Left: iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
REJECT udp -- anywhere anywhere udp dpt:bootps reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp dpt:domain reject-with icmp-port-unreachable
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT tcp -- anywhere anywhere tcp dpt:http
DROP tcp -- anywhere anywhere tcp dpts:0:1023
DROP udp -- anywhere anywhere udp dpts:0:1023
ACCEPT gre -- anywhere 192.168.1.63
ACCEPT tcp -- anywhere 192.168.1.63 tcp dpt:1723
ACCEPT tcp -- anywhere 192.168.1.63 tcp dpt:l2tp
ACCEPT udp -- anywhere 192.168.1.63 udp dpt:isakmp
ACCEPT udp -- anywhere 192.168.1.63 udp dpt:l2tp
ACCEPT tcp -- anywhere 192.168.1.63 tcp dpt:l2tp
ACCEPT tcp -- anywhere 192.168.1.63 tcp dpt:isakmp
ACCEPT udp -- 192.168.1.63 10.0.0.1 udp dpt:isakmp
ACCEPT udp -- 192.168.1.63 10.0.0.1 udp dpt:ipsec-nat-t
ACCEPT esp -- 192.168.1.63 10.0.0.1
ACCEPT ah -- 192.168.1.63 10.0.0.1
ACCEPT esp -- anywhere anywhere
ACCEPT udp -- anywhere anywhere udp dpt:isakmp
ACCEPT udp -- anywhere anywhere udp dpt:ipsec-nat-t
ACCEPT udp -- 192.168.0.0/24 10.0.0.0/24 udp dpt:isakmp
ACCEPT udp -- 192.168.0.0/24 10.0.0.0/24 udp dpt:ipsec-nat-t
ACCEPT esp -- 192.168.0.0/24 10.0.0.0/24
ACCEPT ah -- 192.168.0.0/24 10.0.0.0/24
Chain FORWARD (policy DROP)
target prot opt source destination
DROP all -- anywhere 10.0.0.0/24
DROP all -- anywhere 192.168.0.0/16
ACCEPT all -- 10.0.0.0/24 anywhere
ACCEPT all -- anywhere 10.0.0.0/24
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Right:
iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
REJECT udp -- anywhere anywhere udp dpt:bootps reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp dpt:domain reject-with icmp-port-unreachable
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
DROP tcp -- anywhere anywhere tcp dpts:0:1023
DROP udp -- anywhere anywhere udp dpts:0:1023
ACCEPT udp -- 10.0.0.0/24 192.168.0.0 udp dpt:isakmp
ACCEPT udp -- 10.0.0.0/24 192.168.0.0 udp dpt:ipsec-nat-t
ACCEPT esp -- 10.0.0.0/24 192.168.0.0
ACCEPT ah -- 10.0.0.0/24 192.168.0.0
Chain FORWARD (policy DROP)
target prot opt source destination
DROP all -- anywhere 192.168.0.0/24
ACCEPT all -- 192.168.0.0/24 anywhere
ACCEPT all -- anywhere 192.168.0.0/24
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
請各位幫幫小弟看一下!非常感謝!!統計資料: 發表於 由 rich0203 — 週二 8月 16, 2011 5:58 pm
]]>