#!/bin/sh # Degiskenler Tanitiliyor echo "" echo " Degiskenler Tanitiliyor" echo "" export PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin iptables="/sbin/iptables" # /proc ayarlaniyor echo " Genel guvenlik ayarlari /proc filesystem yapilandiriliyor" echo "" if [ -e /proc/sys/net/ipv4/tcp_syncookies ]; then echo 1 > /proc/sys/net/ipv4/tcp_syncookies; fi if [ -e /proc/sys/net/ipv4/conf/all/rp_filter ]; then echo 1 > /proc/sys/net/ipv4/conf/all/rp_filter; fi if [ -e /proc/sys/net/ipv4/ip_forward ]; then echo 1 > /proc/sys/net/ipv4/ip_forward; fi # Moduller yukleniyor if [ -e /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ip_nat_irc.o ]; then modprobe ip_nat_irc; fi if [ -e /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ip_conntrack_irc.o ]; then modprobe ip_conntrack_irc; fi if [ -e /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ip_conntrack_ftp.o ]; then modprobe ip_conntrack_ftp; fi if [ -e /lib/modules/`uname -r`/kernel/net/ipv4/netfilter/ip_nat_ftp.o ]; then modprobe ip_nat_ftp; fi # Onceki tanimlamalar sifirlaniyor $iptables -F INPUT $iptables -F OUTPUT $iptables -P INPUT DROP $iptables -P OUTPUT ACCEPT # Yonlendirmeler yapiliyor echo " Yonlendirmeler yapiliyor" echo "" $iptables -F FORWARD $iptables -F -t nat $iptables -P FORWARD DROP $iptables -A FORWARD -i eth1 -j ACCEPT $iptables -A INPUT -i eth1 -j ACCEPT $iptables -A OUTPUT -o eth1 -j ACCEPT $iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT $iptables -t nat -A POSTROUTING -s 10.0.1.0/24 -o eth0 -j MASQUERADE # Loopback ten gelen tum paketler kabul ediliyor $iptables -A INPUT -i lo -j ACCEPT $iptables -A OUTPUT -o lo -j ACCEPT $iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT # icmp ayarlaniyor echo " icmp ayarlaniyor" echo "" $iptables -A OUTPUT -p icmp -m state --state NEW -j ACCEPT $iptables -A INPUT -p icmp -m state --state ESTABLISHED,RELATED -j ACCEPT $iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 1/s -i eth0 -j ACCEPT echo " squid yonlendirmeleri yapiliyor" echo "" $iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 3128 echo " Guvenlik duvari acik portlari tanimlaniyor" echo "" $iptables -A INPUT -p tcp --dport 80 -j ACCEPT $iptables -A INPUT -p tcp --dport 21 -j ACCEPT $iptables -A INPUT -p tcp --dport 22 -j ACCEPT echo " Guvenlik duvari acik portlari uygulaniyor" echo "" $iptables -A FORWARD -i eth0 -p tcp --dport 80 -j ACCEPT $iptables -A FORWARD -i eth0 -p tcp --dport 21 -j ACCEPT $iptables -A FORWARD -i eth0 -p tcp --dport 22 -j ACCEPT echo " Guvenlik duvari acik portlari yonlendiriliyor" echo "" $iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to-destination 10.0.1.2:80 $iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 21 -j DNAT --to-destination 10.0.1.2:21 $iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 22 -j DNAT --to-destination 10.0.1.3:22 echo " Guvenlik duvari port sinirlari uygulaniyor" echo "" $iptables -I FORWARD -s 10.0.1.0/24 -p tcp --dport 1863 -j LOG $iptables -I FORWARD -s 10.0.1.0/24 -p tcp --dport 1863 -j REJECT $iptables -I FORWARD -s 10.0.1.0/24 -p tcp --dport 119 -j LOG $iptables -I FORWARD -s 10.0.1.0/24 -p tcp --dport 119 -j REJECT echo " Sinirli portlardan istisnalar uygulaniyor" echo "" $iptables -I FORWARD -s 10.0.1.3 -p tcp --dport 1863 -j ACCEPT $iptables -I FORWARD -s 10.0.1.3 -p tcp --dport 119 -j ACCEPT $iptables -I FORWARD -s 10.0.1.4 -p tcp --dport 119 -j ACCEPT $iptables -I FORWARD -s 10.0.1.5 -p tcp --dport 119 -j ACCEPT $iptables -I FORWARD -s 10.0.1.6 -p tcp --dport 119 -j ACCEPT echo " drop uygulaniyor" echo "" $iptables -A INPUT -i eth0 -p tcp --dport 0:65535 -j DROP $iptables -A INPUT -i eth0 -p udp --dport 0:65535 -j DROP echo "### iptables yuklendi. ###" echo ""