Escolar Documentos
Profissional Documentos
Cultura Documentos
CONFIGURAÇÕES DE KERNEL
options IPFIREWALL # Suporte ao IPFIREWALL
options IPFIREWALL_VERBOSE # Suporte a LOG
options IPFIREWALL_VERBOSE_LIMIT=100 # limite padrao de
registro por regra
options IPFIREWALL_DEFAULT_TO_ACCEPT # Padrao de firewall
aberto
options IPFIREWALL_FORWARD # Adiciona a ação fwd disponivel no
ipfw(encaminha pacote sem reescreve-lo ou seja sem nat)
options IPFIREWALL_NAT # in-kernel NAT
options LIBALIAS # Dependencia do IPFIREWALL_nat
options DUMMYNET # verificar
options IPDIVERT # VERIFICAR
#SINTAXE
ipfw <comando> <acao> <protocolo> from <origem> [porta] to
<destino> [porta]
ver no diretorio treina, arquivo ipfw.txt
log do ipfw - /var/log/security
#SCRIPT DE FIREWALL
#!/bin/sh
fw="/sbin/ipfw"
$fw -f flush
ifi="rl1"
ife="rl0"
redelocal=''10.2.0.0/24"
client_ssh1="10.10.2.64"
client_ssh2="10.10.2.65"
#clientes_SSH="{ 10.10.2.0/22{30,31} or 192.168.4.1 }" # --> menor
processamento
#clientes_SSH="table(1)"
$fw table 1 flush
$fw table 1 add 10.10.2.30
$fw table 1 add 10.10.2.31
$fw table 1 add 192.168.4.1
# Controle de loopback
$fw add allow all from any to any via lo0
$fw add deny log all from 127.0.0.0/8 to any
$fw add deny log all from any to 127.0.0.0/8
# Controle de fragmentacao (se tiver keep-state nao precisa desta
regra)
$fw add deny tcp from any to any frag
# Trata icmp
$fw add allow icmp from any to any icmptypes 0,8,3,11,12 iplen 20-
276
$fw add deny log icmp from any to any
# politica: fechada
#$fw add 65534 deny log all from any to any
#SCRIPT DE FIREWALL STATEFULL
#!/bin/sh
fw="/sbin/ipfw"
$fw -f flush
ifi="rl1"
ife="rl0"
redelocal=''10.2.0.0/24"
client_ssh1="10.10.2.64"
client_ssh2="10.10.2.65"
#clientes_SSH="{ 10.10.2.0/22{30,31} or 192.168.4.1 }" # --> menor
processamento
#clientes_SSH="table(1)"
$fw table 1 flush
$fw table 1 add 10.10.2.30
$fw table 1 add 10.10.2.31
$fw table 1 add 192.168.4.1
# Controle de loopback
$fw add allow all from any to any via lo0
$fw add deny log all from 127.0.0.0/8 to any
$fw add deny log all from any to 127.0.0.0/8
# Trata icmp
$fw add allow icmp from any to any icmptypes 0,8,3,11,12 iplen 20-
276
$fw add deny log icmp from any to any
# DNS - comunicacao publica, porem transf zona apenas slave
$fw add allow udp from any to any 53 in via $ife
$fw add allow tcp from <ip do slave dns> to any 53 in via $ife
$fw add deny log { udp or tcp } from any to any 53 in
# politica: fechada
#$fw add 65534 deny log all from any to any
/audiencias/html/_lib/file/doc/115 (2018-07-12
14'05'04 - 2018-07-12 14'06'15).avi
/audiencias/html/_lib/file/doc/145 (2017 07 08
17'07'34 2017 07 08 17'12'02).mp4
/audiencias/html/_lib/file/doc/185 (2018-07-26
20'45'32 - 2018-07-26 21'03'32).avi
/audiencias/html/_lib/file/doc/39 (2017 07 08
17'16'15 2017 07 08 17'16'42).mp4
/audiencias/html/_lib/file/doc/5 (2019-04-12
04'00'00 - 2019-04-12 05'00'00).avi
/audiencias/html/_lib/file/doc/5 (2019-04-12
04'00'00 - 2019-04-12 05'00'00).mp4
/audiencias/html/_lib/file/doc/9 (2018-12-04
15'17'00 - 2018-12-04 15'18'00).asf
/audiencias/html/_lib/file/doc/video 1- 'Não Tenho
Mágoa de Ninguém' Diz Jovem Que Foi Preso
Injustamente .mp4
/audiencias/html/_lib/file/doc/video (2019-04-12
04'00'00 - 2019-04-12 05'00'00).avi
/audiencias/html/_lib/file/doc/Comarca de
Santana's VMR 100137.mp4
/audiencias/html/_lib/file/doc/Comarca de
Santana's VMR 122402.mp4
/audiencias/html/_lib/file/doc/D'ALMEIDA Produções
e Eventos (@sigaadalmeida) ?~@? Fotos e vídeos do
Instagram_4.mp4
/audiencias/html/_lib/file/doc/Dentro de casa n°
processo 000136-69.2019.8.03.0002.mp4