Portál AbcLinuxu, 11. května 2025 10:45
ip route flush table T1 ip route flush table T2 ip route flush cache ip route add $P0_NET dev $IF0 src $IP0 table T1 ip route add default via $P0 table T1 ip route add $P1_NET dev $IF1 src $IP1 table T2 ip route add default via $P1 table T2 ip route add $P0_NET dev $IF0 src $IP0 ip route add $P1_NET dev $IF1 src $IP1 ip route add default via $P0 #ip route add default via $P1 ip rule add from $IP0 table T1 ip rule add from $IP1 table T2 ip route add $P2_NET dev $IF2 table T1 ip route add $P2_NET dev $IF2 table T2Nastaveni firewallu /vybrane podstatne pasaze/:
# Modul pro FTP prenosy /sbin/modprobe ip_conntrack_ftp /sbin/modprobe ip_nat_ftp # Zapneme routovani paketu echo "1" > /proc/sys/net/ipv4/ip_forward echo "1" > /proc/sys/net/ipv4/tcp_syncookies echo "0" > /proc/sys/net/ipv4/tcp_ecn # Implicitni politikou je zahazovat nepovolene pakety $IPTABLES -P INPUT DROP $IPTABLES -P OUTPUT DROP $IPTABLES -P FORWARD DROP # Proroutrovani FTP $IPTABLES -t nat -A PREROUTING -p tcp -d $INET1_IP --dport 20 -j DNAT --to 10.1.1.2:20 $IPTABLES -A FORWARD -i $INET1_IFACE -o $LAN1_IFACE -p tcp -d 10.1.1.2 --dport 20 -j ACCEPT $IPTABLES -t nat -A PREROUTING -p tcp -d $INET2_IP --dport 20 -j DNAT --to 10.1.1.2:20 $IPTABLES -A FORWARD -i $INET2_IFACE -o $LAN1_IFACE -p tcp -d 10.1.1.2 --dport 20 -j ACCEPT # IP maskarada - SNAT # NATujeme $IPTABLES -t nat -A POSTROUTING -o $INET1_IFACE -j SNAT --to $INET1_IP $IPTABLES -t nat -A POSTROUTING -o $INET2_IFACE -j SNAT --to $INET2_IP # Routing zevnitr site ven neomezujeme $IPTABLES -A FORWARD -i $LAN1_IFACE -j ACCEPT # Routing zvenku dovnitr pouze pro navazana spojeni (stavovy firewall) $IPTABLES -A FORWARD -i $INET1_IFACE -o $LAN1_IFACE -m state --state ESTABLISHED,RELATED -j ACCEPT $IPTABLES -A FORWARD -i $INET2_IFACE -o $LAN1_IFACE -m state --state ESTABLISHED,RELATED -j ACCEPT.. ostatni nastaveni iptables jsem pro usporu vypustil. Diky za nasmerovani.
Na otázku zatím nikdo bohužel neodpověděl.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.