Nat No Linux

download Nat No Linux

If you can't read please download the document

description

Linux

Transcript of Nat No Linux

#Script: /usr/local/bin/firewall #!/bin/bashecho "Ativando compartilhamento "# Ativando Roteamento de pacoteecho 1 > /proc/sys/net/ipv4/ip_forward# NATiptables -t nat -A POSTROUTING -o eth0 -j MASQUERADEecho " Compartilhamento ativado"iptables -I FORWARD -m string --algo bm --string "orkut" -j DROPiptables -I FORWARD -m string --algo bm --string "globo" -j DROPiptables -I FORWARD -m string --algo bm --string "facebook" -j DROP #regra para iptables -t nat -A PREROUTING -d 192.168.1.20 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.0.30:80iptables -t nat -A POSTROUTING -d 192.168.0.30/24 -p tcp -m tcp --dport 80 -j SNAT --to-source 192.168.1.20#Regras para redirecionar a porta 80 de um servidor para determinado IP.iptables -A FORWARD -d 192.168.0.30 -j ACCEPTiptables -A FORWARD -p tcp --dport 80 -j ACCEPTiptables -A FORWARD -s 192.168.0.30/24 -j ACCEPTiptables -A FORWARD -d 192.168.0.30/24 -j ACCEPTiptables -A FORWARD -s 192.168.1.20/24 -j ACCEPTiptables -t nat -D PREROUTING -d 192.168.1.20 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.0.30:80iptables -t nat -A PREROUTING -d 192.168.1.20/24 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.0.30:80#bloquear ICMP de qualquer rede iptables -A INPUT -p icmp -j DROPiptables -A INPUT -i eth0 -p tcp --dport 22 -j DROPiptables -A INPUT -i eth0 -p udp --dport 53 -j DROP