jjunior89
(usa Outra)
Enviado em 06/01/2012 - 17:39h
O problema é no comigo ou com a provedora ?, ve se eu nao inverti alguma coisa do eth0 e eth1, será que tem mais algum arquivo que interfere ?
olha ai novamente, já com as suas mudanças
#/bin/bash
iptables -F
iptables -t nat -F
iptables -X
iptables -X -t nat
iptables -Z
echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe ip_tables
modprobe iptable_nat
modprobe iptable_filter
modprobe ip_nat_ftp
modprobe ip_conntrack_ftp
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
####>
####> Rota de Saida
iptables -t nat -A POSTROUTING -o eth0 -s 192.168.10.0/24 -j SNAT --to 187.73.196.42
#iptables -t nat -A POSTROUTING -p tcp -o eth0 -s 192.168.10.0/24 --dport 3000 -j SNAT --to 189.51.133.40:3000
###> Terminal Service
iptables -t nat -A PREROUTING -p tcp -d 187.73.196.42 --dport 3389 -j DNAT --to-destination 192.168.10.253
###> FTP
iptables -t nat -A PREROUTING -p tcp -d 187.73.196.42 --dport 21 -j DNAT --to-destination 192.168.10.23
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 21 -j DNAT --to 201.63.185.29:21
iptables -A FORWARD -j ACCEPT -p --dport 21
####> Regras de Repasse
iptables -A FORWARD -d 187.73.196.42/32 -s 0/0 -i eth1 -o eth0 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -p icmp -j ACCEPT
iptables -A FORWARD -p tcp --dport 20:21 -j ACCEPT
iptables -A FORWARD -p tcp --dport 22 -j ACCEPT
iptables -A FORWARD -p tcp --dport 25 -j ACCEPT
iptables -A FORWARD -p tcp --dport 53 -j ACCEPT
iptables -A FORWARD -p udp --dport 53 -j ACCEPT
iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
iptables -A FORWARD -p tcp --dport 110 -j ACCEPT
iptables -A FORWARD -p tcp --dport 161:162 -j ACCEPT
iptables -A FORWARD -p tcp --dport 3000 -j ACCEPT
iptables -A FORWARD -p udp --dport 3000 -j ACCEPT
iptables -A FORWARD -p tcp --dport 3128 -j ACCEPT
iptables -A FORWARD -p tcp --dport 3389 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5900 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5800 -j ACCEPT
iptables -A FORWARD -p tcp --dport 1024:65535 -j ACCEPT
iptables -A FORWARD -p udp --dport 1024:65535 -j ACCEPT
iptables -A INPUT -s 127.0.0.1/32 -j ACCEPT
iptables -A INPUT -p icmp -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 161 -j ACCEPT
iptables -A INPUT -p udp --dport 161:162 -j ACCEPT
iptables -A INPUT -p tcp --dport 1723 -j ACCEPT
iptables -A INPUT -p tcp --dport 3000 -j ACCEPT
iptables -A INPUT -p udp --dport 3000 -j ACCEPT
iptables -A INPUT -p tcp --dport 5800 -j ACCEPT
iptables -A INPUT -p tcp --dport 5823 -j ACCEPT
iptables -A INPUT -p tcp --dport 5830 -j ACCEPT
iptables -A INPUT -p tcp --dport 5900 -j ACCEPT
iptables -A INPUT -p tcp --dport 5923 -j ACCEPT
iptables -A INPUT -p tcp --dport 5914 -j ACCEPT
iptables -A INPUT -p tcp --dport 5930 -j ACCEPT
iptables -A INPUT -p tcp --dport 5908 -j ACCEPT
iptables -A INPUT -p tcp --dport 5903 -j ACCEPT
iptables -A INPUT -p tcp --dport 5904 -j ACCEPT
iptables -A INPUT -p tcp --dport 5905 -j ACCEPT
iptables -A INPUT -p tcp --dport 5925 -j ACCEPT
iptables -A INPUT -p tcp --dport 5911 -j ACCEPT
iptables -A INPUT -p tcp --dport 5900 -j ACCEPT
iptables -A INPUT -p tcp --dport 1024:65535 -j ACCEPT
iptables -A INPUT -p udp --dport 1024:65535 -j ACCEPT
##Conectividade Social SEFIP
iptables -t nat -A PREROUTING -p tcp -d 200.201.173.68 --dport 80 -j DNAT --to 200.201.173.68:80
iptables -I FORWARD -p tcp -s 0/0 -d 200.201.173.68/32 --dport 80 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp -d 200.201.166.200 --dport 80 -j DNAT --to 200.201.166.200:80
iptables -I FORWARD -p tcp -s 0/0 -d 200.201.166.200/32 --dport 80 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp -d 200.201.174.207 --dport 80 -j DNAT --to 200.201.174.207:80
iptables -I FORWARD -p tcp -s 0/0 -d 200.201.174.207/32 --dport 80 -j ACCEPT
iptables -I FORWARD -p all -s 200.201.174.0/24 -d 0/0 -j ACCEPT
iptables -I OUTPUT -p all -s 200.201.174.0/24 -d 0/0 -j ACCEPT
iptables -I INPUT -p all -s 200.201.174.0/24 -d 0/0 -j ACCEPT