IPT=/usr/local/sbin/iptables
EXTIF="eth1" # Netzwerkkarte für den Router
INTIF="eth0" # Netzwerkkarte internes LAN
# Anything coming from our internal network should have only our addresses!
$IPT -A FORWARD -i $INTIF -s ! $INTERNALNET -j LOG
$IPT -A FORWARD -i $INTIF -s ! $INTERNALNET -j DROP
# Anything coming from the Internet should have a real Internet address
$IPT -A FORWARD -i $EXTIF -s 192.168.0.0/16 -j DROP
$IPT -A FORWARD -i $EXTIF -s 172.16.0.0/12 -j DROP
$IPT -A FORWARD -i $EXTIF -s 10.0.0.0/8 -j DROP
Statt eth1 nimmst halt die ppp0, dann sollte es funken.
|