Re: Настройка шлюза на FreeBSD 7.3
Добавлено: 01 мар 2011, 16:25
все тагже
Форум сообщества системных администраторов и просто людей, которым не безразличен их компьютер.
https://sitemaps.sysadmins.ws/
а если по ипу говарит что у меги авария пляRaven писал(а):а если по ипу?zaka писал(а):cannot resolve http://www.kg:
твой ИП?zaka писал(а): 77-235-16-105
Код: Выделить всё
cat /etc/ipfw
#!/bin/sh
#peremenie
IPFW="/sbin/ipfw"
EXT="rl0" #vneshni interfeis
INT="rl1" #Vnutrenyi interfeis
EXT_IP="77.235.16.XXX" #vneshii Ip
INT_IP="192.168.0.88" #vnutrenii IP
LAN="192.168.0.0" #localka
MSK="24" #maska pod seti
${IPFW} -f flush
${IPFW} add check-state
${IPFW} add allow ip from any to any via lo0
${IPFW} add deny ip from any to 127.0.0.0/8
${IPFW} add deny ip from 127.0.0.0/8 to any
${IPFW} add allow tcp from any to any via ${INT}
${IPFW} add allow udp from any to any via ${INT}
${IPFW} add allow icmp from any to any via ${INT}
# ${IPFW} add allow all from any to any via ${INT}
${IPFW} add deny ip from any to ${LAN}/${MSK} in via ${EXT}
${IPFW} add deny log icmp from any to 255.255.255.255 in via ${EXT}
${IPFW} add deny log icmp from any to 255.255.255.255 out via ${EXT}
#DNS
${IPFW} add allow udp from any 53 to any via ${EXT}
${IPFW} add allow udp from any to any 53 via ${EXT}
${IPFW} add allow tcp from any 53 to any via ${EXT}
${IPFW} add allow tcp from any to any 53 via ${EXT}
#ssh
${IPFW} add allow tcp from any to ${EXT_IP} 7022 via ${EXT}
#ping
${IPFW} add allow icmp from any to any icmptypes 0,8,11
#squid
${IPFW} add fwd 127.0.0.1:3129 tcp from ${LAN}/${MSK} to any 21,80,443 via
${EXT}
#nat v lan
${IPFW} add divert natd ip from ${LAN}/${MSK} to any out via ${EXT}
${IPFW} add divert natd ip from any to ${EXT_IP} in via ${EXT}
${IPFW} add allow tcp from any established
${IPFW} add deny ip from 10.0.0.0/8 to any out via ${EXT}
${IPFW} add deny ip from 172.16.0.0/12 to any out via ${EXT}
${IPFW} add deny ip from 192.168.0.0/16 to any out via ${EXT}
${IPFW} add deny ip from 0.0.0.0/8 to any out via ${EXT}
${IPFW} add deny ip from 169.254.0.0/16 to any out via ${EXT}
${IPFW} add deny ip from 224.0.0.0/4 to any out via ${EXT}
${IPFW} add allow ip from ${EXT_IP} to any out xmit ${EXT} # setup keep-state
${IPFW} add deny log all from any to any