- 论坛徽章:
- 0
|
#!/bin/sh
#dhcpd eth0
/sbin/modprobe ip_tables
/sbin/modprobe ip_nat_ftp
/sbin/modprobe ip_conntrack_ftp
/sbin/iptables -F
/sbin/iptables -F -t nat
/sbin/iptables -X
/sbin/iptables -Z
#/sbin/iptables -P INPUT ACCEPT
/sbin/iptables -P FORWARD ACCEPT
/sbin/iptables -P OUTPUT ACCEPT
echo "1"> /proc/sys/net/ipv4/ip_forward
iptables -t nat -A PREROUTING -p udp -d 192.168.0.1 --dport 53 -j DNAT --to 61.134.1.4:53
/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
/sbin/iptables -A FORWARD -s 0/0 -d 0/0 -j ACCEPT
#iptables -t nat -A PREROUTING -d 61.185.250.186 -p tcp -m tcp --dport 21 -j DNAT --to-destination 192.168.0.70:21
#iptables -t nat -A POSTROUTING -d 192.168.0.70 -p tcp -m tcp --dport 21 -j SNAT --to-source 192.168.0.1
#/sbin/iptables -t nat -A PREROUTING -i eth0 -p tcp -s 0/0 --dport 80 -j DNAT --to 192.168.0.1:3333
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
iptables -A FORWARD -p tcp --syn -m limit --limit 1000/s -j ACCEPT
#iptables -A FORWARD -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j ACCEPT
#iptables -A FORWARD -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT |
|