|
以下是我的网关上的iptables配置文件,大家帮忙分析一下.多谢了!
- *filter
- :FORWARD ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- # Allow ssh port 22
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- # Accept Inside network webmin management
- -A INPUT -p tcp -m tcp -s 192.168.88.0/24 --dport 10000 -j ACCEPT
- # Accept MRTG web IMG
- -A INPUT -p tcp -m tcp -s 192.168.0.0/16 --dport 80 -j ACCEPT
- # accept tcp port 5900
- -A INPUT -p tcp -m tcp -i ppp0 --dport 5900 -j ACCEPT
- # Accept 192.168.88.52 Admin
- -A INPUT -s 192.168.88.52/32 -i eth1 -j ACCEPT
- # accept tcp port 5800
- -A INPUT -p tcp -m tcp -i ppp0 --dport 5800 -j ACCEPT
- # localhost
- -A INPUT -i lo -j ACCEPT
- # drop 135,145,445
- -A FORWARD -p tcp -m tcp -m multiport -d 192.168.100.0/24 -j DROP --dports 135,139,445
- -A FORWARD -p tcp -m tcp -d 192.168.88.253/32 -j ACCEPT
- # allow server file share
- -A FORWARD -s 192.168.88.188 -j ACCEPT
- -A FORWARD -s 192.168.88.198 -j ACCEPT
- -A FORWARD -s 192.168.88.199 -j ACCEPT
- -A FORWARD -s 192.168.88.52 -j ACCEPT
- -A FORWARD -s 192.168.1.20 -j ACCEPT
- -A FORWARD -s 192.168.10.20 -j ACCEPT
- -A FORWARD -s 192.168.88.253 -j ACCEPT
- -A FORWARD -s 192.168.1.50 -j ACCEPT
- -A FORWARD -s 192.168.88.30 -j ACCEPT
- #drop other microsoft file-share
- -A FORWARD -p tcp -m tcp -m multiport -d 192.168.88.0/24 -j DROP --dports 135,136,137,138,139,445
- -A FORWARD -p udp -m udp -m multiport -d 192.168.1.0/24 -j DROP --dports 135,136,137,138,139,445
- -A FORWARD -p tcp -m tcp -m multiport -d 192.168.1.0/24 -j DROP --dports 135,136,137,138,139,445,5190
- -A FORWARD -p tcp -m tcp -m multiport -d 192.168.10.0/24 -j DROP --dports 135,136,137,138,139,445
- # Drop any
- -A INPUT -j DROP
- # allow localhost access any
- -A OUTPUT -o lo -j ACCEPT
- COMMIT
- # Generated by webmin
- *mangle
- :FORWARD ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :PREROUTING ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- COMMIT
- # Completed
- # Generated by webmin
- *nat
- :PREROUTING ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- # Nat for inside Network
- -A POSTROUTING -o ppp0 -j MASQUERADE
- # 5900 to 88.52
- -A PREROUTING -p tcp -m tcp -i ppp0 --dport 5900 -j DNAT --to-destination 192.168.88.52:5900
- # 5800 to 88.52
- -A PREROUTING -p tcp -m tcp -i ppp0 --dport 5800 -j DNAT --to-destination 192.168.88.52:5800
- COMMIT
- # Completed
复制代码
现在我的问题是,snmp不能搜集网络信息,所以我的MRTG不能正常绘制图形.
此服务器不能访问互联网,包括内部网段的任何一个电脑(除了192.168.88.52).
需要添加什么规则才能满足我的需要? |
|