ºìÁªLinuxÃÅ»§
Linux°ïÖú

iptablesÎÊÌâ

·¢²¼Ê±¼ä:2011-07-13 16:56:52À´Ô´:ºìÁª×÷Õß:qscf_520
-A FORWARD -m set --match-set 30net src -m set --match-set 20ip dst -j ACCEPT
-A FORWARD -m state --state NEW -j DROP

·¢ÏÖÉϲ»ÁËÖ¸¶¨µÄ20ip£¬¶ø30net==¡·ipset -L ¿ÉÒÔ¿´µ½10.0.0.0/16 £¬20ipÀïÓÐ61.152.20.20 Õâ¸öIPµØÖ·£¬µ«ÊǾͷÃÎʲ»ÁË61.152.20.20£¬Ö´ÐÐÏÂÃæ£º
-I FORWARD-s 10.0.0.0/16 -d 61.152.20.20 -j ACCEPT È»ºó¾Í¿ÉÒÔ·ÃÎÊ61.152.20.20¡£

iptables -L FORWARD¿´Îª£º
426 26296 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 match-set 30net src match-set 20ip dst

ÈçºÎ²ÅÄÜÖªµÀ-A FORWARD -m set --match-set 30net src -m set --match-set 20ip dst -j ACCEPTÊÇ·ñÉúЧÁË£¬°üº¬ÁËIPSETÀïµÄ¶ÔÏóÄØ£¿
ÇëÖ¸½Ì¡£ ÔÚÏßµÈ
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 2 ÌõÆÀÂÛ

  1. lastimic ÓÚ 2012-02-13 14:33:49·¢±í:

    ¿´²»¶®

  2. jmkele ÓÚ 2011-12-28 11:13:14·¢±í:

    Ì«¸´ÔÓ£¬Ã»¿´¶®£¬°ïæ¶¥Ò»ÏÂÁË