|
|

楼主 |
发表于 2004-11-17 11:23:52
|
显示全部楼层
最好这样区分,ip从192.100.100.1-192.100.100.127能够自由访问外部和内部internet地址,而从192.100.100.128-192.100.100.255只能访问二级和一级内部网
iptables -F FORWARD
iptables -A FORWARD -j ACCEPT -m state --state ESTABLISHED,RELATED
iptables -A FORWARD -j ACCEPT -s 192.168.100.0/25
iptables -A FORWARD -j ACCEPT -s 192.168.100.128/25 -d 10.10.10.0/24
iptables -A FORWARD -j ACCEPT -s 192.168.100.128/25 -d 192.168.100.0/24
iptables -A FORWARD -j LOG -m limit --limit 10/sec --log-prefix ' DROP '
iptables -A FORWARD -j DROP |
|