# Generated by iptables-save v1.3.3 on Sat Sep 29 07:12:58 2007
*mangle
:PREROUTING ACCEPT [164300:204355389]
:INPUT ACCEPT [158661:202592615]
:FORWARD ACCEPT [1241:139218]
:OUTPUT ACCEPT [102518:46058112]
:POSTROUTING ACCEPT [103759:46197330]
-A PREROUTING -i eth0 -j TTL --ttl-set 64
COMMIT
# Completed on Sat Sep 29 07:12:58 2007
# Generated by iptables-save v1.3.3 on Sat Sep 29 07:12:58 2007
*nat
:PREROUTING ACCEPT [3361744:1054222090]
:POSTROUTING ACCEPT [30948:1867529]
:OUTPUT ACCEPT [37763:2278062]
-A POSTROUTING -o ppp+ -j MASQUERADE
COMMIT
# Completed on Sat Sep 29 07:12:58 2007
# Generated by iptables-save v1.3.3 on Sat Sep 29 07:12:58 2007
*filter
:INPUT DROP [273456:40935723]
:FORWARD ACCEPT [1294:146268]
:OUTPUT ACCEPT [4125688:1492812943]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.0.0 -i eth+ -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:1536 -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Sat Sep 29 07:12:58 2007
以上是本人的iptables设置,本想共享上网,不过现在出了点小问题
客户机都可以ping到互联网的服务器,如baidu, google, 163...都ping得到, 但就是上不了网
希望大家帮帮忙看看问题在那里
[问题]关于iptables 共享上网的问题
-
- 帖子: 333
- 注册时间: 2007-05-13 15:20
- xiehuipiaofeng
- 帖子: 85
- 注册时间: 2007-07-31 23:04
因为你没有说明你网络环境,我不知道你有几块网卡,所以不敢随便改动你的代码。现在只能是尝试解决了。
你在/etc/rc.local中添加一条:
echo 1 >/proc/sys/net/ipv4/ip_forward
然后代码可以尝试改一下:
-A INPUT -i lo -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
#-A INPUT -s 192.168.0.0/255.255.0.0 -i eth+ -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED
#-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:1536 -j TCPMSS --clamp-mss-to-pmtu
eth0为其他机器能访问的局域网内的那个网卡。
你可以先试一下。
你在/etc/rc.local中添加一条:
echo 1 >/proc/sys/net/ipv4/ip_forward
然后代码可以尝试改一下:
-A INPUT -i lo -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
#-A INPUT -s 192.168.0.0/255.255.0.0 -i eth+ -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED
#-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:1536 -j TCPMSS --clamp-mss-to-pmtu
eth0为其他机器能访问的局域网内的那个网卡。
你可以先试一下。
- qianwx
- 帖子: 730
- 注册时间: 2006-07-08 14:41