我在gateway:
et.h0 : 连接internet.
eth1 : 连接lan
我因用VPN,使用防火墙(部分).: 电子
iptables -F
iptables -P INPUT A.CCEPT.
iptables -P OUTP.UT ACCEPT.
iptables -P FORWARD .DROP
i.ptables -A FORWARD -s 192.168.0.0/24 -j ACC.EPT教育
# Keep state of connections .from local machin.e and private subnets 电子
iptables -A. OUTPUT -m state --state NEW -o e.th0 -j ACCEPT
ip.table.s -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT 杀毒
ipta.bles -A FORWARD -m state -.-state NEW -o eth0 -j ACCEPT--- 印刷
iptables -A FORWARD -m state ..--state ESTABLISHED,RELATED -j ACCEPT电影
我现在想对FORWARD做限制,. 鲜花
iptables -F
iptabl.es -P INPUT ACCEPT 乙肝
iptables -P OUTPUT. ACCEPT投资
iptables .-P FORWARD DROP电脑
ip.t.ables -A FORWARD -s 192.168.0.138 -j DROP.
iptable.s -A OUTPUT. -m state --state NEW -o eth0 -j ACCEPT.
iptables -A INPUT -m state --st.ate .ESTABLISHED,RELATED -j ACCEPT 杀毒
iptables -A F.ORWARD. -m state --state NEW -o eth0 -j ACCEPT.
iptabl.es -A FORWARD -m state --state ESTABLI.SHED,RELATED -j ACCEPT 杀毒
然后在192.168.0.138(已配置好GATEWAY)上ping sina..c.om电脑
结果:requ.est time out[成人用品]
但是能够连上网,若没有装态连接.,则不能ping sina.com ,也不能上网..
iptables -F
iptable.s -P INPUT ACCEPT 健康
iptables -P OUTPU.T ACCEPT电脑
iptables -P FORWARD .DROP.
ip.tables -A FORWARD -s 192.168.0..138 -j ACCEPT.
错误在什么地方,请请高手指.点!!谢谢 杀毒