adamolb
(usa Fedora)
Enviado em 04/03/2009 - 14:13h
Olá, quando executo o script descrito abaixo no Fedora Core 8, ele me apresenta diversos erros, já no Red Hat 7.2 onde o mesmo estava eu consigo executar normalmente.
________________________________________________
Erro
./punch-vpn-peers
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
...
...
...
________________________________________________
script
#!/bin/sh
PEERS=`cat /etc/ppp/chap-secrets | grep -v \# | cut -d. -f4`
/sbin/iptables -F VPN
/sbin/iptables -A VPN -j DROP
for X in $PEERS ; do
# Sessao para o Siscomex 10.3.11.1
/sbin/iptables -I VPN -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.11.1/32 --dport 23 -j ACCEPT
/sbin/iptables -I VPN -p tcp -d 192.168.254.$X/32 --dport 1024:65535 -s 10.3.11.1/32 --sport 23 ! --syn -j ACCEPT
# Masquerade
# /sbin/iptables -I POSTROUTING -t nat -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.11.1/32 --dport 23 -j MASQUERADE
# Sessao para 10.3.12.1
/sbin/iptables -I VPN -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.12.1/32 --dport 23 -j ACCEPT
/sbin/iptables -I VPN -p tcp -d 192.168.254.$X/32 --dport 1024:65535 -s 10.3.12.1/32 --sport 23 ! --syn -j ACCEPT
# Masquerade
# /sbin/iptables -I POSTROUTING -t nat -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.12.1/32 --dport 23 -j MASQUERADE
# Sessao para 10.3.254.1
/sbin/iptables -I VPN -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.254.1/32 --dport 23 -j ACCEPT
/sbin/iptables -I VPN -p tcp -d 192.168.254.$X/32 --dport 1024:65535 -s 10.3.254.1/32 --sport 23 ! --syn -j ACCEPT
# Masquerade
# /sbin/iptables -I POSTROUTING -t nat -p tcp -s 192.168.254.$X/32 --sport 1024:65535 -d 10.3.254.1/32 --dport 23 -j MASQUERADE