iptables做mysql端口映射_jiwang1980_51CTO博客

!/bin/bash

/sbin/iptables  -F
/sbin/iptables  -t nat -F
/sbin/iptables  -P INPUT ACCEPT
/sbin/iptables  -P FORWARD ACCEPT
/sbin/iptables  -P OUTPUT ACCEPT
/sbin/modprobe ip_nat_ftp
/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A INPUT -s  127.0.0.1 -j ACCEPT
/sbin/iptables  -t nat -A PREROUTING  -p tcp --dport 53306 -j DNAT --to 192.168.88.128:3306
/sbin/iptables  -t nat -A POSTROUTING  -j  MASQUERADE

# Generated by iptables-save v1.4.21 on Tue Apr  6 19:21:34 2021
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1:152]
:syn-flood - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT

-A INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT

-A INPUT -p tcp -m state --state NEW -m tcp --dport 2181 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 9092 -j ACCEPT

-A INPUT -p tcp -m state --state NEW -m tcp --dport 8000:8999 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 9000:9999 -j ACCEPT

-A INPUT -p tcp -m state --state NEW -m tcp --dport 20000:30000 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 30000:39999 -j ACCEPT

-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT

-A PREROUTING -p tcp --dport 8089 --to 192.168.0.103:3306 -j DNAT
-A POSTROUTING -j MASQUERADE

COMMIT
# Completed on Tue Apr  6 19:21:34 2021
service iptables restart
iptables -t nat -A PREROUTING -p tcp --dport 8089 -j DNAT --to 192.168.0.103:3306
iptables -t nat -A POSTROUTING -j MASQUERADE
iptables -t nat -nvL
Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:8089 to:192.168.0.103:3306

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination

Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination
    0     0 MASQUERADE  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
Failed to start IPv4 firewall with iptables.

原网址: 访问
创建于: 2021-10-18 10:39:02
目录: default
标签: 无

请先后发表评论
  • 最新评论
  • 总共0条评论