Считаете, что Ubuntu недостаточно дружелюбна к новичкам? Помогите создать новое Руководство для новичков!
0 Пользователей и 1 Гость просматривают эту тему.
iptables -t nat -A POSTROUTING -p tcp --dport 1723 -j SNAT --to-source $OUTADDRiptables -t nat -A PREROUTING -p tcp -d $OUTADDR --dport 1723 -j DNAT --to-destination $SRV:1723
Feb 20 18:47:17 server pptpd[20275]: CTRL: Client 92.50.146.30 control connection startedFeb 20 18:47:18 server pptpd[20275]: CTRL: Starting call (launching pppd, opening GRE)Feb 20 18:47:18 server pppd[20276]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.Feb 20 18:47:18 server pppd[20276]: pptpd-logwtmp: $Version$Feb 20 18:47:18 server pptpd[20275]: GRE: Bad checksum from pppd.Feb 20 18:47:21 server pppd[20276]: sent [CHAP Challenge id=0x47 <634a3c17408ee7de0d9705034d325261>, name = "pptpd"]Feb 20 18:47:21 server pptpd[20275]: GRE: read(fd=6,buffer=805a540,len=8196) from PTY failed: status = -1 error = Input/output error, usually caused by unexpected termination of pppd, check option syntax and pppd logsFeb 20 18:47:21 server pptpd[20275]: CTRL: PTY read or GRE write failed (pty,gre)=(6,7)Feb 20 18:47:21 server pptpd[20275]: CTRL: Reaping child PPP[20276]Feb 20 18:47:21 server pptpd[20275]: CTRL: Client 92.50.146.30 control connection finished
sudo iptables-save
# Generated by iptables-save v1.4.4 on Sun Feb 20 19:03:37 2011*nat:PREROUTING ACCEPT [2867050:203216365]:POSTROUTING ACCEPT [34720:1946845]:OUTPUT ACCEPT [60:5394]...-A PREROUTING -d 92.50.146.30/32 -p tcp -m tcp --dport 1723 -j DNAT --to-destination 192.168.1.2:1723 ...-A POSTROUTING -p tcp -m tcp --dport 1723 -j SNAT --to-source 92.50.146.30 ...*filter:INPUT DROP [509:28318]:FORWARD ACCEPT [54915:18902660]:OUTPUT ACCEPT [280:288244]...-A INPUT -p gre -j ACCEPT -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT ...
-A POSTROUTING -p tcp -m tcp --sport 1723 -j SNAT --to-source 92.50.146.30
92.50.146.30 - это IP адрес клиента?
/sbin/modprobe -l | grep pptpkernel/net/netfilter/nf_conntrack_pptp.kokernel/net/ipv4/netfilter/nf_nat_pptp.ko
/sbin/modprobe -l | grep grekernel/net/sched/sch_gred.kokernel/net/sched/sch_ingress.kokernel/net/netfilter/nf_conntrack_proto_gre.kokernel/net/ipv4/netfilter/nf_nat_proto_gre.kokernel/net/ipv4/ip_gre.ko
это какие модули доступныа какие подгружены?
lsmod | grep pptpnf_nat_pptp 1920 0 nf_conntrack_pptp 4413 1 nf_nat_pptpnf_conntrack_proto_gre 4021 1 nf_conntrack_pptpnf_nat_proto_gre 1259 1 nf_nat_pptpnf_nat 15735 3 nf_nat_pptp,nf_nat_proto_gre,iptable_natnf_conntrack 61615 8 xt_conntrack,xt_state,nf_nat_pptp,nf_conntrack_pptp,nf_conntrack_proto_gre,iptable_nat,nf_nat,nf_conntrack_ipv4
lsmod | grep grenf_conntrack_proto_gre 4021 1 nf_conntrack_pptpnf_nat_proto_gre 1259 1 nf_nat_pptpnf_nat 15735 3 nf_nat_pptp,nf_nat_proto_gre,iptable_natnf_conntrack 61615 8 xt_conntrack,xt_state,nf_nat_pptp,nf_conntrack_pptp,nf_conntrack_proto_gre,iptable_nat,nf_nat,nf_conntrack_ipv4
sudo iptables -t nat -A POSTROUTING -p gre -j SNAT --to-source 92.50.146.30
Код: [Выделить]sudo iptables -t nat -A POSTROUTING -p gre -j SNAT --to-source 92.50.146.30
iptables -t nat -A PREROUTING -p gre .....
sudo modprobe -v nf_nat_pptp; sudo modprobe -v nf_conntrack_pptp; sudo modprobe -v nf_conntrack_proto_gre; sudo modprobe -v nf_nat_proto_gresudo sysctl -w net.ipv4.ip_forward=1
# Generated by iptables-save v1.4.4 on Mon Feb 14 19:26:32 2011*filter:INPUT DROP [0:0]:FORWARD DROP [0:0]:OUTPUT ACCEPT [0:0]-A INPUT -m conntrack --ctstate INVALID -j DROP-A INPUT -i ! lo -m addrtype --src-type LOCAL -j DROP-A INPUT -i lo -j ACCEPT-A INPUT -i eth0 -p udp -m udp --sport 67 --dport 68 -j ACCEPT-A INPUT -i eth1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT-A INPUT -i eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT-A INPUT -i eth1 -m conntrack --ctstate NEW -j ACCEPT-A FORWARD -m conntrack --ctstate INVALID -j DROP-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT-A FORWARD -p gre -j ACCEPT-A FORWARD -i eth1 -s 192.168.1.0/24 -p icmp -j ACCEPTCOMMIT# Completed on Mon Feb 14 19:26:32 2011# Generated by iptables-save v1.4.4 on Mon Feb 14 19:26:32 2011*nat:PREROUTING ACCEPT [0:0]:OUTPUT ACCEPT [0:0]:POSTROUTING ACCEPT [0:0] -A PREROUTING -i eth0 -p tcp -m tcp --dport 1723 -j DNAT --to-destination 192.168.1.2:1723-A POSTROUTING -s 192.168.1.2/32 -o eth0 -j SNAT --to-source 92.50.146.30COMMIT# Completed on Mon Feb 14 19:26:32 2011# Generated by iptables-save v1.4.4 on Mon Feb 14 19:26:32 2011*mangle:PREROUTING ACCEPT [0:0]:INPUT ACCEPT [0:0]:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]:POSTROUTING ACCEPT [0:0]-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtuCOMMIT# Completed on Mon Feb 14 19:26:32 2011
Страница сгенерирована за 0.029 секунд. Запросов: 21.