Линуксоид привет! Мне требуется твоя помощь ;)
Есть сервер Asterisk и провайдер. Провайдер пускает sip трафик по 222.57.104.32/28 109.69.76.128/25, порты стандарт 5060 и 10000:65000. Весь трафик DROP кроме разрешённых. (180.40.61.186 OpenVPN)
Прописываю в /etc/sysconfig/iptables
*nat
:PREROUTING ACCEPT [2:478]
:POSTROUTING ACCEPT [5:856]
:OUTPUT ACCEPT [5:856]
COMMIT
*mangle
:PREROUTING ACCEPT [31:11490]
:INPUT ACCEPT [31:11490]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [33:16218]
:POSTROUTING ACCEPT [33:16218]
COMMIT
*filter
:FORWARD DROP [0:0]
:INPUT DROP [0:0]
:OUTPUT DROP [0:0]
-A INPUT -s 127.0.0.1 -j ACCEPT
-A INPUT -d 127.0.0.1 -j ACCEPT
-A INPUT -s 192.168.0.1/24 -j ACCEPT
-A INPUT -d 192.168.0.1/24 -j ACCEPT
-A INPUT -s 222.57.104.32/28 -j ACCEPT
-A INPUT -d 222.57.104.32/28 -j ACCEPT
-A INPUT -s 109.69.76.128/25 -j ACCEPT
-A INPUT -d 109.69.76.128/25 -j ACCEPT
-A INPUT -s 185.4.66.186 -j ACCEPT
-A FORWARD -s 127.0.0.1 -j ACCEPT
-A FORWARD -d 127.0.0.1 -j ACCEPT
-A FORWARD -s 192.168.0.1/24 -j ACCEPT
-A FORWARD -d 192.168.0.1/24 -j ACCEPT
-A FORWARD -s 222.57.104.32/28 -j ACCEPT
-A FORWARD -d 222.57.104.32/28 -j ACCEPT
-A FORWARD -s 109.69.76.128/25 -j ACCEPT
-A FORWARD -d 109.69.76.128/25 -j ACCEPT
-A OUTPUT -s 127.0.0.1 -j ACCEPT
-A OUTPUT -d 127.0.0.1 -j ACCEPT
-A OUTPUT -s 192.168.0.1/24 -j ACCEPT
-A OUTPUT -d 192.168.0.1/24 -j ACCEPT
-A OUTPUT -s 222.57.104.32/28 -j ACCEPT
-A OUTPUT -d 222.57.104.32/28 -j ACCEPT
-A OUTPUT -s 109.69.76.128/25 -j ACCEPT
-A OUTPUT -d 109.69.76.128/25 -j ACCEPT
-A INPUT -d 180.40.61.186 -j ACCEPT
-A FORWARD -s 180.40.61.186 -j ACCEPT
-A FORWARD -d 180.40.61.186 -j ACCEPT
-A OUTPUT -s 180.40.61.186 -j ACCEPT
-A OUTPUT -d 180.40.61.186 -j ACCEPT
-A INPUT -p icmp -i eth0 --icmp-type echo-request -j DROP
COMMIT
Да нуб, да ололо, но ищу среди вас Анателе ;) А вообще ткните носом в ошибку. Спасибо!