Carissimi, mi tocca modificare la seguente configurazione del firewall.
Prima di tutto: c'è una rete interna (192.168.0.0/24) collegata ad un server (192.168.0.10) e da qui si va su internet.
Devo permettere di navigare su internet tramite squid, permettere la mail con pop3(s)/smtp(s), msn e praticamente nient'altro.
Finora le regole (che negavano l'utilizzo del pop3) erano:
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 3128 -j REDIRECT --to-port 9090
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port 6891:6900 -j MASQUERADE
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port 1863 -j MASQUERADE
iptables -A INPUT -p icmp ! --icmp-type echo-reply -j DROP
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP
iptables -A FORWARD -p tcp --syn -j ACCEPT
iptables -A FORWARD -p tcp --tcp-flags SYN,ACK,FIN,RST RST -j ACCEPT
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl1.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl2.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl3.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl4.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl5.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d dl6.avgate.net -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d time.windows.com -j MASQUERADE
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -d update.microsoft.com -j MASQUERADE
iptables -t nat -p tcp -A POSTROUTING -s 192.168.0.0/24 --destination-port rtsp -j MASQUERADE
iptables -t nat -p udp -A POSTROUTING -s 192.168.0.0/24 --destination-port rtsp -j MASQUERADE
ho provato ad aggiungere le seguenti linee sia alla fine sia (ho provato con o senza entrambe) sia dopo le porte 6891:6900
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port 995 -j MASQUERADE
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port 587 -j MASQUERADE
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port pop3 -j MASQUERADE
iptables -t nat -A POSTROUTING -p tcp -s 192.168.0.0/24 --destination-port smtp -j MASQUERADE
iptables -t nat -A POSTROUTING -p udp -s 192.168.0.0/24 --destination-port 995 -j MASQUERADE
iptables -t nat -A POSTROUTING -p udp -s 192.168.0.0/24 --destination-port 587 -j MASQUERADE
iptables -t nat -A POSTROUTING -p udp -s 192.168.0.0/24 --destination-port pop3 -j MASQUERADE
iptables -t nat -A POSTROUTING -p udp -s 192.168.0.0/24 --destination-port smtp -j MASQUERADE
Cosa sbaglio?
Grazie,
Peppe
P.S. le regole non le ho fatte io, me le sono già trovate fatte e in più devo permettere l'utilizzo della mail.