lucasjose
(usa Ubuntu)
Enviado em 10/05/2016 - 13:56h
ainda não passou.
Esse é o meu Firewall
echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe ip_nat_ftp
modprobe ip_nat_pptp
modprobe ip_conntrack_pptp
modprobe ip_gre
iptables -F
iptables -t nat -F
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
###Direciona trafego internet para o proxy liberando Conectividade Social
iptables -t nat -A PREROUTING -i eth0 -d 200.201.174.0/24 -p tcp --dport 80 -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -d 200.201.162.0/24 -p tcp --dport 80 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp -i eth0 -d ! 200.201.174.0/24 --dport 80 -j REDIRECT --to 3128
iptables -A INPUT -s 192.168.0.0/24 -j ACCEPT
#RADIO
iptables -A INPUT -p tcp -i eth0 --dport 8100 -j ACCEPT
iptables -A INPUT -p udp -i eth0 --dport 8100 -j ACCEPT
iptables -A INPUT -p tcp --dport 8100 -j ACCEPT
iptables -A INPUT -p udp --dport 8100 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 8100 -j ACCEPT
iptables -A OUTPUT -p udp --dport 8100 -j ACCEPT
iptables -A FORWARD -p tcp --dport 8100 -j ACCEPT
iptables -A FORWARD -p udp --dport 8100 -j ACCEPT
#DNS
iptables -A INPUT -p tcp --dport 53 -j ACCEPT
#Email
iptables -A INPUT -p tcp --dport 2096 -j ACCEPT
iptables -A FORWARD -p tcp --dport 2096 -j ACCEPT
iptables -A INPUT -p tcp --dport 993 -j ACCEPT
iptables -A FORWARD -p tcp --dport 993 -j ACCEPT
iptables -A INPUT -p tcp --dport 465 -j ACCEPT
iptables -A INPUT -p tcp --dport 143 -j ACCEPT
iptables -A FORWARD -p tcp --dport 143 -j ACCEPT
iptables -A INPUT -p tcp --dport 25 -j ACCEPT
#Internet
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
#VPN
iptables -A FORWARD -p tcp --dport 1024 -j ACCEPT
iptables -A FORWARD -p tcp --dport 65535 -j ACCEPT
iptables -A FORWARD -p tcp --dport 63517 -j ACCEPT
iptables -A FORWARD -p tcp --dport 1723 -j ACCEPT
iptables -A FORWARD -p tcp --dport 500 -j ACCEPT
iptables -A FORWARD -p 47 -j ACCEPT
#Proxy
iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 3128 -j ACCEPT
#Bloqueia Demais Portas de Entrada
iptables -A INPUT -p tcp --syn -j DROP