vault backup: 2026-01-05 13:03:55

This commit is contained in:
windyboy
2026-01-05 13:03:55 +08:00
parent 21460fc35d
commit be7c6cdcc9
589 changed files with 396508 additions and 27 deletions
@@ -0,0 +1,103 @@
Great! Since you're using `root`, there's no need to prepend commands with `sudo`. Here's how to configure `iptables` to allow all traffic on `10.194.64.0/24` without `sudo`:
---
### **1. Check Current iptables Rules**
To inspect the current rules:
```bash
iptables -L -v -n
```
---
### **2. Add Rules to Allow All Traffic on the Subnet**
#### **2.1. Allow Incoming Traffic**
```bash
iptables -A INPUT -s 10.194.64.0/24 -j ACCEPT
```
#### **2.2. Allow Outgoing Traffic**
```bash
iptables -A OUTPUT -d 10.194.64.0/24 -j ACCEPT
```
#### **2.3. Allow Forwarded Traffic (if needed)**
If this system acts as a router or forwards traffic:
```bash
iptables -A FORWARD -s 10.194.64.0/24 -j ACCEPT
iptables -A FORWARD -d 10.194.64.0/24 -j ACCEPT
```
---
### **3. Save the iptables Configuration**
To persist these rules across reboots:
#### **3.1. Save Rules (Legacy Method)**
Use `iptables-save` to save the rules into a configuration file:
```bash
iptables-save > /etc/iptables/rules.v4
```
#### **3.2. For Systems Using `netfilter-persistent`**
If `netfilter-persistent` is installed:
```bash
netfilter-persistent save
```
#### **3.3. For RHEL-Based Systems**
If you're on a RHEL-based system:
```bash
service iptables save
```
---
### **4. Verify Rules**
To confirm the rules are applied:
```bash
iptables -L -v -n
```
---
### **5. Optional: Test Connectivity**
Test traffic to and from the `10.194.64.0/24` subnet:
```bash
ping 10.194.64.1
```
---
### **6. Debugging (if needed)**
If traffic is still blocked:
- Look for conflicting `DROP` rules in the `INPUT`, `OUTPUT`, or `FORWARD` chains:
```bash
iptables -L -v -n
```
- Ensure the system's network interface is properly configured.
Let me know if you need help troubleshooting further or additional features like logging specific traffic!