|
发表于 2012-2-13 16:27:28
|
显示全部楼层
我把你给我的命令写了,还是不好用,这是我用iptables -S命令的结果
) k E7 A F% q) ~root@OpenWrt:/etc# iptables -S
( l: H4 i: P2 Q0 t-P INPUT ACCEPT
0 Y% ]3 a( I* \9 W$ |5 l4 S-P FORWARD DROP7 y6 Y: w }) i& A" i' j8 F
-P OUTPUT ACCEPT0 K7 l h& y+ A- c" B
-N forward f4 _1 Z& w6 s: _
-N forwarding_lan
$ K2 _: w' l& \4 j8 `# Z' A+ o-N forwarding_rule
' C' u3 \4 @9 ^2 z3 \, ~. I7 S-N forwarding_wan3 x! S. s7 P2 B: U9 _* ]) G
-N input
: c. ]+ I8 F6 X X8 a-N input_lan
, d1 E* b R# w* N% S2 U3 p2 [-N input_rule
5 V& _1 d# @2 Y: `9 R4 s-N input_wan% E4 X; p1 ?9 U S& ?: a6 ?3 s$ M
-N output
# w* a9 ?/ v7 c* u-N output_rule
' x) i( _: ^7 R-N reject; y! |1 F- m& x# X
-N syn_flood" D( P, B: J) a8 N: d4 o5 s- H7 W, q! i
-N zone_lan0 |9 h! k# X' a* ?
-N zone_lan_ACCEPT
7 A" x- P" [ W/ x- _-N zone_lan_DROP0 h% T& T# j) c1 ?& E
-N zone_lan_MSSFIX ?/ }' g5 F2 b5 {
-N zone_lan_REJECT7 F2 @- G! ]; k
-N zone_lan_forward. c3 U3 x5 O2 g+ E& o) B; d) E4 R3 C
-N zone_wan* W: [7 T. t9 S3 W/ r
-N zone_wan_ACCEPT
# ]! z' ~; I6 Q# H2 X# q-N zone_wan_DROP$ ]2 o7 N, Y/ O& S, [. X0 O
-N zone_wan_MSSFIX
3 P' T# _" z2 ?/ `$ ~% w1 Z% f-N zone_wan_REJECT, ~* \$ \ {) E- L3 g- v
-N zone_wan_forward$ }1 k9 K& W, ?9 U! T. P
-A INPUT -p tcp -m tcp --dport 3389 -j ACCEPT 0 p/ q# z/ U( l1 N3 Z
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 5 ~3 Q8 K* r% P+ y j) \
-A INPUT -i lo -j ACCEPT + a6 u; g; f! L, R6 S
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn_flood
7 |$ `0 f8 O+ D$ c7 M8 j-A INPUT -j input_rule 4 q9 w$ S( U/ R
-A INPUT -j input $ e6 I& t' x- B5 x8 c( n# i9 r
-A FORWARD -j zone_wan_MSSFIX $ ^( y4 H! ]( A9 E) A7 N! }( J
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT ! D! W/ ?" _& Y/ r- |! \
-A FORWARD -j forwarding_rule
; M) Q5 H" d o8 m, B' T# a4 `/ G-A FORWARD -j forward : h4 n- D1 s# J9 K- ]# j
-A FORWARD -j reject
8 l& V9 V8 X+ J6 N1 m4 E+ h-A FORWARD -d 192.168.1.90/32 -p tcp -m tcp --dport 3389 -j ACCEPT
8 j% H$ x$ F9 N5 p; W-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
' d5 B- ?3 ^1 u% R+ z6 L-A OUTPUT -o lo -j ACCEPT 8 t8 s4 y9 L! k9 |
-A OUTPUT -j output_rule
K% i1 ^* K8 ^$ e5 `& }-A OUTPUT -j output
% j7 }7 H- B' L5 y' r, Y$ z-A forward -i br-lan -j zone_lan_forward
, r+ w7 a% o- K/ o9 Y8 G-A forward -i pppoe-wan -j zone_wan_forward & l9 K$ U: i2 W# Q' m2 y, l, n
-A forwarding_rule -i tun0 -o br-lan -j ACCEPT
- N5 m+ b7 m5 c( Q* t) p-A forwarding_rule -i br-lan -o tun0 -j ACCEPT ( Q# ?1 x7 A& i }
-A input -i br-lan -j zone_lan : [& l6 ?0 y/ g6 P- l1 a5 `
-A input -i pppoe-wan -j zone_wan
5 ?1 G7 x) }6 S-A output -j zone_lan_ACCEPT
- x$ [2 ?7 e n5 }4 {-A output -j zone_wan_ACCEPT - o8 R* k) t/ s% k0 Y( W' _
-A reject -p tcp -j REJECT --reject-with tcp-reset
- D4 {8 k2 b, U [( ?1 p7 k-A reject -j REJECT --reject-with icmp-port-unreachable
8 _4 i4 B8 K+ k! @8 C$ }-A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -j RETURN 8 T% j5 b; Y# e) V0 y) L& l" F" k8 N
-A syn_flood -j DROP
. u' a% P/ }" T' L; j. A' s-A zone_lan -j input_lan # p0 n: P+ L. ]* g- U: L& g7 T+ D- L, x
-A zone_lan -j zone_lan_ACCEPT # O2 f. s& F) v* J# z2 N8 ] m
-A zone_lan_ACCEPT -i br-lan -j ACCEPT
2 W d' o R( C! U% R-A zone_lan_ACCEPT -o br-lan -j ACCEPT 9 o2 U: h( E( z8 T( v6 c* B1 X4 H- r2 o
-A zone_lan_DROP -i br-lan -j DROP ) E& D# c9 \% o: [
-A zone_lan_DROP -o br-lan -j DROP
( h5 t/ Z+ J) p9 ?( x3 C-A zone_lan_MSSFIX -o br-lan -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
$ }( k) b6 k% u2 Q-A zone_lan_REJECT -i br-lan -j reject
+ a' \9 v) f% x* O: x-A zone_lan_REJECT -o br-lan -j reject # E/ S+ U1 K) L
-A zone_lan_forward -j zone_wan_ACCEPT
. o! m' E! f1 r% ^: e( u( p9 L-A zone_lan_forward -j forwarding_lan
' {0 k9 U$ l3 B-A zone_lan_forward -j zone_lan_REJECT $ N: O5 i0 b( J/ R, i$ U# e
-A zone_wan -p udp -m udp --dport 68 -j ACCEPT
( e1 i/ Y. r1 v5 }- d, w- T-A zone_wan -p tcp -m tcp --dport 2601 -j ACCEPT
) b; h% t! Y$ E$ y4 ]# F; ^-A zone_wan -p tcp -m tcp --dport 800 -j ACCEPT 2 \0 q' S8 m. i; S0 V4 W
-A zone_wan -p udp -m udp --dport 3389 -j ACCEPT
3 |. n+ b1 [ N! Q9 s' z-A zone_wan -p tcp -m tcp --dport 3389 -j ACCEPT
. j9 n: \2 c# i9 }- c5 B' X5 H-A zone_wan -j input_wan
- v* C \& S5 p, G3 k-A zone_wan -j zone_wan_ACCEPT i/ n, x) z/ a1 o) |
-A zone_wan_ACCEPT -i pppoe-wan -j ACCEPT - r) I9 U* b/ `$ b+ B$ e5 q+ f
-A zone_wan_ACCEPT -o pppoe-wan -j ACCEPT
% }1 Y7 x8 c6 J S-A zone_wan_DROP -i pppoe-wan -j DROP ' M( K+ Z8 y: O4 u
-A zone_wan_DROP -o pppoe-wan -j DROP ; R% j7 X0 z/ t& B% B
-A zone_wan_MSSFIX -o pppoe-wan -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
3 `9 y+ Z' }$ f- ~3 @; W-A zone_wan_REJECT -i pppoe-wan -j reject ( Y5 R# |1 h/ K- Q7 Z6 e' n) t4 |
-A zone_wan_REJECT -o pppoe-wan -j reject
" E' s) F" u1 @% g% Q& }: j" j-A zone_wan_forward -j forwarding_wan ( i; M( Y j( Y# z. _1 f- G+ k! d
-A zone_wan_forward -j zone_wan_REJECT 6 d) ?1 m$ M2 ^5 v0 ^
这样3389我还是从外网连接不上 |
|