openvpn iptables setting
openvpn nic가 2개 있습니다.
하나는 공인ip, 나머지는 비공인ip로 셋팅되어 있습니다.
windows client에서 접속을 하여 ping을 해 보면
공인ip, 비공인ip, tun0까지 ping이 됩니다.
내부의 비공인ip에 연결이 되게 하고 싶은데
iptables setting을 어떻게 추가해야 하는지요?
iptables -A INPUT -i tun+ -j ACCEPT
iptables -A FORWARD -i tun+ -j ACCEPT
는 추가했는데 추가가 안된 것 같기도하고..
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
vpndog:/# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT 0 -- localhost anywhere
ACCEPT 0 -- vpndog.local anywhere
ACCEPT 0 -- 192.168.100.0/24 anywhere
ACCEPT 0 -- 59.4.128.240 anywhere
ACCEPT 0 -- vpndog.local anywhere
ACCEPT 0 -- 192.168.200.0/24 anywhere
ACCEPT 0 -- 10.8.0.0/24 anywhere
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere vpndog.local multiport dports ftp-data,ftp,ssh,smtp,domain,www,pop3,imap2,https,mysql
ACCEPT udp -- anywhere vpndog.local multiport dports 20,fsp,domain,openvpn
ACCEPT tcp -- anywhere vpndog.local multiport sports ftp-data,ftp,smtp,time,whois,domain,www,https
ACCEPT udp -- anywhere vpndog.local multiport sports domain,openvpn
ACCEPT icmp -- anywhere vpndog.local
DROP tcp -- anywhere vpndog.local tcp spt:netbios-ssn flags:FIN,SYN,RST,ACK/SYN
DROP tcp -- anywhere vpndog.local tcp spt:ripngd flags:FIN,SYN,RST,ACK/SYN
DROP tcp -- anywhere vpndog.local tcp spts:6666:ircd flags:FIN,SYN,RST,ACK/SYN
DROP udp -- anywhere vpndog.local multiport dports loc-srv
LOG 0 -- anywhere anywhere state INVALID LOG level warning prefix `INVALID DROP'
DROP 0 -- anywhere anywhere state INVALID
DROP tcp -- anywhere vpndog.local tcp flags:FIN,SYN,RST,ACK/SYN
ACCEPT 0 -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT 0 -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
댓글 달기