|
|
#!/bin/bash
# load module
modprobe ip_tables
modprobe ip_nat-ftp
# star firewall service with deny all Iptables
iptables -F
iptables -F -t nat
iptables -X
iptables -X -t nat
iptables -P INPUT DROP
iptables -P FORWARD ACCEPT
iptables -P OUTPUT DROP
iptables -A INPUT -i eth1 -j ACCEPT
iptables -A OUTPUT eth0 -j ACCEPT
#CS IP nat
iptables -t nat -A PREROUTING -i eth0 -d a.b.c.d --dsport 27015 -j dnat --to 192.168.1.251:27015
iptables -t nat -A POSTROUTING -o eth0 -s 192.168.1.251 --sport 27015 -j snat --to a.b.c.d:27015
iptables -t nat -A POSTROUTING -s 192.168.0.0/23 -o eth0 -j MASQUERADE
请各位指点。 |
|