|
发表于 2003-6-26 15:57:06
|
显示全部楼层
/sbin/modprobe ip_tables
/sbin/modprobe ip_conntrack
/sbin/modprobe ip_conntrack_ftp
echo 1>/proc/sys/net/ipv4/ip_forward
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
iptables -F
iptables -A INPUT -i eth0 -p tcp --dport 0:1023 -j DROP
iptables -A INPUT -i eth0 -p udp --dport 0:1023 -j DROP
iptables -A FORWARD -i eth1 -j ACCEFP
iptables -A FORWARD -i eth0 -m --state RELATED,ESTABLISHED -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -s "IP地址段" -j MASQUERADE |
|