liviomm
(usa Debian)
Enviado em 29/01/2010 - 15:47h
Uso um programa chamado banesfacil que utiliza as portas 4226,21,20,1024 estou tentando usar as seguintes regras e nao esta funcionando sera que alguem pode me dar uma lUz ???\
iptables -A FORWARD -p TCP -i eth2 --destination-port 21 --destination 192.168.151.50 -j ACCEPT
iptables -t nat -A PREROUTING -p TCP -i eth2 --destination-port 21 -j DNAT --to-destination 192.168.151.50:21
iptables -A FORWARD -p TCP -i eth2 --destination-port 20 --destination 192.168.151.50 -j ACCEPT
iptables -t nat -A PREROUTING -p UDP -i eth2 --destination-port 20 -j DNAT --to-destination 192.168.151.50:20
iptables -A FORWARD -p TCP -i eth2 --destination-port 4226 --destination 192.168.151.50 -j ACCEPT
iptables -t nat -A PREROUTING -p TCP -i eth2 --destination-port 4226 -j DNAT --to-destination 192.168.151.50:4226
iptables -A FORWARD -p TCP -i eth2 --destination-port 1024 --destination 192.168.151.50 -j ACCEPT
iptables -t nat -A PREROUTING -p TCP -i eth2 --destination-port 4226 -j DNAT --to-destination 192.168.151.50:1024
# Libera Banesfacil
# Abre uma porta FTP (inclusive para a Internet)
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A FORWARD -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 20 -j ACCEPT
iptables -A FORWARD -p tcp --dport 20 -j ACCEPT
# Abre uma porta (inclusive para a Internet)
iptables -A INPUT -p tcp --dport 4226 -d eth2 -j ACCEPT
iptables -A INPUT -p udp --dport 4226 -d eth2 -j ACCEPT
iptables -A FORWARD -p udp --dport 4226 -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --dport 4226 -d eth2 -j ACCEPT
iptables -A INPUT -p udp --dport 4226 -d eth2 -j ACCEPT
iptables -A FORWARD -p udp --dport 4226 -d eth2 -j ACCEPT
# Abrindo conexao ftp em modo passivo e ativo
iptables -A INPUT -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 20 -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 20 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 20 -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 21 -m state --state ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 21 -m state --state NEW,ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 21 -m state --state ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED,RELATED -d eth2 -j ACCEPT
iptables -A INPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A FORWARD -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED -d eth2 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 1024: --dport 1024: -m state --state ESTABLISHED,RELATED -d eth2 -j ACCEPT