kakashi963
(usa Debian)
Enviado em 26/03/2011 - 16:23h
Ae rapaz, boa tarde!
Cara o problema é que tentando do servidor, não há perda de pacotes.
Agora quanto tento das máquinas da rede... ai perde os pacotes.
Meu firewall está assim:
########## Compartilha a conexão
modprobe iptable_nat
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o eth2 -j MASQUERADE
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 3128
########## bloqueia pings e protege contra ip spoofing e pacotes invalidos
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
echo 1 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -m state --state INVALID -j DROP
########## interface loopback
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth1 -j ACCEPT
########## Abre para portas especificadas
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 6881 -j ACCEPT
############ Acesso geral
iptables -P OUTPUT ACCEPT
############## Mantem a conexao
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
############## Regras para outlook
iptables -A FORWARD -p udp -s 192.168.0.0/24 -d 201.10.128.3 --dport 53 -j ACCEPT
iptables -A FORWARD -p udp -s 201.10.128.3 --sport 53 -d 192.168.0.0/24 -j ACCEPT
iptables -A FORWARD -p udp -s 192.168.0.0/24 -d 201.10.120.3 --dport 53 -j ACCEPT
iptables -A FORWARD -p udp -s 201.10.120.3 --sport 53 -d 192.168.0.0/24 -j ACCEPT
iptables -A FORWARD -p tcp -s 192.168.0.0/24 --dport 25 -j ACCEPT # smtp
iptables -A FORWARD -p tcp -s 192.168.0.0/24 --dport 110 -j ACCEPT # pop3
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 53 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j ACCEPT
############## bloqueando o resto
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -p tcp --syn -j DROP