ncampos
(usa Debian)
Enviado em 25/04/2016 - 10:28h
Bom dia,
Estou em processo de testes ( aprendendo) como funciona o IPV6. Ate então utilizado um Firewall Simples Iptables com script no arranque + Squid autenticado.
Barrei na questão de repasse do sinal de internet ,vem do "modem" entrada na eth0 e sai pela eth1 para a rede.
como irei fazer o repasse?
como ficara essa linha = echo 1 > /proc/sys/net/ipv4/ip_forward
como ficara essa linha = #iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination IP_DA_REDE:80
em meu script em funcionamento utilizo da seguinte forma em ipv4:
#!/bin/bash
iniciar()
{
modprobe iptable_nat
echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe ip_tables
#
####### eth0 = modem
####### eth1 = rede local
####### OBS: deve estar setado sempre eth do modem em regras de redirecionamento e liberacao.
#############################################################################################
########################################## ACIONANDO INTERNET PARA REDE LOCAL ######
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:1536 -j TCPMSS --clamp-mss-to-pmtu
##################################################### ######################################
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
############################################ PORTAS LIBERADAS ################################
iptables -A INPUT -m multiport -p tcp --dport 22,21,53,80,81,443,8080,8484,6000,6050 -j ACCEPT
#############################################################################################
############################################# PROXY DESABILITADO/HABILITADO ################
##### eth0 = modem ####
############################################# MODO AUTENTICACAO ############################
#iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 10.1.1.250:80 # comentada = USAR SQUID
iptables -t nat -A PREROUTING -s 192.168.1.200/255.255.255.0 -p tcp --dport 80 -j REDIRECT --to-port 3128 # comentada = NAO USAR SQUID
############################################################################################
echo "iniciando servico"
}
parar(){
iptables -F -t nat
echo "parando servico"
}
case "$1" in
"start") iniciar;;
"stop") parar;;
"restart")parar;iniciar;;
*)echo "Use os parametros start,stop ou restart"
esac