Search K
Appearance
Appearance
iptables 的组件名称为 iptables, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
CONFIG_NETFILTER=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Advanced netfilter configuration
CONFIG_NETFILTER_ADVANCED=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Connection mark tracking support
CONFIG_NF_CONNTRACK=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Network Address Translation support
CONFIG_NF_NAT=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
CONFIG_NETFILTER_XTABLES=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_check() {
is_error=false
if ! kernel_config_check CONFIG_NETFILTER; then
is_error=true
fi
if ! kernel_config_check CONFIG_NETFILTER_ADVANCED; then
is_error=true
fi
if ! kernel_config_check CONFIG_NF_CONNTRACK nf_conntrack; then
is_error=true
fi
if ! kernel_config_check CONFIG_NF_NAT nf_nat; then
is_error=true
fi
if ! kernel_config_check CONFIG_NETFILTER_XTABLES x_tables; then
is_error=true
fi
if [ "$is_error" == "true" ]; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -p tcp --dport 6666 --sport 6666; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666 --sport 6666; then
return 1
fi
}iptables MASQUERADE 模块的组件名称为 iptables_masquerade, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> MASQUERADE target support
CONFIG_NETFILTER_XT_TARGET_MASQUERADE=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_masquerade_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_MASQUERADE xt_MASQUERADE; then
return 1
fi
if ! iptables_rule_check nat POSTROUTING -j MASQUERADE; then
return 1
fi
}iptables connmark 模块的组件名称为 iptables_connmark, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> ctmark target and match support
CONFIG_NETFILTER_XT_CONNMARK=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_connmark_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_CONNMARK xt_connmark; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m connmark --mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j CONNMARK --set-mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j CONNMARK --restore-mark; then
return 1
fi
}iptables addrtype 模块的组件名称为 iptables_addrtype, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "addrtype" address type match support
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_addrtype_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_ADDRTYPE xt_addrtype; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m addrtype --dst-type LOCAL; then
return 1
fi
}iptables multiport 模块的组件名称为 iptables_multiport, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "multiport" Multiple port match support
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_multiport_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_MULTIPORT xt_multiport; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666:6699; then
return 1
fi
}iptables mark 模块的组件名称为 iptables_mark, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> nfmark target and match support
CONFIG_NETFILTER_XT_MARK=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_mark_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MARK xt_mark; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m mark --mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j MARK --set-mark 0x66; then
return 1
fi
}iptables comment 模块的组件名称为 iptables_comment, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "comment" match support
CONFIG_NETFILTER_XT_MATCH_COMMENT=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_comment_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_COMMENT xt_comment; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m comment --comment "dodo"; then
return 1
fi
return 0
}iptables tcpmss 模块的组件名称为 iptables_tcpmss, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "TCPMSS" target support
CONFIG_NETFILTER_XT_TARGET_TCPMSS=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "tcpmss" match support
CONFIG_NETFILTER_XT_MATCH_TCPMSS=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_tcpmss_check() {
local is_error
is_error=false
if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_TCPMSS xt_TCPMSS; then
is_error=true
fi
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_TCPMSS xt_tcpmss; then
is_error=true
fi
if [ "$is_error" == "true" ]; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -p tcp -m tcpmss --mss 666; then
return 1
fi
if ! iptables_rule_check filter FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 666; then
return 1
fi
return 0
}