|
以下是我的规则:- # Generated by iptables-save v1.4.8 on Sun Sep 5 18:33:23 2010
- *nat
- :PREROUTING ACCEPT [887:89462]
- :POSTROUTING ACCEPT [315:19125]
- :OUTPUT ACCEPT [315:19125]
- -A POSTROUTING -s 192.168.111.0/24 -j MASQUERADE
- COMMIT
- # Completed on Sun Sep 5 18:33:23 2010
- # Generated by iptables-save v1.4.8 on Sun Sep 5 18:33:23 2010
- *filter
- :INPUT DROP [42:4833]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [12318:15817364]
- -A INPUT -p gre -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 20 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p udp -m udp --sport 53 -j ACCEPT
- -A INPUT -p tcp -m tcp --sport 80 -j ACCEPT
- -A INPUT -p udp -m udp --sport 123 -j ACCEPT
- -A INPUT -p tcp -m tcp --sport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp --sport 110 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
- -A FORWARD -s 192.168.111.0/24 -j ACCEPT
- COMMIT
- # Completed on Sun Sep 5 18:33:23 2010
复制代码
这样客户端PPTP上去以后无法上外网,但是把FORWARD规则改成 ACCEPT 就可以上。说明肯定是FORWARD写得有问题。但是我把FORWARD规则改成
- -A FORWARD -p udp -s 192.168.111.0/24 -j ACCEPT
- -A FORWARD -p tcp -s 192.168.111.0/24 -j ACCEPT
- -A FORWARD -p gre -s 192.168.111.0/24 -j ACCEPT
复制代码
还是通不过,请各位帮忙分析一下,应该怎么写FORWARD才可以让VPN可以上外网 |
|