Portál AbcLinuxu, 26. dubna 2024 13:21
NET_ETH="eth0" LOCAL_ETH="eth1" iptables -F iptables -P INPUT DROP iptables -P OUTPUT DROP iptables -P FORWARD DROP iptables -A INPUT -i $NET_ETH -p ICMP --icmp-type 0 -m limit --limit 1/s --limit-burst 5 -j ACCEPT iptables -A INPUT -i $NET_ETH -p ICMP --icmp-type 3 -m limit --limit 1/s --limit-burst 5 -j ACCEPT iptables -A INPUT -i $NET_ETH -p ICMP --icmp-type 8 -m limit --limit 1/s --limit-burst 5 -j ACCEPT iptables -A INPUT -i $NET_ETH -p ICMP --icmp-type 11 -m limit --limit 1/s --limit-burst 5 -j ACCEPT iptables -A INPUT -i $LOCAL_ETH -p ALL -j ACCEPT iptables -A INPUT -i lo -p ALL -j ACCEPT iptables -A INPUT -p ALL -i $NET_ETH -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A INPUT -p tcp --dport 22 -i $NET_ETH -j ACCEPT iptables -A INPUT -j LOG --log-prefix INPUT-DROP iptables -A OUTPUT -j ACCEPT iptables -A FORWARD -i $LOCAL_ETH -j ACCEPT iptables -A FORWARD -i $NET_ETH -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -t nat -A POSTROUTING -o $NET_ETH -j MASQUERADE
Tiskni Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.