国产一级a片免费看高清,亚洲熟女中文字幕在线视频,黄三级高清在线播放,免费黄色视频在线看

打開APP
userphoto
未登錄

開通VIP,暢享免費電子書等14項超值服

開通VIP
iptalbes 配置文件

iptalbes 配置文件

 

#!/bin/bash

export PATH=/sbin:/usr/sbin:/bin:/usr/bin

echo 1 >/proc/sys/net/ipv4/ip_forward
iptables -F
iptables -t nat -F
iptables -X
iptables -t nat -X
iptables -Z

## Allow forwarding through the internal interface

#deny 126.com mail through internet;
#iptables -I INPUT -s 192.168.6.2 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT

echo "ADSL Starting........"
adsl-stop
adsl-start

echo "Apply Iptables firewall.........."
service iptables stop


#====iptables INPUT DROP====
iptables -P INPUT DROP
iptables -I INPUT -i eht1 -j DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp -m multiport --dports 3128,21,20,110,25,22 -j ACCEPT

#iptables -A INPUT -p tcp --dport 53 -j ACCEPT
#iptables -A INPUT -p udp --dport 53 -j ACCEPT
iptables -A INPUT -p icmp -s 192.168.6.0/24 -j ACCEPT

# Make sure that new TCP connections are SYN packets
iptables -A INPUT -i  ppp0 -p tcp ! --syn -m state --state NEW -j DROP
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
iptables -N syn-flood
iptables -A INPUT -p tcp --syn -j syn-flood
iptables -I syn-flood -p tcp -m limit --limit 3/s --limit-burst 6 -j RETURN
iptables -A syn-flood -j REJECT


#======================================================================
iptables -P OUTPUT ACCEPT
#iptables -P OUTPUT DROP
#ptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
#ptables -A OUTPUT -p tcp -m multiport --dports 22,80,110,25 -j ACCEPT
#ptables -A OUTPUT -p tcp --dport 3128 -j ACCEPT
#ptables -A OUTPUT -p tcp --dport 80 -j ACCEPT
#========================================================================

iptables -A OUTPUT -d 126.com -j DROP
iptables -A OUTPUT -s reg.126.com -j DROP
iptables -A OUTPUT -s www.126.com -j DROP
iptables -A OUTPUT -s mail.126.com -j DROP
iptables -A OUTPUT -s mail.163.com -j DROP
iptables -A OUTPUT -s reg.163.com -j DROP
iptables -A OUTPUT -s photo.163.com -j DROP
iptables -A OUTPUT -s auto.qq.com -j DROP
iptables -A OUTPUT -s reg.163.com -j DROP
iptables -A OUTPUT -s news.qq.com -j DROP
iptables -A OUTPUT -s qq.com -j DROP
iptables -A OUTPUT -s www.qq.com -j DROP
iptables -A OUTPUT -s mail.qq.com -j DROP
iptables -A OUTPUT -s news.qq.com -j DROP
iptables -A OUTPUT -s 61.135.157.72 -j DROP


#===========MASQUERADE ppp+ ================
iptables -t nat -A POSTROUTING -s 192.168.6.0/24 -d 0/0 -o ppp0 -j MASQUERADE

#=============DROP FORWARD===============
iptables -P FORWARD DROP
iptables -A FORWARD -p tcp -m multiport --dports 53,3128,25,110,22 -j ACCEPT
iptables -A FORWARD -p tcp -m multiport --sports 53,3128,25,110,22 -j ACCEPT
iptables -A FORWARD -p udp --sport 53 -j ACCEPT
iptables -A FORWARD -p udp --dport 53 -j ACCEPT

#iptables -I INPUT -s 192.168.6.2 -j ACCEPT
#iptables -I FORWARD -s 192.168.6.2 -j ACCEPT
iptables -A FORWARD -p icmp -j ACCEPT
#iptables -A FORWARD -p tcp --sport 433 -j ACCEPT

#DROP MSN
iptables -A FORWARD -p tcp --dport 1863 -j DROP
iptables -A FORWARD -p udp --dport 1863 -j DROP
iptables -A FORWARD -p tcp --sport 1863 -j DROP
iptables -A FORWARD -p udp --sport 1863 -j DROP
iptables -A FORWARD -d 207.46.104.20 -j DROP
iptables -A FORWARD -d 207.46.110.0/24 -j DROP
iptables -A FORWARD -s 207.46.104.20 -j DROP
iptables -A FORWARD -s 207.46.110.0/24 -j DROP

#DROP dianlv,emule
iptables -A FORWARD -p udp --dport 8000 -j DROP
iptables -A FORWARD -p udp --dport 4000 -j DROP
iptables -A FORWARD -p tcp --dport 443 -j DROP
iptables -A FORWARD -p udp --dport 4661 -j DROP
iptables -A FORWARD -p udp --dport 4662 -j DROP
iptables -A FORWARD -p tcp --dport 4661 -j DROP
iptables -A FORWARD -p tcp --dport 4662 -j DROP
iptables -A FORWARD -p udp --sport 4661 -j DROP
iptables -A FORWARD -p udp --sport 4662 -j DROP
iptables -A FORWARD -p tcp --sport 4661 -j DROP
iptables -A FORWARD -p tcp --sport 4662 -j DROP

#deny ICMP
#iptables -A INPUT -p icmp -i ppp0 -j DROP
#ptables -A FORWARD -p icmp -j DROP
#iptables -A FORWARD -i eth0 -j ACCEPT
#iptables -A FORWARD -o eth0 -j ACCEPT
#iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT

# Make sure that new TCP connections are SYN packets
iptables -A INPUT -i  ppp0 -p tcp ! --syn -m state --state NEW -j DROP

## Do masquerading through ppp0
#iptables -t nat -A POSTROUTING -s 192.168.6.0/24 -d 0/0 -o ppp0 -j MASQUERADE

## SQUID
#iptables -t nat -A PREROUTING -i eth0 -p tcp -s 0/0 --dport 80 -j REDIRECT --to-ports 3128

## DNS
#ptables -A INPUT -i ppp0 -p udp -s 0/0 --sport 53 -m state --state ESTABLISHED -j ACCEPT
#ptables -A INPUT -i ppp0 -p udp -d 0/0 --dport 53 -j ACCEPT

本站僅提供存儲服務(wù),所有內(nèi)容均由用戶發(fā)布,如發(fā)現(xiàn)有害或侵權(quán)內(nèi)容,請點擊舉報。
打開APP,閱讀全文并永久保存 查看更多類似文章
猜你喜歡
類似文章
/etc/sysconfig/iptables 詳解 - secyaher的日志 - 網(wǎng)易...
簡釋iptables防火墻(轉(zhuǎn))
iptables實例
Linux 代理腳本,我見過最牛的腳本
iptable防火墻詳解
IP6tables
更多類似文章 >>
生活服務(wù)
分享 收藏 導(dǎo)長圖 關(guān)注 下載文章
綁定賬號成功
后續(xù)可登錄賬號暢享VIP特權(quán)!
如果VIP功能使用有故障,
可點擊這里聯(lián)系客服!

聯(lián)系客服