dpitta
(usa Debian)
Enviado em 17/05/2018 - 23:49h
Uma curiosidade é que com o FILEZILA não funciona, mas com o CutFTP ele broquei, espera alguns segundos e em seguida passa.
O Firewall esta assim, mas ainda não funciona.
----------------------------------------------------------------------------------------------------------------------------------
iptables -F
iptables -t filter -F # limpa todas as regras dos chain internos
iptables -t filter -X # limpa todas as regras dos chain criados pelo usuário
iptables -t filter -Z # zera os contadores
iptables -A INPUT -p tcp --sport 1024:65535 --dport 1024:65535 -m state --state ESTABLISHED,RELATED -j ACCEPT
MEUIP_01=187.191.99.164
CASA=186.227.215.110
#iptables -t filter -P INPUT DROP
iptables -t filter -P INPUT ACCEPT
iptables -t filter -P OUTPUT ACCEPT
#Aceita conexao na porta 80 e 443 do Site
iptables -A INPUT -p tcp -d $IP_SITE --destination-port 80 -j ACCEPT
iptables -A INPUT -p tcp -d $IP_SITE --destination-port 443 -j ACCEPT
iptables -A INPUT -p tcp -s $MEUIP_01 -d $MEUIP_01 --destination-port 3306 -j ACCEPT
iptables -A INPUT -p tcp --dport 1024:65535 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --destination-port 20 -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --destination-port 21 -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --destination-port 22 -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --destination-port 3306 -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --dport 20 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp -s $CASA -d $MEUIP_01 --dport 21 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A INPUT -p udp -m multiport --sport 53 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
modprobe ip_conntrack
modprobe ip_conntrack_ftp
iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-reply -m limit --limit 1/s -j RETURN
iptables -A INPUT -j LOG --log-prefix [fw-input-drop]
iptables -A INPUT -p tcp -j DROP
---------------------------------------------------------------------------------------------------------------
Os logs esta pegando isso no DROP.
root@emissor:/usr/local# tail -f /var/log/messages |grep 186.227.215.110
May 17 23:44:13 emissor kernel: [188953.956615] [fw-input-drop]IN=eth0 OUT= MAC=00:16:3e:2c:b1:09:0c:c4:7a:1e:a3:1e:08:00 SRC=186.227.215.110 DST=187.191.99.164 LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=314 DF PROTO=TCP SPT=58442 DPT=64360 WINDOW=64240 RES=0x00 SYN URGP=0
May 17 23:44:19 emissor kernel: [188959.955572] [fw-input-drop]IN=eth0 OUT= MAC=00:16:3e:2c:b1:09:0c:c4:7a:1e:a3:1e:08:00 SRC=186.227.215.110 DST=187.191.99.164 LEN=52 TOS=0x00 PREC=0x00 TTL=114 ID=315 DF PROTO=TCP SPT=58442 DPT=64360 WINDOW=64240 RES=0x00 SYN URGP=0