adyfeitosa
(usa Outra)
Enviado em 19/02/2013 - 20:30h
brunoh1n1 escreveu:
Qual serviço esse linux está fornecendo?? proxy??
configura no etc/hosts que é pra ir
apenas ip e endereço
abraço.
Amigo boa noite!
O meu cenario é esse: uso proxy transparente, onde o meu arquivo rc.local faço a minha configuração do firewall e uso também o squid3.
Arquivo rc.local
************************************************
# Limpando o Cache
service squid3 stop
rm -rf /var/cache/squid3/*
cd /var/cache/
chown proxy /var/cache/squid3
chgrp proxy /var/cache/squid3
squid3 -z
service squid3 start
##############################################
# Compatilhando a Internet
##############################################
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
modprobe iptable_nat
iptables -A POSTROUTING -t nat -s 192.168.254.0/24 -o eth0 -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
echo 1 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth1 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --syn -j DROP
echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_all
iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
iptables -A FORWARD -p tcp --dport 8080 -j ACCEPT
iptables -A FORWARD -p tcp --dport 3389 -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 8080 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 3389 -j REDIRECT --to-port 3128
echo nameserver 8.8.8.8 > /etc/resolv.conf
echo nameserver 8.8.4.4 >> /etc/resolv.conf
echo nameserver 200.165.132.155 >> /etc/resolv.conf
exit 0