|
|
使用以下设定后ping 200.200.199.x的机器能通ssh连不上
echo 7 > /proc/sys/net/ipv4/tcp_retries2
echo 30 > /proc/sys/net/ipv4/tcp_fin_timeout
echo 1 > /proc/sys/net/ipv4/ip_forward
echo 1 >/proc/sys/net/ipv4/conf/eth1/proxy_arp
echo 1 >/proc/sys/net/ipv4/conf/eth0/proxy_arp
[root@localhost ~]# iptables -F INPUT
[root@localhost ~]# iptables -F FORWARD
[root@localhost ~]# iptables -P FORWARD DROP
[root@localhost ~]# iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
[root@localhost ~]# iptables -A FORWARD -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
[root@localhost ~]# iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to-source 200.200.199.0
[root@localhost ~]# iptables -A INPUT -i eth0 -j ACCEPT |
|