+ Responder ao Tópico



  1. #1
    dB
    Visitante

    Padrão erro no iptables

    caros estou rodando o firewall e esta dando o seguinte erro:

    modprobe: Can't locate module iptables_nat
    Using /lib/modules/2.4.26/kernel/net/ipv4/netfilter/ip_conntrack_ftp.o.gz
    Using /lib/modules/2.4.26/kernel/net/ipv4/netfilter/ip_nat_ftp.o.gz
    iptables v1.2.10: --tcp-flags requires two args.
    Try `iptables -h' or 'iptables --help' for more information.


    Meu iptables ta assim:



    Código :
    #!/bin/bash
    echo 1 > /proc/sys/net/ipv4/ip_forward
    modprobe iptables_nat
    insmod ip_conntrack_ftp
    insmod ip_nat_ftp
     
    # Limpa tabela
    #iptables -F
     
    # Fecha tudo
    iptables -P INPUT DROP
    #iptables -P OUTPUT DROP
    iptables -P FORWARD DROP
     
    # Proteção contra ping suspeito
    iptables -A FORWARD -m unclean -j DROP
     
    # Contra ping
    iptables -A FORWARD -p icmp --icmp-type echo-request -j DROP
     
    # Contra ping of death
    iptables -A FORWARD -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT
     
    # Contra syn-floods
    iptables -A FORWARD -p tcp -m limit --limit 1/s -j ACCEPT
     
    # Contra port scanners
    iptables -A FORWARD -p tcp --tcp-flags SYN,ACK,FIN,RST -m limit --limit 1/s -j ACCEPT
     
    # Mascaramento
    iptables -t nat -A POSTROUTING -o eth+ -j MASQUERADE
     
    # Liberando portas
    iptables -A FORWARD -p tcp --dport 80 -j ACCEPT
    iptables -A FORWARD -p tcp --dport 25 -j ACCEPT
    iptables -A FORWARD -p tcp --dport 110 -j ACCEPT
    iptables -A FORWARD -p tcp --dport 22 -j ACCEPT

  2. #2
    Visitante

    Padrão erro no iptables

    tem o modulo de NAT no kernel?

  3. #3
    karfax
    Visitante

    Padrão erro no iptables

    modprobe iptable_nat

    O seu está iptables_nat :cry:

    Sds,