DumbaF
(usa Debian)
Enviado em 19/11/2015 - 13:01h
Desculpe amigo
mas eu tenho o debian 7 como firewall.
esta tudo funcionando perfeito
veja o skript firewall
#!/bin/bash
#echo 1 > /proc/sys/net/ipv4/ip_forward
modprobe iptable_nat
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
#iptables -t mangle -F
#
iptables -t mangle -X
#
#IPTABLES_MODULES="nf_conntrack_ftp"
iptables -A FORWARD -i eth0 -s 192.168.7.100 -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
# e-mail
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -m state --state INVALID -j DROP
######
#ACESSO REMOTO
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
############
iptables -A INPUT -p tcp --dport 25 -j ACCEPT
iptables -A FORWARD -p tcp --dport 25 -j ACCEP
T
####################
iptables -A INPUT -p tcp --dport 110 -j ACCEPT
iptables -A INPUT -p udp --dport 110 -j ACCEPT
iptables -A FORWARD -p tcp --dport 110 -j ACCEPT
#########
iptables -A INPUT -p tcp --dport 10000 -j ACCEPT
###########
iptables -A INPUT -p tcp --dport 587 -j ACCEPT
iptables -A INPUT -p udp --dport 587 -j ACCEPT
iptables -A FORWARD -p tcp --dport 587 -j ACCEPT
####################
iptables -A INPUT -p udp --dport 53 -j ACCEPT
iptables -A FORWARD -p tcp --dport 53 -j ACCEPT
iptables -A INPUT -m state --state INVALID -j DROP
#IP SPOOFING
#
iptables -N syn-flood
#iptables -A INPUT -i eth0 -p tcp --syn -j syn-flood
iptables -A FORWARD -p tcp --syn -m limit --limit 10/s -j ACCEPT
iptables -A FORWARD -p tcp --syn -j DROP