Zdravím - potrebuji radu:
Mam na virtualnim serveru VPN - IPSEC (STRONGSWAN). Potrebuji zablokovat veskerou prichozi komunikaci z WAN, ale povolit veskerou komunikaci z VPN. Mam navic zaplou maskaradu. Jakou router mi to funguje docela dobre, ale nemuzu se pripojit pres napr pres SSH. Poradi mi nejaky odbornik?
IPTables vypdaji nejak takto:
iptables --policy INPUT DROP
iptables --policy OUTPUT ACCEPT
iptables --policy FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
#IPSEC
iptables -A INPUT -p udp -i $WAN --dport 500 -m state --state NEW -j ACCEPT
iptables -A INPUT -p udp -i $WAN --dport 4500 -m state --state NEW -j ACCEPT
iptables -A INPUT -i $WAN -p 50 -j ACCEPT
iptables -A INPUT -i $WAN -p 51 -j ACCEPT
#vpn traffic
iptables -A INPUT -m policy --dir in --pol ipsec -s 172.22.36.0/24 -j ACCEPT
iptables -A FORWARD -m policy --dir in --pol ipsec -s 172.22.36.0/24 -j ACCEPT
# Enable MASQUERADE (NAT) on WAN
iptables -t nat -A POSTROUTING -o $WAN ! -d 172.22.0.0/16 -j MASQUERADE