jefsni
(usa Debian)
Enviado em 17/08/2018 - 17:13h
Boa tarde, tenho um servidor Debian 7 com porxy, iptables, e não consigo liberar Terminal Service externamente?
1- Cabo Modem ligado na eth0 IP 192.168.0.250
2- Modem Net Pace C6500 com DMZ para o IP 192.168.2.250 do servidor proxy/firewall na eth1
3- #/etc/init.d/rc.firewall
# Variaveis
IPT='/sbin/iptables' #caminho para executavel do Iptables
WAN="eth0" #internet (onboard)
WAN0="192.168.0.250"
LAN="eth1" #redelocal (offboard)
LAN0='192.168.2.250' # IP eth1
LAN1='192.168.2.0/24' # Rede Local
TS='192.168.2.200' # IP WS2016
DVR='192.168.2.150' # IP DVR
PORTASUDP="53"
PORTASTCP="21,25,53,80,110,143,443,587,993,995"
PORTASTCP1="22,3128,3389,33899,3322"
PORTASDVR="8000,8001,554"
# Limpar regras antigas
$IPT --flush
$IPT --delete-chain
$IPT -F
$IPT -X
$IPT -F -t nat
$IPT -X -t nat
$IPT -F -t mangle
$IPT -X -t mangle
# Carregar os modulos do kernel para funcionamento do firewall
modprobe ip_conntrack
modprobe ip_conntrack_ftp
modprobe ip_nat_ftp
modprobe ipt_LOG
modprobe ipt_REJECT
modprobe ipt_MASQUERADE
modprobe iptable_nat
# PoliticAs Padrao
$IPT -P INPUT ACCEPT
$IPT -P OUTPUT ACCEPT
$IPT -P FORWARD ACCEPT
# Ativa o sistema roteamento de pacotes
echo 1 > /proc/sys/net/ipv4/ip_forward
# Ativa o mascararamento (nat com a internet)
$IPT -t nat -A POSTROUTING -o $WAN -j MASQUERADE
# Ida e volta acesso nas chains INPUT, OUTPUT e FORWARD
$IPT -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPT -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPT -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
# Redireciona internet para o Proxy
$IPT -t nat -A PREROUTING -i $LAN -p tcp --dport 80 -j REDIRECT --to-port 3128
$IPT -t nat -A PREROUTING -i $LAN -p udp --dport 80 -j REDIRECT --to-port 3128
# Liberar trafego loopback
$IPT -A INPUT -i lo -j ACCEPT
$IPT -A OUTPUT -o lo -j ACCEPT
# Liberar DNS
$IPT -A INPUT -m multiport -p udp --dports $PORTASUDP -j ACCEPT
$IPT -A FORWARD -m multiport -p udp --dports $PORTASUDP -j ACCEPT
# Liberar Portas TCP
$IPT -A INPUT -p tcp -m multiport --dports $PORTASDVR -j ACCEPT
$IPT -A INPUT -p tcp -m multiport --dports $PORTASTCP -j ACCEPT
$IPT -A INPUT -p tcp -m multiport --dports $PORTASTCP1 -j ACCEPT
$IPT -A FORWARD -p tcp -m multiport --dports $PORTASDVR -j ACCEPT
$IPT -A FORWARD -p tcp -m multiport --dports $PORTASTCP -j ACCEPT
$IPT -A FORWARD -p tcp -m multiport --dports $PORTASTCP1 -j ACCEPT
# NAT redirecionamento de portas
$IPT -t nat -A PREROUTING -i $WAN -p tcp --dport 3389 -j DNAT --to-destination $TS:3389
$IPT -t nat -A PREROUTING -i $WAN -p tcp -m tcp --dport 3322 -j DNAT --to-destination $LAN0:3322
$IPT -t nat -A PREROUTING -i $WAN -p tcp -m tcp --dport 8001 -j DNAT --to-destination $DVR:8001
$IPT -t nat -A PREROUTING -i $WAN -p tcp -m tcp --dport 8000 -j DNAT --to-destination $DVR:8000
$IPT -t nat -A PREROUTING -i $WAN -p tcp -m tcp --dport 554 -j DNAT --to-destination $DVR:554