daniel.todero
(usa CentOS)
Enviado em 02/12/2010 - 09:39h
Bom Dia Renato,
na hora de escrever aqui no fórum, que coloquei a posição da porta errada.. mas está correto sim!
Segue o script das regras.
#####################################
## Habilitaçoes Especificas ##
#####################################
echo "1" > /proc/sys/net/ipv4/ip_forward
#echo "1" > /proc/sys/net/ipv4/tcp_syncookies
#echo "0" > /proc/sys/net/ipv4/ip_dynaddr
#echo "0" > /proc/sys/net/ipv4/conf/all/rp_filter
#echo "0" > /proc/sys/net/ipv4/conf/all/accept_source_route
echo "1" > /proc/sys/net/ipv4/conf/all/accept_redirects
#echo "0" > /proc/sys/net/ipv4/conf/all/log_martians
#echo "0" > /proc/sys/net/ipv4/icmp_echo_ignore_all
#echo "0" > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
#echo "1" > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses
##### Carregando modulos #####
/sbin/modprobe ip_conntrack
/sbin/modprobe ip_conntrack_ftp
/sbin/modprobe ip_nat_ftp
/sbin/modprobe ipt_LOG
/sbin/modprobe ip_tables
/sbin/modprobe ipt_state
/sbin/modprobe iptable_nat
/sbin/modprobe ipt_limit
#### LIMPA AS 3 TABELAS
/sbin/iptables -F
/sbin/iptables -t nat -F
/sbin/iptables -t mangle -F
/sbin/iptables -X
/sbin/iptables -t nat -X
/sbin/iptables -t mangle -X
##### DEFAULT PARA OPERACOES EH NEGAR
/sbin/iptables -P INPUT DROP
/sbin/iptables -P FORWARD DROP
/sbin/iptables -P OUTPUT ACCEPT
##### ACEITA LOOP BACK PADRAO E CONECTIVIDADE PADRAO ####
/sbin/iptables -A INPUT -i lo -j ACCEPT
/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A INPUT -i eth0 -j ACCEPT
/sbin/iptables -A OUTPUT -o lo -j ACCEPT
/sbin/iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A FORWARD -o eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A FORWARD -o eth0 -j ACCEPT
/sbin/iptables -A FORWARD -o eth0 -j ACCEPT
/sbin/iptables -A FORWARD -o ppp0 -j ACCEPT
/sbin/iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
/sbin/iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
##### REDIRECIONAMENTOS #####
/sbin/iptables -A FORWARD -o eth1 -p TCP --dport 8089 -d 192.168.8.3 -j ACCEPT
/sbin/iptables -t nat -A PREROUTING -s 0.0.0.0/0 -p tcp -m tcp --dport 8089 -d 201.x.x.x/32 -j DNAT --to-destination 192.168.8.3:8089
##### ENTRADA DA INTERNET #####
/sbin/iptables -A INPUT -i eth1 -p TCP --dport 8089 -j ACCEPT
Muito Obrigado.
Att,
Daniel Tódero