Ocean Mist

4 Mar 2010

firewall NAT on 2 ethernet

Posted by taryana

eth0 <-> ppp0  internet

eth1 -> local access internet
#!/bin/sh
INTIF=”eth1″
#EXTIF=”eth0″
EXTIF=”ppp0″

/sbin/depmod -a
/sbin/modprobe ip_tables
/sbin/modprobe ip_conntrack
/sbin/modprobe ip_conntrack_ftp
/sbin/modprobe ip_conntrack_irc
/sbin/modprobe iptable_nat
/sbin/modprobe ip_nat_ftp
echo “1″ > /proc/sys/net/ipv4/ip_forward
echo “1″ > /proc/sys/net/ipv4/ip_dynaddr
iptables -P INPUT ACCEPT
iptables -F INPUT
iptables -P OUTPUT ACCEPT
iptables -F OUTPUT
iptables -P FORWARD DROP
iptables -F FORWARD
iptables -t nat -F
iptables -t nat -A PREROUTING -i eth1 -p tcp –dport 80 -j REDIRECT
–to-port 3128
iptables -A FORWARD -i $EXTIF -o $INTIF -m state –state
ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i $INTIF -o $EXTIF -j ACCEPT
iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE

Popularity: 3% [?]

Leave a Reply

Message: