#!/bin/bash
echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe ip_tables
modprobe ip_nat_ftp
/sbin/iptables -F -t nat
/sbin/iptables -F INPUT
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -p tcp -s 0/0 --dport 80 -j REDIRECT --to-ports 3128
iptables -A INPUT -s 192.168.200.0/24 -j ACCEPT
iptables -A INPUT -s 172.16.64.0/24 -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A POSTROUTING -s 172.16.64.0/24 -o eth0 -j MASQUERADE
阅读(488) | 评论(0) | 转发(0) |