eduardoniluiz
(usa Slackware)
Enviado em 20/09/2012 - 19:42h
este é o script original, ele esta todo comentado por que o server foi reiniciado e ele acusou erro em todas as linhas, e não estava funcionando mais a aplicação.
comentei todas as linhas e tentei realizar só a liberação da porta 3340.
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 3340 -j DNAT --to-dest 192.168.1.7:3340
iptables -A FORWARD -p tcp -i eth0 --dport 3340 -d 192.168.1.7 -j ACCEPT
iptables -t nat -A POSTROUTING -d 192.168.1.7 -p tcp --dport 3340 -j SNAT --to 201.72.255.98
iptables -A INPUT -p tcp --destination-port 3340 -j ACCEPT
iptables -A INPUT -p tcp --syn -s 192.168.1.0/255.255.255.0 -j ACCEPT
# Generated by iptables-save v1.3.5 on Thu Sep 20 14:50:23 2012
#*mangle
#:PREROUTING ACCEPT [7302072:4343392023]
#:INPUT ACCEPT [991801:481604530]
#:FORWARD ACCEPT [6293674:3855476794]
#:OUTPUT ACCEPT [973351:578431023]
#:POSTROUTING ACCEPT [7265951:4433807315]
#COMMIT
# Completed on Thu Sep 20 14:50:23 2012
# Generated by iptables-save v1.3.5 on Thu Sep 20 14:50:23 2012
#*nat
#:PREROUTING ACCEPT [188734:13784818]
#:POSTROUTING ACCEPT [12082:739265]
#:OUTPUT ACCEPT [26169:1947241]
#-A PREROUTING -p tcp -m tcp --dport 3340 -j DNAT --to-destination 192.168.1.7
#-A PREROUTING -d 201.72.255.98 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.13:8080
#-A PREROUTING -d 201.72.255.98 -p tcp -m tcp --dport 5269 -j DNAT --to-destination 192.168.1.11:5269
#-A PREROUTING -d 201.72.255.98 -p tcp -m tcp --dport 5222 -j DNAT --to-destination 192.168.1.11:5222
#-A PREROUTING -d 201.72.255.98 -p tcp -m tcp --dport 9090 -j DNAT --to-destination 192.168.1.11:9090
#-A POSTROUTING -o eth0 -j MASQUERADE
#-A POSTROUTING -d 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -d 192.168.1.13 -p tcp -m tcp --dport 8080 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -d 192.168.1.11 -p tcp -m tcp --dport 9090 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -d 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 189.39.15.155
#-A POSTROUTING -d 192.168.1.1 -p tcp -m tcp --dport 3340 -j SNAT --to-source 189.39.15.155
#-A POSTROUTING -d 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -d 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -s 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 201.72.255.98
#-A POSTROUTING -s 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 189.39.15.155
#-A POSTROUTING -d 192.168.1.7 -p tcp -m tcp --dport 3340 -j SNAT --to-source 189.39.15.155
#COMMIT
# Completed on Thu Sep 20 14:50:23 2012
# Generated by iptables-save v1.3.5 on Thu Sep 20 14:50:23 2012
#*filter
#:INPUT ACCEPT [823901:464750460]
#:FORWARD ACCEPT [6290279:3854390518]
#:OUTPUT ACCEPT [972277:578330521]
#-A INPUT -s 202.138.226.216 -j DROP
#-A INPUT -s 72.64.137.43 -j DROP
#-A INPUT -s 67.63.56.91 -j DROP
#-A INPUT -i eth0 -p tcp -m tcp --dport 88 -j ACCEPT
#-A INPUT -i eth0 -p tcp -m tcp --dport 3340 -j ACCEPT
#-A INPUT -s 72.233.118.138 -j DROP
#-A INPUT -s 221.13.34.3 -j DROP
#-A INPUT -s 221.134.144.147 -j DROP
#-A INPUT -s 209.193.93.246 -j DROP
#-A INPUT -s 67.63.56.92 -j DROP
#-A INPUT -s 27.0.15.37 -j DROP
#-A INPUT -s 88.134.24.76 -j DROP
#-A INPUT -s 200.141.223.78 -j DROP
#-A INPUT -s 109.169.80.126 -j DROP
#-A INPUT -s 182.48.20.141 -j DROP
#-A INPUT -s 67.63.56.88 -j DROP
#-A INPUT -s 67.63.56.89 -j DROP
#-A INPUT -s 200.85.122.11 -j DROP
#-A FORWARD -p tcp -m tcp --dport 3340 -j ACCEPT
#-A FORWARD -i eth0 -p tcp -m tcp --dport 88 -j ACCEPT
#-A FORWARD -i eth0 -p tcp -m tcp --dport 3340 -j ACCEPT
#COMMIT
# Completed on Thu Sep 20 14:50:23 2012