ifconfig -a的结果(外网地址以XXXX代替,外网广播地址以XXX255代替):
eth0 Link encap:Ethernet HWaddr 00:10:5A:5EB:1E

inet addr:192.168.1.254 Bcast:192.168.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:359424 errors:0 dropped:0 overruns:0 frame:0
TX packets:291329 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:348952094 (332.7 Mb) TX bytes:84176244 (80.2 Mb)
Interrupt:5 Base address:0xe400
eth1 Link encap:Ethernet HWaddr 00:01:02:97:9DF

inet addr:192.168.2.254 Bcast:192.168.2.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1788739 errors:0 dropped:0 overruns:0 frame:0
TX packets:1614261 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:394482732 (376.2 Mb) TX bytes:1366247939 (1302.9 Mb)
Interrupt:5 Base address:0xe800
eth1:0 Link encap:Ethernet HWaddr 00:01:02:97:9DF

inet addr:10.162.16.126 Bcast:10.162.16.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882654 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027802 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260231 (1339.2 Mb) TX bytes:684999823 (653.2 Mb)
Interrupt:5 Base address:0xe800
eth2 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882654 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027802 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260231 (1339.2 Mb) TX bytes:684999823 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:0 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882654 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027802 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260231 (1339.2 Mb) TX bytes:684999823 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:1 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882655 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027804 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260297 (1339.2 Mb) TX bytes:685002835 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:2 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882655 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027804 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260297 (1339.2 Mb) TX bytes:685002835 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:3 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882655 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027804 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260297 (1339.2 Mb) TX bytes:685002835 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:4 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882655 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027805 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260297 (1339.2 Mb) TX bytes:685002895 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:5 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882655 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027805 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260297 (1339.2 Mb) TX bytes:685002895 (653.2 Mb)
Interrupt:5 Base address:0xec00
eth2:6 Link encap:Ethernet HWaddr 00:04:76:71:3C:64
inet addr:XXXX Bcast:XXX255 Mask:255.255.255.240
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:1882656 errors:0 dropped:0 overruns:0 frame:0
TX packets:2027806 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:1404260363 (1339.2 Mb) TX bytes:685004401 (653.2 Mb)
Interrupt:5 Base address:0xec00
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:101 errors:0 dropped:0 overruns:0 frame:0
TX packets:101 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:12027 (11.7 Kb) TX bytes:12027 (11.7 Kb)
---------------------------------------------------------------
主要的iptables配置:
iptables -F
iptables -X
iptables -Z
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:2 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:3 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:4 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:5 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:6 --dport 80 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:2 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:3 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:4 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:5 --dport 22 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:2 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:3 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:4 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 53 -j ACCEPT
iptables -A INPUT -p UDP -i eth2 --dport 53 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 110 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 443 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:2 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:3 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:4 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:5 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6001 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6002 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6003 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6004 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6005 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6006 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 6007 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 7002 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 7002 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:1 --dport 3389 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 3389 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 7890 -j ACCEPT
iptables -A INPUT -p TCP -i eth1 --dport 8001 -j ACCEPT
iptables -A INPUT -p icmp -i eth1 -j ACCEPT
iptables -A INPUT -p TCP -i eth1 --dport 23 -j ACCEPT
iptables -A INPUT -p TCP -i eth1 --dport 21 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 8115 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 8116 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:2 --dport 8005 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 7001 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 8089 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 7001 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 8089 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 3389 -j ACCEPT
iptables -A INPUT -p TCP -i eth2:0 --dport 88 -j ACCEPT
iptables -A INPUT -p TCP -i eth2 --dport 8080 -j ACCEPT
arp -H ether -i eth1 -f
iptables -t nat -F
iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
iptables -t nat -A POSTROUTING -s 10.162.16.0/24 -j MASQUERADE
[ 本帖最后由 deep2001 于 2007-6-28 17:23 编辑 ]