janejane
发表于 2004-10-19 14:26:14
只有一台电脑是LINUX系统!
具体到哪里设,我也不大清楚!
其它电脑只能上一些开放的网址!
janejane
发表于 2004-10-19 14:29:25
我想不通的是为什么我把我的IP加到/ETC/SYSCONFIG/IPTABLES里也还要出现一个密码
lanche
发表于 2004-10-19 14:32:06
只有服务器是Linux,你自己的机器呢?
你现在动的是Linux服务器?请将iptables -L的结果贴出来。
janejane
发表于 2004-10-19 14:35:17
Chain INPUT (policy ACCEPT)
target prot opt source destination
RH-Lokkit-0-50-INPUTall--anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
RH-Lokkit-0-50-INPUTall--anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain RH-Lokkit-0-50-INPUT (2 references)
target prot opt source destination
ACCEPT tcp--anywhere anywhere tcp dpt:ssh flags:SYN,RST,ACK/SYN
ACCEPT tcp--anywhere anywhere tcp dpt:smtp flags:SYN,RST,ACK/SYN
ACCEPT tcp--anywhere anywhere tcp dpt:http flags:SYN,RST,ACK/SYN
ACCEPT tcp--anywhere anywhere tcp dpt:ftp flags:SYN,RST,ACK/SYN
ACCEPT all--anywhere anywhere
ACCEPT all--anywhere anywhere
ACCEPT udp--192.168.8.1 anywhere udp spt:domain
-bash-2.05b#
janejane
发表于 2004-10-19 14:37:36
Firewall configuration written by lokkit
# Manual customization of this file is not recommended.
# Note: ifup-post will punch the current nameservers through the
# firewall; such entries will *not* be listed here.
*mangle
:PREROUTING ACCEPT
:INPUT ACCEPT
:FORWARD ACCEPT
:OUTPUT ACCEPT
:POSTROUTING ACCEPT
COMMIT
*nat
:PREROUTING ACCEPT
:POSTROUTING ACCEPT
:OUTPUT ACCEPT
-A POSTROUTING -s 192.168.8.3 -j MASQUERADE
-A POSTROUTING -s 192.168.8.6 -j MASQUERADE
-A POSTROUTING -s 192.168.8.7 -j MASQUERADE
-A POSTROUTING -s 192.168.8.8 -j MASQUERADE
-A POSTROUTING -s 192.168.8.9 -j MASQUERADE
-A POSTROUTING -s 192.168.8.10 -j MASQUERADE
-A POSTROUTING -s 192.168.8.72 -j MASQUERADE
-A POSTROUTING -s 192.168.8.0/24 -d 219.238.233.202 -j MASQUERADE
janejane
发表于 2004-10-19 14:39:03
# 210.21.115.17 -j MASQUERADE
-A POSTROUTING -s 192.168.8.0/24 -d 219.133.39.250 -j MASQUERADE
COMMIT
*filter
:INPUT ACCEPT
:FORWARD ACCEPT
:OUTPUT ACCEPT
:RH-Lokkit-0-50-INPUT -
-A INPUT -j RH-Lokkit-0-50-INPUT
-A FORWARD -j RH-Lokkit-0-50-INPUT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 22 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 25 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 80 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 21 --syn -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i lo -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i eth0 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p udp -m udp -s 192.168.8.1 --sport 53 -d 0/0 -j ACCEPT
janejane
发表于 2004-10-19 14:42:22
#192.168.8.32 00:E0:4C:3D:1A:E9#jinxiaoning
#192.168.8.41 00:80:C8:55:2C:64
#192.168.8.71 00:50:BA:A5:E9:63
#192.168.8.190 00:80:C8:EA:E6:F3
#192.168.8.11200:40:46:50:06:8A
#192.168.8.20 00:80:C8:EB:2B:B2
#192.168.8.19 00:50:BA:01:3D:73
#192.168.8.72 00:00:1C:50:37:1A #hejinjin
#192.168.8.201 00:80:C8:EE:50:A2
#192.168.8.142 00:80:C8:EB:CB:85
#192.168.8.61 00:80:C8:49:C8:9F
#192.168.8.62 00:40:46:50:06:32
#192.168.8.4 00:00:4C:B1:B0:DB
#192.168.8.140 00:80:C8:E5:45:92
192.168.8.10 00:80:C8:E6:3C:6D
#cpc008
#192.168.8.71 00:50:BA:A5:E9:63
#192.168.8.41 00:80:C8:55:2C:64
#192.168.8.66 00:00:21:E8:79:23
#192.168.8.64 00:40:46:50:07:73
#192.168.8.73 00:D0:09:5E:F4:4C
#192.168.8.123 00:50:BA:67:F9:F5
#192.168.8.38 00:0E:1F:00:93:3E
lanche
发表于 2004-10-19 14:55:01
我在吃饭,等会儿回复。
janejane
发表于 2004-10-19 14:57:45
q我们的不是LINUX系统
lanche
发表于 2004-10-19 15:11:25
当前的iptables配置没有什么特殊,对内网机器都是一视同仁的,重点是要检查客户机的配置。
你要配置的IP为192.168.8.72的机器用的是什么版本的windows,以及什么网络登录方式?顺便将网络属性全贴出来(包含工作组或域、计算机名,是否登录到域及域的名称等,能写上的全写上)。
janejane
发表于 2004-10-19 15:14:55
我的是xp 网关是192.168.8.253和192.168.8.19(这个在拔号器上)
janejane
发表于 2004-10-19 15:17:51
计算机名是hejinjin
工作组是retnt
域是sziric
janejane
发表于 2004-10-19 15:27:33
局域网里的设置是这样的192.168.8.253端口是3128就这么多
lanche
发表于 2004-10-19 15:31:22
你的XP是域登录的方式联入网络,如果没有正确地输入帐号和密码那是无法访问网络的(包括本地网络和外部网络如InterNet的)。
janejane
发表于 2004-10-19 15:32:43
但是他们的可以呀