Enviado em 15/05/2018 - 15:08h
Bom dia galera,#!/bin/bash
echo "1" > /proc/sys/net/ipv4/ip_forward
/sbin/iptables -F
/sbin/iptables -t filter -P INPUT DROP
/sbin/iptables -t filter -P OUTPUT ACCEPT
/sbin/iptables -t filter -P FORWARD ACCEPT
/sbin/iptables -t nat -P PREROUTING ACCEPT
/sbin/iptables -t nat -P POSTROUTING ACCEPT
/sbin/iptables -t nat -P OUTPUT ACCEPT
/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
/sbin/iptables -t filter -A INPUT -i eth1 -j ACCEPT
/sbin/iptables -t filter -A INPUT -i lo -j ACCEPT
#SSH
/sbin/iptables -A INPUT -p tcp --dport 22 -i eth0 -j ACCEPT
/sbin/iptables -A INPUT -p tcp --dport 22 -i eth1 -j ACCEPT
#PING
/sbin/iptables -A INPUT -p icmp -i eth0 -j ACCEPT
/sbin/iptables -A INPUT -p icmp -i eth1 -j ACCEPT
#DHCP
/sbin/iptables -A INPUT -p tcp --dport 67 -i eth1 -j ACCEPT
/sbin/iptables -A INPUT -p tcp --dport 68 -i eth1 -j ACCEPT
/sbin/iptables -t filter -A FORWARD -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -t filter -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
/sbin/iptables -t filter -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT