【问题标题】:iptables ip rule fwmark doesn' t workiptables ip rule fwmark 不起作用
【发布时间】:2015-12-04 09:21:28
【问题描述】:

我正在尝试创建 iptables 并将其标记为 ip 规则。 标记不起作用。

# ip rule
0:      from all lookup local 
32762:  from all fwmark 0x2 lookup rteth4 
32763:  from all fwmark 0x1 lookup rteth4 
32764:  from all to 93.xxx.xxx.xxx lookup rteth4 
32765:  from 93.xxx.xxx.xxx lookup rteth4 
32766:  from all lookup main 
32767:  from all lookup default

# iptables -A INPUT -j MARK --set-mark 2

# iptables-save > /etc/network/iptables.up.rules

# iptables-apply

# iptables -L INPUT --line-number
Chain INPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    MARK       all  --  anywhere             anywhere             MARK set 0x2

如何应用这个:iptables -L INPUT --line-number 使用表 rteth4? 以及如何创建匹配 localhost:port 请求的 iptables 命令?

谢谢

【问题讨论】:

    标签: linux ip iptables rule


    【解决方案1】:

    IPTABLES 和路由表没有任何关系,你的意思是应用 iptables 来使用表 rteth4。

    要标记数据包,最好放在PREROUTING 链中,最好是mangle 表。

    要将数据包标记为匹配 localhost:23,您可以这样做:

    iptables -t mangle -I PREROUTING -d localhost -p tcp --dport 23 -j MARK --set-mark 2
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2022-08-22
      • 2017-08-02
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多