You are on page 1of 1

#Script:

/usr/local/bin/firewall
#!/bin/bash
echo "Ativando compartilhamento "
# Ativando Roteamento de pacote
echo 1 > /proc/sys/net/ipv4/ip_forward
# NAT
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
echo " Compartilhamento ativado"
iptables -I FORWARD -m string --algo bm --string "orkut" -j DROP
iptables -I FORWARD -m string --algo bm --string "globo" -j DROP
iptables -I FORWARD -m string --algo bm --string "facebook" -j DROP
#regra para
iptables -t nat -A PREROUTING -d 192.168.1.20 -p tcp -m tcp --dport 80 -j DNAT -to-destination 192.168.0.30:80
iptables -t nat -A POSTROUTING -d 192.168.0.30/24 -p tcp -m tcp --dport 80 -j SN
AT --to-source 192.168.1.20
#Regras para redirecionar a porta 80 de um servidor para determinado IP.
iptables -A FORWARD -d 192.168.0.30 -j ACCEPT
iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
iptables -A FORWARD -s 192.168.0.30/24 -j ACCEPT
iptables -A FORWARD -d 192.168.0.30/24 -j ACCEPT
iptables -A FORWARD -s 192.168.1.20/24 -j ACCEPT
iptables -t nat -D PREROUTING -d 192.168.1.20 -p tcp -m tcp --dport 80 -j DNAT -to-destination 192.168.0.30:80
iptables -t nat -A PREROUTING -d 192.168.1.20/24 -p tcp -m tcp --dport 80 -j DNA
T --to-destination 192.168.0.30:80
#bloquear ICMP de qualquer rede
iptables -A INPUT -p icmp -j DROP
iptables -A INPUT -i eth0 -p tcp --dport 22 -j DROP
iptables -A INPUT -i eth0 -p udp --dport 53 -j DROP

You might also like