欢迎来到好人卡资源网,专注网络技术资源收集,我们不仅是网络资源的搬运工,也生产原创资源。寻找资源请留言或关注公众号:烈日下的男人

屏蔽BT下载/邮件滥用 防警告

linux sky995 3年前 (2021-06-14) 768次浏览 0个评论

本文及资源最后更新时间 2021-06-14 by sky995

清除所有规则

iptables -F

禁止所有进站/转发 允许所有出站
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT

允许已建立的进站 允许PING 允许本机内部环回
iptables -A INPUT -m state –state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p icmp –icmp-type echo-request -j ACCEPT
iptables -A INPUT -i lo -p all -j ACCEPT

允许已建立的转发
iptables -A FORWARD -m state –state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -p udp –dport 2408 -d 162.159.192.1 -j ACCEPT
iptables -t nat -A PREROUTING -p udp –dport 8443 -j DNAT –to-destination 162.159.192.1:2408
iptables -t nat -A POSTROUTING -d 162.159.192.1 -p udp –dport 2408 -j MASQUERADE
sysctl -w net.ipv4.ip_forward=1

允许进站端口
iptables -A INPUT -p tcp –dport 22 -j ACCEPT
iptables -A INPUT -p tcp –dport 80 -j ACCEPT
iptables -A INPUT -p tcp –dport 443 -j ACCEPT
iptables -A INPUT -p udp –dport 53 -j ACCEPT
iptables -A INPUT -p udp –dport 8443 -j ACCEPT
iptables -A INPUT -p udp –dport 2408 -j ACCEPT
iptables -A INPUT -p udp –dport 4000 -j ACCEPT

关键词封锁
iptables -A OUTPUT -m string –string “torrent” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “.torrent” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “peer_id=” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “announce” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “info_hash” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “get_peers” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “find_node” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “BitTorrent” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “announce_peer” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “BitTorrent protocol” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “announce.php?passkey=” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “magnet:” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “xunlei” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “sandai” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “Thunder” –algo bm –to 65535 -j DROP
iptables -A OUTPUT -m string –string “XLLiveUD” –algo bm –to 65535 -j DROP

屏蔽BT下载/邮件滥用 防警告

参考

1 Security Guide Red Hat Enterprise Linux 6 _ Red Hat Customer Portal.html
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html-single/security_guide/index#sect-Security_Guide-Firewalls-Using_IPTables

2『原创』iptables 封禁 BT_PT_SPAM(垃圾邮件)和自定义端口_关键词 一键脚本 _ 逗比根据地.html
https://doubibackup.com/tfma58rb.html


好人卡资源网 , 版权所有丨如未注明 , 均为原创丨本网站采用BY-NC-SA协议进行授权
转载请注明原文链接:屏蔽BT下载/邮件滥用 防警告
喜欢 (0)
发表我的评论
取消评论

表情 贴图 加粗 删除线 居中 斜体 签到

Hi,您需要填写昵称和邮箱!

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址