Djhony
(usa Debian)
Enviado em 24/06/2014 - 15:48h
minhas regras estão assim, espero que ajude, outra coisa uso sim um proxy que é uma outra máquina separada, mas é virtual, se precisar de alguma outra coisa me avise Carlos.
fwmt:/etc# vim iptables.up.rules
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -o eth1 -j MASQUERADE
-A POSTROUTING -o eth2 -j MASQUERADE
-A PREROUTING -p tcp -m tcp -i eth1 --dport 3390 -j DNAT --to-destination 192.168.0.220:3389
-A PREROUTING -p tcp -m tcp -i eth1 --dport 3391 -j DNAT --to-destination 192.168.0.20:3389
-A PREROUTING -p tcp -m tcp -i eth1 --dport 3393 -j DNAT --to-destination 192.168.0.100:3389
-A PREROUTING -p tcp -m tcp -i eth1 --dport 3394 -j DNAT --to-destination 192.168.0.102:3389
-A PREROUTING -p tcp -m tcp -i eth1 --dport 3395 -j DNAT --to-destination 192.168.0.230:3389
-A PREROUTING -p tcp -m tcp -i eth2 --dport 3389 -j DNAT --to-destination 192.168.0.220:3389
-A PREROUTING -p tcp -m tcp -s 50.30.37.46 -i eth2 --dport 1433 -j DNAT --to-destination 192.168.0.253:1433
-A PREROUTING -p tcp -m tcp -s 50.30.37.46 -i eth2 --dport 1433 -j DNAT --to-destination 192.168.0.249:1433
-A PREROUTING -p tcp -m tcp -s 50.30.37.46 -i eth1 --dport 1433 -j DNAT --to-destination 192.168.0.253:1433
-A PREROUTING -p tcp -m tcp -s 50.30.37.46 -i eth1 --dport 1433 -j DNAT --to-destination 192.168.0.249:1433
-A PREROUTING -p tcp -m tcp -s 187.37.49.56 -i eth1 --dport 1433 -j DNAT --to-destination 192.168.0.253:1433
-A PREROUTING -p tcp -m tcp -s 191.183.41.149 -i eth1 --dport 1433 -j DNAT --to-destination 192.168.0.253:1433
COMMIT
# Completed on Fri Feb 10 09:52:39 2012
# Generated by iptables-save v1.4.8 on Fri Feb 10 09:52:39 2012
*mangle
:FORWARD ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -s 192.168.0.20 -j ACCEPT
-A PREROUTING -s 192.168.0.220 -j ACCEPT
-A PREROUTING -s 192.168.0.253 -j ACCEPT
-A PREROUTING -s 192.168.0.249 -j ACCEPT
-A PREROUTING -s 192.168.0.238 -j ACCEPT
-A PREROUTING -s 192.168.0.252 -j ACCEPT
-A PREROUTING -s 192.168.0.106 -j ACCEPT
-A PREROUTING -s 192.168.0.104 -j ACCEPT
-A PREROUTING -s 192.168.0.230 -j ACCEPT
-A PREROUTING -s 192.168.0.160 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.253 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.252 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.0/24 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.249 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.156 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -s 192.168.0.100 ! -d 192.168.0.0/16 -i eth0 -j MARK --set-xmark 0x1/0xffffffff
COMMIT
# Completed on Fri Feb 10 09:52:39 2012
# Generated by iptables-save v1.4.8 on Fri Feb 10 09:52:39 2012
*filter
:FORWARD ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A FORWARD -s 50.30.37.46 -j ACCEPT
-A FORWARD -s 192.168.0.20 -j ACCEPT
-A FORWARD -s 192.168.0.100 -j ACCEPT
-A FORWARD -s 192.168.0.101 -j ACCEPT
-A FORWARD -s 192.168.0.102 -j ACCEPT
-A FORWARD -s 192.168.0.105 -j ACCEPT
-A FORWARD -s 192.168.0.107 -j ACCEPT
-A FORWARD -s 192.168.0.108 -j ACCEPT
-A FORWARD -s 192.168.0.109 -j ACCEPT
-A FORWARD -s 192.168.0.200 -j ACCEPT
-A FORWARD -s 192.168.0.237 -j ACCEPT
-A INPUT -s 177.140.171.243 -j ACCEPT
-A FORWARD -s 192.168.0.247 -j ACCEPT
-A FORWARD -s 192.168.0.249 -j ACCEPT
-A FORWARD -s 192.168.0.252 -j ACCEPT
-A FORWARD -s 192.168.0.253 -j ACCEPT
-A FORWARD -p tcp -m tcp -s 192.168.0.215 --sport 8080 -j ACCEPT
-A FORWARD -s 192.168.0.199 -j ACCEPT
-A FORWARD -s 189.120.183.239 -j ACCEPT
-A FORWARD -s 192.168.0.114 -j ACCEPT
-A FORWARD -s 192.168.0.118 -j ACCEPT
-A FORWARD -p tcp -m tcp -s 192.168.0.230 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.240 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.241 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.243 --dport 80 -j DROP
-A OUTPUT -p tcp -m tcp -o eth1 --sport 10000 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.242 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.244 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.245 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.246 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp -s 192.168.0.249 --dport 80 -j DROP
-A FORWARD -p tcp -m tcp --dport 80 -j DROP
COMMIT