Tema: Re: Klausimas del Squid
Autorius: Nerijus
Data: 2008-07-08 19:58:29
Ziuriu dvi nuomones cia :)
Bet ar kartais neturetu Squid'as ir siaip matyti visa trafica kai 
squid.conf padarai "http_port 3128 transparent"?

iptables -F
iptables -P INPUT DROP
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i lo -j ACCEPT
#
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -i eth1 -s 192.168.100.0/24 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type 8 -s 0/0 -d $WAN_IP -m state 
--state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to $WAN_IP
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 3306 -j DNAT 
--to-destination 192.168.100.250
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5500 -j DNAT 
--to-destination 192.168.100.95:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5600 -j DNAT 
--to-destination 192.168.100.93:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5700 -j DNAT 
--to-destination 192.168.100.51:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5701 -j DNAT 
--to-destination 192.168.100.51:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30022 -j DNAT 
--to-destination 192.168.100.50:22
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30040 -j DNAT 
--to-destination 192.168.100.250:3389
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30041 -j DNAT 
--to-destination 192.168.100.30:30041

iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 8181 -j DNAT 
--to-destination 192.168.100.50
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 6881 -j DNAT 
--to-destination 192.168.100.50
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 4444 -j DNAT 
--to-destination 192.168.100.50

iptables -A INPUT -i eth0 -p tcp --dport 20 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 1701 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 1723 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 3306 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5600 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5901 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 5901 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5900 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 5900 -j ACCEPT

#FTP Passive mode
iptables -A INPUT -i eth0 -p tcp --dport 49152:65534 -j ACCEPT