Ovako napravih jednom skriptu koja radi fenomenalno
samo ako neko moze da mi kaze kako da podesim lease time za IP adrese
odnosno vreme koje privatna adresa ima javnu adresu
evo skripte
# virtualne
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
/usr/local/bin/ip address add public IP dev eth1
#
#Ocistimo postojece TAbele
#
#
/usr/sbin/iptables -t nat -F
#Ovo je u slucaja ako se koriste PPP veze
#/usr/sbin/iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
#kada se koriste staticke adrese onda je bolje koristiit SNAT umesto Masqurade
/usr/sbin/iptables -t nat -A POSTROUTING -o eth1 -j SNAT --to public-ip-range
#Syn
/usr/sbin/iptables -A FORWARD -p tcp --syn -m limit --limit 1/s -j ACCEPT
#Furtive port scanner:
/usr/sbin/iptables -A FORWARD -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j ACCEPT
#Ping of death:
/usr/sbin/iptables -A FORWARD -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT
e ajdde pa mi odgovorite please












NAT IP TABLES
Re: NAT IP TABLES
Re: NAT IP TABLES
Re: NAT IP TABLES