Portál AbcLinuxu, 16. listopadu 2025 20:22
díky za rady
vypis firehol.conf:
lan_ips="192.168.0.1"
mazin_ips="192.168.10.1"
dnat to 192.168.0.2:5901 inface eth1 src not "${home_ips} ${mazin_ips}" proto tcp dport 5901
interface eth1 internet src not "${home_ips} ${mazin_ips}"
protection strong 10/sec 10
#server ident reject with tcp-reset
server ping accept
server ssh accept
client icmp accept
client ping accept
client dns accept
client http accept
client https accept
client ntp accept
interface eth2 lan
policy reject
server ssh accept
client all accept
interface eth0 mazin
policy reject
client all accept
router lan2internet inface eth2 outface eth1
masquerade
route all accept
router mazin2internet inface eth0 outface eth1
masquerade
route all accept
router internet2lan inface eth1 outface eth2
route ident reject with tcp-reset
server vnc accept dst 192.168.0.2
router internet2mazin inface eth1 outface eth0
route ident reject with tcp-reset
router lan2mazin inface eth2 outface eth0
route all accept
Na otázku zatím nikdo bohužel neodpověděl.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.