stefaniobrunhara
(usa CentOS)
Enviado em 10/09/2013 - 17:03h
Faça este básico que depois vamos rodar um script e finalizar sua maquina com tudo que você precisa para ela funcionar como firewall e proxy com eficiência.
vim /etc/hosts
192.168.1.253 sbh0px01
vim /etc/sysconfig/network-scripts/ifcfg-eth1
#Estefanio Brunhara
DEVICE=eth1
ONBOOT=yes
BOOTPROTO=static
IPADDR=192.168.1.253
NETMASK=255.255.255.0
HOSTNAME=SVBH0PX01
vim /etc/dhcp/dhcpd.conf
#====== San Giovanne Informatica Ltda (31)3375-1202 ======#
# Estefanio Brunhara 12-08-2013 BH-MG-BR #
#==========================================#
server-identifier sbh0px01;
#ddns-update-style ad-hoc;
default-lease-time 3600;
max-lease-time 3600;
option domain-name-servers 192.168.1.253;
option netbios-name-servers 192.168.1.253;
option netbios-node-type 0x8;
option routers 192.168.1.253;
option host-name "sbh0px01";
shared-network net {
###################################################
subnet 192.168.1.0 netmask 255.255.255.0 {
range 192.168.1.1 192.168.1.20;
authoritative;
}
###################################################
vim /etc/init.d/firewall
iptables -F
iptables -X
iptables -t nat -F
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
echo 0 > /proc/sys/net/ipv4/conf/all/log_martians
echo 1 > /proc/sys/net/ipv4/ip_forward
echo 1 > /proc/sys/net/ipv4/tcp_syncookies
echo 1 > /proc/sys/net/ipv4/ip_dynaddr
modprobe iptable_nat
modprobe ip_conntrack
modprobe ip_conntrack_ftp
modprobe ip_tables
iptables -A FORWARD -t filter -j ACCEPT
iptables -A FORWARD -t filter -j ACCEPT -m state --state ESTABLISHED,RELATED
iptables -A FORWARD -s 0/0 -d 0/0 -j ACCEPT
iptables -t nat -A POSTROUTING -s 0/0 -d 0/0 -o eth+ -j MASQUERADE
chmod +x /etc/init.d/firewall
/etc/init.d/firewall
/etc/init.d/dhcpd start