LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 722|回复: 1

RH4下影射cs服务器端口的问题!

[复制链接]
发表于 2005-3-13 14:58:25 | 显示全部楼层 |阅读模式
eth0:内网
eth1:外网
外网ip:218.16.xxx.xx
内网cs服务器:192.168.0.140
端口27015

# Firewall configuration written by system-config-securitylevel
# Manual customization of this file is not recommended.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
#-A INPUT --dport 27015 -j ACCEPT
#-A FORWARD --dport 27015 -j ACCEPT
#-A OUTPUT --dport 27015 -j ACCEPT
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -i eth1 -j ACCEPT
-A RH-Firewall-1-INPUT -i eth0 -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p 50 -j ACCEPT
-A RH-Firewall-1-INPUT -p 51 -j ACCEPT
#-A RH-Firewall-1-INPUT -p udp --dport 5353 -d 224.0.0.251 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 27010 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 27012 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 27020 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 27015 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 5273 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 7002 -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 27015 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 27015 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 5273 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 7002 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m udp -p udp --dport 27015 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m udp -p udp --dport 27010 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m udp -p udp --dport 27012 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m udp -p udp --dport 27020 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -i eth0 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -i eth1 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
COMMIT

*nat
REROUTING ACCEPT [0:0]
OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A POSTROUTING -s 192.168.0.0/24 -j SNAT --to 218.16.xxx.xx
-A PREROUTING -i eth1 -p udp --dport 27015 -j DNAT --to 192.168.0.140:27015
-A POSTROUTING -o eth0 -p udp -s 192.168.0.0/24 -d 192.168.0.140 -j SNAT --to-source 192.168.0.58
-A PREROUTING -i eth1 -p tcp --dport 27015 -j DNAT --to 192.168.0.140:27015
-A POSTROUTING -o eth0 -p tcp -s 192.168.0.0/24 -d 192.168.0.140 -j SNAT --to-source 192.168.0.58
#-A PREROUTING -p tcp -d 218.16.xxx.xx --dport 27015 -j DNAT --to 192.168.0.140:27015
#-A PREROUTING -p udp -d 218.16.xxx.xx --dport 27015 -j DNAT --to 192.168.0.140:27015
COMMIT

一直不成功!也试过这样
#-A PREROUTING -p tcp -d 218.16.xxx.xx --dport 27015 -j DNAT --to 192.168.0.140:27015
#-A PREROUTING -p udp -d 218.16.xxx.xx --dport 27015 -j DNAT --to 192.168.0.140:27015
一样不行!请成功的朋友看看!
 楼主| 发表于 2005-3-13 20:50:39 | 显示全部楼层
自己顶了~
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表