谢谢楼上!可是我把规则加进去,还是ping不通呢?
###-----------------------------------------------------###
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
###-----------------------------------------------------###
# Open lo
###-----------------------------------------------------###
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
###-----------------------------------------------------###
# Open localhost
###-----------------------------------------------------###
iptables -A INPUT -i $LAN_IFACE -j ACCEPT
iptables -A OUTPUT -o $LAN_IFACE -j ACCEPT
iptables -A FORWARD -i $LAN_IFACE -j ACCEPT
iptables -A FORWARD -o $LAN_IFACE -j ACCEPT
###-----------------------------------------------------###
# Open Related package
###-----------------------------------------------------###
iptables -A INPUT -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
###-----------------------------------------------------###
# Masquerade
###-----------------------------------------------------###
iptables -t nat -A POSTROUTING -o $INNET_IFACE -s $LAN_RANGE -j SNAT --to-source 10.0.0.2
###-----------------------------------------------------###
# PROXY
###-----------------------------------------------------###
iptables -t nat -A PREROUTING -i $LAN_IFACE -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
###-----------------------------------------------------###
# Open Ping
###-----------------------------------------------------###
iptables -A OUTPUT -o eth0 -p icmp -s $FW_IP --icmp-type 8 -d any/0 -j ACCEPT
iptables -A INPUT -i eth0 -p icmp -s any/0 --icmp-type 0 -d $FW_IP -j ACCEPT
复制代码