Servidor_de_comunicacions_Institut_les_Planes
# nano /proc/sys/net/ipv4/ip_forward
# nano /etc/network/if-up.d/router
#!/bin/sh -e echo 1 > /proc/sys/net/ipv4/ip_forward #iptables -A INPUT -i lo -j ACCEPT #iptables -A INPUT -m conntrack --ctstate ESTABLISHED.RELATED -j ACCEPT #iptables -A INPUT -m conntrack --ctstate NEW ! -i eth0 -j ACCEPT iptables -A FORWARD -i internet -o intranet -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT iptables -A FORWARD -i intranet -o internet -j ACCEPT iptables -t nat -A POSTROUTING -o internet -j MASQUERADE
# chmod +x /etc/network/if-up.d/router
# /etc/network/if-up.d/router
sudo tcpdump -env -i any icmp
# iptables-save # Generated by iptables-save v1.4.4 on Sun Jun 5 18:32:53 2011 *nat :PREROUTING ACCEPT [164:33980] :OUTPUT ACCEPT [6070:269651] :POSTROUTING ACCEPT [6049:267936] -A POSTROUTING -o eth0 -j MASQUERADE -A POSTROUTING -o internet -j MASQUERADE COMMIT # Completed on Sun Jun 5 18:32:53 2011 # Generated by iptables-save v1.4.4 on Sun Jun 5 18:32:53 2011 *filter :INPUT ACCEPT [12714:587735] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [12502:564789] -A FORWARD -i eth0 -o eth1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i eth1 -o eth0 -j ACCEPT -A FORWARD -i eth1 -o eth0 -j ACCEPT -A FORWARD -i eth1 -o eth0 -j ACCEPT -A FORWARD -i internet -o intranet -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i intranet -o internet -j ACCEPT COMMIT # Completed on Sun Jun 5 18:32:53 2011