找回密码
 立即注册
搜索
热搜: 活动 交友 discuz
查看: 9|回复: 0

iptables 求助

[复制链接]

148

主题

690

回帖

1856

积分

金牌会员

积分
1856
发表于 2012-12-26 11:38:08 | 显示全部楼层 |阅读模式
一键包装的pptp/l2tp  现在ipsec验证 xl2tp等服务都正常,就是l2tp连不上(678),应该是iptables 的问题,求高手解惑

# Generated by iptables-save v1.3.5 on Tue Dec 25 19:26:00 2012
*nat


REROUTING ACCEPT [1:40]


OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 8.8.8.8
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 8.8.4.4
-A POSTROUTING -s 10.10.77.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.88.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.99.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.77.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
-A POSTROUTING -s 10.10.88.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
-A POSTROUTING -s 10.10.99.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
COMMIT
# Completed on Tue Dec 25 19:26:00 2012
# Generated by iptables-save v1.3.5 on Tue Dec 25 19:26:00 2012
*filter
:INPUT ACCEPT [51501:66947707]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [28105:2455938]
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i tun+ -j ACCEPT
-A INPUT -i tap+ -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 500 -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 4500 -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 1701 -j ACCEPT
-A FORWARD -i tun+ -j ACCEPT
-A FORWARD -i tap+ -j ACCEPT
COMMIT
# Completed on Tue Dec 25 19:26:00 2012
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|Discuz! X

GMT+8, 2025-1-11 15:09 , Processed in 0.020061 second(s), 6 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表