QUOTE:原帖由 ssffzz1 于 2007-7-19 12:26 发表

:INPUT ACCEPT [0:0]这句的规则是允许,当然就允许了。
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
...
:INPUT DROP [0:0]这句的规则是允许,当然就允许了。
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
#-A RH-Firewall-1-INPUT -i eth0 -j ACCEPT 这句也允许了。
改成这样了,还是不行啊