|
近日装放火墙,尝试将家中的电脑连起来。
最近发现iptables -L -n 时出现121.9.13.185这个IP。 (关闭防火墙就没有了)
Chain INPUT (policy DROP)
target prot opt source destination
DROP all -- 192.168.0.0/16 0.0.0.0/0
DROP all -- 10.0.0.0/8 0.0.0.0/0
DROP all -- 172.16.0.0/12 0.0.0.0/0
DROP all -- 127.0.0.0/8 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 53
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 60022
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 60022
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
LOG icmp -- 0.0.0.0/0 0.0.0.0/0 limit: avg 3/sec burst 5 LOG flags 0 level 6 prefix `ICMP packet IN: '
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 limit: avg 6/min burst 5
syn-flood tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW,RELATED,ESTABLISHED tcp dpt:21
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW,RELATED,ESTABLISHED tcp dpt:20
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 60021,60022,20
ACCEPT tcp -- 192.168.2.0/24 0.0.0.0/0 multiport dports 60021,60022,20
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 60021,60022,20
ACCEPT tcp -- 192.168.2.0/24 0.0.0.0/0 multiport sports 60021,60022,20
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpts:55500:55600
Chain FORWARD (policy DROP)
target prot opt source destination
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 flags:0x17/0x02 #conn/24 > 48
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp spt:53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 53,25,110,80,443,1863,60021
ACCEPT tcp -- 192.168.2.0/24 0.0.0.0/0 multiport dports 53,25,110,80,443,1863,60021
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 53,25,110,80,443,1863,60021
ACCEPT tcp -- 0.0.0.0/0 121.9.13.185 multiport sports 53,25,110,80,443,1863,60021
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 53,25,110,80,443,1863
ACCEPT udp -- 192.168.2.0/24 0.0.0.0/0 multiport dports 53,25,110,80,443,1863
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 multiport sports 53,25,110,80,443,1863
ACCEPT udp -- 0.0.0.0/0 121.9.13.185 multiport sports 53,25,110,80,443,1863
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- 127.0.0.1 127.0.0.1
Chain syn-flood (1 references)
target prot opt source destination
RETURN tcp -- 0.0.0.0/0 0.0.0.0/0 limit: avg 3/sec burst 6
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
-----------------------------------------------------------------------------------------------------
防火墙规则见附件。
近日使用 不带密匙的方式下载了镜象,不知道是否这里有问题,重装软件也是如。 |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有帐号?注册
x
|