|
这个是我的IPTABLES文件
*filter
:INPUT ACCEPT [2577:213316]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [72:9034]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A FORWARD -i eth1 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -s 172.16.0.0/16 -j ACCEPT
要上网的电脑是172.16.0.2.默认策略是DROP,就不能上网,默认策略是ACCEPT才能上网。但是我在FORWARD里定义了-A FORWARD -s 172.16.0.0/16 -j ACCEPT ,172.16.0.2是属于172.16.0.0/16里的啊 |
|