由 阿信 » 週六 5月 08, 2004 6:49 pm
IPTBL=/sbin/iptables
### DROP tcp packets
$IPTBL -P INPUT DROP
$IPTBL -P OUTPUT ACCEPT
$IPTBL -I INPUT -p icmp --icmp-type 8 -j DROP
$IPTBL -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
AICMP="0 3 3/4 4 11 12 14 16 18"
for tyicmp in $AICMP
do
$IPTBL -A INPUT -i eth0 -p icmp --icmp-type $tyicmp -j ACCEPT
done
$IPTBL -A INPUT -i eth0 -p tcp --dport 80 -j ACCEPT
## LAN with Samba
$IPTBL -A INPUT -i eth0 -s 192.168.0.0/24 -p tcp --dport 137:139 -j ACCEPT
$IPTBL -A INPUT -i eth0 -s 192.168.0.0/24 -p tcp --dport 445 -j ACCEPT