-A FORWARD -m set --match-set 30net src -m set --match-set 20ip dst -j ACCEPT
-A FORWARD -m state --state NEW -j DROP
·¢ÏÖÉϲ»ÁËÖ¸¶¨µÄ20ip£¬¶ø30net==¡·ipset -L ¿ÉÒÔ¿´µ½10.0.0.0/16 £¬20ipÀïÓÐ61.152.20.20 Õâ¸öIPµØÖ·£¬µ«ÊǾͷÃÎʲ»ÁË61.152.20.20£¬Ö´ÐÐÏÂÃæ£º
-I FORWARD-s 10.0.0.0/16 -d 61.152.20.20 -j ACCEPT È»ºó¾Í¿ÉÒÔ·ÃÎÊ61.152.20.20¡£
iptables -L FORWARD¿´Îª£º
426 26296 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 match-set 30net src match-set 20ip dst
ÈçºÎ²ÅÄÜÖªµÀ-A FORWARD -m set --match-set 30net src -m set --match-set 20ip dst -j ACCEPTÊÇ·ñÉúЧÁË£¬°üº¬ÁËIPSETÀïµÄ¶ÔÏóÄØ£¿
ÇëÖ¸½Ì¡£ ÔÚÏßµÈ
lastimic ÓÚ 2012-02-13 14:33:49·¢±í:
¿´²»¶®
jmkele ÓÚ 2011-12-28 11:13:14·¢±í:
Ì«¸´ÔÓ£¬Ã»¿´¶®£¬°ïæ¶¥Ò»ÏÂÁË