julianderson
(usa Debian)
Enviado em 01/12/2010 - 10:50h
Pessoal obrigado novamente, ate o momento ainda nao consegui liberar o sefip e nem a conectivade social, mais segue o meu arquivo firewall
# Libera portas do localhost
POLE_PROXY=192.168.1.0/24
$IPTABLES -F
$IPTABLES -Z
$IPTABLES -X
$IPTABLES -F -t nat
$IPTABLES -X -t nat
$IPTABLES -F -t mangle
$IPTABLES -X -t mangle
$IPTABLES -Z -t mangle
$IPTABLES -N CONNLIMIT
$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 953 -j ACCEPT
$IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 3128 -j ACCEPT
$IPTABLES -A INPUT -p tcp --syn -s 192.168.1.0/24 --dport 3128 -j ACCEPT
# ------------------------------------------------------------
$IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 8080 -j ACCEPT
$IPTABLES -A INPUT -p tcp --syn -s 192.168.1.0/24 --dport 8080 -j ACCEPT
# ------------------------------------------------------------
#libera as ports principais
$IPTABLES -A INPUT -p tcp --dport 25 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 53 -j ACCEPT
$IPTABLES -A INPUT -p udp --dport 53 -j ACCEPT
$IPTABLES -A INPUT -p udp --dport 20 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 21 -j ACCEPT
$IPTABLES -A INPUT -p tcp --dport 80 -j ACCEPT
$IPTABLES -A INPUT -p udp --dport 8000:20000 -j ACCEPT
# ------------------------------------------------------------
echo "|:Regras de OUTPUT:...................ok:|"
$IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -P OUTPUT ACCEPT
# ------------------------------------------------------------
# ------------------------------------------------------------
echo "|========================================|"
echo "|:REGRAS PREROUTING E POSTROUTING:....ok:|"
echo "|========================================|"
echo "|:REGRAS PARA A CONEXAO SEGURA DA CAIXA FEDERAL E PROXY TRANSPARENTE:|"
$IPTABLES -t nat -A PREROUTING -i eth0 -p tcp -d ! 200.201.174.207 --dport 80 -j REDIRECT --to-port 3128
# ------------------------------------------------------------
echo "|:Proxy transparente da redes:........ok:|"
#$IPTABLES -A PREROUTING -t nat -p tcp -s $POLE_PROXY --dport 80 -j REDIRECT --to-port 3128
# ------------------------------------------------------------
echo "|:Ativar o mascaramento de saída:.....ok:|"
$IPTABLES -t nat -A POSTROUTING -o eth0 -j MASQUERADE
# ------------------------------------------------------------
echo "|:Ativar o redirecionemento:............:|"
echo "1" > /proc/sys/net/ipv4/ip_forward
echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
echo "|:Regas de forward para saída:........ok:|"
# ------------------------------------------------------------
$IPTABLES -A FORWARD -p tcp ! --syn -m state --state NEW -j DROP
$IPTABLES -A FORWARD -m state --state INVALID -j DROP
$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
# ------------------------------------------------------------
echo "|:Liberar portas de saída:..............:|"
$IPTABLES -A FORWARD -p tcp --dport 25 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 25 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p udp --dport 53 -j ACCEPT
$IPTABLES -A FORWARD -p udp --dport 53 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 80 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 80 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 110 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 110 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 143 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 143 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 443 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 443 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 587 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 587 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 995 -j ACCEPT
$IPTABLES -A FORWARD -p tcp --dport 995 --sport 1024:65535 -j ACCEPT
$IPTABLES -A FORWARD -p udp --dport 8000:20000 -j ACCEPT
# ------------------------------------------------------------