【发布时间】:2013-11-16 23:27:46
【问题描述】:
我正在像这样设置 udp 端口转发:
for i in `seq 0 9`
do
sudo iptables -A PREROUTING -t nat -i eth0 -p udp --dport 600${i} -j DNAT --to 192.168.7.1${i}
sudo iptables -A FORWARD -p udp -d 192.168.7.1${i} --dport 600${i} -j ACCEPT
done
虽然我不记得了,但我很确定我对 tcp 端口转发做了同样的事情,但是当我运行 iptables -L 时,我得到以下信息:
$ sudo iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere 192.168.0.109 tcp dpt:6009
ACCEPT tcp -- anywhere 192.168.0.108 tcp dpt:6008
ACCEPT tcp -- anywhere 192.168.0.107 tcp dpt:x11-7
ACCEPT tcp -- anywhere 192.168.0.106 tcp dpt:x11-6
ACCEPT tcp -- anywhere 192.168.0.105 tcp dpt:x11-5
ACCEPT tcp -- anywhere 192.168.0.104 tcp dpt:x11-4
ACCEPT tcp -- anywhere 192.168.0.103 tcp dpt:x11-3
ACCEPT tcp -- anywhere 192.168.0.102 tcp dpt:x11-2
ACCEPT tcp -- anywhere 192.168.0.101 tcp dpt:x11-1
ACCEPT tcp -- anywhere 192.168.0.100 tcp dpt:x11
ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level warning
ACCEPT udp -- anywhere main udp dpt:x11
ACCEPT udp -- anywhere desktop1 udp dpt:x11-1
ACCEPT udp -- anywhere desktop2 udp dpt:x11-2
ACCEPT udp -- anywhere desktop3 udp dpt:x11-3
ACCEPT udp -- anywhere desktop4 udp dpt:x11-4
ACCEPT udp -- anywhere desktop5 udp dpt:x11-5
ACCEPT udp -- anywhere desktop6 udp dpt:x11-6
ACCEPT udp -- anywhere 192.168.7.17 udp dpt:x11-7
ACCEPT udp -- anywhere 192.168.7.18 udp dpt:6008
ACCEPT udp -- anywhere 192.168.7.19 udp dpt:6009
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
为什么是X11?如何删除此(清除规则?)并将其设置回 600_
【问题讨论】:
-
不是x系统吧?我是一个 linux 菜鸟,但这就是我想到的。
-
@MikeCheel,是的,但为什么呢?
标签: router iptables portforwarding