- 论坛徽章:
- 0
|
我目前用的是这个规则
#!/bin/sh
echo "1" > /proc/sys/net/ipv4/ip_forward
modprobe ip_tables
modprobe iptable_filter
modprobe iptable_nat
modprobe ip_conntrack_ftp
modprobe ip_nat_ftp
iptables -F
iptables -t nat -F
iptables -X
iptables -t nat -X
iptables -P INPUT DROP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp -m multiport --dports 110,25 -j ACCEPT
iptables -A INPUT -i eth1 -p udp -m multiport --dports 53 -j ACCEPT
iptables -A INPUT -p tcp --dport 3128 -j ACCEPT
iptables -A INPUT -p tcp --dport 88 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -P FORWARD DROP
iptables -A FORWARD -p udp -s 196.196.0.0/24 --dport 53 -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -p tcp -i eth1 -m multiport --dports 110,25 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 22223 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 22221 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 22224 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 16801 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 16811 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 4000 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 25 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 110 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1863 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 569 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8014 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8084 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 4443 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 443 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8601 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7709 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8001 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8002 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8003 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8004 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8009 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8109 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8209 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 6677 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7711 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1080 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 9080 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7708 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7709 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 4430 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 6001 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8905 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8101 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 3128 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 9999 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 9000 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 9001 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 9002 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 23 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8016 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1119 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1088 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 17991 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1800 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1810 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7001 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 8016 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 110 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 6188 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 5188 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 25 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 1119 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 88 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 81 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 6666 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7711 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7777 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7773 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 7008 -j ACCEPT
iptables -A FORWARD -p tcp --dport 22 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 16000 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp --dport 3724 -j ACCEPT
/sbin/sysctl -w net.ipv4.netfilter.ip_conntrack_tcp_timeout_established=3800 &>/dev/null
iptables -t nat -A PREROUTING -s 196.196.0.0/24 -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A POSTROUTING -s 196.196.0.8/24 -o ppp0 -j MASQUERADE
|
|