VPS配置VPN之后,客户机无法上网
Tofloor
poster avatar
mnday
deepin
2015-08-31 19:06
Author
Hi,
本人在VPS中配置了VPN服务,现在客户端可以连接,我觉得PPTPD服务没有问题。无法上网我觉得是iptables规则有误,各位能否帮忙看看我的转发规则是否正确呢?谢谢。

  1. # Generated by iptables-save v1.4.7 on Mon Aug 31 01:54:12 2015
  2. *nat
  3. :PREROUTING ACCEPT [0:0]
  4. :POSTROUTING ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. -A POSTROUTING -s 192.168.9.0/24 -o eth0 -j MASQUERADE
  7. COMMIT
  8. # Completed on Mon Aug 31 01:54:12 2015
  9. # Generated by iptables-save v1.4.7 on Mon Aug 31 01:54:12 2015
  10. *filter
  11. :INPUT ACCEPT [0:0]
  12. :FORWARD ACCEPT [0:0]
  13. :OUTPUT ACCEPT [31:3060]
  14. -A INPUT -p tcp -m tcp --dport 53 -j ACCEPT
  15. -A INPUT -p gre -j ACCEPT
  16. -A INPUT -p tcp -m tcp --dport 47 -j ACCEPT
  17. -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
  18. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  19. -A INPUT -p icmp -j ACCEPT
  20. -A INPUT -i lo -j ACCEPT
  21. -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
  22. -A INPUT -j REJECT --reject-with icmp-host-prohibited
  23. -A INPUT -p tcp -m tcp --dport 47 -j ACCEPT
  24. -A INPUT -p gre -j ACCEPT
  25. -A INPUT -p udp -m udp --dport 53 -j ACCEPT
  26. -A FORWARD -j REJECT --reject-with icmp-host-prohibited
  27. COMMIT
  28. # Completed on Mon Aug 31 01:54:12 2015
Copy the Code

Reply Favorite View the author
All Replies
pjbright
deepin
2015-09-01 05:25
#1
目测,53已经包含,DNS没有被墙。你客户机可以试试用IP上网,PING VPS的DNS试试
Reply View the author
mnday
deepin
2015-09-01 19:27
#2
问题已解决。删除两条reject规则就work了。
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
Reply View the author
New Thread

Popular Events

More
国际排名
WHLUG