|
|

楼主 |
发表于 2005-8-23 17:37:02
|
显示全部楼层
搞定,137,138是udp,139tcp
现在的iptables规则:
]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
RH-Firewall-1-INPUT all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
RH-Firewall-1-INPUT all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain RH-Firewall-1-INPUT (2 references)
target prot opt source destination
LOG all -- Luo anywhere LOG level warning prefix `packets'
ACCEPT all -- anywhere anywhere
ACCEPT icmp -- anywhere anywhere icmp any
ACCEPT ipv6-crypt-- anywhere anywhere
ACCEPT ipv6-auth-- anywhere anywhere
ACCEPT udp -- anywhere ns-px.online.sh.cn udp dpt:domain
ACCEPT udp -- anywhere ns-pd.online.sh.cn udp dpt:domain
ACCEPT udp -- anywhere 224.0.0.251 udp dpt:5353
ACCEPT udp -- anywhere anywhere udp dpt:ipp
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:microsoft-ds
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:netbios-ssn
ACCEPT udp -- anywhere anywhere state NEW multiport dports netbios-ns,netbios-dgm
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:http
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:https
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ssh
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:mysql
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:cvspserver
ACCEPT tcp -- anywhere anywhere state NEW tcp dpts:6881:6889
ACCEPT tcp -- anywhere anywhere state NEW tcp dpts:2101:2121
ACCEPT udp -- anywhere anywhere state NEW udp dpt:14672
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:14662
REJECT all -- anywhere anywhere reject-with icmp-host-prohibited
但理论上还有个疑问:既然客户机53端口连的目的ip是dns服务器,不是网关服务器,网关只是转发,为什么会被防火墙拦截? |
|