?? iptables 簡介.mht
字號:
<TR>
<TD bgColor=3D#cccccc width=3D134>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D108>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D310>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D134>
<P>--log-level</P></TD>
<TD width=3D108>
<P>LEVEL</P></TD>
<TD width=3D310>
<P>=ADn=B0O=BF=FD=A8=ECSYSLOG=AA=BA=B5=A5=AF=C5</P></TD></TR>
<TR>
<TD width=3D134>
<P>--log-prefix</P></TD>
<TD width=3D108>
<P>PREFIX</P></TD>
<TD width=3D310>
<P>=B0O=BF=FD=A8=ECSYSLOG=AA=BA=A6W=BA=D9</P></TD></TR>
<TR>
<TD width=3D134>
<P>--log-tcp-sequence</P></TD>
<TD width=3D108>
<P> </P></TD>
<TD width=3D310>
<P>=AC=F6=BF=FDTCP=AA=BASequence=B8=EA=B0T</P></TD></TR>
<TR>
<TD width=3D134>
<P>--log-tcp-options</P></TD>
<TD width=3D108>
<P> </P></TD>
<TD width=3D310>
<P>=AC=F6=BF=FDTCP=AA=BAOption=A4=BA=AEe</P></TD></TR>
<TR>
<TD width=3D134>
<P>--log-ip-options</P></TD>
<TD width=3D108>
<P> </P></TD>
<TD width=3D310>
=
<P>=AC=F6=BF=FDIP=AA=BAOption=A4=BA=AEe</P></TD></TR></TBODY></TABLE>
<P>=AA=ED=AE=E67 MARK=AC=DB=C3=F6=AA=BA=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D134>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D108>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D310>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D134>
<P>--set-mark</P></TD>
<TD width=3D108>
<P>MARK</P></TD>
<TD width=3D310>
=
<P>=BC=D0=AA`=AC=DB=C3=F6=AA=BA=B8=EA=B0T</P></TD></TR></TBODY></TABLE>
<P>=AA=ED=AE=E68 REJECT=AC=DB=C3=F6=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D134>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D108>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D310>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D134>
<P>--reject-eith</P></TD>
<TD width=3D108>
<P>TYPE</P></TD>
<TD width=3D310>
=
<P>=ADn=B0h=A6^=AA=BA=AD=EC=A6]=A1CTYPE=A5]=A7t=A1G<BR>icmp-net-unreachab=
le<BR>icmp-host-unreachable<BR>icmp-port-unreachable<BR>icmp-proto-unreac=
hable<BR>icmp-net-prohibited<BR>icmp-host-prohibited</P></TD></TR></TBODY=
></TABLE>
<P>=AA=ED=AE=E69 TOS=AC=DB=C3=F6=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D134>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D108>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D310>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D134>
<P>--set-tos</P></TD>
<TD width=3D108>
<P>TOS</P></TD>
<TD width=3D310>
<P>=ADn=B3]=A9w=AA=BATOS=AD=C8</P></TD></TR></TBODY></TABLE>
<P>=AA=ED=AE=E610 SNAT=AC=DB=C3=F6=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D126>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D169>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D266>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D126>
<P>--to-source</P></TD>
<TD width=3D169>
<P>IP1-IP2:PORT1:PORT2</P></TD>
<TD width=3D266>
=
<P>=ADn=B1N=A8=D3=B7=BD=A6=EC=A7}=C2=E0=C4=B6=A6=A8=AC=B0IP1=A8=ECIP2=AA=BA=
IP=A1A=A5H=A4=CEPORT1=A8=ECPORT2=AA=BAPort</P></TD></TR></TBODY></TABLE>
<P>=AA=ED=AE=E611 DNAT=AC=DB=C3=F6=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D126>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD width=3D169>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D266>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D126>
<P>--to-destination</P></TD>
<TD width=3D169>
<P>IP1-IP2:PORT1:PORT2</P></TD>
<TD width=3D266>
=
<P>=ADn=B1N=A5=D8=AA=BA=A6=EC=A7}=C2=E0=C4=B6=A6=A8=AC=B0IP1=A8=ECIP2=AA=BA=
IP=A1A=A5H=A4=CEPORT1=A8=ECPORT2=AA=BAPort</P></TD></TR></TBODY></TABLE>
<P>=AA=ED=AE=E612 MASQUERADE=AC=DB=C3=F6=B0=D1=BC=C6</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D126>
<P><B>=B0=D1=BC=C6</B></P></TD>
<TD bgColor=3D#cccccc width=3D169>
<P><B>=A4=BA=AEe</B></P></TD>
<TD bgColor=3D#cccccc width=3D266>
<P><B>=BB=A1=A9=FA</B></P></TD></TR>
<TR>
<TD width=3D126>
<P>--to-ports</P></TD>
<TD width=3D169>
<P>PORT1-PORT2</P></TD>
<TD width=3D266>
=
<P>=A6=DB=B0=CA=C2=E0=C4=B6IP=A6=EC=A7}=AE=C9=A1A=AD=AD=A9w=A5u=C2=E0Sour=
ce =
Port=AC=B0PORT1=A8=ECPORT2=BDd=B3=F2=AA=BA=AB=CA=A5]</P></TD></TR></TBODY=
></TABLE>
<H2>=BDd=A8=D2</H2>
<P align=3Dcenter><IMG border=3D0 height=3D415=20
src=3D"http://www.savs.hcc.edu.tw/~chuavv/articles/netfilter.img/netfilte=
r2.gif"=20
width=3D553></P>
<H3>=A6h=B9=EF=A4@NAT</H3>
<P>[root@gateway root]# <B>iptables =A1Vt nat =A1VA POSTROUTING =A1Vo =
eth0 =A1Vj=20
MASQUERADE</B></P>
<H3>=A9=E8=BE=D7=B9=EFLinux=A5D=BE=F7=B2=A7=BC=CB=AA=BAICMP=AB=CA=A5]</H3=
>
<P>1.=C2=B2=A9=F6=B3]=A9w</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>iptables =A1VA INPUT =A1Vp icmp --icmp-type =
echo-request=20
=A1Vj REJECT</B></P></BLOCKQUOTE>
<P>2. =B6i=B6=A5=B3]=A9w</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>iptables =A1VI INPUT =A1Vp imcp --icmp-type =
echo-request=20
=A1Vm limit --limit 6/min --limit-burst 2 =A1Vj =
ACCEPT</B></P></BLOCKQUOTE>
<H3>=B4=A3=A8=D1Transparent Proxy (=B3z=B3q=A6=A1Proxy)</H3>
<P>1. =AD=D7=A7=EFSquid =
Proxy=A1A=A8=CF=A8=E4=B4=A3=A8=D1Transparent Proxy=AAA=B0=C8</P>
<P>=B1N=A4U=AD=B1=AA=BA=A4=BA=AEe=A5[=A4J=A6bSquid Proxy =
Server=AA=BA=B3]=A9w=C0=C9(/etc/squid/squid.conf)=A4=BA=A1G</P>
<TABLE border=3D1 cellPadding=3D0 cellSpacing=3D0>
<TBODY>
<TR>
<TD bgColor=3D#cccccc width=3D526>
<P bgcolor=3D"#CCCCCC">http_port 8080<BR>httpd_accel_host=20
virtual<BR>httpd_accel_port 80<BR>httpd_accel_with_proxy=20
on<BR>httpd_accel_uses_host_header =
on</P></TD></TR></TBODY></TABLE>
<P>=A7=B9=A6=A8=AB=E1=A1A=AD=AB=B7s=B1=D2=B0=CASquid Server=A1G</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>service squid restart</B></P></BLOCKQUOTE>
<P>2. =B2=D5=BAANetFilter=B3W=ABh</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>iptables =A1Vt nat =A1VA PREROUTING =A1Vi =
eth1 =A1Vp tcp=20
--dport 80 =A1Vj REDIRECT --to-ports 8080</P></BLOCKQUOTE>
<H3></B>=ABO=C5@=A4=BD=B6}=AAA=B0=C8</H3>
<P>1. =B1N=B4=A3=A8=D1=A4=BD=B6}=AAA=B0=C8=A4=A7=A6=F8=AAA=BE=B9=A1A=
=A9=F1=B6i=A4=BA=B3=A1=BA=F4=B8=F4=A1C</P>
<P>2. =B2=D5=BAA=A4U=AD=B1=B3W=ABh =
(=A5H=A6s=A8=FA54.38.54.49=AA=BASMTP=B3s=BDu=A1A=C2=E0=A6=DC=A4=BA=B3=A1=AA=
=BA192.168.5.1 Mail Server=B3B=B2z=AC=B0=A8=D2):</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>iptables =A1Vt nat =A1VA PREROUTING =A1Vd =
54.38.54.49 =A1Vp tcp=20
--dport 25 =A1Vj DNAT --to 192.168.5.1:25</P></BLOCKQUOTE>
<H3>=ADt=B8=FC=A7=A1=BF=C5=A6=A1NAT</H3></B>
<P>1. =A6b=A4=BA=B3=A1=BA=F4=B8=F4=A4=A4=AC[=B3]=A6h=A5x=AA=BAServer=
=A1C</P>
<P>2. =B2=D5=BAA=A4U=AD=B1=B3W=ABh =
(=A5H=A6s=A8=FA54.38.54.49=AA=BAHTTP=B3s=BDu=A1A=A4=C0=A7O=C2=E0=A6=DC=A4=
=BA=B3=A1=AA=BA 192.168.5.1=BBP192.168.5.2=AA=BAWeb=20
Server=B3B=B2z=AC=B0=A8=D2)=A1G</P>
<BLOCKQUOTE>
<P>[root@gateway root]# <B>iptables =A1Vt nat =A1VA PREROUTING =A1Vd =
54.38.54.49 =A1Vp tcp=20
--dport 80 =A1Vj DNAT --to =
192.168.5.1-192.168.5.2:80</B></P></BLOCKQUOTE>
<P> </P>
<H2>=B0=D1=A6=D2=B8=EA=AE=C6</H2>
<UL>
<LI>=AE=D1=C4y=BBP=A4=E5=A5=F3=20
<UL>
<LI>iptables ManPage=20
<LI>PacketFilter HOWTO=20
<LI>NAT HOWTO=20
<LI>IP Masquerading HOWTO=20
<LI>Firewall HOWTO<BR></LI></UL>
<LI>=BA=F4=B8=F4=B8=EA=B7=BD=20
<UL>
<LI>http://www.netfilter.org/=20
<LI>http://www.linuxsecurity.org/=20
<LI>http://www.study-area.org/=20
<LI>http://www.linux-study.org/ </LI></UL></LI></UL></BODY></HTML>
------=_NextPart_000_0000_01C48156.5EDE8B30
Content-Type: image/gif
Content-Transfer-Encoding: base64
Content-Location: http://www.savs.hcc.edu.tw/~chuavv/articles/netfilter.img/netfilter1.gif
R0lGODlhQAKZAXcAMSH+GlNvZnR3YXJlOiBNaWNyb3NvZnQgT2ZmaWNlACH5BAEAAAAALDEADQDR
AWcBhIGBgQAAAP///wECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwEC
AwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwECAwL/hI+py+0Po5y02ouz
3rz7D4ZNQJamiKbqyrbuC8eyZ9b2jOf6zvf+z7IJa8Ci8YhMKpeOobPEjEqn1Kp1JBRot1rh9QsO
M57ksvmMTg+rWa67SxTL59TA+47P6/f8vv8ewGbyd0NneGhk97fI2Oi4FzhV0xiHaHk5o/i4ydmZ
Fxk1SXmCWWq6oumpuuoIyiQ6CnU6S6tAQpHKqrv7mekaAdsqW0s8W9kEOQiXSiKg+MRVsiUt7ZzV
bK3ZnIv363LcVL1JWlyOuTbCp+083QXnbhffzu5eT88ur/08jw3pW4il3yNw5grKIbOA2xt9buTZ
u7cu176HEKdNZNbHWwuE/wnFjRtmMGSYMwgUNqTWkKI9ZRJXpnTp0KQejUHMJFDGiZzInRjU+Py5
RuY8igyjtVtntGLSijEtCl0GNGoaAMEGguSJVYLUrT6pqlsKb6jSifzEKqWHDaM6rmyfUMX58VbW
ucBobrR54Ok9l9YeIkU79C9ftH/1OvvHMa9Hq3LpOh5jt6aThMkk9ovHbFvaZwKzncQM2u/iboi9
dOwsrPHj1YpzoBvDK7bsaKWv2hrNiCBrx6pj6LY1OzivyCl+30ad2/Zu3sRV9H5gWLj0jL4qVE3+
fDnd7EiiT/9OWsp1P8a18+R+xDv49dMkwSWk0zxzSezrk6/zPmN8+XPRJ/+yD+BMguDWTXn8ieRf
EW0tyGBX+I33mXIHYpXghLsNUaCBFhpU4XYbKubgh9s11x+JF6oh4mMdZrXiiXilOB9/ElroFoyr
tbjTfjaGMOOOV+CIYI8+XoCTjkO6J6ORR+LylIlLKuhkkEo+CYE+NlhEJZLmAZTlBIJFo02Xr0QZ
kmliVvnOTO2d2R2ZBb3GZjp7fdJFnOm5aQ6cdt6kEp2H7fkDkG/qCShZ5NUJaA+CllNjogYYmhGi
juqwaDGNOupQbn9O6hqell5a6JyHesppB5XWUsakkI7a4IJdnponqUOuGmmrrmYJK6OyzipqrXe+
uuunpZbU61fBipDriQf/JrtjpoRICgSzNx6LKrUw0qrmptFaG6N80tqILSDQbgvsstymGO5C4wZ6
bii2vovGQe2KmC4/SXxL33Tq5STvsMD1VeC65DIaoGzz+nbwh5dZhuW9Cd9bcGwPfzPxhpl5VPEG
+IoX8XD9+tvRJxlrPHK0He9ScnEpTziZeCsrerIuL/M4M8gU51lZNeKIollooumcXy9ibGwzuzhD
clRgZZ01J1JfCj1SzUWjIrVrX+HzktODOau1WeFFPbUlRL+y1jZZ79xU0k4JZljVprodNs1HZ+ss
YC2Z7ZRRavW50Mdx0zH2EnrtXY+hZhe29F5t+/0346herfRggEU+ltdf/4MReOMyZA7xTJ2hzVni
1PQMFYGAOK65e6CeEzMrcJOc+o+rs966Kq9rwHnsKhNKe+2d3J5B7roj27IxvnsCfE/JD18l770f
PxDqzAtupvHQjyP99A5zecq+19M29PLaBzSl2PCenxjm4o8PWfn0msu+y+4rDH/8YwqJbv32Uy/8
oOv/uj/+/S98A4RSAPkHrAIO7IAOw9X8zqPAAPYvVvijUAT3d0HZVRCCDOygBarHmgmGDX0kBGH3
uDctD1rne634lIY4qEIvsZASxCheCDN4JO+xEIckM2G3YoimGS6Ch7hzXomAqBUhDrFaNlQREZsF
ptEBzQlRzNsUJ7EZhv9w44lEmt0RkRhEpXUNa4WjXETICDCnbZGJRrQgGMMIk6WRpW5zfAlELgIW
gZ1Qf2+ETRQ5s7AsQqqOSzljvbhYRD728V9m4VoZv0RIM5LRSg2JlSIXSaw8RrKMTZPcWUKnuL7p
6pKYfJQd+XJGTn7Sjmqk3JqElaRSUiZvyyjdldL4uVyGRmd/FCUsvYVIdCmREJaMpSz5NEzqjNKY
x8xLMpX5yy0Fk17PVEcxgdnMTFYTajWcJsKy6cxtcrNapCylDr/nzQ+m8wUinFoJ37nBQ7QzfOD8
pgPLWU8UzLOb+Myn3O7JTH9SrVwBFajKCIpNgw4UoAlV6EEZKk2HOmf/nQBsqET/SaV9qu+i+qRo
IkgEz5AChaPEQ2g4RIpSkpAUBBqlRYdaulJTwLRT76xLTJ8009qgz6Y3zaFHeWq0ns7qp80zoFB9
lNPNJS+pR50DU2Hw1EcRtanViaaipkpVe/JzgVlVGFaxYNSuenWZQRWrxb4KmbCalWVo7Yha11pQ
Yyy1rXAtqVV5ENW6uousPsirXqnH16v+Na575OpglXXXHfj1sBUlp2EZ68TA4pWukE1kYilF2coq
T7KKzaxm1clZzH42hZft1GgjW1ocLPa0ndUV8FbLWtNWq2GTje0XTwgIt8HWtkrFredEy1sYXgI5
BVKtZ4MLVvMJo7fI/w0SIogLH6get7m3MQR0R3Ez6nIondf9SE20u93wCSdzuwXvRNUHnrGV17wd
lZ19NrZe9mLUZRH7Vnzl+4H7vqV1zNIvfjkQ3+4CKFf+/a9lHTbDUxXYwJttUzIXtWAGg/aj4gRS
hCXMJCiJE0xemi57nyrgB4PUw+ZNaoi3maALY1grbrLWiTdsjeQCdcV7tU48Q7YQuIDOM9nA0NrY
xpJAmi47FXohjfvaYhRCRyhjRFxYMoURKLOSKJbjcEns0sYjP7Z5TbwN5OjoyTGCxZGqLPNvpXqc
LGsZyepM1U2iw5KsNXJt4lIbVBpputy+BUTpW3ObdvpiNLaEaZVTF/8tUSln7DTIz509n1SHaOZN
EnrKW6MyYxbN6AHN7sRNduUqKf3pVBZLz292c1oz/SAfvrkyaVqMq3v26l3CGpBUXMuSu3xlVKf6
xvuFsXc7rOTW6Fp+sgq0r2OsvB6pWMsuPqeIaRCZZQ+7iMcurnSnXSZnH2+f0sY2yY7d0m57+9so
?? 快捷鍵說明
復制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -