|
发表于 2010-3-12 21:50:49
|
显示全部楼层
重新编译了两次内核,终于可以正常启用iptables ,
但还是不能上youtube.com
从下面可以看出,已经正常启用了iptables。- gentoo-pjq examples # iptables -L
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- ZHANG tcp -- anywhere anywhere tcp spt:http flags:FIN,SYN,RST,ACK/SYN,ACK state ESTABLISHED match-set NOCLIP src
- LOG tcp -- anywhere anywhere tcp spt:http state ESTABLISHED gfw LOG level info prefix `gfw: '
- DROP udp -- anywhere anywhere udp spt:domain state ESTABLISHED gfw
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- gentoo-pjq examples #
复制代码
从/var/log/message中可以看到相关log,我试过刷youtube.com和facebook.com的时候,就会刷新log.
- ar 12 21:54:01 localhost kernel: [ 870.407387] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.146.25 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=1844 DF PROTO=TCP SPT=80 DPT=40578 WINDOW=771 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:05 localhost kernel: [ 873.641274] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.146.25 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=65 ID=60778 DF PROTO=TCP SPT=80 DPT=40579 WINDOW=25 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:05 localhost kernel: [ 873.643237] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.146.25 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=65 ID=60778 DF PROTO=TCP SPT=80 DPT=40579 WINDOW=25 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:05 localhost kernel: [ 873.643372] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.146.25 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=65 ID=60778 DF PROTO=TCP SPT=80 DPT=40579 WINDOW=25 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:05 localhost kernel: [ 873.643534] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.146.25 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=40579 WINDOW=25735 RES=0x00 RST URGP=0
- Mar 12 21:54:06 localhost kernel: [ 874.981351] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=55880 WINDOW=22225 RES=0x00 RST URGP=0
- Mar 12 21:54:06 localhost kernel: [ 874.981481] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=45 ID=47190 DF PROTO=TCP SPT=80 DPT=55880 WINDOW=197 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:06 localhost kernel: [ 874.983318] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=45 ID=47190 DF PROTO=TCP SPT=80 DPT=55880 WINDOW=197 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:06 localhost kernel: [ 874.983455] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=45 ID=47190 DF PROTO=TCP SPT=80 DPT=55880 WINDOW=197 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:07 localhost kernel: [ 876.139776] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=55881 WINDOW=18868 RES=0x00 RST URGP=0
- Mar 12 21:54:07 localhost kernel: [ 876.140049] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=68 ID=25149 DF PROTO=TCP SPT=80 DPT=55881 WINDOW=476 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:07 localhost kernel: [ 876.140272] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=68 ID=25149 DF PROTO=TCP SPT=80 DPT=55881 WINDOW=476 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:07 localhost kernel: [ 876.140436] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=68 ID=25149 DF PROTO=TCP SPT=80 DPT=55881 WINDOW=476 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:15 localhost kernel: [ 883.825748] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=15353 DF PROTO=TCP SPT=80 DPT=55882 WINDOW=600 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:15 localhost kernel: [ 883.825881] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=15353 DF PROTO=TCP SPT=80 DPT=55882 WINDOW=600 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:15 localhost kernel: [ 883.826045] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=64 ID=15353 DF PROTO=TCP SPT=80 DPT=55882 WINDOW=600 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:15 localhost kernel: [ 883.827646] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=66.220.145.13 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=55882 WINDOW=10435 RES=0x00 RST URGP=0
- Mar 12 21:54:17 localhost kernel: [ 885.719980] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48143 WINDOW=31252 RES=0x00 RST URGP=0
- Mar 12 21:54:17 localhost kernel: [ 885.721914] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=47 ID=26808 DF PROTO=TCP SPT=80 DPT=48143 WINDOW=455 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:17 localhost kernel: [ 885.727769] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=49 ID=26650 DF PROTO=TCP SPT=80 DPT=48143 WINDOW=457 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:17 localhost kernel: [ 885.729722] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48143 WINDOW=16627 RES=0x00 RST URGP=0
- Mar 12 21:54:18 localhost kernel: [ 886.907824] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48144 WINDOW=11326 RES=0x00 RST URGP=0
- Mar 12 21:54:18 localhost kernel: [ 886.909774] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=67 ID=65484 DF PROTO=TCP SPT=80 DPT=48144 WINDOW=795 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:18 localhost kernel: [ 886.913793] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48144 WINDOW=17455 RES=0x00 RST URGP=0
- Mar 12 21:54:18 localhost kernel: [ 886.915776] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=41 ID=62674 DF PROTO=TCP SPT=80 DPT=48144 WINDOW=1 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:19 localhost kernel: [ 887.799886] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48145 WINDOW=1660 RES=0x00 RST URGP=0
- Mar 12 21:54:19 localhost kernel: [ 887.800573] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=90 ID=13299 DF PROTO=TCP SPT=80 DPT=48145 WINDOW=626 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:19 localhost kernel: [ 887.809859] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=92 ID=13141 DF PROTO=TCP SPT=80 DPT=48145 WINDOW=628 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:19 localhost kernel: [ 887.810030] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=72.14.203.138 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=56 ID=64 PROTO=TCP SPT=80 DPT=48145 WINDOW=13333 RES=0x00 RST URGP=0
- Mar 12 21:54:20 localhost kernel: [ 889.305938] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=31342 RES=0x00 RST URGP=0
- Mar 12 21:54:20 localhost kernel: [ 889.357987] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=93 ID=2950 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=757 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:20 localhost kernel: [ 889.358123] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=93 ID=2950 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=757 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:20 localhost kernel: [ 889.361074] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=93 ID=2950 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=757 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.579920] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=23836 RES=0x00 RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.633952] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=98 ID=2555 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=762 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.658574] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=16780 RES=0x00 RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.660272] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=3298 RES=0x00 RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.660429] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=10426 RES=0x00 RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.660592] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=64 PROTO=TCP SPT=80 DPT=39338 WINDOW=25771 RES=0x00 RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.705985] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=100 ID=2397 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=764 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.706136] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=102 ID=2239 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=766 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.706299] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=40 ID=2081 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=768 RES=0x00 ACK RST URGP=0
- Mar 12 21:54:21 localhost kernel: [ 889.707904] gfw: IN=eth0 OUT= MAC=00:e0:4d:1b:76:9c:00:1b:11:a6:7f:bc:08:00 SRC=69.63.181.15 DST=192.168.0.160 LEN=40 TOS=0x00 PREC=0x00 TTL=42 ID=1923 DF PROTO=TCP SPT=80 DPT=39338 WINDOW=770 RES=0x00 ACK RST URGP=0
复制代码 |
|