julianderson
(usa Debian)
Enviado em 26/10/2010 - 16:11h
ola pessoal da vol.
Voces poderia me dizer se as regras do meu firewall estao correto
Figo muito grato pela de ajuda de voce.
#!/bin/sh
#Configuração do Firewall através do iptables
#Interfaces de Rede e Servidores
LAN=192.168.3.1
WAN=192.168.1.116
REDE=192.168.3.0/24
IPTABLES=iptables
$IPTABLES -F
$IPTABLES -X
$IPTALBES -t nat -F
$IPTABLES -t nat -X
$IPTABLES -t mangle -F
$IPTABLES -t mangles -X
$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT ACCEPT
$IPTABLES -P FORWARD DROP
# ativar o redirecionamento no arquivo ip_forward
echo 1 > /proc/sys/net/ipv4/ip_forward
$IPTABLES -t nat -A POSTROUTING -o $WAN -j MASQUERADE
$IPTABLES -t nat -A PREROUTING -i $LAN -p tcp --dport 80 -j REDIRECT --to-port 3128
#habilitando o fluxo interno entre os processos
$IPTABLES -I INPUT -i lo -j ACCEPT
$IPTABLES -I INPUT -i $LAN -j ACCEPT
$IPTABLES -I INPUT -i $LAN -j ACCEPT
#liberar as portas principais do servidor
$IPTABLES -A INPUT -p tcp --dport 80 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 53 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 443 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 25 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 110 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 80 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 53 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 443 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 25 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 110 -j ACCEPT
#liberando a chain INPUT para o localhost:
$IPTABLES -A INPUT -p ALL -s 127.0.0.1 -i lo -j ACCEPT
$IPTABLES -A INPUT -p ALL -s $LAN -i lo -j ACCEPT
$IPTABLES -A INPUT -p ALL -s $WAN -i lo -j ACCEPT
$IPTABLES -A INPUT -m state --state ESTABLISHED -j ACCEPT
$IPTABLES -A INPUT -m state --state RELATED -j ACCEPT
#liberando resposta dos servidores DNS:
$IPTABLES -I INPUT -p udp -s $WAN --dport 53 -j ACCEPT
$IPTABLES -I FORWARD -p udp --sport 53 -d $WAN -j ACCEPT
$IPTABLES -I FORWARD -p udp -s $WAN --dport 53 -j ACCEPT
$IPTABLES -I OUTPUT -p udp --sport 53 -d $WAN -j ACCEPT
$IPTABLES -A INPUT -p tcp -m tcp -m state -s $WAN --state NEW,ESTABLISHED,RELATED -j ACCEPT
#mantendo conexoes ativas:
$IPTABLES -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT