Enviado em 18/01/2013 - 12:06h
Estou com o meu Firewall funcionando muito bem porem quando ativo a regra para redirecionar a porta 80 para 3128 ativando o proxy transparente o navegador informa: ERROR The requested URL could not be retrieved.
echo "#####################################################"
echo "INICIANDO REGRAS BASICAS DO FEREWALL"
echo "#####################################################"
echo "#####################################################"
echo "DEFININDO AS POLITICAS PADROES DROP"
echo "#####################################################"
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
######"HABILITA O ROTEAMENTO NO KERNEL"#######
echo 1 > /proc/sys/net/ipv4/ip_forward
######"CONFIGURACAO DE CONEXOES"######
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
#============================REGRAS=====N A T=====================================================================================
#COMPARTILHA A INTERNET#
iptables -t nat -A POSTROUTING -s $REDE_INTERNA -o $INFACE_WEB -j MASQUERADE
#ACESSO TERMINAL SERVER SERVICE#
iptables -t nat -A PREROUTING -p tcp --dport 33444 -j DNAT --to 192.168.0.3:3389
#DIRECIONANDO PORTA 80 PARA SQUID#
iptables -t nat -A PREROUTING -p tcp -i $INFACE_INTERNA --dport 80 -j REDIRECT --to-port 3128
#=============================REGRAS======I N P U T================================================================================
#LIBERANDO SSH#
iptables -A INPUT -p tcp -s $REDE_INTERNA --dport 22 -j ACCEPT
#LIBERA PING DA REDE INTERNA#
iptables -A INPUT -s $REDE_INTERNA -p icmp --icmp-type 8 -j ACCEPT
#LIBERA COMUNICAÇÃO NA PORTA DO SQUID
iptables -A INPUT -p tcp --dport 3128 -j ACCEPT
#=============================REGRAS======O U T P T=================================================================================
#LIBERAÇÃO DAS PORTAS SEGURAS PARA O FIREWALL
iptables -A OUTPUT -p tcp -m multiport --dports $PORTAS_LIBERADAS_TCP -j ACCEPT
iptables -A OUTPUT -p tcp -m multiport --dports $PORTAS_LIBERADAS_UDP -j ACCEPT
iptables -A OUTPUT -p icmp --icmp-type 8 -j ACCEPT
#=============================REGRAS=====F O R W A R D==============================================================================
#LIBERA PORTAS ICMP PARA MAQUINAS DA REDE INTERNA PINGAR FORA#
iptables -A FORWARD -s $REDE_INTERNA -p icmp --icmp-type 8 -j ACCEPT
#LIBERAÇÃO DAS PORTAS SEGRURAS PARA REDE INTERNA#
iptables -A FORWARD -p tcp -m multiport --dports $PORTAS_REDE_INTERNA -j ACCEPT
#LIBERA PORTA PARA NAT TERMINAL SERVER SERVICE#
iptables -A FORWARD -p tcp --dport 3389 -d 192.168.0.3 -j ACCEPT
#BLOQUEIO GERAL DO FORWARD
#iptables -A FORWARD -j DROP