QUOTE:原帖由 platinum 于 2007-11-23 10:56 发表

不要贴脚本,贴 iptables-save 的结果
# Generated by iptables-save v1.2.11 on Fri Nov 23 11:20:28 2007
*mangle
REROUTING ACCEPT [38155:17645793]

:INPUT ACCEPT [4674:452380]
:FORWARD ACCEPT [26548:15478267]
:OUTPUT ACCEPT [4861:992438]
OSTROUTING ACCEPT [31381:16468544]

COMMIT
# Completed on Fri Nov 23 11:20:28 2007
# Generated by iptables-save v1.2.11 on Fri Nov 23 11:20:28 2007
*filter
:INPUT ACCEPT [4674:452380]
:FORWARD DROP [28:2161]
:OUTPUT ACCEPT [4862:992594]
-A INPUT -s 192.186.100.0/255.255.255.0 -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p tcp -m iprange --src-range 192.168.100.71-192.168.100.79 -m multiport --dports 80,8080,7002,7001,443,3333 -j ACCEPT
-A FORWARD -s 192.168.100.215 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.211 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.214 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.212 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.188 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.181 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.158 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.173 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.170 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.164 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.163 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.159 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.157 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.156 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.151 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.68 -p tcp -j DROP
-A FORWARD -s 192.168.100.66 -p tcp -j DROP
-A FORWARD -s 192.168.100.65 -p tcp -j DROP
-A FORWARD -s 192.168.100.70 -p tcp -m tcp --dport 4000 -j ACCEPT
-A FORWARD -s 192.168.100.67 -p tcp -j ACCEPT
-A FORWARD -p tcp -m iprange --src-range 192.168.100.61-192.168.100.70 -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.100.220 -p tcp -m multiport --dports 443,80 -j ACCEPT
-A FORWARD -s 192.168.100.221 -p tcp -m multiport --dports 443,80 -j ACCEPT
-A FORWARD -s 192.168.100.60 -p tcp -m multiport --dports 443,80 -j ACCEPT
-A FORWARD -p tcp -m iprange --src-range 192.168.100.103-192.168.100.119 -m multiport --dports 443,80,8081,3389 -j ACCEPT
-A FORWARD -m iprange --src-range 192.168.100.2-192.168.100.50 -j ACCEPT
-A FORWARD -s 192.168.100.0/255.255.255.0 -p tcp -m multiport --dports 110,25 -j ACCEPT
-A FORWARD -s 192.168.100.0/255.255.255.0 -p udp -m multiport --dports 53,1800,1810,8000,8080 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p udp -m udp --dport 53 -j ACCEPT
COMMIT
# Completed on Fri Nov 23 11:20:28 2007
# Generated by iptables-save v1.2.11 on Fri Nov 23 11:20:28 2007
*nat
REROUTING ACCEPT [8594:1826625]

OSTROUTING ACCEPT [14:892]

:OUTPUT ACCEPT [23:1648]
-A PREROUTING -s 192.168.100.0/255.255.255.0 -d 202.96.186.240 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A POSTROUTING -s 192.168.100.0/255.255.255.0 -j MASQUERADE
COMMIT
# Completed on Fri Nov 23 11:20:28 2007