pak kyai, coba paste kesini hasil dari perintah (dinode) : iptables-save
Code:
[root@s110798 ~]# iptables-save
# Generated by iptables-save v1.4.7 on Fri Sep 22 04:44:45 2017
*nat
:PREROUTING ACCEPT [18681:1101397]
:POSTROUTING ACCEPT [11633:821584]
:OUTPUT ACCEPT [15839:1138492]
-A POSTROUTING -s 192.168.0.0/24 ! -d 192.168.0.0/24 -p tcp -j MASQUERADE --to-p orts 1024-65535
-A POSTROUTING -s 192.168.0.0/24 ! -d 192.168.0.0/24 -p udp -j MASQUERADE --to-p orts 1024-65535
-A POSTROUTING -s 192.168.0.0/24 ! -d 192.168.0.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE -- to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE -- to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
-A POSTROUTING -o vmbr0 -j MASQUERADE
COMMIT
# Completed on Fri Sep 22 04:44:45 2017
# Generated by iptables-save v1.4.7 on Fri Sep 22 04:44:45 2017
*mangle
:PREROUTING ACCEPT [2028249:328574317]
:INPUT ACCEPT [177586:131882598]
:FORWARD ACCEPT [1850970:196741798]
:OUTPUT ACCEPT [182862:72954329]
:POSTROUTING ACCEPT [2033315:269627746]
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
COMMIT
# Completed on Fri Sep 22 04:44:45 2017
# Generated by iptables-save v1.4.7 on Fri Sep 22 04:44:45 2017
*filter
:INPUT ACCEPT [76908:94203004]
:FORWARD ACCEPT [605:113444]
:OUTPUT ACCEPT [182862:72955237]
-A INPUT -i virbr1 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr1 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr1 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr1 -p tcp -m tcp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m multiport --dports 111,662,892,1515,2049,3389,32803 -j ACCEPT
-A INPUT -p udp -m multiport --dports 662,892,2049,3389,32769 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 5900:6900 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 15900:16900 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 49152:49261 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m multiport --dports 111,662,892,1515,2049,32803 -j ACCEPT
-A INPUT -p udp -m multiport --dports 662,892,2049,32769 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 5900:6900 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 15900:16900 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 49152:49261 -j ACCEPT
-A INPUT -p udp -m udp --dport 5404:5405 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 21064 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 41966:41969 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 50006:50009 -j ACCEPT
-A INPUT -p udp -m udp --dport 50007 -j ACCEPT
-A FORWARD -d 192.168.0.0/24 -o virbr1 -m state --state RELATED,ESTABLISHED -j A CCEPT
-A FORWARD -s 192.168.0.0/24 -i virbr1 -j ACCEPT
-A FORWARD -i virbr1 -o virbr1 -j ACCEPT
-A FORWARD -o virbr1 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr1 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -s 192.168.0.0/24 -j ACCEPT
-A FORWARD -d 192.168.0.0/24 -j ACCEPT
COMMIT