wcorrea
(usa Fedora)
Enviado em 10/03/2011 - 10:30h
A eth0 é a interface de web sim, e estou fazarndoo a conecção po PPPoE
Segue abaixo o meu firewall
#!/bin/bash
#
# Variaveis
LanExt=200.161.254.213
LanInt=192.168.0.5
PlacaExt=eth0
placaInt=eth1
Rede=192.168.0.0/24
# LIMPANDO AS REGRAS
iptables -X
iptables -Z
iptables -F INPUT
iptables -F OUTPUT
iptables -F POSTROUTING -t nat
iptables -F PREROUTING -t nat
iptables -F FORWARD
iptables -F -t nat
iptables -F -t mangle
# POLITICAS PADROES
#iptables -t filter -P INPUT DROP
iptables -t filter -P INPUT ACCEPT
iptables -t filter -P OUTPUT ACCEPT
#iptables -t filter -P FORWARD DROP
iptables -t filter -P FORWARD ACCEPT
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P OUTPUT ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
iptables -t mangle -P PREROUTING ACCEPT
iptables -t mangle -P OUTPUT ACCEPT
# Manter conexoes jah estabelecidas para nao parar
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# Aceita todo o trafego vindo do loopback e indo pro loopback
iptables -t filter -A INPUT -i lo -j ACCEPT
# COMPARTILHAR INTERNET
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -j MASQUERADE
#---> REDIRECIONAMENTO DE PORTAS -------------------------------------------------------------
iptables -t nat -d $LanExt -A PREROUTING -p tcp --dport 1234 -j DNAT --to-destination 192.168.0.3:1234
iptables -t nat -A POSTROUTING -d 192.168.0.3 -p tcp --dport 1234 -j MASQUERADE
iptables -A INPUT -d $LanExt -p tcp --dport 1234 -j ACCEPT
iptables -I FORWARD -d 192.168.0.3 -p tcp --dport 1234 -j ACCEPT