- 论坛徽章:
- 0
|
!/bin/bash
echo "1">/proc/sys/net/ipv4/ip_forward
INET_IFACE=''eth1"
INET_IP="0.0.0.0"
IPT="/usr/sbin/iptables"
/sbin/depmod -a
/sbin/modprobe ip_tables
/sbin/modprobe iptables_nat
/sbin/modprobe ipt_LOG
$IPT -P INPUT ACCEPT
$IPT -P FORWARD ACCEPT
$IPT -P OUTPUT ACCEPT
$IPT -t nat -P PRETOUTING ACCEPT
$IPT -t nat -P POSTROUTING ACCEPT
for TABLE in filter nat mangle ; do
$IPT -t $TABLE -F
$IPT -t $TABLE -X
done
$IPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
for DNS is $(grep ^n /etc/resolv.conf|awk `{print $2}`; do
$IPT -A INPUT -p udp -s $DNS --sport domain -j ACCEPT
done
$IPT -N LOGDENY
$IPT -A LOGDENY -j DROP
$IPT -A INPUT -p tcp --dport 3721 -j ACCEPT
$IPT -A INPUT -i ! lo -m state --state NEW,INVALID -j LOGDENY
if [ "$INET_IFACE" = ppp0 ]; then
$IPT -t nat -A POSTROUTING -o $INET_IFACE -j MASQUERADE
else
$IPT -t nat -A POSTROUTING -o $INET_IFACE -j SNAT --to $INET_IP
fi
以上在suse中做nat实现
不知道它这个开放3721口是干什么用的......给木马开门的? |
|