[root@sip ~]# iptables-save
*filter
:INPUT ACCEPT [2:400]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [297807605:70997680385]
:ELASTIX_FORWARD - [0:0]
:ELASTIX_INPUT - [0:0]
:ELASTIX_OUTPUT - [0:0]
-A INPUT -j ELASTIX_INPUT
-A FORWARD -j ELASTIX_FORWARD
-A OUTPUT -j ELASTIX_OUTPUT
-A ELASTIX_FORWARD -j REJECT --reject-with icmp-port-unreachable
-A ELASTIX_INPUT -i lo -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p icmp -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 5004:5082 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 4569 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 5036 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 10000:20000 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 2727 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --sport 53 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p udp -m udp --dport 69 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 22 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 25 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 80 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 110 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 143 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 443 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 993 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 995 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 5222 -j ACCEPT
-A ELASTIX_INPUT -s 10.8.0.0/255.255.0.0 -p tcp -m tcp --dport 9090 -j ACCEPT
-A ELASTIX_INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A ELASTIX_INPUT -j REJECT --reject-with icmp-port-unreachable
COMMIT
*nat
:PREROUTING ACCEPT [9140484:901139790]
:POSTROUTING ACCEPT [59623:10341929]
:OUTPUT ACCEPT [59623:10341929]
COMMIT
Вот так реализован мой firewall плюс не забываем настройки permit/deny и сложные пароли .
ответил
2012-02-07 19:52:14 +0400
Dmitry1987 190 ● 18 ● 4 ● 16
http://www.google.ru/