linux防火墙应用网关,Linux网关防火墙简单版本

#!bin/sh

IFCONFIG=/sbin/ifconfig

IP=/sbin/ip

IPTABLES=/sbin/iptables

if [ ! -x $IFCONFIG ]; then

echo "$IFCONFIG does not exist."

exit 1

fi

if [ ! -x $IP ]; then

echo "$IP does not exist."

exit 1

fi

if [ ! -x $IPTABLES ]; then

echo "$IPTABLES does not exist."

exit 1

fi

# BASE is the lowest IP address your server is allowed

# to hand out.

LOCT=`ifconfig eth0|grep 'inet addr:'|awk -F: '{print $2}'|awk '{print $1}'`

# NAT is the set of addresses which your server will

# NAT behind it. Other addresses behind your server

# WILL NOT be NATed.

NAT=`ip route list|grep 'dev eth0'|awk '{print $1}'`

# MYIP is the public IP address of this server.

MYIP=`ifconfig eth1|grep 'inet addr:'|awk -F: '{print $2}'|awk '{print $1}'`

#clear firewall rule

$IPTABLES -t filter -F

$IPTABLES -t mangle -F

$IPTABLES -t nat -F

$IPTABLES -t raw -F

#mangle PREROUTING

$IPTABLES -t mangle -P PREROUTING ACCEPT

#nat PREROUTING

$IPTABLES -t nat -P PREROUTING ACCEPT

$IPTABLES -t nat -A PREROUTING -p tcp --dport 80 -m mark ! --mark 0x8 -j DNAT --to-destination $LOCT:80

#filter FORWARD

$IPTABLES -P FORWARD DROP

$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT

$IPTABLES -A FORWARD -p icmp -j ACCEPT

$IPTABLES -A FORWARD -p tcp --dport 22 -j ACCEPT

$IPTABLES -A FORWARD -p tcp --sport 22 -j ACCEPT

$IPTABLES -A FORWARD -p udp --dport 53 -j ACCEPT

$IPTABLES -A FORWARD -p udp --sport 53 -j ACCEPT

$IPTABLES -A FORWARD -p udp --dport 68 -j ACCEPT

$IPTABLES -A FORWARD -p udp --sport 68 -j ACCEPT

$IPTABLES -A FORWARD -p udp --dport 1812 -j ACCEPT

$IPTABLES -A FORWARD -p udp --sport 1812 -j ACCEPT

$IPTABLES -A FORWARD -p udp --dport 1813 -j ACCEPT

$IPTABLES -A FORWARD -p udp --sport 1813 -j ACCEPT

$IPTABLES -A FORWARD -s $LOCT -j ACCEPT

$IPTABLES -A FORWARD -d $LOCT -j ACCEPT

#nat POSTROUTING

$IPTABLES -t nat -P POSTROUTING ACCEPT

$IPTABLES -t nat -A POSTROUTING -s $NAT -j SNAT --to-source $MYIP

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值