
dpinho
(usa Debian)
Enviado em 13/04/2009 - 13:54h
FTP Funcionando!!!!! Segue iptables
#!/bin/sh
# /etc/rc.local
modprobe iptable_nat
modprobe ip_nat_ftp
modprobe ipt_REDIRECT
modprobe ipt_REJECT
modprobe ip_conntrack
modprobe ip_conntrack_ftp
# Compartilhamento e Mascara
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
# Squid
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j \
REDIRECT --to-port 3128
# Libera FTP
iptables -t filter -A INPUT -i eth1 -p tcp -m multiport --dports 21,20 -j ACCEPT
iptables -t filter -A INPUT -i eth1 -p udp -m multiport --sports 21,20 -j ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth0 -j ACCEPT
# Torrent
iptables -A INPUT -p tcp --destination-port 6881:6999 -j ACCEPT
iptables -A FORWARD -j ACCEPT -p tcp --dport 6881:6999
iptables -A INPUT -p udp --destination-port 6881:6999 -j ACCEPT
iptables -A FORWARD -j ACCEPT -p udp --dport 6881:6999
# Libera SSH
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# Drops
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
echo 1 > /proc/sys/net/ipv4/conf/default/rp_filter
iptables -A INPUT -m state --state INVALID -j DROP
iptables -A INPUT -p tcp --syn -j DROP