Advertisement
Guest User

Untitled

a guest
Sep 12th, 2012
23
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.81 KB | None | 0 0
  1. *filter
  2. :INPUT DROP [0:0]
  3. :FORWARD DROP [0:0]
  4. :OUTPUT ACCEPT [0:0]
  5. -A INPUT -i lo -j ACCEPT
  6. -A FORWARD -i lo -j ACCEPT
  7. -A INPUT -m state --state INVALID -j DROP
  8. -A INPUT -p icmp -m icmp --icmp-type 0 -m length --length 30:1100 -m limit --limit 4/sec -j ACCEPT
  9. -A INPUT -p icmp -m icmp --icmp-type 0 -j DROP
  10. -A INPUT -p icmp -m icmp --icmp-type 8 -m length --length 30:1100 -m limit --limit 4/sec -j ACCEPT
  11. -A INPUT -p icmp -m icmp --icmp-type 8 -j DROP
  12. -A INPUT -p icmp -j ACCEPT
  13. -A INPUT -p tcp --dport 2250 -j ACCEPT
  14. -A INPUT -p tcp -m multiport --dports 22,53,67,80,953 -j ACCEPT
  15. -A INPUT -p udp -m multiport --dports 53,67,80,953 -j ACCEPT
  16. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  17. #
  18. #####################################################################
  19. ### Inicio das configuracoes para o AltecnetCard na tabela filter ###
  20. #####################################################################
  21. #
  22. # Cria a chain ALTECNETCARD na tabela filter
  23. -N ALTECNETCARD
  24. #
  25. ### Acesso aos radios
  26. #
  27. -A FORWARD -s 172.16.0.0/16 -d 192.168.1.0/24 -j ACCEPT
  28. -A FORWARD -d 172.16.0.0/16 -s 192.168.1.0/24 -j ACCEPT
  29. #
  30. # Redireciona o resto do FORWARD (trafego entrante e sainte) para ALTECNETCARD
  31. -A FORWARD -j ALTECNETCARD
  32. # Permite acesso livre ao login.altecnetcard.com.br
  33. -A ALTECNETCARD -s 187.17.96.84 -j ACCEPT
  34. -A ALTECNETCARD -d 187.17.96.84 -j ACCEPT
  35. -A ALTECNETCARD -s 72.232.181.75 -j ACCEPT
  36. -A ALTECNETCARD -d 72.232.181.75 -j ACCEPT
  37. -A ALTECNETCARD -s 72.232.38.195 -j ACCEPT
  38. -A ALTECNETCARD -d 72.232.38.195 -j ACCEPT
  39. # Bloqueia o resto
  40. -A ALTECNETCARD -j DROP
  41. #############################################################
  42. ### Final das configuracoes para o AltecnetCard na filter ###
  43. #############################################################
  44. #
  45. COMMIT
  46. *nat
  47. :PREROUTING ACCEPT [0:0]
  48. :POSTROUTING ACCEPT [0:0]
  49. :OUTPUT ACCEPT [0:0]
  50. -A POSTROUTING -o eth0 -j MASQUERADE
  51. #
  52. ##################################################################
  53. ### Inicio das configuracoes para o AltecnetCard na tabela nat ###
  54. ##################################################################
  55. #
  56. # Cria a chain ALTECNETCARD na tabela nat
  57. -N ALTECNETCARD
  58. #
  59. ### Acesso aos radios
  60. #
  61. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8001 -j DNAT --to 192.168.1.1:80
  62. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8002 -j DNAT --to 192.168.1.2:80
  63. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8003 -j DNAT --to 192.168.1.3:80
  64. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8004 -j DNAT --to 192.168.1.4:80
  65. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8005 -j DNAT --to 192.168.1.5:80
  66. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8006 -j DNAT --to 192.168.1.6:80
  67. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8007 -j DNAT --to 192.168.1.7:80
  68. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8008 -j DNAT --to 192.168.1.8:80
  69. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8009 -j DNAT --to 192.168.1.9:80
  70. -A PREROUTING -s 172.16.0.0/16 -p tcp --dport 8010 -j DNAT --to 192.168.1.10:80
  71. -A POSTROUTING -s 172.16.0.0/16 -d 192.168.1.0/24 -j SNAT --to 192.168.1.254
  72. #
  73. # Redireciona o resto da PREROUTING (trafego sainte) para ALTECNETCARD
  74. -A PREROUTING -i eth1 -j ALTECNETCARD
  75. # Permite acesso livre ao login.altecnetcard.com.br
  76. -A ALTECNETCARD -d 187.17.96.84 -j ACCEPT
  77. -A ALTECNETCARD -d 72.232.181.75 -j ACCEPT
  78. -A ALTECNETCARD -d 72.232.38.195 -j ACCEPT
  79. # Captura pacotes DNS e HTTP
  80. -A ALTECNETCARD -p tcp -m multiport --dports 53,80 -j REDIRECT
  81. -A ALTECNETCARD -p udp -m multiport --dports 53,80 -j REDIRECT
  82. -A ALTECNETCARD -p tcp --dport 8000 -j REDIRECT --to 80
  83. -A ALTECNETCARD -p tcp --dport 8080 -j REDIRECT --to 80
  84. #################################################################
  85. ### Final das configuracoes para o AltecnetCard na tabela nat ###
  86. #################################################################
  87. #
  88. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement