scsrat
(usa Ubuntu)
Enviado em 09/01/2021 - 17:34h
Olá, não tenho regras limitando conexão, abaixo estou postando um resumo das regras (Nota: ips e endereços estão editados por questão de segurança).
modprobe iptable_nat
modprobe ipt_string
modprobe ip_conntrack_ftp
#modprobe ip_nat_sip
#modprobe ip_conntrack_sip
#modprobe 8021q ### VLAN
################################################
# TORRENT
iptables -N LOGDROP > /dev/null 2> /dev/null
iptables -F LOGDROP
iptables -A LOGDROP -j LOG --log-prefix "LOGDROP "
iptables -A LOGDROP -m mac --mac-source xx:xx:xx:xx:xx:xx -j ACCEPT #Silvano
iptables -A LOGDROP -m mac --mac-source xx:xx:xx:xx:xx:xx -j ACCEPT #Silvano
iptables -A LOGDROP -j DROP
################################################
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 22 -j ACCEPT
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 22 -j ACCEPT
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 22 -j ACCEPT
iptables -A INPUT -p udp -s xxx.xxx.xxx.xxx/24 --dport 161 -j ACCEPT
iptables -A INPUT -p udp -s xxx.xxx.xxx.xxx/24 --dport 161 -j ACCEPT
iptables -A INPUT -p udp -s xxx.xxx.xxx.xxx/24 --dport 161 -j ACCEPT
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 3389 -j ACCEPT
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 3389 -j ACCEPT
iptables -A INPUT -p tcp -s xxx.xxx.xxx.xxx/24 --dport 3389 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 22 -j DROP
iptables -A INPUT -i eth0 -p udp --dport 161 -j DROP
iptables -A INPUT -i eth0 -p tcp --dport 3389 -j DROP
iptables -A INPUT -i eth0 -p udp -s xxx.xxx.xxx.xxx/24 --dport 161 -j DROP
# PING
iptables -A INPUT -i eth0 -p icmp --icmp-type echo-request -j DROP
iptables -A FORWARD -d endereco.com.br -p tcp --dport 465 -j ACCEPT
iptables -A INPUT -d endereco.com.br -p tcp --dport 465 -j ACCEPT
iptables -A OUTPUT -d endereco.com.br -p tcp --dport 465 -j ACCEPT
iptables -A FORWARD -d endereco.com.br -p tcp --dport 587 -j ACCEPT
iptables -A INPUT -d endereco.com.br -p tcp --dport 587 -j ACCEPT
iptables -A OUTPUT -d endereco.com.br -p tcp --dport 587 -j ACCEPT
iptables -A FORWARD -p tcp --dport 465 -j DROP
iptables -A INPUT -p tcp --dport 465 -j DROP
iptables -A OUTPUT -p tcp --dport 465 -j DROP
iptables -A FORWARD -p tcp --dport 587 -j DROP
iptables -A INPUT -p tcp --dport 587 -j DROP
iptables -A OUTPUT -p tcp --dport 587 -j DROP
############################## REDIRECIONA HTTP #####################################
iptables -t nat -A PREROUTING -p tcp -i eth1 --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -p tcp -i eth2 --dport 80 -j REDIRECT --to-port 3128
################################################################################################################
iptables -A FORWARD -i eth1 -m string --algo bm --string "spotify.com" -m mac --mac-source xx:xx:xx:xx:xx:xx -j ACCEPT
iptables -I FORWARD -i eth1 -p tcp --dport 80 -m string --algo bm --string "spotify.com" ! -s xxx.xxx.xxx.xxx/24 -j REJECT
iptables -I FORWARD -i eth1 -p udp --dport 80 -m string --algo bm --string "spotify.com" ! -s xxx.xxx.xxx.xxx/24 -j REJECT
iptables -I FORWARD -i eth1 -p tcp --dport 443 -m string --algo bm --string "spotify.com" ! -s xxx.xxx.xxx.xxx/24 -j REJECT
iptables -I FORWARD -i eth1 -p udp --dport 443 -m string --algo bm --string "spotify.com" ! -s xxx.xxx.xxx.xxx/24 -j REJECT
############# BLOQ TIMERS ###################
iptables -t filter -A FORWARD -p tcp --dport 443 -m string --algo bm --string "www.youtube.com" -j DROP -m time --weekdays Mon,Tue,Wed,Thu,Fri --timestart 8:10 --timestop 12:40 --kerneltz
iptables -t filter -A FORWARD -p tcp --dport 80 -m string --algo bm --string "www.youtube.com" -j DROP -m time --weekdays Mon,Tue,Wed,Thu,Fri --timestart 8:10 --timestop 12:40 --kerneltz
############### Block Torrent #######################################################
iptables -A FORWARD -m string --algo bm --string "announce.php?passkey=" -j LOGDROP
iptables -A FORWARD -m string --algo bm --string "torrent" -j LOGDROP
iptables -A FORWARD -m string --algo bm --string "announce" -j LOGDROP
iptables -A FORWARD -m string --algo bm --string "get_peers" -j LOGDROP
iptables -A FORWARD -m string --algo bm --string "announce_peer" -j LOGDROP
iptables -A FORWARD -m string --algo bm --string "find_node" -j LOGDROP
#####################################################################################
####### PCS WHATSAPP BLOCK ##########################################################
iptables -A FORWARD -s xxx.xxx.xxx.xxx/24 -p tcp --dport 443 -m string --algo bm --string "whatsapp.com" -j ACCEPT
iptables -A FORWARD -s xxx.xxx.xxx.xxx/24 -p tcp --dport 443 -m string --algo bm --string "whatsapp.com" -j ACCEPT
#iptables -A FORWARD -p tcp --dport 443 -m string --algo bm --string "whatsapp.com" -j DROP
#iptables -A INPUT -p tcp --dport 443 -m string --algo bm --string "whatsapp.com" -j DROP
# Libernado portas
iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
iptables -A FORWARD -p udp --dport 80 -j ACCEPT
iptables -A FORWARD -p tcp --dport 3389 -j ACCEPT
iptables -A FORWARD -p udp --dport 3389 -j ACCEPT
iptables -A FORWARD -p tcp --dport 4899 -j ACCEPT
iptables -A FORWARD -p udp --dport 4899 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5001 -j ACCEPT
iptables -A FORWARD -p udp --dport 5001 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5005 -j ACCEPT
iptables -A FORWARD -p udp --dport 5005 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5007 -j ACCEPT
iptables -A FORWARD -p udp --dport 5007 -j ACCEPT
iptables -A FORWARD -p tcp --dport 5008 -j ACCEPT
iptables -A FORWARD -p udp --dport 5008 -j ACCEPT
iptables -A FORWARD -p tcp --dport 8443 -j ACCEPT
iptables -A FORWARD -p udp --dport 8443 -j ACCEPT
iptables -A FORWARD -p tcp --dport 9101 -j ACCEPT
iptables -A FORWARD -p udp --dport 9101 -j ACCEPT
iptables -A FORWARD -p tcp --dport 9102 -j ACCEPT
iptables -A FORWARD -p udp --dport 9102 -j ACCEPT
iptables -A FORWARD -p tcp --dport 9103 -j ACCEPT
iptables -A FORWARD -p udp --dport 9103 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50000 -j ACCEPT
iptables -A FORWARD -p udp --dport 50000 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50001 -j ACCEPT
iptables -A FORWARD -p udp --dport 50001 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50002 -j ACCEPT
iptables -A FORWARD -p udp --dport 50002 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50003 -j ACCEPT
iptables -A FORWARD -p udp --dport 50003 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50004 -j ACCEPT
iptables -A FORWARD -p udp --dport 50004 -j ACCEPT
iptables -A FORWARD -p tcp --dport 50005 -j ACCEPT
iptables -A FORWARD -p udp --dport 50005 -j ACCEPT
iptables -A FORWARD -p tcp --dport 40001 -j ACCEPT
iptables -A FORWARD -p udp --dport 40001 -j ACCEPT
iptables -A FORWARD -p tcp --dport 60001 -j ACCEPT
iptables -A FORWARD -p udp --dport 60001 -j ACCEPT
iptables -t nat -A POSTROUTING -j MASQUERADE
############################### LISTAO
[*****] E STREAMING #################################################
#iptables -A FORWARD -m string --algo bm --string "windowsupdate" -j REJECT
#iptables -A FORWARD -m string --algo bm --string "definitionupdates" -j REJECT
#iptables -A FORWARD -m string --algo bm --string "ardownload" -j REJECT
iptables -A FORWARD -m string --algo bm --string "gkojfkhlekighikafcpjkiklfbnlmeio" -j REJECT #hola vpn
iptables -A FORWARD -m string --algo bm --string "freevpn.zone" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hola-free" -j REJECT
iptables -A FORWARD -m string --algo bm --string "client.hola" -j REJECT
iptables -A FORWARD -m string --algo bm --string "perr.hola" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hola.org" -j REJECT
iptables -A FORWARD -m string --algo bm --string "proxysite" -j REJECT
iptables -A FORWARD -m string --algo bm --string "jogosfas" -j REJECT
iptables -A FORWARD -m string --algo bm --string "ojogos" -j REJECT
iptables -A FORWARD -m string --algo bm --string "onlinevideoconverter" -j REJECT
iptables -A FORWARD -m string --algo bm --string "whoer.net" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hide.me" -j REJECT
iptables -A FORWARD -m string --algo bm --string "kproxy" -j REJECT
iptables -A FORWARD -m string --algo bm --string "secureproxy" -j REJECT
iptables -A FORWARD -m string --algo bm --string "tubsex" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****].org" -j REJECT
iptables -A FORWARD -m string --algo bm --string "videosporn" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****]" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornostar" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornoteca" -j REJECT
iptables -A FORWARD -m string --algo bm --string "minhateca" -j REJECT
iptables -A FORWARD -m string --algo bm --string "gshow.globo" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chaturbate" -j REJECT
iptables -A FORWARD -m string --algo bm --string "randomchat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "sexcams" -j REJECT
iptables -A FORWARD -m string --algo bm --string "bongacams" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****].com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "imeetzu" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camvoice" -j REJECT
iptables -A FORWARD -m string --algo bm --string "afreechat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chatforfree" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chatroule" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camsexy" -j REJECT
iptables -A FORWARD -m string --algo bm --string "firecams" -j REJECT
iptables -A FORWARD -m string --algo bm --string "tinychat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chat-gay" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camerahot" -j REJECT
iptables -A FORWARD -m string --algo bm --string "ome-chat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "sexcamera" -j REJECT
iptables -A FORWARD -m string --algo bm --string "worldchatonline" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camster" -j REJECT
iptables -A FORWARD -m string --algo bm --string "flirtymania" -j REJECT
iptables -A FORWARD -m string --algo bm --string "whoagirls" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chatcom" -j REJECT
iptables -A FORWARD -m string --algo bm --string "chatparade" -j REJECT
iptables -A FORWARD -m string --algo bm --string "cam4" -j REJECT
iptables -A FORWARD -m string --algo bm --string "mnogochat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camdudes" -j REJECT
iptables -A FORWARD -m string --algo bm --string "livesexspin" -j REJECT
iptables -A FORWARD -m string --algo bm --string "myfreeimplants" -j REJECT
iptables -A FORWARD -m string --algo bm --string "maturecompilat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "topchats" -j REJECT
iptables -A FORWARD -m string --algo bm --string "secretfriends" -j REJECT
iptables -A FORWARD -m string --algo bm --string "mayoralaviation" -j REJECT
iptables -A FORWARD -m string --algo bm --string "gayconnect" -j REJECT
iptables -A FORWARD -m string --algo bm --string "xnxxvideos" -j REJECT
iptables -A FORWARD -m string --algo bm --string "randomchatus" -j REJECT
iptables -A FORWARD -m string --algo bm --string "couplecam" -j REJECT
iptables -A FORWARD -m string --algo bm --string "mommyscamera" -j REJECT
iptables -A FORWARD -m string --algo bm --string "xvideos" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****]" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornhub" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornvideo" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****].com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "cameraprive" -j REJECT
iptables -A FORWARD -m string --algo bm --string "bongacamsvip" -j REJECT
iptables -A FORWARD -m string --algo bm --string "teenrandom" -j REJECT
iptables -A FORWARD -m string --algo bm --string "loveroulette" -j REJECT
iptables -A FORWARD -m string --algo bm --string "camsbr" -j REJECT
iptables -A FORWARD -m string --algo bm --string "xercams" -j REJECT
iptables -A FORWARD -m string --algo bm --string "seniorcamchat" -j REJECT
iptables -A FORWARD -m string --algo bm --string "adultfriend" -j REJECT
iptables -A FORWARD -m string --algo bm --string "shield-free" -j REJECT
iptables -A FORWARD -m string --algo bm --string "HotspotShield" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hotspotshield" -j REJECT
iptables -A FORWARD -m string --algo bm --string "anchorfree" -j REJECT
iptables -A FORWARD -m string --algo bm --string "
[*****]" -j REJECT
iptables -A FORWARD -m string --algo bm --string "megavideo" -j REJECT
iptables -A FORWARD -m string --algo bm --string "megafilme" -j REJECT
iptables -A FORWARD -m string --algo bm --string "toppornsites" -j REJECT
iptables -A FORWARD -m string --algo bm --string "zoniexx" -j REJECT
iptables -A FORWARD -m string --algo bm --string "mackaddict" -j REJECT
iptables -A FORWARD -m string --algo bm --string "couponfinancial" -j REJECT
iptables -A FORWARD -m string --algo bm --string "des4you" -j REJECT
iptables -A FORWARD -m string --algo bm --string "ejbonline" -j REJECT
iptables -A FORWARD -m string --algo bm --string "yukoeng" -j REJECT
iptables -A FORWARD -m string --algo bm --string "suchvalue" -j REJECT
iptables -A FORWARD -m string --algo bm --string "provass" -j REJECT
iptables -A FORWARD -m string --algo bm --string "intelifilm" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hanetryty" -j REJECT
iptables -A FORWARD -m string --algo bm --string "hospedagemempresarial.ws" -j REJECT
iptables -A FORWARD -m string --algo bm --string "webenviador.top" -j REJECT
iptables -A FORWARD -m string --algo bm --string "zerentas.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "sovps.com.br" -j REJECT
iptables -A FORWARD -m string --algo bm --string "atlanheap.net" -j REJECT
iptables -A FORWARD -m string --algo bm --string "jaguot.net" -j REJECT
iptables -A FORWARD -m string --algo bm --string "modertis.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "finddard.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "powequis.net" -j REJECT
iptables -A FORWARD -m string --algo bm --string "finddard.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "roomapartment.net" -j REJECT
iptables -A FORWARD -m string --algo bm --string "goldular.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "advertizehop.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "publiruby.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "artesloja.com.br" -j REJECT
iptables -A FORWARD -m string --algo bm --string "instrutoriatreinar.com.br" -j REJECT
iptables -A FORWARD -m string --algo bm --string "goolberry.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "globolojas.com.br" -j REJECT
iptables -A FORWARD -m string --algo bm --string "energytech.com.br" -j REJECT
iptables -A FORWARD -m string --algo bm --string "leetnet.us" -j REJECT
iptables -A FORWARD -m string --algo bm --string "bigboxhost.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "ultrasurf" -j REJECT
iptables -A FORWARD -m string --algo bm --string "uptodown.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "freevpnsdownload" -j REJECT
iptables -A FORWARD -m string --algo bm --string "ultrareach" -j REJECT
iptables -A FORWARD -m string --algo bm --string "sex.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornobuceta" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pornonacion" -j REJECT
iptables -A FORWARD -m string --algo bm --string "anyporn" -j REJECT
iptables -A FORWARD -m string --algo bm --string "livejasmin" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pinflix" -j REJECT
iptables -A FORWARD -m string --algo bm --string "pretty.
[*****]" -j REJECT
iptables -A FORWARD -m string --algo bm --string "xhihi.com" -j REJECT
iptables -A FORWARD -m string --algo bm --string "taxi69" -j REJECT
iptables -A FORWARD -m string --algo bm --string "private-girls" -j REJECT
iptables -A FORWARD -m string --algo bm --string "moviestube" -j REJECT
iptables -A FORWARD -m string --algo bm --string "adultdvd" -j REJECT
iptables -A FORWARD -m string --algo bm --string "porn300" -j REJECT
iptables -A FORWARD -m string --algo bm --string "teenpornvideo" -j REJECT
iptables -A FORWARD -m string --algo bm --string "18tubehd" -j REJECT
iptables -A FORWARD -m string --algo bm --string "teenporn" -j REJECT
Att: Silvano Crivelli