Rafael Luz
(usa Ubuntu)
Enviado em 15/07/2011 - 12:15h
Eu nao sei o que aconteceu...
Reiniciei o servidor e agora nao consigo acessar a internet nos PCs da rede, somente do servidor...
O iptables esta assim:
# Generated by iptables-save v1.4.8 on Fri Jul 15 12:13:28 2011
*mangle
:PREROUTING ACCEPT [50570:7130470]
:INPUT ACCEPT [23901:5649336]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [20278:14747745]
:POSTROUTING ACCEPT [20579:14780295]
COMMIT
# Completed on Fri Jul 15 12:13:28 2011
# Generated by iptables-save v1.4.8 on Fri Jul 15 12:13:28 2011
*nat
:PREROUTING ACCEPT [27008:1519778]
:POSTROUTING ACCEPT [120:9456]
:OUTPUT ACCEPT [542:36250]
-A PREROUTING -p tcp -m tcp --dport 8008 -j DNAT --to-destination 192.168.2.8:8008
-A PREROUTING -p tcp -m tcp --dport 8007 -j DNAT --to-destination 192.168.2.7:8007
-A PREROUTING -p tcp -m tcp --dport 8006 -j DNAT --to-destination 192.168.2.6:8006
-A PREROUTING -p tcp -m tcp --dport 8005 -j DNAT --to-destination 192.168.2.5:8005
-A PREROUTING -p tcp -m tcp --dport 8004 -j DNAT --to-destination 192.168.2.4:8004
-A PREROUTING -p tcp -m tcp --dport 8003 -j DNAT --to-destination 192.168.2.3:8003
-A PREROUTING -p tcp -m tcp --dport 8002 -j DNAT --to-destination 192.168.2.2:8002
-A PREROUTING -p tcp -m tcp --dport 3558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 4558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 5558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 6558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 3557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 4557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 5557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 6557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 3556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 4556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 5556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 6556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 3555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 4555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 5555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 6555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 3554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 4554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 5554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 6554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 3553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 4553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 5553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 6553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 3552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 4552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 5552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 6552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 8008 -j DNAT --to-destination 192.168.2.8:8008
-A PREROUTING -p tcp -m tcp --dport 8007 -j DNAT --to-destination 192.168.2.7:8007
-A PREROUTING -p tcp -m tcp --dport 8006 -j DNAT --to-destination 192.168.2.6:8006
-A PREROUTING -p tcp -m tcp --dport 8005 -j DNAT --to-destination 192.168.2.5:8005
-A PREROUTING -p tcp -m tcp --dport 8004 -j DNAT --to-destination 192.168.2.4:8004
-A PREROUTING -p tcp -m tcp --dport 8003 -j DNAT --to-destination 192.168.2.3:8003
-A PREROUTING -p tcp -m tcp --dport 8002 -j DNAT --to-destination 192.168.2.2:8002
-A PREROUTING -p tcp -m tcp --dport 3558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 4558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 5558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 6558 -j DNAT --to-destination 192.168.2.8
-A PREROUTING -p tcp -m tcp --dport 3557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 4557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 5557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 6557 -j DNAT --to-destination 192.168.2.7
-A PREROUTING -p tcp -m tcp --dport 3556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 4556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 5556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 6556 -j DNAT --to-destination 192.168.2.6
-A PREROUTING -p tcp -m tcp --dport 3555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 4555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 5555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 6555 -j DNAT --to-destination 192.168.2.5
-A PREROUTING -p tcp -m tcp --dport 3554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 4554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 5554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 6554 -j DNAT --to-destination 192.168.2.4
-A PREROUTING -p tcp -m tcp --dport 3553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 4553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 5553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 6553 -j DNAT --to-destination 192.168.2.3
-A PREROUTING -p tcp -m tcp --dport 3552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 4552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 5552 -j DNAT --to-destination 192.168.2.2
-A PREROUTING -p tcp -m tcp --dport 6552 -j DNAT --to-destination 192.168.2.2
-A POSTROUTING -s 192.168.122.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.122.0/24 -j MASQUERADE
-A POSTROUTING -o eth1 -j MASQUERADE
-A POSTROUTING -o eth1 -j MASQUERADE
COMMIT
# Completed on Fri Jul 15 12:13:28 2011
# Generated by iptables-save v1.4.8 on Fri Jul 15 12:13:28 2011
*filter
:INPUT ACCEPT [23901:5649336]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [20278:14747745]
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
-A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o virbr0 -j ACCEPT
-A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A FORWARD -p tcp -m limit --limit 1/sec -j ACCEPT
-A FORWARD -i eth2 -o eth1 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j ACCEPT
-A FORWARD -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A FORWARD -p tcp -m limit --limit 1/sec -j ACCEPT
-A FORWARD -i eth2 -o eth1 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j ACCEPT
COMMIT
# Completed on Fri Jul 15 12:13:28 2011