|
结构: 公司使用adsl通过linux redhat上网,两张网卡,一张接内网是192.168.16.0,一张接adsl,现在要使用ts工具(一种聊天工具),服务器设在192.168.16.18:8767上,我做了映射,可是没法连接上,不知道那里错了~~
防火墙设置如下:
# Generated by iptables-save v1.3.0 on Tue Jun 27 09:45:44 2006
*mangle
:FORWARD ACCEPT [26436:1557350]
:INPUT ACCEPT [416444:169196149]
:OUTPUT ACCEPT [412729:171417124]
OSTROUTING ACCEPT [415147:171735666]
REROUTING ACCEPT [443648:170792259]
#-A FORWARD -o eth0 -d 192.168.16.24 -j MARK --set-mark 10
COMMIT
# Completed on Tue Jun 27 09:45:44 2006
# Generated by iptables-save v1.3.0 on Tue Jun 27 09:45:44 2006
*filter
:FORWARD ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -i eth0 -j ACCEPT
# -A INPUT -i eth3 -j ACCEPT
#-A INPUT -p tcp -m tcp -i ppp0 --dport 6502 -j ACCEPT
# ň獀 SYN-Flood 窰ю阑
-N syn-flood
-A syn-flood -m limit --limit 100/s --limit-burst 150 -j RETURN
-A syn-flood -j DROP
-I INPUT -j syn-flood
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp -i ppp0 --icmp-type any -j ACCEPT
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags SYN,RST SYN,RST -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --tcp-flags FIN,SYN FIN,SYN -j DROP
-A INPUT -p tcp -s 61.31.18.192/255.255.255.240 -i ppp0 -j ACCEPT
-A INPUT -p tcp -m tcp -s 61.31.18.192/255.255.255.240 -i ppp0 --dport 21 -j ACCEPT
-A INPUT -p tcp -m tcp -s 61.31.18.192/255.255.255.240 -i ppp0 --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp -s 61.31.18.192/255.255.255.240 -i ppp0 --dport 873 -j ACCEPT
#-A INPUT -p tcp -m tcp -s 61.31.18.192/255.255.255.240 -i ppp0 --dport 10000 -j ACCEPT
-A INPUT -p tcp -m tcp -s 220.132.101.200/32 -i ppp0 -j ACCEPT
-A INPUT -p tcp -m tcp -s 220.132.101.200/32 -i ppp0 --dport 21 -j ACCEPT
-A INPUT -p tcp -m tcp -i ppp0 --dport 25 -j ACCEPT
-A INPUT -p tcp -m tcp -i ppp0 --dport 22 -j DROP
-A INPUT -p tcp -m tcp -i ppp0 --dport 23 -j DROP
-A INPUT -p udp -m udp -i ppp0 --dport 23 -j DROP
-A OUTPUT -p tcp -s 192.168.16.18 -j ACCEPT
-A OUTPUT -p udp -s 192.168.16.18 -j ACCEPT
-A OUTPUT -p tcp -m tcp -s 192.168.16.0/255.255.255.0 --dport 110 --sport 1024:65535 -j ACCEPT
# Completed on Tue Jun 27 09:45:44 2006
# Generated by iptables-save v1.3.0 on Tue Jun 27 09:45:44 2006
*nat
:OUTPUT ACCEPT [4:284]
OSTROUTING ACCEPT [5:332]
REROUTING ACCEPT [542:45946]
-A PREROUTING -s 192.168.16.20/32 -p tcp -m tcp --dport 22 -j ACCEPT
-A PREROUTING -s 192.168.16.40/32 -p tcp -m tcp --dport 22 -j ACCEPT
-A POSTROUTING -s 192.168.16.0/255.255.255.0 -o ppp0 -j MASQUERADE
#-A PREROUTING -s 192.168.16.253/255.255.255.240 -p tcp -m tcp --dport 80 -j ACCEPT
#-A PREROUTING -s 192.168.16.0/255.255.255.0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A PREROUTING -s 192.168.16.0/255.255.255.0 -p tcp -m tcp --dport 22 -j DROP
-A PREROUTING -i ppp0 -p tcp -m tcp --dport 8767 -j DNAT --to-destination 192.168.16.18:8767
-A POSTROUTING -s 192.168.16.0/24 -d 192.168.16.18 -p tcp -m tcp --dport 8767 -j SNAT --to-source 192.168.16.3
COMMIT
# Completed on Tue Jun 27 09:45:44 2006 |
|