R.S.P Andre
(usa Debian)
Enviado em 04/07/2010 - 14:47h
Fala Renato.
Realmente eu percebi isso mesmoo.
Sem querer perguntar de mais qual a regras que eu teria que colocar de modo que somente o que eu quisesse fosse liberado para o forward?
Apesar que se eu deixar essa regras sem as demais a net não funfa não.
E se eu por as outras regras e não por essa a net também não funfa.
Segue meu firewall teste atual:
iniciar(){
#########################################
####### FIrewall Teste #############
echo "Iniciando o Firewall by: R.S.P André"
echo "######################################"
echo "######### Limpando as Regras #########"
iptables -F
iptables -t nat -F
echo "########### Regras Zeradas ###########"
echo "######################################"
echo "####### Compartilhando a NET #########"
modprobe iptable_nat
iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward
echo "######### NET COMPARTILHADA ##########"
echo "##### Definindo Politica Padrão ######"
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
echo "######## Padrão estabelecido #########"
echo "######################################"
echo "########### Regras INPUT #############"
### recusando pacotes invalidos
iptables -A INPUT -i ppp0 -m state --state INVALID -j DROP
#### Aceitando pacotes validos
iptables -A INPUT -i ppp0 -m state --state ESTABLISHED,RELATED -j ACCEPT
## Abrindo a lo
iptables -A INPUT -i lo -j ACCEPT
#iptables -A INPUT -i ppp0 -j ACCEPT
### Bloquando acesso por maquina da rede local #####
#iptables -A INPUT -m mac --mac-source 08:00:27:83:7b:48 -p tcp --dport 137:1000 -j DROP
## Aceitando ping local
iptables -A INPUT -i eth1 -p icmp -j ACCEPT
## Aceitando as maquinas locais ##
iptables -A INPUT -s 192.168.10.0/24 -j ACCEPT
echo "####### Regras INPUT PRONTAS #########"
echo "######################################"
echo "#### carregando Regras FORWARD #######"
############ Bloqueando via iptables #######"
#iptables -A FORWARD -m mac --mac-source 08:00:27:83:7b:48 -j DROP
#iptables -A FORWARD -s 192.168.10.50 -d
www.orkut.com -j REJECT
##############################################################
### Forward de internet para a rede local
#iptables -A FORWARD -i ppp0 -d 192.168.10.0/24 -j ACCEPT
#############ACEITANDO PING DE DENTRO PRA FORA ################
iptables -A FORWARD -s 192.168.10.0/24 -p icmp -j ACCEPT #ping
############################################
### Aceitando pacotes estabilizados ###
iptables -A FORWARD -i eth1 -m state --state INVALID -j DROP
iptables -A FORWARD -s 192.168.10.0/24 -m state --state RELATED,ESTABLISHED -j ACCEPT
#####################################################
## Abrindo portas para a rede local com a internet Falta a pop e smtp
iptables -A FORWARD -p tcp -s 192.168.10.0/24 --dport 80 -j ACCEPT #http
iptables -A FORWARD -p tcp -s 192.168.10.0/24 --dport 53 -j ACCEPT #DNS
iptables -A FORWARD -p udp -s 192.168.10.0/24 --dport 53 -j ACCEPT #DNS
##### HTTPS###### sem elA nao tem orkut e nem outros https#########
iptables -A FORWARD -p tcp -s 192.168.10.0/24 --dport 443 -j ACCEPT #HTTPS
Abraço!