Professional Documents
Culture Documents
HOME:
SEARCH
Network: 192.168.20.0/24
Search
DO THIS ON ALL MACHINES:
vi /etc/sysconfig/iptables
openwrt pam parental control
perl port check port scanner post x
------
proxmox proxy qcow2 raspberry pi
*filter
:INPUT ACCEPT [0:0] redirect rhel7 robots.txt rsyslog
:FORWARD ACCEPT [0:0] samba sannce sed smbclient sms
:OUTPUT ACCEPT [0:0] snapshot soft raid spam ssh ssl
static route thinlinc tlwebaccess
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
tuning ubuntu ufw upgrade vRA
vRO vmware watchdog webcam
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
wget wireshark wlan
youtube restricted search yum
# openvpn
-A INPUT -p udp --dport 8001 -j ACCEPT zimbra
# do not allow anything else
-A INPUT -j REJECT --reject-with icmp-host-prohibited
# openvpn
-A FORWARD -s 192.168.10.0/24 -d 192.168.20.0/24 -j ACCEPT
-A FORWARD -s 192.168.20.0/24 -d 192.168.10.0/24 -j ACCEPT
# do not allow anything else
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
------
vi /etc/openvpn/home-office.conf
------
remote office.compress.to
port 4001
float
proto udp
dev tun1
ifconfig 172.10.0.2 172.10.0.1
persist-tun
persist-local-ip
persist-remote-ip
comp-lzo
ping 15
secret /etc/openvpn/office-home.key
route 192.168.10.0 255.255.255.0
user openvpn
group openvpn
syslog office-home
verb 1
------
vi /etc/sysconfig/iptables
------
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
# openvpn
-A INPUT -p udp --dport 8001 -j ACCEPT
# do not allow anything else
-A INPUT -j REJECT --reject-with icmp-host-prohibited
# openvpn
-A FORWARD -s 192.168.10.0/24 -d 192.168.20.0/24 -j ACCEPT
-A FORWARD -s 192.168.20.0/24 -d 192.168.10.0/24 -j ACCEPT
# do not allow anything else
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
------
Atom Top