
		julianderson
		
		(usa Debian)
		
		Enviado em 01/12/2010 - 10:50h 
		Pessoal obrigado novamente, ate o momento ainda nao consegui liberar o sefip e nem a conectivade social, mais segue o meu arquivo firewall
# Libera portas do localhost
POLE_PROXY=192.168.1.0/24
                $IPTABLES -F
                $IPTABLES -Z
                $IPTABLES -X
                $IPTABLES -F -t nat
                $IPTABLES -X -t nat
                $IPTABLES -F -t mangle
                $IPTABLES -X -t mangle
                $IPTABLES -Z -t mangle
                $IPTABLES -N CONNLIMIT
                $IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
                $IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 953 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 3128 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --syn -s 192.168.1.0/24 --dport 3128 -j ACCEPT
                # ------------------------------------------------------------
                $IPTABLES -A INPUT -p tcp --syn -s 127.0.0.1/32 --dport 8080 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --syn -s 192.168.1.0/24 --dport 8080 -j ACCEPT
                # ------------------------------------------------------------
#libera as ports principais
                $IPTABLES -A INPUT -p tcp --dport 25 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --dport 53 -j ACCEPT
                $IPTABLES -A INPUT -p udp --dport 53 -j ACCEPT
                $IPTABLES -A INPUT -p udp --dport 20 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --dport 21 -j ACCEPT
                $IPTABLES -A INPUT -p tcp --dport 80 -j ACCEPT
                $IPTABLES -A INPUT -p udp --dport 8000:20000 -j ACCEPT
               
                # ------------------------------------------------------------
                echo "|:Regras de OUTPUT:...................ok:|"
                $IPTABLES -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
                $IPTABLES -P OUTPUT ACCEPT
                # ------------------------------------------------------------
 # ------------------------------------------------------------
                echo "|========================================|"
                echo "|:REGRAS PREROUTING E POSTROUTING:....ok:|"
                echo "|========================================|"
               
                echo "|:REGRAS PARA A CONEXAO SEGURA DA CAIXA FEDERAL E PROXY TRANSPARENTE:|"
                $IPTABLES -t nat -A PREROUTING -i eth0 -p tcp -d ! 200.201.174.207 --dport 80 -j REDIRECT --to-port 3128
                # ------------------------------------------------------------
                echo "|:Proxy transparente da redes:........ok:|"
                #$IPTABLES -A PREROUTING -t nat -p tcp -s $POLE_PROXY --dport 80 -j REDIRECT --to-port 3128
                # ------------------------------------------------------------
                echo "|:Ativar o mascaramento de saída:.....ok:|"
                $IPTABLES -t nat -A POSTROUTING -o eth0 -j MASQUERADE          
                # ------------------------------------------------------------
                echo "|:Ativar o redirecionemento:............:|"
                echo "1" > /proc/sys/net/ipv4/ip_forward
                echo "1" > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
                echo "|:Regas de forward para saída:........ok:|"
                # ------------------------------------------------------------
                $IPTABLES -A FORWARD -p tcp ! --syn -m state --state NEW -j DROP
                $IPTABLES -A FORWARD -m state --state INVALID -j DROP
                $IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
                # ------------------------------------------------------------
                echo "|:Liberar portas de saída:..............:|"
                      
                $IPTABLES -A FORWARD -p tcp --dport 25 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 25 --sport 1024:65535 -j ACCEPT
                $IPTABLES -A FORWARD -p udp --dport 53 -j ACCEPT
                $IPTABLES -A FORWARD -p udp --dport 53 --sport 1024:65535 -j ACCEPT              
                $IPTABLES -A FORWARD -p tcp --dport 80 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 80 --sport 1024:65535 -j ACCEPT              
                $IPTABLES -A FORWARD -p tcp --dport 110 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 110 --sport 1024:65535 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 143 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 143 --sport 1024:65535 -j ACCEPT              
                $IPTABLES -A FORWARD -p tcp --dport 443 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 443 --sport 1024:65535 -j ACCEPT                
                $IPTABLES -A FORWARD -p tcp --dport 587 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 587 --sport 1024:65535 -j ACCEPT                
                $IPTABLES -A FORWARD -p tcp --dport 995 -j ACCEPT
                $IPTABLES -A FORWARD -p tcp --dport 995 --sport 1024:65535 -j ACCEPT           
                $IPTABLES -A FORWARD -p udp --dport 8000:20000 -j ACCEPT
                 # ------------------------------------------------------------