有没有Linux防火墙高手~?来下这个问题!!

王朝知道·作者佚名  2009-08-03
窄屏简体版  字體: |||超大  
 
分類: 電腦/網絡 >> 操作系統/系統故障
 
問題描述:

if[ "$CONNECTION_TRACKING" = "1" ]; then

$iptables -A OUTPUT -p tcp -s 192.168.55.222 --dport 25 -m state --state NEW -j ACCEPT

iptables -A OUTPUT -p tcp -s 192.168.55.222 --dport 25 -j ACCEPT

iptables -A INPUT -p tcp ! --syn --sport 25 -d 192.168.55.222 -j ACCEPT

上面三个条件分别是什么意思..有没有高手解释下..

參考答案:

_D_MULTICAST="224.0.0.0/4" # Class D multicast addresses

CLASS_E_RESERVED_NET="240.0.0.0/5" # Class E reserved addresses

BROADCAST_SRC="0.0.0.0" # broadcast source address

BROADCAST_DEST="255.255.255.255" # broadcast destination address

PRIVPORTS="0:1023" # well-known, privileged port range

UNPRIVPORTS="1024:65535" # unprivileged port range

NFS_PORT="2049"

LOCKD_PORT="4045"

SOCKS_PORT="1080"

OPENWINDOWS_PORT="2000"

XWINDOW_P0RT="6000:6063"

SQUID_PORT="3128"

# traceroute usually uses -S 32769:65535 -D 33434:33523

TRACEROUTE_SRC_PORTS="32769:65535"

TRACEROUTE_DEST_PORTS="33434:33523"

USER_CHAINS="EXT-input EXT-output \

tcp-state-flags connection-tracking \

source-address-check destination-address-check \

local-dns-server-query remote-dns-server-response \

local-tcp-client-request remote-tcp-server-response \

remote-tcp-client-request local-tcp-server-response \

local-udp-client-request remote-udp-server-response \

local-dhcp-client-query remote-dhcp-server-response \

EXT-icmp-out EXT-icmp-in \

EXT-log-in EXT-log-out \

log-tcp-state"

小贴士:① 若网友所发内容与教科书相悖,请以教科书为准;② 若网友所发内容与科学常识、官方权威机构相悖,请以后者为准;③ 若网友所发内容不正确或者违背公序良俗,右下举报/纠错。
 
 
 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
 
 
© 2005- 王朝網路 版權所有 導航