#!/bin/sh
echo -n Aplicando Reglas de Firewall...
## FLUSH de reglas
iptables -F
iptables -X
iptables -Z
iptables -t nat -F
## Establecemos politica por defecto: DROP!!!
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
## Permito ssh al firewall (localhost)
iptables -A INPUT -p tcp --dport 22 -i eth0 -j ACCEPT
iptables -A OUTPUT -p tcp --sport 22 -o eth0 -j ACCEPT
---------------------
total-queda:(iptables-save)
*nat
REROUTING ACCEPT [4:533]
OSTROUTING ACCEPT [0:0]
UTPUT ACCEPT [11:959]
COMMIT
# Completed on Tue Jul 4 12:20:23 2006
# Generated by iptables-save v1.3.3 on Tue Jul 4 12:20:23 2006
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
UTPUT DROP [0:0]
-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 22 -j ACCEPT
COMMIT