Search K
Appearance
Appearance
iptables 的组件名称为 iptables, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
CONFIG_NETFILTER=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Advanced netfilter configuration
CONFIG_NETFILTER_ADVANCED=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Connection mark tracking support
CONFIG_NF_CONNTRACK=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Network Address Translation support
CONFIG_NF_NAT=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
CONFIG_NETFILTER_XTABLES=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
CONFIG_IP_NF_IPTABLES=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> raw table support (required for NOTRACK/TRACE)
CONFIG_IP_NF_RAW=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> Packet mangling
CONFIG_IP_NF_MANGLE=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> iptables NAT support
CONFIG_IP_NF_NAT=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> IP: Netfilter configuration
# -> IP tables support (required for filtering/masq/NAT)
# -> Packet filtering
CONFIG_IP_NF_FILTER=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_check() {
is_error=false
if ! kernel_config_check CONFIG_NETFILTER; then
is_error=true
fi
if ! kernel_config_check CONFIG_NETFILTER_ADVANCED; then
is_error=true
fi
if ! kernel_config_check CONFIG_NF_CONNTRACK nf_conntrack; then
is_error=true
fi
if ! kernel_config_check CONFIG_NF_NAT nf_nat; then
is_error=true
fi
if ! kernel_config_check CONFIG_NETFILTER_XTABLES x_tables; then
is_error=true
fi
if ! kernel_config_check CONFIG_IP_NF_IPTABLES ip_tables; then
is_error=true
fi
if ! kernel_config_check CONFIG_IP_NF_RAW iptable_raw; then
is_error=true
fi
if ! kernel_config_check CONFIG_IP_NF_MANGLE iptable_mangle; then
is_error=true
fi
if ! kernel_config_check CONFIG_IP_NF_NAT iptable_nat; then
is_error=true
fi
if ! kernel_config_check CONFIG_IP_NF_FILTER iptable_filter; then
is_error=true
fi
if [ "$is_error" == "true" ]; then
return 1
fi
local tables="raw mangle nat filter"
for table in $tables; do
local chains
case $table in
"raw")
chains="PREROUTING OUTPUT"
;;
"mangle")
chains="PREROUTING INPUT FORWARD OUTPUT POSTROUTING"
;;
"nat")
chains="PREROUTING INPUT OUTPUT POSTROUTING"
;;
"filter")
chains="INPUT FORWARD OUTPUT"
;;
*)
echo "invalid table '$table'"
return 1
;;
esac
for chain in $chains; do
if ! iptables_rule_check $table $chain -p tcp --dport 6666 --sport 6666; then
return 1
fi
if ! iptables_rule_check $table $chain -p udp --dport 6666 --sport 6666; then
return 1
fi
done
done
return 0
}iptables MASQUERADE 模块的组件名称为 iptables_masquerade, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> MASQUERADE target support
CONFIG_NETFILTER_XT_TARGET_MASQUERADE=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_masquerade_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_TARGET_MASQUERADE xt_MASQUERADE; then
return 1
fi
if ! iptables_rule_check nat POSTROUTING -j MASQUERADE; then
return 1
fi
}iptables connmark 模块的组件名称为 iptables_connmark, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> ctmark target and match support
CONFIG_NETFILTER_XT_CONNMARK=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_connmark_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_CONNMARK xt_connmark; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m connmark --mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j CONNMARK --set-mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j CONNMARK --restore-mark; then
return 1
fi
}iptables addrtype 模块的组件名称为 iptables_addrtype, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "addrtype" address type match support
CONFIG_NETFILTER_XT_MATCH_ADDRTYPE=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_addrtype_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_ADDRTYPE xt_addrtype; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m addrtype --dst-type LOCAL; then
return 1
fi
}iptables multiport 模块的组件名称为 iptables_multiport, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "multiport" Multiple port match support
CONFIG_NETFILTER_XT_MATCH_MULTIPORT=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_multiport_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_MULTIPORT xt_multiport; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -p udp --dport 6666:6699; then
return 1
fi
}iptables mark 模块的组件名称为 iptables_mark, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> nfmark target and match support
CONFIG_NETFILTER_XT_MARK=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_mark_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MARK xt_mark; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m mark --mark 0x66; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -j MARK --set-mark 0x66; then
return 1
fi
}iptables comment 模块的组件名称为 iptables_comment, 相关内核选项为
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> "comment" match support
CONFIG_NETFILTER_XT_MATCH_COMMENT=y检查工具为
#!/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
iptables_comment_check() {
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_COMMENT xt_comment; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m comment --comment "dodo"; then
return 1
fi
return 0
}