1 | iptables-save > /etc/iptables.rules |
1 2 3 4 5 6 7 | <![CDATA[ auto eth0 iface eth0 inet static address 99.99.99.0 netmask 255.255.255.0 pre-up iptables-restore < /etc/iptables.rules ]]> |
1 2 3 4 | iptables -A FORWARD -s 192.168.0.0/255.255.0.0 -i eth0 -o eth1 -m\ conntrack --ctstate NEW -j ACCEPT iptables -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT iptables -A POSTROUTING -t nat -j MASQUERADE |
1 | sh -c "echo 1 > /proc/sys/net/ipv4/ip_forward" |
1 2 | net.ipv4.conf.default.forwarding=1 net.ipv4.conf.all.forwarding=1 |
1 2 3 | echo 1024 > /proc/sys/net/ipv4/neigh/default/gc_thresh1 echo 2048 > /proc/sys/net/ipv4/neigh/default/gc_thresh2 echo 4096 > /proc/sys/net/ipv4/neigh/default/gc_thresh3 |
1 2 3 4 5 6 | Nov 22 11:36:16 firewall kernel: [92374.325689] Neighbour table overflow. Nov 22 11:36:20 firewall kernel: [92379.089870] printk: 37 messages suppressed. Nov 22 11:36:20 firewall kernel: [92379.089876] Neighbour table overflow. Nov 22 11:36:26 firewall kernel: [92384.333161] printk: 51 messages suppressed. Nov 22 11:36:26 firewall kernel: [92384.333166] Neighbour table overflow. Nov 22 11:36:30 firewall kernel: [92389.084373] printk: 200 messages suppressed. |
欢迎光临 电子技术论坛_中国专业的电子工程师学习交流社区-中电网技术论坛 (http://bbs.eccn.com/) | Powered by Discuz! 7.0.0 |