Tema: Re: Klausimas del Squid
Autorius: Nerijus
Data: 2008-07-08 19:58:29
Ziuriu dvi nuomones cia :)
Bet ar kartais neturetu Squid'as ir siaip matyti visa trafica kai 
squid.conf padarai "http_port 3128 transparent"?

iptables -F
iptables -P INPUT DROP
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i lo -j ACCEPT
#
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -i eth1 -s 192.168.100.0/24 -j ACCEPT
iptables -A INPUT -p icmp --icmp-type 8 -s 0/0 -d $WAN_IP -m state 
--state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to $WAN_IP
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 3306 -j DNAT 
--to-destination 192.168.100.250
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5500 -j DNAT 
--to-destination 192.168.100.95:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5600 -j DNAT 
--to-destination 192.168.100.93:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5700 -j DNAT 
--to-destination 192.168.100.51:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5701 -j DNAT 
--to-destination 192.168.100.51:5500
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30022 -j DNAT 
--to-destination 192.168.100.50:22
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30040 -j DNAT 
--to-destination 192.168.100.250:3389
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30041 -j DNAT 
--to-destination 192.168.100.30:30041

iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 8181 -j DNAT 
--to-destination 192.168.100.50
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 6881 -j DNAT 
--to-destination 192.168.100.50
iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 4444 -j DNAT 
--to-destination 192.168.100.50

iptables -A INPUT -i eth0 -p tcp --dport 20 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 22 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 1701 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 1723 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 3306 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5600 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5901 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 5901 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 5900 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 5900 -j ACCEPT

#FTP Passive mode
iptables -A INPUT -i eth0 -p tcp --dport 49152:65534 -j ACCEPT
3Dastronomyagricultureaudioautosautos.audiautos.audioautos.binariesautos.bmwautos.clubautos.fordautos.hondacrxautos.japanautos.mercedesautos.opelautos.sportautos.volvoautos.vwaviaavia.binariesbankcardsbinariesbooksbuildingcinemacommercecomp.hardwarecomp.softwarecomp.lietuvinimascomp.networksculturedarbas.ieskaudarbas.siulaudesigneconomicselectronicsfaunafauna.aquafauna.binariesfishingflorafotofoto.binariesgamesgames.csgames.onlinegsmgurmanaihumourhumour.binariesinternetlawmicrosoftmotomusicmusic.binariesmusic.instrumentsmusic.LT.binariesnavigacijaphppoliticsprogrammingrpgsportstudyingsveikatatalktesttranslationtransportationtraveltravel.binariestvunixvideovideo.binarieswatersportswwwwww.flashpdaautos.supermama.ltmobiledarbasretro.3Dretro.agricultureretro.astronomyretro.audioretro.autosretro.autos.audiretro.autos.audioretro.autos.binariesretro.autos.bmwretro.autos.clubretro.autos.fordretro.autos.hondacrxretro.autos.japanretro.autos.mercedesretro.autos.opelretro.autos.sportretro.autos.supermamaretro.autos.supermama.ltretro.autos.volvoretro.autos.vwretro.aviaretro.avia.binariesretro.bankcardsretro.beosretro.binariesretro.booksretro.buildingretro.cinemaretro.commerceretro.compretro.comp.hardwareretro.comp.lietuvinimasretro.comp.networksretro.comp.softwareretro.cultureretro.darbasretro.darbas.ieskauretro.darbas.siulauretro.designretro.economicsretro.electronicsretro.e-vejasretro.faunaretro.fauna.aquaretro.fauna.binariesretro.fishingretro.floraretro.fotoretro.foto.binariesretro.gamesretro.games.csretro.games.onlineretro.games.rpgretro.genealogijaretro.gsmretro.gurmanairetro.humourretro.humour.binariesretro.internetretro.YZFretro.YZF.nebukretro.YZF.nebuk.netikintisretro.YZF.nebuk.netikintis.bukretro.YZF.nebuk.netikintis.buk.tikintisretro.lawretro.microsoftretro.mobileretro.motoretro.musicretro.music.binariesretro.music.instrumentsretro.music.LTretro.music.LT.binariesretro.navigacijaretro.newsretro.news.taisyklesretro.newuserretro.pdaretro.phpretro.politicsretro.programmingretro.rpgretro.sportretro.studyingretro.sveikataretro.talkretro.translationretro.transportationretro.travelretro.travel.binariesretro.tvretro.unixretro.videoretro.video.binariesretro.watersportsretro.wwwretro.www.flashdiylt.rkm.news.announcelt.rkm.news.newuser