Enviado em 30/09/2016 - 11:14h
Bom dia Pessoal,
iptables -F
iptables -X
iptables -F -t nat
iptables -X -t nat
iptables -F -t mangle
iptables -X -t mangle
modprobe ip_tables
modprobe iptable_nat
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
# Aceitar loopback.
iptables -A INPUT -i lo -j ACCEPT
# Rejeita pacotes TCP novos de conexoes nao estabelecidas.
iptables -A FORWARD -p tcp ! --syn -m state --state NEW -j DROP
# Aceitar pacotes de conexoes ja estabelecidas.
iptables -A INPUT -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
# Aceitar envio de pacotes novos para fora.
iptables -A OUTPUT -m state --state ESTABLISHED,RELATED,NEW -j ACCEPT
#iptables -A FORWARD -s 192.168.2.10 -p tcp -i eth1 --dport 80 -j REJECT
# Aceitar direcionamento de conexoes novas.
iptables -A FORWARD -m state --state ESTABLISHED,RELATED,NEW -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A INPUT -p icmp -j ACCEPT
iptables -A INPUT -p tcp --sport 53 -j ACCEPT
iptables -A INPUT -p udp --sport 53 -j ACCEPT
iptables -A INPUT -p tcp --sport 953 -j ACCEPT
iptables -A INPUT -p udp -m udp --dport 53 -j ACCEPT
iptables -A INPUT -m state --state NEW -m tcp -p tcp --dport 53 -j ACCEPT
iptables -A INPUT -m state --state NEW -m udp -p udp --dport 53 -j ACCEPT
iptables -t nat -A PREROUTING -s 192.168.2.0/24 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -s 192.168.2.0/24 -p tcp --dport 443 -j REDIRECT --to-port 3128
iptables -A FORWARD -s 192.168.2.0/24 -p tcp --dport 443 -j DROP
iptables -A FORWARD -s 192.168.2.0/24 -p tcp --dport 80 -j DROP
option wpad code 252 = text;
option wpad "http://wpad.dominio.com/wpad.dat\n";
ddns-update-style none;
ddns-domainname "dominio.com";
option domain-name "dominio.com";
option domain-name-servers 192.168.2.1, 8.8.8.8, 8.8.4.4;
default-lease-time 600;
max-lease-time 7200;
log-facility local7;
subnet 192.168.2.0 netmask 255.255.255.0 {
range 192.168.2.10 192.168.2.99;
option broadcast-address 192.168.2.254;
option routers 192.168.2.1;
}