Enviado em 23/07/2013 - 10:57h
Senhores, bom dia!
#!/bin/bash
iniciar(){
#Compartilhar a conexao
modprobe iptable_nat
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -s 0/0 -j MASQUERADE
iptables -A FORWARD -s 0/0 -d 0/0 -j ACCEPT
echo "Compartilhamento ativado"
#Proxy Transparente
#iptables -t nat -A PREROUTING -s 192.168.0.0/16 -p tcp --dport 80 -j REDIRECT --to-port 3128
#echo "Proxy transparente ativado"
#Permite conexoes na interface de rede local e na porta 22 465 993
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
iptables -A INPUT -p tcp --dport 2525 -j ACCEPT
iptables -A INPUT -p tcp --dport 110 -j ACCEPT
#Regras basicas de firewall
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -s 192.168.0.0/24 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
echo 1 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -p tcp --syn -j DROP
#Bloqueia as portas UDP de 0 a 1023
iptables -A INPUT -p udp --dport 0:1023 -j DROP
echo "Regras de firewall e compartilhamento ativados"
}
parar(){
iptables -F
iptables -t nat -F
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
echo 0 > /proc/sys/net/ipv4/ip_forward
echo "Regras de firewall e compartilahmento desativados"
}
case "$1" in
"start") iniciar ;;
"stop") parar ;;
"restart") parar; iniciar ;;
*) echo "Use os parametros start ou stop"
esac
===========================================================================
e o do squid
===========================================================================
http_port 3128
visible_hostname fw-001
cache_mgr carlos.werner@gmail.com
#
hierarchy_stoplist cgi-bin ?
#
error_directory /usr/share/squid3/errors/Portuguese
#
#
acl all src
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl SSL_ports port 443 563
acl Safe_ports port 21 80 443 563 70 210 280 488 59 777 901 1025-65535
acl purge method PURGE
acl CONNECT method CONNECT
http_access allow manager localhost
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
#Bloqueio de sites por URL
acl sites_liberados url_regex -i "/etc/squid3/regras/sites_liberados"
http_access allow sites_liberados
#Bloqueio de sites por URL
acl sites_proibidos url_regex -i "/etc/squid3/regras/sites_proibidos"
http_access deny sites_proibidos
# Bloqueio de downloads por extensão
#acl downloads_proibidos url_regex -i \.exe \.torrent \.avi
#http_access deny downloads_proibidos
#
#
acl redelocal src 192.168.0.0/16
#
http_access allow localhost
http_access allow redelocal
http_access allow all
===========================================================================