我现在用的rc.local 文件如下,自行更改些IP地址就可以了。
我的
eth0是 10.10.151.63 (城域网的IP,ADSL的不设)
eth1是 192.168.0.254
但你先要用 Setup 把 ipchains 去掉,把iptables选上才行。
QUOTE:#!/bin/sh
#
# This script will be executed *after* all the other init scripts.
# You can put your own initialization stuff in here if you don't
# want to do the full Sys V style init stuff.
touch /var/lock/subsys/local
echo 1 >; /proc/sys/net/ipv4/tcp_syncookies #防syn攻击
echo 1 >; /proc/sys/net/ipv4/icmp_echo_ignore_all #防Ping
echo 1 >; /proc/sys/net/ipv4/ip_forward #打开IP转发
modprobe ip_tables
iptables -F INPUT
iptables -F FORWARD
iptables -F POSTROUTING -t nat
iptables -t nat -F
iptables -P FORWARD DROP
iptables -A FORWARD -s 192.168.0.0/24 -j ACCEPT
iptables -A FORWARD -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -s 192.168.0.0/24 -j MASQUERADE