可以NAT内网上网的防火墙配置

# Generated by iptables-save v1.4.7 on Fri Jul 29 05:35:17 2016
*filter
:INPUT ACCEPT [2598:255716]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2047:454521]
-A INPUT -p tcp -m tcp --dport 8022 -j ACCEPT 
-A INPUT -i natbr1 -p udp -m udp --dport 53 -j ACCEPT 
-A INPUT -i natbr1 -p tcp -m tcp --dport 53 -j ACCEPT 
-A INPUT -i natbr1 -p udp -m udp --dport 67 -j ACCEPT 
-A INPUT -i natbr1 -p tcp -m tcp --dport 67 -j ACCEPT 
-A FORWARD -d 192.168.1.0/24 -o natbr1 -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A FORWARD -s 192.168.1.0/24 -i natbr1 -j ACCEPT 
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT 
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable 
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable 
COMMIT
# Completed on Fri Jul 29 05:35:17 2016
# Generated by iptables-save v1.4.7 on Fri Jul 29 05:35:17 2016
*mangle
:PREROUTING ACCEPT [2605:256080]
:INPUT ACCEPT [2601:255876]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2047:454521]
:POSTROUTING ACCEPT [2047:454521]
-A POSTROUTING -o natbr1 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill 
COMMIT
# Completed on Fri Jul 29 05:35:17 2016
# Generated by iptables-save v1.4.7 on Fri Jul 29 05:35:17 2016
*nat
:PREROUTING ACCEPT [43:2947]
:POSTROUTING ACCEPT [16:1104]
:OUTPUT ACCEPT [16:1104]
-A POSTROUTING -s 192.168.1.0/24 ! -d 192.168.1.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535 
-A POSTROUTING -s 192.168.1.0/24 ! -d 192.168.1.0/24 -p udp -j MASQUERADE --to-ports 1024-65535 
-A POSTROUTING -s 192.168.1.0/24 ! -d 192.168.1.0/24 -j MASQUERADE 
COMMIT
# Completed on Fri Jul 29 05:35:17 2016
赞 (0)

评论 0

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址