clansman
(usa Debian)
Enviado em 17/04/2013 - 11:53h
Buckminster escreveu:
Posta teu script do IPtables aqui.
Opa, segue :
#--------------------------------------------------------------------------------------
#Antes de criar as ROTAS e REGRAS Monta particao para backup;
mount /dev/sdb1 /hd_backup/
#limpando as regras ####
iptables -t filter -F
iptables -t nat -F
# Carregando modulos
modprobe iptable_nat
modprobe ip_conntrack_ftp
modprobe ip_nat_ftp
modprobe ipt_LOG
modprobe ipt_MASQUERADE
modprobe ipt_multiport
modprobe iptable_mangle
modprobe ipt_tos
modprobe ipt_limit
modprobe ipt_mark
modprobe ipt_MARK
####### Definicao de Policiamento ######
# Tabela filter
iptables -t filter -P INPUT ACCEPT
iptables -t filter -P OUTPUT ACCEPT
iptables -t filter -P FORWARD ACCEPT
# Tablea nat
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P OUTPUT ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
# Tabela mangle
iptables -t mangle -P PREROUTING ACCEPT
iptables -t mangle -P POSTROUTING ACCEPT
iptables -t mangle -P OUTPUT ACCEPT
iptables -t mangle -P INPUT ACCEPT
iptables -t mangle -P FORWARD ACCEPT
#Apagando Rotas
route del -net 0.0.0.0 netmask 0.0.0.0 gw 192.168.1.1
#Criando Rotas
route add -net 192.168.2.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.3.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.4.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.5.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.20.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.30.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.40.0 netmask 255.255.255.0 gw 192.168.10.254
route add -net 192.168.50.0 netmask 255.255.255.0 gw 192.168.10.254
#Direciona pacotes para SQUID
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
#
iptables -A FORWARD -s 192.168.1.100 -d 200.1.1.1 --dport 443 -j ACCEPT
iptables -A FORWARD -s 192.168.1.101 -d 200.1.1.1 --dport 443 -j ACCEPT
#Direciona Para TS
iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 2222 -j DNAT --to-dest 192.168.1.100:3333
#Mascara de Pacotes
iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -o eth1 -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward
#--------------------------------------------------------------------------------------
Ta ai.
flw !