AlexeiKozlov
Silver Member | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору [admin1@(none) root]$ iptables -L -v Chain INPUT (policy ACCEPT 197 packets, 35954 bytes) pkts bytes target prot opt in out source destination 5538 1513K MACS all -- br0 any anywhere anywhere 0 0 DROP all -- any any anywhere anywhere state INVALID 9405 829K ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED 664 39840 ACCEPT all -- lo any anywhere anywhere state NEW 101 5582 ACCEPT all -- br0 any anywhere anywhere state NEW Chain FORWARD (policy ACCEPT 1634 packets, 90804 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- any any 192.168.1.0/24 10.9.112.64/28 4 160 ACCEPT all -- any any 192.168.1.2 anywhere 749K 669M MACS all -- br0 any anywhere anywhere 0 0 ACCEPT all -- br0 br0 anywhere anywhere 0 0 DROP all -- any any anywhere anywhere state INVALID 1859K 1564M ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED 0 0 DROP all -- !br0 vlan1 anywhere anywhere 4 192 ACCEPT all -- any any anywhere anywhere ctstate DNAT 0 0 DROP all -- any br0 anywhere anywhere Chain OUTPUT (policy ACCEPT 14758 packets, 4092K bytes) pkts bytes target prot opt in out source destination Chain MACS (2 references) pkts bytes target prot opt in out source destination 751K 669M RETURN all -- any any anywhere anywhere MAC 00:0C:6E:EE:04:F8 0 0 RETURN all -- any any anywhere anywhere MAC 00:1C:B3:B4:9F:78 0 0 RETURN all -- any any anywhere anywhere MAC 00:1C:B3:2C:38:8B 0 0 RETURN all -- any any anywhere anywhere MAC 00:1B:63:9B:2F:7A 0 0 RETURN all -- any any anywhere anywhere MAC 00:11:0A:2C:F1:F9 0 0 RETURN all -- any any anywhere anywhere MAC 00:1E:8C:78:57:3B 0 0 RETURN all -- any any anywhere anywhere MAC 00:13:CE:5C:45:3B 0 0 RETURN all -- any any anywhere anywhere MAC 00:80:48:28:CB:48 3735 1398K DROP all -- any any anywhere anywhere Chain SECURITY (0 references) pkts bytes target prot opt in out source destination 0 0 RETURN tcp -- any any anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 1/sec burst 5 0 0 RETURN tcp -- any any anywhere anywhere tcp flags:FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5 0 0 RETURN udp -- any any anywhere anywhere limit: avg 5/sec burst 5 0 0 RETURN icmp -- any any anywhere anywhere limit: avg 5/sec burst 5 0 0 DROP all -- any any anywhere anywhere Chain logaccept (0 references) pkts bytes target prot opt in out source destination 0 0 LOG all -- any any anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `ACCEPT ' 0 0 ACCEPT all -- any any anywhere anywhere Chain logdrop (0 references) pkts bytes target prot opt in out source destination 0 0 LOG all -- any any anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `DROP ' NAT [admin1@(none) root]$ iptables -L -v -t nat Chain PREROUTING (policy ACCEPT 2061 packets, 159K bytes) pkts bytes target prot opt in out source destination 9 6502 VSERVER all -- any any anywhere 10.9.112.72 0 0 NETMAP udp -- any any anywhere 10.9.112.72 udp spt:6112 192.168.1.0/24 0 0 autofw tcp -- br0 any anywhere anywhere tcp dpt:9018 autofw tcp dpt:9018 to:9018 0 0 autofw udp -- br0 any anywhere anywhere udp dpt:12164 autofw udp dpt:12164 to:12164 0 0 autofw tcp -- br0 any anywhere anywhere tcp dpt:ftp autofw tcp dpt:21 to:21 0 0 autofw tcp -- br0 any anywhere anywhere tcp dpt:43123 autofw tcp dpt:43123 to:43123 Chain POSTROUTING (policy ACCEPT 694 packets, 42193 bytes) pkts bytes target prot opt in out source destination 0 0 NETMAP udp -- any any 192.168.1.0/24 anywhere udp dpt:6112 10.9.112.72/32 1539 85406 MASQUERADE all -- any vlan1 !10.9.112.72 anywhere 4 240 MASQUERADE all -- any br0 192.168.1.0/24 192.168.1.0/24 Chain OUTPUT (policy ACCEPT 694 packets, 42241 bytes) pkts bytes target prot opt in out source destination Chain VSERVER (1 references) pkts bytes target prot opt in out source destination 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:6113 to:192.168.1.2:6113 0 0 DNAT udp -- any any anywhere anywhere udp dpt:16183 to:192.168.1.23:16183 0 0 DNAT udp -- any any anywhere anywhere udp dpt:6113 to:192.168.1.2:6113 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:16183 to:192.168.1.23:16183 2 104 DNAT tcp -- any any anywhere anywhere tcp dpt:16000 to:192.168.1.2:16000 0 0 DNAT udp -- any any anywhere anywhere udp dpt:16000 to:192.168.1.2:16000 0 0 DNAT tcp -- any any anywhere anywhere tcp dpts:ftp-data:ftp to:192.168.1.2 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:6113 to:192.168.1.2:6113 0 0 DNAT udp -- any any anywhere anywhere udp dpt:6113 to:192.168.1.2:6113 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:6200 to:192.168.1.2:6200 0 0 DNAT udp -- any any anywhere anywhere udp dpt:6200 to:192.168.1.2:6200 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:6114 to:192.168.1.2:6114 0 0 DNAT udp -- any any anywhere anywhere udp dpt:6114 to:192.168.1.2:6114 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:6112 to:192.168.1.2:6112 0 0 DNAT udp -- any any anywhere anywhere udp dpt:6112 to:192.168.1.2:6112 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:bbs to:192.168.1.2:7000 0 0 DNAT udp -- any any anywhere anywhere udp dpt:7000 to:192.168.1.2:7000 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:7001 to:192.168.1.23:7001 0 0 DNAT udp -- any any anywhere anywhere udp dpt:7001 to:192.168.1.23:7001 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:16001 to:192.168.1.23:16001 0 0 DNAT udp -- any any anywhere anywhere udp dpt:16001 to:192.168.1.23:16001 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:14199 to:192.168.1.2:14199 0 0 DNAT udp -- any any anywhere anywhere udp dpt:14199 to:192.168.1.2:14199 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:7002 to:192.168.1.15:7002 0 0 DNAT udp -- any any anywhere anywhere udp dpt:7002 to:192.168.1.15:7002 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:27950 to:192.168.1.2:27950 0 0 DNAT udp -- any any anywhere anywhere udp dpt:27950 to:192.168.1.2:27950 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:27952 to:192.168.1.2:27952 0 0 DNAT udp -- any any anywhere anywhere udp dpt:27952 to:192.168.1.2:27952 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:27960 to:192.168.1.2:27960 2 88 DNAT udp -- any any anywhere anywhere udp dpt:27960 to:192.168.1.2:27960 0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:27965 to:192.168.1.2:27965 0 0 DNAT udp -- any any anywhere anywhere udp dpt:27965 to:192.168.1.2:27965 это уже с учетом твоих правил на forward. слушай,а после добавления правило,оно сразу начнет работать да? пока не работает я добавил одно твое правило для подсети. и с умели выйти на шлюз. |