Jump to content

Firewall(iptables)


Recommended Posts

Вопрос к знающим людям по настройке iptables.

Сервер раздаёт инет.

eth0 - world

eth1 - local

Стоит биллинг "Stargazer".

Не проходит пинг с сервера на локальные интерфейсы.

Уже и не знаю что делать(((...

 

 

#!/bin/bash

 

echo "1" > /proc/sys/net/ipv4/ip_forward

 

 

###### Clearing firewall ######

iptables -F

iptables -X

iptables -t nat -F

iptables -t nat -X

 

 

###### Policy ######

iptables -P INPUT DROP

iptables -P INPUT DROP

iptables -P FORWARD DROP

 

 

###### Chain for checking tcp packets ######

iptables -N tcp_check

iptables -A tcp_check -p TCP --syn -j ACCEPT

iptables -A tcp_check -p TCP -m state --state ESTABLISHED,RELATED -j ACCEPT

iptables -A tcp_check -p TCP -j DROP

 

###### INPUT chain rules ######

iptables -A INPUT -d 127.0.0.1 -j ACCEPT

 

#Packets for established connections

iptables -A INPUT -p ALL -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT

 

##TCP rules

iptables -A INPUT -p TCP -i eth0 --dport 21 -j tcp_check

iptables -A INPUT -p TCP -i eth0 --dport 22 -j tcp_check

iptables -A INPUT -p TCP -i eth0 --dport 80 -j tcp_check

iptables -A INPUT -p TCP -i eth0 --dport 113 -j tcp_check

#SSH from admin

iptables -A INPUT -p TCP -s 192.168.0.2 -d 192.168.0.1 --dport 22 -j ACCEPT

#Stargazer configurator

iptables -A INPUT -p TCP -s 192.168.0.2 -d 192.168.0.1 --dport 5555 -j ACCEPT

 

##UDP rules

iptables -A INPUT -p UDP -i eth0 --dport 53 -j ACCEPT

#InetAccess

iptables -A INPUT -p UDP -s 192.168.0.0/24 --sport 5555 -d 192.168.0.1 --dport 5555 -j ACCEPT

 

 

##ICMP rules

iptables -A INPUT -p ICMP --icmp-type 8 -j ACCEPT

iptables -A INPUT -p ICMP --icmp-type 11 -j ACCEPT

 

 

###### OUTPUT chain rules ######

iptables -A OUTPUT -p ALL -s 127.0.0.1 -j ACCEPT

iptables -A OUTPUT -p ALL -s 192.168.0.1 -j ACCEPT

iptables -A OUTPUT -p ALL -o eth0 -j ACCEPT

 

###### MASQUERDING ######

iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

 

Что не так???

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...