ping°ü¾¹ýiptables±íÁ´³öÏÖÎÊÌâ
¸÷λǰ±²£º×î½üÔÚ¶ÁOskar AndreassonÏÈÉúµÄ¡¶Iptables Tutorial 1.2.0¡·£¬¾õµÃ»ñÒæÆÄ¶à¡£ÔÚ¶Á "14.6. rc.test-iptables.txt" Õⲿ·ÖʱÎÒÏëʵ¼Ê²âÊÔһϣ¬¾Í½«Õâ¸ö½Å±¾downloadÏÂÀ´²¢ÔÚһ̨linux£¨redhat9.0£¬Kernel 2.4.20-8 on an i686£©»úÆ÷(ÆäÃû×ÖΪ Lab01)Ö´ÐÐÖ®£¬È»ºóÎÒÔÚÁíһ̨linux»úÆ÷£¨ÆäÃû×ÖΪFirewall£¬ÓëLab01ÔÚͬһ¸ö¾ÖÓòÍøÄÚ£©ÉÏÖ´ÐÐÃüÁî "ping -c 1 Lab01"¡£½ÓÏÂÀ´ÎÒÔÚ Lab01ÉÏ×Ðϸ²é¿´Îļþ /var/log/messages£¬¸ù¾Ý"6. Traversing of tables and chains"²¿·ÖËù½²£¬ÎÒÆÚ´ýÔÚ/var/log/messagesÖп´µ½ÓÉÉÏÊöpingÃüÁî²úÉúµÄicmp°ü°´ÕÕÏÂÃæµÄ´ÎÐò´©¹ýiptables£º
mangle(PREROUTING)->nat(PREROUTING)->mangle(INPUT)->filter(INPUT) (icmp-type Ϊ"echo request"µÄÊý¾Ý°ü)£¬
mangle(OUTPUT)->nat(OUTPUT)->filter(OUTPUT)->mangle(POSTROUTING)->nat(POSTROUTING) (icmp-typeΪ "echo reply"µÄÊý¾Ý°ü)¡£
µ«ÊÇÊÂʵÉÏÎÒÔÚ/var/log/messagesÖп´µ½ÉÏÊöpingÃüÁî²úÉúµÄicmp°üÊǰ´ÕÕÏÂÃæµÄ´ÎÐò´©¹ýiptablesµÄ£º
mangle(PREROUTING)->nat(PREROUTING)->mangle(INPUT)->filter(INPUT) (icmp-type Ϊ"echo request"µÄÊý¾Ý°ü),
mangle(OUTPUT)->filter(OUTPUT)->mangle(POSTROUTING) (¸ù±¾Ã»Óо¹ýnat(OUTPUT)&nat(POSTROUTING)Á½¸öÁ´¡£) (icmp-typeΪ "echo reply"µÄÊý¾Ý°ü).
ÕâÓ¦¸ÃÈçºÎ½âÊÍ£¿
ºóÀ´ÎÒÓÖ×öÁËÁíÍâÒ»¸ö²âÊÔ£»ÔÚÕâ¸ö²âÊÔÖÐLab01×÷Ϊһ¸ö·ÓÉÆ÷¹¤×÷£¬²âÊÔÍøÂçÍØÆËͼÈçÏ£º
PC----Lab01----Firewall¡£
ÔÚFirewllÉÏÖ´ÐÐÃüÁî"ping -c 1 PC"ºóÎÒ×Ðϸ²é¿´ Lab01µÄ/var/log/messagesÎļþ£¬Í¬Ñù£¬¸ù¾Ý"6. Traversing of tables and chains"²¿·ÖËù½²£¬ÎÒÆÚ´ýÔÚ/var/log/messagesÖп´µ½ÓÉÉÏÊöpingÃüÁî²úÉúµÄicmp°ü°´ÕÕÏÂÃæµÄ´ÎÐò´©¹ýiptables£º
mangle(PREROUTING)->nat(PREROUTING)->mangle(FORWARD)->filter(FORWARD)->mangle(POSTROUTING)->nat(POSTROUTING) (icmp-type Ϊ"echo request"µÄÊý¾Ý°ü),
mangle(PREROUTING)->nat(PREROUTING)->mangle(FORWARD)->filter(FORWARD)->mangle(POSTROUTING)->nat(POSTROUTING) (icmp-typeΪ "echo reply"µÄÊý¾Ý°ü).
µ«ÊÇÊÂʵÉÏÎÒÔÚ/var/log/messagesÖп´µ½ÉÏÊöpingÃüÁî²úÉúµÄicmp°üÊǰ´ÕÕÏÂÃæµÄ´ÎÐò´©¹ýiptablesµÄ£º
mangle(PREROUTING)->nat(PREROUTING)->mangle(FORWARD)->filter(FORWARD)->mangle(POSTROUTING)->nat(POSTROUTING) (icmp-type Ϊ"echo request"µÄÊý¾Ý°ü),
mangle(PREROUTING)->mangle(FORWARD)->filter(FORWARD)->mangle(POSTROUTING) (¸ù±¾Ã»Óо¹ýnat(PREROUTING)&nat(POSTROUTING)Á½¸öÁ´¡£) (icmp-typeΪ "echo reply"µÄÊý¾Ý°ü).
ÕâÓ¦¸ÃÈçºÎ½âÊÍ£¿
ÎÒÈ·ÐÅ×Ô¼ºÒѾÕýÈ·Ö´ÐÐÁ˽ű¾rc.test-iptables.txt£¬ÎÒÈ·ÐÅ×Ô¼ºÔڲ鿴Lab01ÉϵÄÎļþ
/var/log/messagesʱûÓп´´í¡£
ÆÚ´ý¸÷λǰ±²²»Áߴͽ̣¬Ð»Ð»¡£
Ò³:
[1]