iptables问题

qq_28512059 2017-11-04 11:39:58
pptp拨号,已经连接并且分配到了地址,但是服务器和客户端之间互相Ping不通,关闭防火墙后可Ping通,求解答,下边是有问题的防火墙配置
# Generated by iptables-save v1.4.10 on Sat Nov  4 11:03:42 2017
*nat
:PREROUTING ACCEPT [17511:2855459]
:INPUT ACCEPT [53:2922]
:OUTPUT ACCEPT [62:4122]
:POSTROUTING ACCEPT [3:184]
:MINIUPNPD - [0:0]
:postrouting_rule - [0:0]
:prerouting_lan - [0:0]
:prerouting_rule - [0:0]
:prerouting_wan - [0:0]
:zone_lan_nat - [0:0]
:zone_lan_prerouting - [0:0]
:zone_wan_nat - [0:0]
:zone_wan_prerouting - [0:0]
-A PREROUTING -j prerouting_rule
-A PREROUTING -i br-lan -j zone_lan_prerouting
-A PREROUTING -i eth0.2 -j zone_wan_prerouting
-A PREROUTING -i pptp-pptp -j zone_wan_prerouting
-A POSTROUTING -j postrouting_rule
-A POSTROUTING -o br-lan -j zone_lan_nat
-A POSTROUTING -o eth0.2 -j zone_wan_nat
-A POSTROUTING -o pptp-pptp -j zone_wan_nat
-A zone_lan_prerouting -j prerouting_lan
-A zone_wan_nat -j MASQUERADE
-A zone_wan_prerouting -j MINIUPNPD
-A zone_wan_prerouting -j prerouting_wan
COMMIT
# Completed on Sat Nov 4 11:03:42 2017
# Generated by iptables-save v1.4.10 on Sat Nov 4 11:03:42 2017
*raw
:PREROUTING ACCEPT [18080:2906894]
:OUTPUT ACCEPT [1059:263557]
:zone_lan_notrack - [0:0]
:zone_wan_notrack - [0:0]
-A PREROUTING -i br-lan -j zone_lan_notrack
-A PREROUTING -i eth0.2 -j zone_wan_notrack
-A PREROUTING -i pptp-pptp -j zone_wan_notrack
COMMIT
# Completed on Sat Nov 4 11:03:42 2017
# Generated by iptables-save v1.4.10 on Sat Nov 4 11:03:42 2017
*mangle
:PREROUTING ACCEPT [18103:2910338]
:INPUT ACCEPT [9451:1500074]
:FORWARD ACCEPT [58:25745]
:OUTPUT ACCEPT [1064:263939]
:POSTROUTING ACCEPT [1064:263939]
:limit_chain - [0:0]
:zone_wan_MSSFIX - [0:0]
-A FORWARD -j zone_wan_MSSFIX
-A FORWARD -j limit_chain
-A zone_wan_MSSFIX -o eth0.2 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A zone_wan_MSSFIX -o pptp-pptp -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Sat Nov 4 11:03:42 2017
# Generated by iptables-save v1.4.10 on Sat Nov 4 11:03:42 2017
*filter
:INPUT ACCEPT [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
:MINIUPNPD - [0:0]
:forward - [0:0]
:forwarding_lan - [0:0]
:forwarding_rule - [0:0]
:forwarding_wan - [0:0]
:input - [0:0]
:input_lan - [0:0]
:input_rule - [0:0]
:input_wan - [0:0]
:output - [0:0]
:output_rule - [0:0]
:reject - [0:0]
:syn_flood - [0:0]
:zone_lan - [0:0]
:zone_lan_ACCEPT - [0:0]
:zone_lan_DROP - [0:0]
:zone_lan_REJECT - [0:0]
:zone_lan_forward - [0:0]
:zone_wan - [0:0]
:zone_wan_ACCEPT - [0:0]
:zone_wan_DROP - [0:0]
:zone_wan_REJECT - [0:0]
:zone_wan_forward - [0:0]
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn_flood
-A INPUT -j input_rule
-A INPUT -j input
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j forwarding_rule
-A FORWARD -j forward
-A FORWARD -j reject
-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -j output_rule
-A OUTPUT -j output
-A forward -i br-lan -j zone_lan_forward
-A forward -i eth0.2 -j zone_wan_forward
-A forward -i pptp-pptp -j zone_wan_forward
-A input -i br-lan -j zone_lan
-A input -i eth0.2 -j zone_wan
-A input -i pptp-pptp -j zone_wan
-A output -j zone_lan_ACCEPT
-A output -j zone_wan_ACCEPT
-A reject -p tcp -j REJECT --reject-with tcp-reset
-A reject -j REJECT --reject-with icmp-port-unreachable
-A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -j RETURN
-A syn_flood -j DROP
-A zone_lan -j input_lan
-A zone_lan -j zone_lan_ACCEPT
-A zone_lan_ACCEPT -o br-lan -j ACCEPT
-A zone_lan_ACCEPT -i br-lan -j ACCEPT
-A zone_lan_DROP -o br-lan -j DROP
-A zone_lan_DROP -i br-lan -j DROP
-A zone_lan_REJECT -o br-lan -j reject
-A zone_lan_REJECT -i br-lan -j reject
-A zone_lan_forward -j zone_wan_ACCEPT
-A zone_lan_forward -j forwarding_lan
-A zone_lan_forward -j zone_lan_REJECT
-A zone_wan -p udp -m udp --dport 68 -j ACCEPT
-A zone_wan -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A zone_wan -j input_wan
-A zone_wan -j zone_wan_REJECT
-A zone_wan_ACCEPT -o eth0.2 -j ACCEPT
-A zone_wan_ACCEPT -i eth0.2 -j ACCEPT
-A zone_wan_ACCEPT -o pptp-pptp -j ACCEPT
-A zone_wan_ACCEPT -i pptp-pptp -j ACCEPT
-A zone_wan_DROP -o eth0.2 -j DROP
-A zone_wan_DROP -i eth0.2 -j DROP
-A zone_wan_DROP -o pptp-pptp -j DROP
-A zone_wan_DROP -i pptp-pptp -j DROP
-A zone_wan_REJECT -o eth0.2 -j reject
-A zone_wan_REJECT -i eth0.2 -j reject
-A zone_wan_REJECT -o pptp-pptp -j reject
-A zone_wan_REJECT -i pptp-pptp -j reject
-A zone_wan_forward -j MINIUPNPD
-A zone_wan_forward -j forwarding_wan
-A zone_wan_forward -j zone_wan_REJECT
COMMIT
# Completed on Sat Nov 4 11:03:42 2017
...全文
159 3 打赏 收藏 转发到动态 举报
写回复
用AI写文章
3 条回复
切换为时间正序
请发表友善的回复…
发表回复
qq_28512059 2017-11-06
  • 打赏
  • 举报
回复
这论坛已经废了,估计没几个人了
清风絮语 2017-11-06
  • 打赏
  • 举报
回复
人太少了,发了帖子都很少人回!
曹宇飞丶 2017-11-06
  • 打赏
  • 举报
回复
添加两条规则在121行之前试试: iptables –A INPUT –p icmp --icmp-type echo-reply –j ACCEPT iptables –A OUTPUT –p icmp --icmp-type echo-request –j ACCEPT

19,612

社区成员

发帖
与我相关
我的任务
社区描述
系统使用、管理、维护问题。可以是Ubuntu, Fedora, Unix等等
社区管理员
  • 系统维护与使用区社区
加入社区
  • 近7日
  • 近30日
  • 至今
社区公告
暂无公告

试试用AI创作助手写篇文章吧