全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 377|回复: 0
打印 上一主题 下一主题

iptables 求助

[复制链接]
跳转到指定楼层
1#
发表于 2012-12-26 11:38:08 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
一键包装的pptp/l2tp  现在ipsec验证 xl2tp等服务都正常,就是l2tp连不上(678),应该是iptables 的问题,求高手解惑

# Generated by iptables-save v1.3.5 on Tue Dec 25 19:26:00 2012
*nat
REROUTING ACCEPT [1:40]
OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 8.8.8.8
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 8.8.4.4
-A POSTROUTING -s 10.10.77.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.88.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.99.0/255.255.255.0 -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.10.77.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
-A POSTROUTING -s 10.10.88.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
-A POSTROUTING -s 10.10.99.0/255.255.255.0 -j SNAT --to-source 173.254.240.1
COMMIT
# Completed on Tue Dec 25 19:26:00 2012
# Generated by iptables-save v1.3.5 on Tue Dec 25 19:26:00 2012
*filter
:INPUT ACCEPT [51501:66947707]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [28105:2455938]
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i tun+ -j ACCEPT
-A INPUT -i tap+ -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 500 -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 4500 -j ACCEPT
-A INPUT -d 173.254.240.1 -p udp -m udp --dport 1701 -j ACCEPT
-A FORWARD -i tun+ -j ACCEPT
-A FORWARD -i tap+ -j ACCEPT
COMMIT
# Completed on Tue Dec 25 19:26:00 2012
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2025-11-1 11:29 , Processed in 0.057872 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表