guilmar
(usa Outra)
Enviado em 20/05/2011 - 08:51h
Acrescentei e tbm n deu certo...
Segue meu arquivo iptables
--------------------------------------------
# Generated by iptables-save v1.3.5 on Thu Nov 27 09:23:38 2008
*nat
:PREROUTING ACCEPT [2776:202210]
:POSTROUTING ACCEPT [9:723]
:OUTPUT ACCEPT [11:902]
# Acceso para la gente del Corporate al server
-A PREROUTING -s 189.19.219.41 -d 189.3.125.162 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 172.16.32.4:3389
-A PREROUTING -s 189.19.019.00 -d [IP] -p tcp -m tcp --dport 1433 -j DNAT --to-destination 172.16.32.4:1433
-A PREROUTING -s 189.14.000.00 -d [IP] -p tcp -m tcp --dport 3389 -j DNAT --to-destination 172.16.32.4:3389
-A PREROUTING -s 189.14.000.00 -d [IP] -p tcp -m tcp --dport 1433 -j DNAT --to-destination 172.16.32.4:1433
#-A PREROUTING -d 189.3.125.162 -p tcp -m tcp --dport 1022 -j DNAT --to-destination 172.16.32.3:22
#-A POSTROUTING -o eth0 -j MASQUERADE
# Acesso Gilmar ao pc-pabx
-A PREROUTING -s 187.36.000.000 -d [IP] -p tcp -m tcp --dport 3389 -j DNAT --to-destination 172.16.32.50:3389
-A PREROUTING -s 187.36.000.000 -d [IP] -p tcp -m tcp --dport 1433 -j DNAT --to-destination 172.16.32.50:1433
# Redirect to Squid
-A PREROUTING -i eth1 -s 172.16.32.0/24 -p tcp --dport 80 -j REDIRECT --to-port 3128
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Thu Nov 27 09:23:38 2008
# Generated by iptables-save v1.3.5 on Thu Nov 27 09:23:38 2008
*filter
:INPUT ACCEPT [2208:218904]
:FORWARD DROP [133001:111218316]
:OUTPUT ACCEPT [2193:237849]
# Squid
-A INPUT -i eth1 -p tcp --dport 3128 -j ACCEPT
# M20 de Vitoria
-A INPUT -i eth1 -p tcp -m tcp -s 172.16.32.6 --dport 25 -j ACCEPT
# Bloqueo el puerto smtp internamente para todos menos para la M20
-A INPUT -i eth1 -p tcp -m tcp --dport 25 -j DROP
# Server smtp gateway en Bs As
-A INPUT -i eth0 -s 209.13.00.00 -j ACCEPT
# Bloqueo el puerto smtp para todo el mundo menos para el gw en Bs As
-A INPUT -i eth0 -p tcp -m tcp --dport 25 -j DROP
# Acceso para la gente de Corporate (no al ssh del gateway)
-A INPUT -i eth0 -s 189.19.000.00 -j ACCEPT
-A INPUT -i eth0 -s 187.61.00.000 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp -s 189.000.000.41 --dport 22 -j DROP
-A INPUT -i eth0 -p tcp -m tcp -s 187.000.000.106 --dport 22 -j DROP
# McAfee
-A INPUT -i eth0 -p tcp -m tcp -s 216.49.88.143 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp -s 63.116.246.41 -j ACCEPT
# Bloqueo el acceso al resto de los equipos
-A INPUT -i eth0 -j DROP
# Trafico Rio-Vix Vix-Rio
-A FORWARD -s 172.16.31.0/24 -d 172.16.32.0/24 -j ACCEPT
-A FORWARD -d 172.16.31.0/24 -s 172.16.32.0/24 -j ACCEPT
# Notebook Gilmar
-A FORWARD -s 172.16.32.36 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.36 -j ACCEPT
-A FORWARD -s 172.16.32.37 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.37 -j ACCEPT
# Notebook de Holger
-A FORWARD -s 172.16.32.44 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.44 -j ACCEPT
-A FORWARD -s 172.16.32.45 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.45 -j ACCEPT
#####################################
# Filtros para los protocolos de IM #
#####################################
-A FORWARD -d 213.61.87.200 -j ACCEPT
-A FORWARD -s 213.61.87.200 -j ACCEPT
-A FORWARD -d 216.112.126.107 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 64.72.122.87 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 213.114.36.59 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 85.114.159.46 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 216.32.90.26 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 89.149.217.78 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 69.147.115.128 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 74.208.12.174 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 69.36.250.253 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 209.197.124.245 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 207.46.30.34 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 8.6.13.62 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 193.238.160.62 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 65.54.239.82 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 65.54.239.142 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 65.55.128.48 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 65.54.179.203 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 207.46.30.34 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 1863 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -s 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 1863 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 207.46.0.0/255.255.0.0 -p tcp -m tcp --dport 80 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 207.46.18.94 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 64.4.21.189 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 65.55.192.126 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 5222 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -p tcp -m tcp --dport 5223 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 5050 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -s 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 5050 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -d 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 5190 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -s 172.16.32.0/255.255.255.0 -p tcp -m tcp --dport 5190 -j REJECT --reject-with icmp-port-unreachable
# Mayckon
-A FORWARD -s 172.16.32.25 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.25 -j ACCEPT
# Alexandre
-A FORWARD -s 172.16.32.26 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.26 -j ACCEPT
# Livia
-A FORWARD -s 172.16.32.29 -m mac --mac-source MAC -j ACCEPT
-A FORWARD -d 172.16.32.29 -j ACCEPT
#####################################
# Enderecos MAC bloqueados #
#####################################
# Claudio-PC
-I FORWARD -m mac --mac-source MAC -j DROP
# André
-I FORWARD -m mac --mac-source MAC -j DROP
# Unknown
-I FORWARD -m mac --mac-source MAC -j DROP
COMMIT
------------------------------------------------------------------
Não me pergunte pq esse iptables é assim, pq quando entrei na empresa, ele já existia, e não posso muda-lo... =//
Vlews!!!!!