weltonpba
(usa Debian)
Enviado em 27/04/2010 - 08:14h
Infelizmente não deu certo bixo olha como ficou a regra e me corrija se estiver algo que eu fiz errado.
segue minha conf do /etc/rc.local inteira
/etc/rc.local [----] 0 L:[ 1+ 0 1/ 92] *(0 /3952b)= # 35 0x23
#!/bin/sh -e
#
# rc.local
#
# This script is executed at the end of each multiuser runlevel.
# Make sure that the script will "exit 0" on success or any other
# value on error.
#
# In order to enable or disable this script just change the execution
# bits.
#
# By default this script does nothing.
modprobe iptable_nat
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
echo 1 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth0 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --syn -j DROP
#-----------------------------------------------------------------------------------------------------
iptables -A FORWARD -s 10.0.0.0/8 -p tcp -d 0/0 --dport 21 -j ACCEPT
iptables -A FORWARD -s 10.0.0.0/8 -p udp -d 0/0 --dport 21 -j ACCEPT
iptables -A FORWARD -s 10.0.0.0/8 -p tcp -d 0/0 --dport 24001 -j ACCEPT
iptables -A FORWARD -s 10.0.0.0/8 -p udp -d 0/0 --dport 24001 -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -s 10.0.0.0/8 -p tcp -d 0/0 --dport 21 -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -s 10.0.0.0/8 -p udp -d 0/0 --dport 24001 -j ACCEPT
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
iptables -t nat -A PREROUTING -i eth0 -s 10.0.0.0/8 -p udp -d 0/0 --dport 21 -j ACCEPT
iptables -t nat -A PREROUTING -i eth0 -s 10.0.0.0/8 -p udp -d 0/0 --dport 24001 -j ACCEPT
#------------------------------------------------------------------------------------------------------
#CONECTIVIDADE SOCIAL
iptables -t nat -A PREROUTING -p tcp -d 200.201.0.0/16 -j ACCEPT
iptables -A FORWARD -p tcp -d 200.201.0.0/16 -j ACCEPT
#PROXY TRANSPARENTE
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
#BLOQUEAR MSN
iptables -I FORWARD -p tcp -s 10.0.0.0/8 --dport 1863 -j DROP
#REDIRECIONAMENTO TERMINAL SERVICE WELTON
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 3389 -i eth1 -j DNAT --to 10.1.1.10
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 3389 -i eth1 -j DNAT --to 10.1.1.10
#REDIRECIONAMENTO FTP
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 21 -i eth1 -j DNAT --to 10.1.1.202
#REDIRECIONAMENTO TERMINAL SERVICE TESTE
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 3391 -i eth1 -j DNAT --to 10.1.1.202:3389
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 3391 -i eth1 -j DNAT --to 10.1.1.202:3389
#REDIRECIONAMENTO TERMINAL SERVICE TESTE
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 29 -i eth1 -j DNAT --to 10.1.1.28:3389
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 29 -i eth1 -j DNAT --to 10.1.1.28:3389
#VNC DELL
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 6900 -i eth1 -j DNAT --to 10.1.1.200
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 5700 -i eth1 -j DNAT --to 10.1.1.200
#REDIRECIONAMENTO PALM
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 6500 -i eth1 -j DNAT --to 10.1.1.200
#REDIRECIONAMENTO CENTRAL
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 2004 -i eth1 -j DNAT --to 10.1.1.62
#REDIRECIONAMENTO EMULE SUPORTE 01 ED
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 4668 -i eth1 -j DNAT --to 10.1.1.37
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 4669 -i eth1 -j DNAT --to 10.1.1.37
#REDIRECIONAMENTO EMULE WELTON
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 4450 -i eth1 -j DNAT --to 10.1.1.10
iptables -t nat -A PREROUTING -p udp -s 0/0 --dport 4451 -i eth1 -j DNAT --to 10.1.1.10
#REDIRECIONAMENTO ACESSO PONTO
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 4810 -i eth1 -j DNAT --to 10.1.1.31
#REDIRECIONAMENTO ACESSO PONTO 2
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 4811 -i eth1 -j DNAT --to 10.1.1.42
#REDERICIONAMENTO TORRENT
iptables -t nat -A PREROUTING -p tcp -s 0/0 --dport 5151 -i eth1 -j DNAT --to 10.1.1.10