Доброго времени суток.
Не могу понять в чём причина, но при отключённом iptables есть доступ к серверу по имени, а при включённом доступ только по ip. Причём в iptables всё разрешено и политики по умолчанию разрешены:
*mangle
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
COMMIT
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A PREROUTING -i enp5s0 -j ACCEPT
-A PREROUTING -i enp6s0 -j ACCEPT
-A PREROUTING -i enp8s0 -j ACCEPT
-A PREROUTING -j LOG --log-prefix "--PREROUTING "
-A POSTROUTING -s 192.168.100.0/24 -j SNAT --to-source 192.168.1.5
-A POSTROUTING -s 192.168.50.0/24 -j SNAT --to-source 192.168.1.5
-A POSTROUTING -s 192.168.0.0/24 -j SNAT --to-source 192.168.1.5
-A POSTROUTING -j LOG --log-prefix "--POSTROUTING "
COMMIT
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
#--------------------------
-A INPUT -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p udp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp --dport 80 -j ACCEPT
#---------------------------------------------1
-A INPUT -d 192.168.1.5 -p tcp --dport 80 -j ACCEPT
-A INPUT -d 192.168.1.5 -p tcp --dport 22 -j ACCEPT
-A OUTPUT -s 192.168.1.5 -j ACCEPT
-A INPUT -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
-A OUTPUT -s 127.0.0.1 -d 127.0.0.1 -j ACCEPT
-A INPUT -s 192.168.0.0/24 -j ACCEPT
-A INPUT -s 192.168.50.0/24 -j ACCEPT
-A INPUT -s 192.168.100.0/24 -j ACCEPT
-A OUTPUT -s 192.168.0.0/24 -j ACCEPT
-A OUTPUT -s 192.168.50.0/24 -j ACCEPT
-A OUTPUT -s 192.168.100.0/24 -j ACCEPT
-A INPUT -d 192.168.1.5 -j DROP
#-----------------------------------VNC
-A INPUT -p tcp --dport 5900:5902 -j ACCEPT
-A INPUT -p udp --dport 5900:5902 -j ACCEPT
-A INPUT -j LOG --log-prefix " INPUT none "
-A OUTPUT -j LOG --log-prefix " OUTPUT none "
-A FORWARD -s 192.168.100.0/24 -j ACCEPT
-A FORWARD -s 192.168.50.0/24 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -j ACCEPT
-A FORWARD -d 192.168.100.0/24 -j ACCEPT
-A FORWARD -d 192.168.50.0/24 -j ACCEPT
-A FORWARD -d 192.168.0.0/24 -j ACCEPT
-A FORWARD -s 192.168.100.0/24 -j LOG --log-prefix "--FORWARD 100 "
-A FORWARD -s 192.168.50.0/24 -j LOG --log-prefix "--FORWARD 50 "
-A FORWARD -s 192.168.0.0/24 -j LOG --log-prefix "--FORWARD 0 "
-A FORWARD -j LOG --log-prefix " FORWARD none "
COMMIT
В Samba тоже вроде бы всё нормально:
[global]
log file = /var/log/samba/%m.log
load printers = no
domain master = no
hide dot files = yes
map to guest = Bad Password
show add printer wizard = no
encrypt passwords = yes
wins support = true
dns proxy = no
netbios name = data-server
server string = Data server
dos charset = cp866
local master = Yes
workgroup = WORK
os level = 50
security = user
preferred master = yes
unix charset = UTF8
max log size = 50
disable spoolss = yes
OS CentOS 7 x64
Уже не знаю куда копать. В Selinux тоже вроде бы всё разрешил