- 论坛徽章:
- 0
|
这个是filter表的默认配置,已经确定是FORWARD链的规则把报文丢弃了- root@unknown:/tmp/home/root# iptables -t filter -L -n -v
- Chain INPUT (policy DROP 23430 packets, 1112K bytes)
- pkts bytes target prot opt in out source destination
- 1006 154K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 29496 4795K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 27571 4139K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0
- 172 22157 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy DROP 12 packets, 1008 bytes)
- pkts bytes target prot opt in out source destination
- 15M 16G ACCEPT all -- * br0 0.0.0.0/0 0.0.0.0/0
- 33771 1478K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 138K 7372K TCPMSS tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 TCPMSS clamp to PMTU
- 12M 1378M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 12 1008 wanin all -- vlan1 * 0.0.0.0/0 0.0.0.0/0
- 289K 19M wanout all -- * vlan1 0.0.0.0/0 0.0.0.0/0
- 294K 24M ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0
- 12 1008 upnp all -- vlan1 * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 74818 packets, 21M bytes)
- pkts bytes target prot opt in out source destination
- Chain upnp (1 references)
- ...
- Chain wanin (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.2.32 tcp dpt:5617
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.2.32 udp dpt:5627
- Chain wanout (1 references)
- pkts bytes target prot opt in out source destination
复制代码 |
|