- 論壇徽章:
- 0
|
服務(wù)器情況如下:
1)A機(jī)器IP地址:218.108.23.52--------》對(duì)外提供訪問(wèn)的IP
2)B機(jī)器IP地址:10.252.0.50---------》內(nèi)部真實(shí)的ftp服務(wù)器地址,ftp服務(wù)器軟件用的 proftp
A機(jī)器對(duì)外提供21號(hào)端口,并通過(guò)nat映射到B機(jī)器上。下面是A機(jī)器上的iptables語(yǔ)句:
# Generated by iptables-save v1.2.11 on Wed Nov 7 17:41:20 2007
*filter
:INPUT ACCEPT [65595:34165759]
:FORWARD ACCEPT [179914:97541584]
:OUTPUT ACCEPT [1843:154216]
-A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --sport 1024:65535 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --sport 20 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 21 -j ACCEPT
-A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 1024:65535 --dport 1024:65535 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 20 -m state --state ESTABLISHED -j ACCEPT COMMIT
# Completed on Wed Nov 7 17:41:20 2007
# Generated by iptables-save v1.2.11 on Wed Nov 7 17:41:20 2007
*nat
REROUTING ACCEPT [967:53787]
OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [1431:100410]
-A PREROUTING -d 218.108.23.52 -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED -j DNAT --to-destination 10.252.0.50:21
-A POSTROUTING -d 10.252.0.50 -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED -j SNAT --to-source 218.108.23.52
-A POSTROUTING -j MASQUERADE
COMMIT
# Completed on Wed Nov 7 17:41:20 2007
另外A服務(wù)器已經(jīng)加載了ip_nat_ftp和ip_conntrack_ftp模塊,并且ip_forward已經(jīng)打開(kāi)轉(zhuǎn)發(fā)
我連接218.108.23.52沒(méi)有反映,用網(wǎng)際快車(chē)連接顯示結(jié)果如下:
Wed Nov 07 16:50:00 2007 正在連接 218.108.23.52 [IP=218.108.23.52:21]
Wed Nov 07 16:50:00 2007 Socket已連接 ,等待歡迎信息
Wed Nov 07 16:50:20 2007 超時(shí).
Wed Nov 07 16:50:20 2007 有錯(cuò)誤發(fā)生!
Wed Nov 07 16:50:20 2007 等待 2秒后重試
Wed Nov 07 16:50:22 2007 正在連接 218.108.23.52 [IP=218.108.23.52:21]
Wed Nov 07 16:50:22 2007 Socket已連接 ,等待歡迎信息
我怎么解決這個(gè)問(wèn)題?? |
|