maurolarrat
(usa Ubuntu)
Enviado em 05/05/2011 - 14:06h
# NAO uSO SQUID
root@FIREWALL:~# iptables -L FORWARD
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:30000
ACCEPT udp -- anywhere anywhere udp dpt:30000
ACCEPT tcp -- anywhere anywhere tcp dpt:30000
ACCEPT tcp -- anywhere anywhere tcp dpt:30000
ACCEPT udp -- 189.82.0.0/16 192.168.0.0/24
ACCEPT tcp -- 192.168.0.0/24 189.82.0.0/16
ACCEPT tcp -- 189.82.0.0/16 192.168.0.0/24
ACCEPT udp -- anywhere anywhere udp dpt:6050
ACCEPT tcp -- anywhere anywhere tcp dpt:6050
ACCEPT udp -- anywhere anywhere udp dpt:mmcc
ACCEPT tcp -- anywhere anywhere tcp dpt:mmcc
ACCEPT udp -- anywhere anywhere udp dpt:8010
ACCEPT tcp -- anywhere anywhere tcp dpt:8010
ACCEPT tcp -- 201-36-121-4.intelignet.com.br anywhere tcp dpt:3388
ACCEPT tcp -- 201-36-121-4.intelignet.com.br anywhere tcp dpt:ms-sql-s
ACCEPT tcp -- anywhere anywhere tcp dpts:10001:10220
ACCEPT tcp -- anywhere anywhere tcp dpts:10001:10220
ACCEPT udp -- anywhere anywhere udp dpts:ms-sql-s:ms-sql-m
ACCEPT tcp -- anywhere anywhere tcp dpts:ms-sql-s:ms-sql-m
ACCEPT udp -- anywhere anywhere udp dpt:3389
ACCEPT tcp -- anywhere anywhere tcp dpt:3389
ACCEPT udp -- anywhere anywhere udp dpt:3389
ACCEPT tcp -- anywhere anywhere tcp dpt:3389
ACCEPT udp -- anywhere anywhere udp dpt:3388
ACCEPT tcp -- anywhere anywhere tcp dpt:3388
ACCEPT udp -- anywhere anywhere udp dpt:3388
ACCEPT tcp -- anywhere anywhere tcp dpt:3388
ACCEPT udp -- anywhere anywhere multiport dports 5900,5500,5800
ACCEPT tcp -- anywhere anywhere multiport dports 5900,5500,5800
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "4shared" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "4shared" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "filecrop" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "filecrop" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "rapidshare" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "rapidshare" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "easyshare" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "easyshare" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "megaupload" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "megaupload" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "torrent" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "torrent" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "p2p" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "p2p" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "twitter" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "twitter" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "facebook" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "facebook" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "orkut" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "orkut" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "yahoo" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "yahoo" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "gmail" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "gmail" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "hotmail" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "hotmail" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "youtube" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "youtube" ALGO name bm TO 65535
DROP udp -- !192.168.0.57 anywhere udp dpt:https STRING match "msn" ALGO name bm TO 65535
DROP tcp -- !192.168.0.57 anywhere tcp dpt:www STRING match "msn" ALGO name bm TO 65535
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpts:ftp-data:ssh
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT tcp -- anywhere anywhere multiport dports www,https
ACCEPT tcp -- anywhere anywhere multiport dports www,https
ACCEPT all -- 192.168.0.0/24 200.201.173.0/24
ACCEPT all -- 192.168.0.0/24 200.201.166.0/24
ACCEPT all -- 192.168.0.0/24 200.201.174.0/24
ACCEPT all -- 192.168.0.0/24 200.201.174.0/24
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:3456
ACCEPT tcp -- 192.168.0.0/24 201.23.207.124.nqt.com.br multiport dports supdup,3307
ACCEPT udp -- 192.168.0.0/24 201.23.207.124.nqt.com.br multiport dports 95,3307
ACCEPT tcp -- 201.23.207.124.nqt.com.br 192.168.0.0/24 multiport dports supdup,3307
ACCEPT udp -- 201.23.207.124.nqt.com.br 192.168.0.0/24 multiport dports 95,3307
ACCEPT tcp -- 192.168.0.0/24 201.33.134.55 tcp dpt:http-alt
ACCEPT tcp -- anywhere anywhere multiport dports submission,smtp
ACCEPT tcp -- anywhere anywhere multiport dports submission,smtp
ACCEPT udp -- anywhere anywhere multiport dports submission,25
ACCEPT udp -- anywhere anywhere multiport dports submission,25
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:imaps
ACCEPT tcp -- anywhere anywhere tcp dpt:imaps
ACCEPT tcp -- anywhere anywhere tcp dpt:ssmtp
ACCEPT tcp -- anywhere anywhere tcp dpt:ssmtp