|
|
发表于 2004-10-16 14:31:50
|
显示全部楼层
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -p tcp -m tcp --dport 21 -j DNAT --to 172.16.255.2:21
iptables -t nat -A PREROUTING -i eth1 -p tcp -m tcp -d $FW_IP --dport 21 -j DNAT --to 172.16.255.2:21
iptables -A FORWARD -p tcp -d 172.16.255.2 --dport 21 -m state --state NEW -j ACCEPT
iptables -t nat -A POSTROUTING -s 172.16.255.0/24 -d 172.16.255.2 -p tcp -m tcp --dport 21 -j SNAT --to $FW_IP |
|