R.S.P Andre
(usa Debian)
Enviado em 07/07/2010 - 20:50h
Fala ai Irado!
Tudo bom?
Cara eu segui as suas dicas mais estou tenho um imparce.
Eu fwd geral e no INPUT eu só ponho o que eu quero. Certo?
mais com isso a rede esta tenho uma navegação totalmente livre.
Segue meu meio firewal
modprobe iptable_nat
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o ppp0 -s 192.168.10.0/24 -j MASQUERADE
########################################
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT
######################################
######## INPUT #######################
iptables -A INPUT -i lo -j ACCEPT
#iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -i ppp0 -m state --state ESTABLISHED,RELATED -j ACCEPT
#iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -t filter -A INPUT -p icmp -m icmp --icmp-type echo-request -m limit --limit 5/sec --limit-burst 5 -j ACCEPT
################## rede interna
##########BLOQUEIO POR MAC
#iptables -A INPUT -i eth1 -m mac --mac-source xx:xx:xx:xx:xx:xx -j DROP
######### PORTAS ##################################
iptables -A INPUT -p tcp -i eth1 --dport 80 -j ACCEPT
iptables -A INPUT -p tcp -i eth1 --dport 53 -j ACCEPT
iptables -A INPUT -p udp -i eth1 --dport 53 -j ACCEPT
####################################################
##### FORWARD #############
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i eth1 -j ACCEPT
~
obrigado por usa atenção ai cara.
ABS