|
发表于 2003-4-25 11:48:23
|
显示全部楼层
echo "1" > /proc/sys/net/ipv4/ip_forward
/sbin/modprobe ip_tables
/sbin/modprobe iptable_filter
/sbin/modprobe iptable_nat
/sbin/modprobe ip_conntrack
/sbin/modprobe ip_conntrack_ftp
/sbin/modprobe ip_nat_ftp
/sbin/iptables -F INPUT
/sbin/iptables -F FORWARD
/sbin/iptables -F POSTROUTING -t nat
/sbin/iptables -t nat -F
/sbin/iptables -P FORWARD DROP
/sbin/iptables -t nat -A POSTROUTING -o eth0 -s 192.168.7.0/255.255.255.240 -j MASQUERADE
/sbin/iptables -A FORWARD -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A FORWARD -s 192.168.7.0/255.255.255.240 -d 0/0 -j ACCEPT
/sbin/iptables -t nat -A PREROUTING -i eth1 -p tcp -s 192.168.7.0/255.255.255.240 -d 0/0 --dport 80 -j DNAT --to 192.168.7.1:80
/sbin/iptables -t nat -I PREROUTING -p tcp -d x.x.x.x --dport 80 -j DNAT --to 192.168.7.2:80
/sbin/iptables -t nat -I POSTROUTING -p tcp -s 192.168.7.0/24 -d 192.168.7.2 --dport 80 -j SNAT --to x.x.x.x
/sbin/iptables -t nat -A PREROUTING -i eth0 -d x.x.x.x -p tcp --dport 80 -j DNAT --to 192.168.7.2
/sbin/iptables -A FORWARD -i eth0 -d 192.168.7.2 -p tcp --dport 80 -j ACCEPT
/sbin/iptables -A FORWARD -s 192.168.7.2 -o eth0 -p tcp --sport 80 -m state --state ESTABLISHED,RELATED -j ACCEPT |
|