home *** CD-ROM | disk | FTP | other *** search
IPTables Text | 2004-07-06 | 1.3 KB | 34 lines |
-
- $IPTABLES -P INPUT DROP
- $IPTABLES -P OUTPUT ACCEPT
- $IPTABLES -P FORWARD DROP
- $IPTABLES -F
- $IPTABLES -t nat -F
- $IPTABLES -X
-
- echo "1" > /proc/sys/net/ipv4/ip_dynaddr
- echo "1" > /proc/sys/net/ipv4/ip_forward
-
- /sbin/modprobe ip_vs
- /sbin/modprobe ip_nat_ftp
- /sbin/modprobe ip_conntrack_ftp
-
- $IPTABLES -A INPUT -i lo -j ACCEPT
- $IPTABLES -A INPUT -i $DEV_INT -j ACCEPT
- $IPTABLES -A INPUT -i $DEV_EXT -m state --state ESTABLISHED,RELATED -j ACCEPT
-
- $IPTABLES -A INPUT -i $DEV_EXT -p icmp --icmp-type 3 -j ACCEPT
- $IPTABLES -A INPUT -i $DEV_EXT -p icmp --icmp-type 4 -j ACCEPT
- $IPTABLES -A INPUT -i $DEV_EXT -p icmp --icmp-type 11 -j ACCEPT
- $IPTABLES -A INPUT -i $DEV_EXT -p icmp --icmp-type 12 -j ACCEPT
-
- $IPTABLES -A FORWARD -o eth1 -m state --state NEW -p TCP --sport 1024:65535 --dport 21 -j ACCEPT
- $IPTABLES -A FORWARD -o eth1 -m state --state NEW -p TCP --sport 1024:65535 --dport 1024:65535 -j ACCEPT
- $IPTABLES -A FORWARD -i $DEV_INT -o $DEV_EXT -m state --state ESTABLISHED,NEW,RELATED -j ACCEPT
- $IPTABLES -A FORWARD -i $DEV_EXT -o $DEV_INT -m state --state ESTABLISHED,RELATED -j ACCEPT
-
- $IPTABLES -t nat -A POSTROUTING -o $DEV_EXT -j MASQUERADE
- $IPTABLES -I FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-
- $IPTABLES -A INPUT -p udp --dport 5060 -i $DEV_INT -j DROP
-