Inhaltsverzeichnis

Netzwerke

134.97.126.0/24

Eigenschaft Wert
Domain bytespeicher.local
Exit via Alphacron

Firewall

Firewall - Custom Rules

#related freigeben
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
ip6tables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
ip6tables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT

#RA
ip6tables -A INPUT -s fe80::203:97ff:fe2a:b400 -j ACCEPT

ip6tables -A INPUT -s ff00::/8 -j ACCEPT
ip6tables -A INPUT -s fe80::/10 -j ACCEPT


#ICMP
iptables -A INPUT -p icmp -j ACCEPT
iptables -A FORWARD -p icmp -j ACCEPT

ip6tables -A INPUT -p icmpv6 -j ACCEPT
ip6tables -A FORWARD -p icmpv6 -j ACCEPT

#INPUT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i br-lan -j ACCEPT 
iptables -A INPUT -i br-nat -j ACCEPT
iptables -A INPUT -s 195.190.142.0/24 -j ACCEPT
iptables -A INPUT -s 134.97.0.0/16 -j ACCEPT
iptables -A INPUT -s 37.26.200.0/24 -j ACCEPT
iptables -A INPUT -s 10.99.0.0/16 -j ACCEPT
iptables -A INPUT -s 192.168.126.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 22348 -j ACCEPT #ssh
iptables -A INPUT -s 88.198.111.196 -j ACCEPT #status-kiste

ip6tables -A INPUT -i lo -j ACCEPT
ip6tables -A INPUT -i br-lan -j ACCEPT 
ip6tables -A INPUT -s 2001:650::/32 -j ACCEPT
ip6tables -A INPUT -p tcp --dport 22348 -j ACCEPT

#mtu-fix
iptables -A FORWARD -p tcp -o pppoe-wan1 --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
ip6tables -A FORWARD -p tcp -o pppoe-wan1 --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu

#FORWARD
iptables -A FORWARD -i lo -j ACCEPT
iptables -A FORWARD -s 195.190.142.0/24 -j ACCEPT
iptables -A FORWARD -s 134.97.0.0/16 -j ACCEPT
iptables -A FORWARD -s 37.26.200.0/24 -j ACCEPT
iptables -A FORWARD -s 10.99.0.0/16 -j ACCEPT
iptables -A FORWARD -s 192.168.126.0/24 -j ACCEPT

iptables -A FORWARD -s 88.198.234.12 -d 134.97.126.39 -j ACCEPT #meshvpn
iptables -A FORWARD -s 62.141.56.190 -d 134.97.126.39 -j ACCEPT #meshvpn
iptables -A FORWARD -s 144.76.76.98 -d 134.97.126.39 -j ACCEPT #meshvpn

iptables -A FORWARD -m iprange --dst-range 134.97.126.2-134.97.126.49 -j ACCEPT
iptables -A FORWARD -m iprange --dst-range 134.97.126.51-134.97.126.254 -j ACCEPT
#alles ausser der .50 zulassen


ip6tables -A FORWARD -i lo -j ACCEPT
ip6tables -A FORWARD -s 2001:650::/32 -j ACCEPT
ip6tables -A FORWARD -d 2001:650:dd4e::/48 -j ACCEPT

#SNAT
iptables -t nat -A POSTROUTING -o pppoe-wan -s 192.168.126.0/24 -j SNAT --to-source 134.97.126.254
iptables -t nat -A POSTROUTING -o eth0.34 -s 134.97.126.0/24 -j SNAT --to-source 10.99.50.1
iptables -t nat -A POSTROUTING -o eth0.34 -s 192.168.126.0/24 -j SNAT --to-source 10.99.50.1

#ENDDROP
iptables -A INPUT -j DROP
iptables -A FORWARD -j DROP
ip6tables -A INPUT -j DROP
ip6tables -A FORWARD -j DROP

Software

Installierte Pakete