iptables

允许端口转发

sudo vi /etc/sysctl.conf
    net.ipv4.ip_forward = 1
sudo sysctl -p
sudo iptables -P FORWARD DROP
sudo iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
sudo iptables -t nat -A PREROUTING -d 127.0.0.1 -p tcp --dport 10445 -j DNAT --to 127.0.0.1:445
sudo iptables -A FORWARD -d 127.0.0.1 -p tcp --dport 10445 -j ACCEPT
sudo iptables -t nat -A POSTROUTING -d 127.0.0.1 -p tcp --dport 445 -j SNAT --to 127.0.0.1:10445

sudo iptables -L -n  --line-number  # 列出所有链
sudo iptables -t nat -L         # 列出所有nat链
sudo iptables -D FORWARD 2      # 删除 FORWARD 链第2项

保存 iptables

/etc/init.d/iptables save       # 保存在 /var/lib/iptables/rules-save
/etc/init.d/iptables restart

你可能感兴趣的:(iptables)