|
目前,我已经实现局域网内主机通过NAT映射上网(访问IE,QQ,QQ游戏,边锋游戏都可以使用),
接下来是:
封局域网内网络游戏,如:
QQ游戏(QQ聊天、传文件不能封);
边锋游戏等一切网络游戏,
不知怎么做?
请大侠指导一下,谢谢!
环境:
1、eth0(连入总公司,外网)
IP=192.168.10.22
2、eth1(本公司局域网)
IP=192.168.0.1
3、操作系统RHEL5.2
目前NAT主机iptables配置如下:(即:/etc/sysconfig/iptables中配置)
# Generated by iptables-save v1.3.5 on Sat May 16 10:18:16 2009
*filter
:INPUT DROP [101:14382]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [51:7309]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p udp -m udp --dport 137 -j ACCEPT
-A INPUT -p udp -m udp --dport 138 -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 8000 -j ACCEPT
-A FORWARD -p udp -m udp --dport 8000 -j ACCEPT
-A FORWARD -p udp -m udp --dport 4000 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -j ACCEPT
COMMIT
# Completed on Sat May 16 10:18:16 2009
# Generated by iptables-save v1.3.5 on Sat May 16 10:18:16 2009
*nat
REROUTING ACCEPT [997:61455]
OSTROUTING ACCEPT [29:3949]
:OUTPUT ACCEPT [29:3949]
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth0 -j MASQUERADE
COMMIT
# Completed on Sat May 16 10:18:16 2009 |
|