dazhu100 发表于 2007-10-31 22:30:12

求助

哪位高手能给我解释下面的语句吗?
iptables -t nat -P PREROUTING DROP
iptables -t nat -A PREROUTING -s 192.168.1.104 -m mac --mac-source ! 00-13-D3-3C-D1-71 -j DROP
iptables -t nat -A PREROUTING -s 192.168.1.104 -j ACCEPT
iptables -t nat -A PREROUTING -s 192.168.1.105 -m mac --mac-source ! 00-13-D3-3C-CE-20 -j DROP
iptables -t nat -A PREROUTING -s 192.168.1.105 -j ACCEPT
iptables -t nat -A PREROUTING -s 192.168.1.106 -m mac --mac-source ! 00-13-D3-3C-D1-72 -j DROP
iptables -t nat -A PREROUTING -s 192.168.1.106 -j ACCEPT
iptables -t nat -A PREROUTING -s 192.168.1.107 -m mac --mac-source ! 00-13-D3-3C-CF-3F -j DROP
iptables -t nat -A PREROUTING -s 192.168.1.107 -j ACCEPT

大致意思我明白,我想了解详细点,并想将这将第一句改为限网段如192.168.1.1/24都绑定 其它网段不绑定

qtdszws 发表于 2007-12-10 16:54:23

规则写的极锉,谁写的?

NAT表中最好只有SNAT和DNAT两个target
页: [1]
查看完整版本: 求助