QUOTE:原帖由 Suniverse 于 2007-2-9 10:39 发表于 1楼
我利用IPTABLES配置了NAT和路由服务器
请问如何查看当前的访问信息及工作状态
比如 有多少内网IP正在通过NAT访问外网
# cat /proc/net/ip_conntrack | grep "EST" | head -n 10
tcp 6 419843 ESTABLISHED src=192.168.123.254 dst=192.168.2.92 sport=3128 dport=6523 packets=1 bytes=1458 src=192.168.2.92 dst=192.168.123.254 sport=6523 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 352771 ESTABLISHED src=192.168.123.254 dst=192.168.2.127 sport=3128 dport=1108 packets=1 bytes=1458 src=192.168.2.127 dst=192.168.123.254 sport=1108 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 431950 ESTABLISHED src=192.168.1.99 dst=220.130.132.163 sport=1059 dport=80 packets=63 bytes=23754 src=192.168.1.254 dst=192.168.1.99 sport=3128 dport=1059 packets=77 bytes=56788 [ASSURED] mark=0 use=1
tcp 6 194691 ESTABLISHED src=192.168.123.254 dst=192.168.2.1 sport=3128 dport=1049 packets=1 bytes=1458 src=192.168.2.1 dst=192.168.123.254 sport=1049 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 367054 ESTABLISHED src=192.168.123.254 dst=192.168.2.56 sport=3128 dport=1037 packets=1 bytes=1458 [UNREPLIED] src=192.168.2.56 dst=192.168.123.254 sport=1037 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 368677 ESTABLISHED src=192.168.123.254 dst=192.168.2.167 sport=3128 dport=1099 packets=1 bytes=1458 src=192.168.2.167 dst=192.168.123.254 sport=1099 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 333593 ESTABLISHED src=192.168.123.254 dst=192.168.2.167 sport=3128 dport=1040 packets=1 bytes=1458 src=192.168.2.167 dst=192.168.123.254 sport=1040 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 198161 ESTABLISHED src=192.168.123.254 dst=192.168.2.153 sport=3128 dport=1045 packets=1 bytes=1456 src=192.168.2.153 dst=192.168.123.254 sport=1045 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 197574 ESTABLISHED src=192.168.123.254 dst=192.168.2.13 sport=3128 dport=1261 packets=1 bytes=1458 src=192.168.2.13 dst=192.168.123.254 sport=1261 dport=3128 packets=0 bytes=0 mark=0 use=1
tcp 6 195242 ESTABLISHED src=192.168.123.254 dst=192.168.2.50 sport=3128 dport=1047 packets=1 bytes=1458 src=192.168.2.50 dst=192.168.123.254 sport=1047 dport=3128 packets=0 bytes=0 mark=0 use=1
复制代码
# netstat-nat -n | grep EST | head -n 10
tcp 192.168.1.100:1700 64.4.36.50:1863 ESTABLISHED
tcp 192.168.1.100:1053 69.159.190.33:55876 ESTABLISHED
tcp 192.168.1.100:1045 84.13.226.136:37859 ESTABLISHED
tcp 192.168.1.100:1077 207.46.109.78:1863 ESTABLISHED
tcp 192.168.1.100:2517 220.130.132.195:443 ESTABLISHED
tcp 192.168.1.172:1741 220.130.132.195:443 ESTABLISHED
tcp 192.168.1.99:1058 192.168.1.254:80 ESTABLISHED
tcp 192.168.1.99:1059 192.168.1.254:80 ESTABLISHED
tcp 192.168.1.99:1057 192.168.1.254:80 ESTABLISHED
tcp 192.168.1.99:1060 192.168.1.254:80 ESTABLISHED
复制代码
--