From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Message-ID: <3E9E2631.7020101@aeroflot-don.ru> Date: Thu, 17 Apr 2003 07:57:37 +0400 From: Igo-aeroflot User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ru-RU; rv:1.3) Gecko/20030309 X-Accept-Language: ru-ru, ru MIME-Version: 1.0 To: community@altlinux.ru Subject: Re: [Comm] nat =?KOI8-R?Q?=CE=C5_=CE=C1=D3=D4=D2=CF=C5=CE_=D7?= =?KOI8-R?Q?_iptables_=C1_=D7=D3=C5=D2=C1=D7=CE=CF_=D2=C1=C2=CF=D4?= =?KOI8-R?Q?=C1=C5=D4?= References: <3E9D40EE.9070108@aeroflot-don.rndavia.ru> In-Reply-To: <3E9D40EE.9070108@aeroflot-don.rndavia.ru> Content-Type: text/plain; charset=KOI8-R; format=flowed Content-Transfer-Encoding: 8bit Sender: community-admin@altlinux.ru Errors-To: community-admin@altlinux.ru X-BeenThere: community@altlinux.ru X-Mailman-Version: 2.0.9 Precedence: bulk Reply-To: community@altlinux.ru List-Unsubscribe: , List-Id: List-Post: List-Help: List-Subscribe: , List-Archive: Archived-At: List-Archive: List-Post: 1 Я останавливаю iptables service iptables stop service iptables status Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination 2 потом конектюсь к ftp://ftp.altlinux.ru b смотрю /proc/net/ipcontract tcp 6 431995 ESTABLISHED src=127.0.0.1 dst=127.0.0.1 sport=32768 dport=3493 src=127.0.0.1 dst=127.0.0.1 sport=3493 dport=32768 [ASSURED] use=1 mark=0 tcp 6 430995 ESTABLISHED src=192.168.89.3 dst=192.168.89.1 sport=3023 dport=993 src=192.168.89.1 dst=192.168.89.3 sport=993 dport=3023 [ASSURED] use=1 mark=0 tcp 6 431951 ESTABLISHED src=192.168.89.3 dst=81.222.130.6 sport=3027 dport=21 src=81.222.130.6 dst=80.80.122.40 sport=21 dport=3027 [ASSURED] use=2 mark=0 tcp 6 34 SYN_SENT src=192.168.89.3 dst=62.118.250.7 sport=3026 dport=21 [UNREPLIED] src=62.118.250.7 dst=80.80.122.40 sport=21 dport=3026 use=1 mark=0 udp 17 25 src=80.80.122.40 dst=192.48.79.30 sport=32779 dport=53 src=192.48.79.30 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 udp 17 20 src=80.80.122.40 dst=194.226.96.30 sport=32779 dport=53 src=194.226.96.30 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 udp 17 131 src=80.80.122.40 dst=195.112.96.132 sport=32779 dport=53 src=195.112.96.132 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 udp 17 24 src=80.80.122.40 dst=81.211.1.234 sport=32779 dport=53 src=81.211.1.234 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 udp 17 20 src=80.80.122.40 dst=195.112.97.17 sport=32779 dport=53 src=195.112.97.17 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 udp 17 0 src=192.168.89.3 dst=192.168.89.1 sport=137 dport=137 src=192.168.89.1 dst=192.168.89.3 sport=137 dport=137 [ASSURED] use=1 mark=0 udp 17 28 src=80.80.122.40 dst=62.118.250.235 sport=32779 dport=53 src=62.118.250.235 dst=80.80.122.40 sport=53 dport=32779 [ASSURED] use=1 mark=0 tcp 6 71 TIME_WAIT src=81.222.130.6 dst=80.80.122.40 sport=20 dport=3028 src=192.168.89.3 dst=81.222.130.6 sport=3028 dport=20 [ASSURED] use=1 mark=0 udp 17 131 src=192.168.89.3 dst=192.168.89.1 sport=3012 dport=53 src=192.168.89.1 dst=192.168.89.3 sport=53 dport=3012 [ASSURED] use=1 mark=0 tcp 6 431437 ESTABLISHED src=192.168.89.3 dst=192.168.89.1 sport=3019 dport=993 src=192.168.89.1 dst=192.168.89.3 sport=993 dport=3019 [ASSURED] use=1 mark=0 tcp 6 430270 ESTABLISHED src=192.168.89.3 dst=192.168.89.1 sport=3020 dport=993 src=192.168.89.1 dst=192.168.89.3 sport=993 dport=3020 [ASSURED] use=1 mark=0 tcp 6 431999 ESTABLISHED src=192.168.89.3 dst=192.168.89.1 sport=3021 dport=22 src=192.168.89.1 dst=192.168.89.3 sport=22 dport=3021 [ASSURED] use=1 mark=0 192.168.89.3 - это комп из локальной сети 192.168.89.1 - это адрес сетевухи которая смотрит в локальную сеть 80.80.122.40 - интернет IP