christianmarques
(usa Ubuntu)
Enviado em 09/05/2011 - 18:04h
Prezados, testei várias regras, diversas, mas este IMO parece ter alguma particularidade a mais.
Nenhuma, das centenas regras criadas e replicadas da internet não funcionou.
Minhas regras estão assim:
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state ESTABLISHED
ACCEPT all -- anywhere anywhere state RELATED
ACCEPT all -- anywhere anywhere
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:3128
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:domain
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:bootps
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:bootpc
ACCEPT udp -- 192.168.0.0/24 anywhere udp dpt:domain
ACCEPT udp -- 192.168.0.0/24 anywhere udp dpt:bootps
ACCEPT udp -- 192.168.0.0/24 anywhere udp dpt:bootpc
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:902
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:webmin
ACCEPT udp -- 192.168.0.0/24 anywhere udp dpt:902
ACCEPT icmp -- 192.168.0.0/24 anywhere icmp echo-request
ACCEPT all -- 192.168.0.0/24 anywhere
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT tcp -- anywhere anywhere tcp dpt:8333
ACCEPT tcp -- anywhere anywhere tcp dpt:902
ACCEPT udp -- anywhere anywhere udp dpt:902
ACCEPT tcp -- anywhere anywhere tcp dpt:8222
ACCEPT tcp -- anywhere anywhere tcp dpt:5900
ACCEPT tcp -- anywhere anywhere tcp dpt:8085
LOG all -- anywhere anywhere LOG level warning prefix `INPUT_DROP '
ACCEPT tcp -- 192.168.0.0/24 200.201.173.0/24 tcp dpt:www
ACCEPT tcp -- 192.168.0.0/24 200.201.174.0/24 tcp dpt:www
ACCEPT tcp -- 192.168.0.0/24 200.201.166.0/24 tcp dpt:www
ACCEPT tcp -- anywhere anywhere multiport dports 3550,3650,4550,5550,6550,bootps,bootpc,81,8192,http-alt
ACCEPT all -- anywhere anywhere
ACCEPT udp -- anywhere anywhere udp dpt:openvpn
ACCEPT all -- anywhere anywhere
ACCEPT all -- 10.0.0.0/24 anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:openvpn
ACCEPT udp -- anywhere anywhere udp dpt:openvpn
ACCEPT all -- anywhere anywhere
DROP tcp -- anywhere 64.13.161.61 tcp dpt:https
DROP tcp -- anywhere 64.13.161.61 tcp dpt:https
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere 200.201.174.207 tcp dpt:www
ACCEPT tcp -- anywhere 200.201.166.200 tcp dpt:www
ACCEPT tcp -- anywhere obsupgdp.caixa.gov.br tcp dpt:www
ACCEPT tcp -- anywhere 200.201.174.204 tcp dpt:www
ACCEPT tcp -- anywhere mail.migrate.com.br tcp dpt:www
ACCEPT all -- 192.168.0.0/24 192.168.1.0/24
ACCEPT all -- anywhere anywhere
ACCEPT tcp -- anywhere 161.148.0.0/16 tcp dpt:3456
ACCEPT tcp -- anywhere 200.223.0.0
ACCEPT tcp -- anywhere 200.201.0.0/16
ACCEPT all -- anywhere anywhere state ESTABLISHED
ACCEPT all -- anywhere anywhere state RELATED
ACCEPT all -- 192.168.0.0/24 anywhere
ACCEPT all -- 192.168.0.0/24 atlas.linuxtech.com.br
ACCEPT all -- 192.168.0.0/24 serasa.com.br
ACCEPT all -- 192.168.0.0/24 200.201.166.200
ACCEPT all -- 192.168.0.0/24 obsupgdp.caixa.gov.br
ACCEPT all -- 192.168.0.0/24 200.201.174.207
ACCEPT all -- 192.168.0.0/24 200.201.174.204
ACCEPT all -- 192.168.0.0/24 gestaoar.certisign.com.br
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:smtp
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:pop3
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:ssmtp
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:imaps
ACCEPT tcp -- 192.168.0.0/24 anywhere tcp dpt:https
ACCEPT tcp -- anywhere 192.168.0.2 tcp dpt:8333
ACCEPT tcp -- anywhere 192.168.0.2 tcp dpt:902
ACCEPT tcp -- anywhere 192.168.0.2 tcp dpt:8222
ACCEPT tcp -- anywhere 192.168.0.2 tcp dpt:1722
ACCEPT tcp -- anywhere 192.168.0.2 tcp dpt:8085
ACCEPT tcp -- anywhere 192.168.0.25 tcp dpt:5900
ACCEPT tcp -- anywhere 192.168.0.25 tcp dpt:5800
LOG all -- anywhere anywhere LOG level warning prefix `FORWARD_DROP '
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
DROP tcp -- anywhere 64.13.161.61 tcp dpt:https
DROP tcp -- anywhere 64.13.161.61 tcp dpt:https
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state ESTABLISHED
ACCEPT all -- anywhere anywhere state RELATED
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT tcp -- anywhere dynupdate.no-ip.com
ACCEPT all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level warning prefix `OUTPUT_DROP '
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
ACCEPT tcp -- anywhere anywhere tcp dpt:www
ACCEPT tcp -- anywhere anywhere tcp dpt:https
ACCEPT tcp -- anywhere anywhere tcp dpt:902
ACCEPT tcp -- anywhere anywhere tcp dpt:1722
ACCEPT tcp -- anywhere anywhere tcp dpt:msnp
ACCEPT tcp -- anywhere anywhere tcp dpt:4628
ACCEPT tcp -- anywhere anywhere tcp dpt:5800
ACCEPT tcp -- anywhere anywhere tcp dpt:5900
ACCEPT tcp -- anywhere anywhere tcp dpt:8009
ACCEPT tcp -- anywhere anywhere tcp dpt:8011
ACCEPT tcp -- anywhere anywhere tcp dpt:8012
ACCEPT tcp -- anywhere anywhere tcp dpt:8085
ACCEPT tcp -- anywhere anywhere tcp dpt:8222
ACCEPT tcp -- anywhere anywhere tcp dpt:8333
ACCEPT tcp -- anywhere anywhere tcp dpt:webmin
ACCEPT tcp -- anywhere anywhere tcp dpt:20000
ACCEPT tcp -- anywhere anywhere tcp dpt:16789