乌邦图ubuntu配置iptables的NAT上网

时间:2023-03-09 19:24:57
乌邦图ubuntu配置iptables的NAT上网

cat /etc/network/iptables.up.rules

# Generated by iptables-save v1.6.0 on Mon Nov  ::
*nat
:PREROUTING ACCEPT [:]
:INPUT ACCEPT [:]
:OUTPUT ACCEPT [:]
:POSTROUTING ACCEPT [:]
-A POSTROUTING -s 10.86.2.0/ -o ppp0 -j MASQUERADE
COMMIT
# Completed on Mon Nov ::
# Generated by iptables-save v1.6.0 on Mon Nov ::
*filter
:INPUT ACCEPT [:]
:FORWARD ACCEPT [:]
:OUTPUT ACCEPT [:]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p udp -m udp --dport
-A INPUT -p tcp -m state --state NEW -m tcp --dport -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -s 10.86.2.0/ -j ACCEPT
-A FORWARD -d 10.86.2.0/ -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
# Completed on Mon Nov ::
# Generated by iptables-save v1.6.0 on Mon Nov ::
*mangle
:PREROUTING ACCEPT [:]
:INPUT ACCEPT [:]
:FORWARD ACCEPT [:]
:OUTPUT ACCEPT [:]
:POSTROUTING ACCEPT [:]
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss : -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Mon Nov ::