iptables + rc.local + outlook
	
	
		guardian_metal...fiz o que vc sugeriu e mesmo assim nao funcionou...ai tirei praticamente todas as regras do firewall....e ficou assim...
route add default gw 172.16.2.1
#REGRA PARA LIMPEZA DAS REGRAS (FLUSH) 
iptables -F 
iptables -Z 
iptables -X 
iptables -t nat -F 
iptables -t nat -X 
iptables -t nat -Z 
#Ativa Mprobe iptables_nat 
modprobe ip_conntrack_ftp 
modprobe ip_nat_ftp 
echo "1" > /proc/sys/net/ipv4/ip_forward 
echo "1" > /proc/sys/net/ipv4/conf/all/rp_filter 
#Regras para bloquear entradas netbios e outras portas (OK) 
iptables -t filter -A INPUT -p udp --dport 137 -j DROP 
iptables -t filter -A INPUT -p udp --sport 138 -j DROP 
iptables -t filter -A INPUT -p udp --dport 138 -j DROP 
iptables -t filter -A INPUT -p udp --sport 139 -j DROP 
iptables -t filter -A INPUT -p udp --dport 139 -j DROP 
iptables -t filter -A INPUT -p udp --sport 445 -j DROP 
iptables -t filter -A INPUT -p udp --dport 445 -j DROP 
iptables -t filter -A INPUT -p tcp --sport 445 -j DROP 
iptables -t filter -A INPUT -p tcp --dport 445 -j DROP 
iptables -t filter -A INPUT -p tcp --sport 1025 -j DROP 
iptables -t filter -A INPUT -p tcp --dport 1025 -j DROP 
iptables -t filter -A INPUT -p udp --sport 1025 -j DROP 
iptables -t filter -A INPUT -p udp --dport 1025 -j DROP 
#Regras para bloquear saida netbios e outras portas (OK) 
iptables -t filter -A OUTPUT -p udp --dport 137 -j DROP 
iptables -t filter -A OUTPUT -p udp --sport 138 -j DROP 
iptables -t filter -A OUTPUT -p udp --dport 138 -j DROP 
iptables -t filter -A OUTPUT -p udp --sport 139 -j DROP 
iptables -t filter -A OUTPUT -p udp --dport 139 -j DROP 
iptables -t filter -A OUTPUT -p udp --sport 445 -j DROP 
iptables -t filter -A OUTPUT -p udp --dport 445 -j DROP 
iptables -t filter -A OUTPUT -p tcp --sport 445 -j DROP 
iptables -t filter -A OUTPUT -p tcp --dport 445 -j DROP 
iptables -t filter -A OUTPUT -p tcp --sport 1025 -j DROP 
iptables -t filter -A OUTPUT -p tcp --dport 1025 -j DROP 
iptables -t filter -A OUTPUT -p udp --sport 1025 -j DROP 
iptables -t filter -A OUTPUT -p udp --dport 1025 -j DROP 
#Regra para proteger contra port scanners 
iptables -N SCANNER 
iptables -A SCANNER -m limit --limit 15/m -j LOG --log-level 6 --log-prefix "FIREWALL: port scanner:" 
iptables -A SCANNER -j DROP 
iptables -A INPUT -p tcp --tcp-flags ALL FIN,URG,PSH -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags ALL NONE -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags ALL ALL -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags ALL FIN,SYN -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -i eth0 -j SCANNER 
iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -i eth0 -j SCANNER 
#Regra para proteger contra Trojans 
iptables -N TROJAN 
iptables -A TROJAN -m limit --limit 15/m -j LOG --log-level 6 --log-prefix "FIREWALL:trojan:" 
iptables -A TROJAN -j DROP 
iptables -A INPUT -p TCP -i eth0 --dport 666 -j TROJAN 
iptables -A INPUT -p TCP -i eth0 --dport 4000 -j TROJAN 
iptables -A INPUT -p TCP -i eth0 --dport 6000 -j TROJAN 
iptables -A INPUT -p TCP -i eth0 --dport 6006 -j TROJAN 
iptables -A INPUT -p TCP -i eth0 --dport 16660 -j TROJAN 
#Regra para fazer OUTLOOK funcionar (OK) 
iptables -A FORWARD -s 10.1.1.0/24 -p tcp --dport 110 -j ACCEPT 
iptables -A FORWARD -s 10.1.1.0/24 -p tcp --dport 25 -j ACCEPT 
iptables -A FORWARD -d 10.1.1.0/24 -p tcp --dport 110 -j ACCEPT 
iptables -A FORWARD -d 10.1.1.0/24 -p tcp --dport 25 -j ACCEPT 
#Regra para fazer REDIRECIONAMENTO para a porta 8080 (PROXY)(OK) 
iptables -t nat -A PREROUTING -i eth0 -s 10.1.1.0/24 -p tcp --dport 80 -j REDIRECT --to-port 8080 
iptables -t nat -A PREROUTING -s localhost -p tcp --dport 80 -j REDIRECT --to-port 8080
Agora o OUTLOOK nao esta funcionando
Abraços