lupamont
(usa Debian)
Enviado em 05/01/2010 - 09:29h
Antes de qualquer coisa, obrigado a todos pela força
segue abaixo minhas regras:
*nat
:PREROUTING ACCEPT [75:4930]
:POSTROUTING ACCEPT [52:3324]
:OUTPUT ACCEPT [12:728]
-A PREROUTING -s 192.168.0.0/255.255.255.0 -d 200.201.174.207 -p tcp -m tcp --dport 2631 -j ACCEPT
-A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
-A POSTROUTING -o eth0 -j MASQUERADE
-A POSTROUTING -o eth1 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/255.255.255.0 -o eth0 -j SNAT --to-source 192.168.254.1
COMMIT
# Completed on Sun Mar 9 17:18:27 2008
# Generated by iptables-save v1.3.6 on Sun Mar 9 17:18:27 2008
*filter
:INPUT ACCEPT [28:1799]
:FORWARD ACCEPT [30:1993]
:OUTPUT ACCEPT [12:728]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -d 200.xxx.xxx.140 -p icmp -m icmp --icmp-type 8 -j DROP
-A INPUT -d 200.xxx.xxx.140 -p icmp -m icmp --icmp-type 0 -j DROP
-A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 0 -m limit --limit 1/sec -j RETURN
-A INPUT -s 192.168.0.100 -m state --state NEW -j ACCEPT
-A FORWARD -p tcp --dport 1970 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 200.xxx.xxx.140 -p icmp -m icmp --icmp-type 8 -j DROP
-A FORWARD -d 200.xxx.xxx.140 -p icmp -m icmp --icmp-type 0 -j DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j ACCEPT
-A FORWARD -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j ACCEPT
-A FORWARD -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A FORWARD -d 192.168.1.245 -p tcp -j ACCEPT
-A FORWARD -s 192.168.1.245 -p tcp -j ACCEPT
-A FORWARD -s 192.168.0.100 -m state --state NEW -j ACCEPT
-A FORWARD -s 192.168.0.1 -d 200.xxx.xxx.140 -m state --state NEW -j ACCEPT
-A FORWARD -s 200.xxx.xxx.140 -d 192.168.0.1 -m state --state NEW -j ACCEPT
-A FORWARD -p tcp -m multiport --dports 23,79,111,113,515 -j DROP
-A FORWARD -p udp -m multiport --dports 23,79,111,113,515 -j DROP
-A FORWARD -p tcp -m multiport --dports 1214,1290,1863,4242,4462,4661,5190,6346 -j DROP
-A FORWARD -p udp -m multiport --dports 1214,1290,1863,4242,4462,4661,5190,6346 -j DROP
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
COMMIT