Mandrack
(usa Debian)
Enviado em 13/04/2016 - 16:51h
A mesmas coisas alguns sites abrem bem rápido outros demoram muito pra dar carga mais abrem e o Google não abre de jeito nenhum.
veja o meu firewall Iptables
#!/bin/sh
echo 'script de compartilhamento da internet'
# Carrega os módulos
modprobe iptables
modprobe iptable_nat
# Compartilha a conexão
modprobe iptable_nat
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward
# protege contra pacotes danificados (usados em ataques DoS por exemplo) é:
# iptables -A FORWARD -m unclean -j DROP
# Redireciona para SQUID - Aqui eu travei essas duas linhas pq o squid nao estava rodando bem na rede então liberei pelo Iptables
# iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 3128
# iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 443 -j REDIRECT --to-port 3128
# Abre para a rede local
iptables -A INPUT -p tcp --syn -s 192.168.2.0/255.255.255.0 -j ACCEPT
#Liberando Outlook
iptables -A FORWARD -p udp -s 192.168.2.5 -d 208.67.222.222 --dport 53 -j ACCEPT
iptables -A FORWARD -p udp -s 208.67.222.222 --sport 53 -d 192.168.2.5 -j ACCEPT
# Liberando portas outlook
iptables -A FORWARD -p TCP -s 192.168.2.5 --dport 587 -j ACCEPT
iptables -A FORWARD -p TCP -s 192.168.2.5 --dport 110 -j ACCEPT
iptables -A FORWARD -p tcp --sport 587 -j ACCEPT
iptables -A FORWARD -p tcp --sport 110 -j ACCEPT
#fecha o resto
iptables -A INPUT -p tcp --syn -j DROP
# REGRAS DO SQUID
#
# Squid normally listens to port 3128
http_port 3128
visible_hostname WEBPROXY
acl rede_local src 192.168.2.0/24 #rede local
acl acesso src 192.168.1.1 #link acesso
acl computador src 192.168.2.5 #ip_computador
acl SSL_ports port 443
acl safe_ports port 587 # mail-outlook
acl safe_ports port 110 # mail-outlook
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
#delegando as permissoes e acessos
http_access allow rede_local
http_access allow acesso
http_access allow computador
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
http_access allow localhost
http_access deny all
cache_mem 1024 MB
maximum_object_size_in_memory 512 MB
minimum_object_size 0 KB
maximum_object_size 512 KB
cache_swap_low 90
cache_swap_high 95
cache_dir aufs /var/spool/squid3 2048 16 256
access_log /var/log/squid3/access.log squid
cache_log /var/log/squid3/cache.log
coredump_dir /etc/squid3/var/cache/squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320