Dove metti questo script? In /etc/rc.d? Sicuro che sia eseguibile?
esattamente questo script è: /etc/rc.d/rc.firewall, e dopo averlo scritto, ho esaguito chmod +x /etc/.......
postaci un iptables -L -v -n dopo che l'hai lanciato.
questo è il post di iptables -L -n -v :
Chain INPUT (policy DROP 124 packets, 8057 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- lo * 127.0.0.1 127.0.0.1
0 0 ACCEPT icmp -- * * 192.168.192.0/24 192.168.192.168
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.0.10 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.0.10 multiport sports 80,443 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.0.10 multiport sports 80,443 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 151.168.0.1 192.168.0.10 tcp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 151.168.0.1 192.168.0.10 udp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 151.168.100.1 192.168.0.10 tcp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 151.168.100.1 192.168.0.10 udp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.192.0/24 192.168.192.168 tcp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.192.0/24 192.168.192.168 udp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.0.10 tcp spt:21 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.0.10 udp spt:21 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.0.10 tcp spt:20 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.0.10 udp spt:20 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.0.10 tcp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.0.10 udp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.192.0/24 192.168.192.168 tcp dpt:3128 state NEW,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.192.0/24 192.168.192.168 udp dpt:3128 state NEW,ESTABLISHED
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 192.168.192.0/24 0.0.0.0/0
0 0 ACCEPT icmp -- * * 0.0.0.0/0 192.168.192.0/24 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.192.0/24 0.0.0.0/0 multiport dports 80,443 state NEW,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.192.0/24 0.0.0.0/0 multiport dports 80,443 state NEW,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.192.0/24 multiport sports 80,443 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 0.0.0.0/0 192.168.192.0/24 multiport sports 80,443 state RELATED,ESTABLISHED
Chain OUTPUT (policy DROP 68 packets, 4920 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * lo 127.0.0.1 127.0.0.1
0 0 ACCEPT icmp -- * * 192.168.192.168 192.168.192.0/24
0 0 ACCEPT icmp -- * * 192.168.0.10 0.0.0.0/0 state NEW,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 0.0.0.0/0 multiport dports 80,443 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 0.0.0.0/0 multiport dports 80,443 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 151.168.0.1 tcp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 151.168.0.1 udp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 151.168.100.1 tcp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 151.168.100.1 udp dpt:53 state NEW,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.192.168 192.168.192.0/24 tcp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.192.168 192.168.192.0/24 udp spt:53 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 0.0.0.0/0 tcp dpt:21 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 0.0.0.0/0 udp dpt:21 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 0.0.0.0/0 tcp dpt:20 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 0.0.0.0/0 udp dpt:20 state NEW,RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.0.10 0.0.0.0/0 tcp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.0.10 0.0.0.0/0 udp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 192.168.192.168 192.168.192.0/24 tcp spt:3128 state RELATED,ESTABLISHED
0 0 ACCEPT udp -- * * 192.168.192.168 192.168.192.0/24 udp spt:3128 state RELATED,ESTABLISHED
Citazione:
# $IPTABLES -A INPUT -p icmp -i lo -d 127.0.0.1 -s 127.0.0.1 -j ACCEPT
$IPTABLES -A OUTPUT -p icmp -o lo -d 127.0.0.1 -s 127.0.0.1 -j ACCEPT
....???
serve per i ping della macchina dei vari programmi...
p.s. Grazie a tutti voi....
ps del ps E per i port scanner??? cosa devo fare?