fazambuja
(usa CentOS)
Enviado em 09/11/2009 - 08:07h
Esse é meu firewall
#!/bin/bash
# zerar regras carregadas anteriormente
/sbin/iptables -F
/sbin/iptables -t nat -F
/sbin/iptables -t mangle -F
/sbin/iptables -X
/sbin/iptables -Z
#habilita ip_forward
echo "1" > /proc/sys/net/ipv4/ip_forward
# politicas padroes
/sbin/iptables -P INPUT ACCEPT
/sbin/iptables -P OUTPUT ACCEPT
/sbin/iptables -P FORWARD ACCEPT
# liberacoes loopback
/sbin/iptables -A INPUT -i lo -j ACCEPT
/sbin/iptables -A OUTPUT -o lo -j ACCEPT
/sbin/iptables -A FORWARD -i lo -o lo -j ACCEPT
# ultimas linhas das tabelas
/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
#proxy transparente
/sbin/iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
# mascarar saida da rede interna
/sbin/iptables -t nat -A POSTROUTING -s 192.168.0.0/16 -o eth1 -j MASQUERADE