[网络管理] 请教IPTABLES 无法停止问题

weixin_38051633 2009-12-02 12:29:43

各位老大,最近在设置IPTABLES 规则时遇到一个棘手问题,(IPTABLES SAVE 如下),启用规则是没有问题的,就是在停止或重启规则时候,在UNLOAD MODULE 的时候就定住不动了,等了很久很久都不行,GOOGLE了一下,有类似的问题是由于设置了无效的规则导致的,可是我检查了几遍了,都没发现问题,还望各位老大帮解决解决,先谢谢各位了!



# Generated by iptables-save v1.2.11 on Mon Nov 30 16:14:00 2009
*nat
REROUTING ACCEPT [0:0]
OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
REFW - [0:0]
:REDFW - [0:0]
-A PREROUTING -j REDFW
-A POSTROUTING -j MASQUERADE
-A REDFW -s 192.168.1.133 -p tcp -m mac --mac-source 00:19:B9:47:70:28 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.143 -p tcp -m mac --mac-source 00:13:20:B2:ED:48 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.161 -p tcp -m mac --mac-source 00:0D:61:EC:7B:FF -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.156 -p tcp -m mac --mac-source 00:0D:61:E8:82:47 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.155 -p tcp -m mac --mac-source 00:13:20:B2:EC:B5 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.23 -p tcp -m mac --mac-source 00:133:F5:59:3E -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.195 -p tcp -m mac --mac-source 00:1C:25C:0B:2E -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.36 -p tcp -m mac --mac-source 00:50:04:BF:AF:78 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.71 -p tcp -m mac --mac-source 00:01:6C:42:86:27 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.163 -p tcp -m mac --mac-source 00:19:B9:47:E4F -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.250 -p tcp -m mac --mac-source 00:03:0D:CC:A4:B7 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.185 -p tcp -m mac --mac-source 00:19:B9:47:6B:F7 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.165 -p tcp -m mac --mac-source 00:25:11:E7:81:9E -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.138 -p tcp -m mac --mac-source 00:01:6C:4B:F1:47 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.106 -p tcp -m mac --mac-source 00:14:2A:5B:20:43 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.201 -p tcp -m mac --mac-source 00:14:C2:5F:4D:8A -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.193 -p tcp -m mac --mac-source 00:133:F5:34:F4 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.176 -p tcp -m mac --mac-source 00:01:6C:AA:29:17 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.128 -p tcp -m mac --mac-source 00:13:20:EC:FD:F6 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.144 -p tcp -m mac --mac-source 00:E0:4C:12:37:86 -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.149 -p tcp -m mac --mac-source 00:19:B9:47:70:1F -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.161 -p tcp -m mac --mac-source 00:0D:61:EC:7B:FF -m tcp --dport 80 -j REDIRECT --to-ports 8088
-A REDFW -s 192.168.1.89 -p tcp -m mac --mac-source 00:19:B9:47:6D:F5 -m tcp --dport 80 -j REDIRECT --to-ports 8088
COMMIT
# Completed on Mon Nov 30 16:14:00 2009
# Generated by iptables-save v1.2.11 on Mon Nov 30 16:14:00 2009
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
:FORFW - [0:0]
:INPUTFW - [0:0]
:MAC - [0:0]
ORTFW - [0:0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i bond0 -p icmp -j ACCEPT
-A INPUT -i bond0 -p tcp -j ACCEPT
-A INPUT -i bond0 -p udp -j ACCEPT
-A INPUT -j INPUTFW
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p udp -m udp --dport 53 -j ACCEPT
-A FORWARD -j FORFW
-A FORFW -s 192.168.1.89 -p tcp -m mac --mac-source 00:19:B9:47:6D:F5 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.149 -p tcp -m mac --mac-source 00:19:B9:47:70:1F -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.143 -p tcp -m mac --mac-source 00:13:20:B2:ED:48 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.128 -p tcp -m mac --mac-source 00:13:20:EC:FD:F6 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.133 -p tcp -m mac --mac-source 00:19:B9:47:70:28 -m multiport --dports 443,21,23,7708,7727 -j ACCEPT
-A FORFW -s 192.168.1.156 -p tcp -m mac --mac-source 00:0D:61:E8:82:47 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.165 -p tcp -m mac --mac-source 00:25:11:E7:81:9E -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.185 -p tcp -m mac --mac-source 00:19:B9:47:6B:F7 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.250 -p tcp -m mac --mac-source 00:03:0D:CC:A4:B7 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.163 -p tcp -m mac --mac-source 00:19:B9:47:E4F -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.71 -p tcp -m mac --mac-source 00:01:6C:42:86:27 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.36 -p tcp -m mac --mac-source 00:50:04:BF:AF:78 -m multiport --dports 443 -j ACCEPT
-A FORFW -s 192.168.1.155 -p tcp -m mac --mac-source 00:13:20:B2:EC:B5 -m multiport --dports 7888 -j ACCEPT
-A FORFW -s 192.168.1.23 -p tcp -m mac --mac-source 00:133:F5:59:3E -m multiport --dports 443 -j ACCEPT
-A FORFW -p tcp -j DROP
-A FORFW -p udp -j DROP
-A INPUTFW -p tcp -m tcp --dport 222 -j ACCEPT
COMMIT
# Completed on Mon Nov 30 16:14:00 2009
...全文
44 6 打赏 收藏 转发到动态 举报
写回复
用AI写文章
6 条回复
切换为时间正序
请发表友善的回复…
发表回复

435

社区成员

发帖
与我相关
我的任务
社区描述
其他技术讨论专区
其他 技术论坛(原bbs)
社区管理员
  • 其他技术讨论专区社区
加入社区
  • 近7日
  • 近30日
  • 至今
社区公告
暂无公告

试试用AI创作助手写篇文章吧