iptables -A INPUT -p udp -m udp --dport 53 -j DROP iptables -A INPUT -p udp -m udp --dport 135 -j DROP iptables -A INPUT -p udp -m udp --dport 137 -j DROP iptables -A INPUT -p udp -m udp --dport 138 -j DROP iptables -A INPUT -p udp -m udp --dport 139 -j DROP iptables -A INPUT -p udp -m udp --dport 65535 -j DROP iptables -A INPUT -p tcp -m tcp --dport 53 -j DROP iptables -A INPUT -p tcp -m tcp --dport 135 -j DROP iptables -A INPUT -p tcp -m tcp --dport 137 -j DROP iptables -A INPUT -p tcp -m tcp --dport 138 -j DROP iptables -A INPUT -p tcp -m tcp --dport 139 -j DROP iptables -A INPUT -p tcp -m tcp --dport 65535 -j DROP iptables -A INPUT -p tcp -m tcp --dport 65535 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 53 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 135 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 137 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 138 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 139 -j DROP iptables -A OUTPUT -p tcp -m tcp --dport 65535 -j DROP iptables -A OUTPUT -p udp -m udp --dport 53 -j DROP iptables -A OUTPUT -p udp -m udp --dport 135 -j DROP iptables -A OUTPUT -p udp -m udp --dport 137 -j DROP iptables -A OUTPUT -p udp -m udp --dport 138 -j DROP iptables -A OUTPUT -p udp -m udp --dport 139 -j DROP iptables -A OUTPUT -p udp -m udp --dport 65535 -j DROP
Archive for March, 2001
iptables block Worm
iptables warnet standar
sebenarnya ini dah banyak banget di tulis para pendahulu..
saya post ini buat mengingat dan mempermudah saya saat setting router warnet
vi /etc/sysconfig/network vi /etc/sysconfig/network-scripts/ifcfg-eth0 vi /etc/resolv.conf vi /etc/sysctl.conf /etc/init.d/network restart chkconfig --level 2345 network on ping 202.134.0.155 ping google.com /etc/init.d/named restart chkconfig --level 2345 named on vi /etc/sysconfig/network-scripts/ifcfg-eth1 /etc/init.d/network restart ping 192.168.0.1 /etc/init.d/iptables stop /sbin/iptables -A PREROUTING -t nat -i eth1 -p udp --dport 80 -j REDIRECT --to-port 3128 /sbin/iptables -A PREROUTING -t nat -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 3128 /sbin/iptables -t nat -A POSTROUTING -o eth0 -s 192.168.0.0/24 -j MASQUERADE /sbin/iptables-save > /etc/sysconfig/iptables /etc/init.d/iptables restart
