DAnke ATahualpa
Hab jetzt diesen Config. Hab sie mir mit diesem Konfigurator den mir hmz empfohlen hat generiert, und bin voll zufrieden. Jetzt kommt noch qmail oder postfix dran dann noch ein php_accelerator für typo3 (des läuft zwar aber elends langsam).
# Generated by iptables-save v1.2.7a on Fri Sep 26 20:59:40 2003
*mangle

REROUTING ACCEPT [1937:757227]
:INPUT ACCEPT [40:17537]
:FORWARD ACCEPT [1896:739586]

UTPUT ACCEPT [6:681]

OSTROUTING ACCEPT [1901:739923]
COMMIT
# Completed on Fri Sep 26 20:59:40 2003
# Generated by iptables-save v1.2.7a on Fri Sep 26 20:59:40 2003
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]

UTPUT DROP [0:0]
:MY_DROP - [0:0]
:MY_REJECT - [0:0]
-A INPUT -m state --state INVALID -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,ACK FIN -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags PSH,ACK PSH -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags ACK,URG URG -j MY_DROP
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth1 -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -i eth1 -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth0 -m state --state NEW -j ACCEPT
-A INPUT -j MY_REJECT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,ACK FIN -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags PSH,ACK PSH -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags ACK,URG URG -j MY_DROP
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -i ! eth1 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 192.168.0.1 -i eth1 -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 4661 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 4662 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p tcp -m state --state NEW -m tcp --dport 5900 -j ACCEPT
-A FORWARD -d 192.168.0.2 -i eth1 -p udp -m state --state NEW -m udp --dport 5900 -j ACCEPT
-A FORWARD -j MY_REJECT
-A OUTPUT -m state --state INVALID -j DROP
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -j MY_REJECT
-A MY_DROP -j DROP
-A MY_REJECT -p tcp -j REJECT --reject-with tcp-reset
-A MY_REJECT -p udp -j REJECT --reject-with icmp-port-unreachable
-A MY_REJECT -p icmp -j DROP
-A MY_REJECT -j REJECT --reject-with icmp-proto-unreachable
COMMIT
# Completed on Fri Sep 26 20:59:40 2003
# Generated by iptables-save v1.2.7a on Fri Sep 26 20:59:40 2003
*nat

REROUTING ACCEPT [197:28718]

OSTROUTING ACCEPT [31:2968]

UTPUT ACCEPT [1:72]
-A PREROUTING -i eth1 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.0.1
-A PREROUTING -i eth1 -p tcp -m tcp --dport 110 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p tcp -m tcp --dport 143 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p tcp -m tcp --dport 4661 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p tcp -m tcp --dport 4662 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p tcp -m tcp --dport 5900 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -i eth1 -p udp -m udp --dport 5900 -j DNAT --to-destination 192.168.0.2
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 80 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 110 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 143 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 25 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 4661 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 4662 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p tcp -m tcp --dport 5900 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth0 -p udp -m udp --dport 5900 -j SNAT --to-source 192.168.0.254
-A POSTROUTING -o eth1 -j MASQUERADE
COMMIT