Carol
at 2012-12-04T15:07
Linux菜鳥請想問大家 該如何用awk拆解這個config file: andlt;videoin_c0_textandgt; Dog andlt;videoin_c0_colorandgt; 1 andlt;videoin_c0_s0_resolutionandgt; 320x240 andlt;vi ...