Iptables ื•ืกื™ื ื•ืŸ ืชื ื•ืขื” ืฉืœ ืžืชื ื’ื“ื™ื ืขื ื™ื™ื ื•ืขืฆืœื ื™ื

ื”ืจืœื•ื•ื ื˜ื™ื•ืช ืฉืœ ื—ืกื™ืžืช ื‘ื™ืงื•ืจื™ื ื‘ืžืฉืื‘ื™ื ืืกื•ืจื™ื ืžืฉืคื™ืขื” ืขืœ ื›ืœ ืžื ื”ืœ ืฉืขืฉื•ื™ ืœื”ื™ื•ืช ืžื•ืืฉื ืจืฉืžื™ืช ื‘ืื™ ืฆื™ื•ืช ืœื—ื•ืง ืื• ืœืคืงื•ื“ื•ืช ืฉืœ ื”ืจืฉื•ื™ื•ืช ื”ืจืœื•ื•ื ื˜ื™ื•ืช.

Iptables ื•ืกื™ื ื•ืŸ ืชื ื•ืขื” ืฉืœ ืžืชื ื’ื“ื™ื ืขื ื™ื™ื ื•ืขืฆืœื ื™ื

ืœืžื” ืœื”ืžืฆื™ื ืืช ื”ื’ืœื’ืœ ืžื—ื“ืฉ ื›ืฉื™ืฉ ืชื•ื›ื ื™ื•ืช ื•ื”ืคืฆื•ืช ืžื™ื•ื—ื“ื•ืช ืœืžืฉื™ืžื•ืช ืฉืœื ื•, ืœืžืฉืœ: Zeroshell, pfSense, ClearOS.

ืœื”ื ื”ืœื” ื”ื™ื™ืชื” ืฉืืœื” ื ื•ืกืคืช: ื”ืื ืœืžื•ืฆืจ ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื™ืฉ ืชืขื•ื“ืช ื‘ื˜ื™ื—ื•ืช ืžื”ืžื“ื™ื ื” ืฉืœื ื•?

ื”ื™ื” ืœื ื• ื ื™ืกื™ื•ืŸ ื‘ืขื‘ื•ื“ื” ืขื ื”ื”ืคืฆื•ืช ื”ื‘ืื•ืช:

  • Zeroshell โ€“ ื”ืžืคืชื—ื™ื ืืคื™ืœื• ืชืจืžื• ืจื™ืฉื™ื•ืŸ ืœืฉื ืชื™ื™ื, ืื‘ืœ ื”ืชื‘ืจืจ ืฉืขืจื›ืช ื”ื”ืคืฆื” ืฉื‘ื” ื”ืชืขื ื™ื™ื ื•, ื‘ืื•ืคืŸ ืœื ื”ื’ื™ื•ื ื™, ื‘ื™ืฆืขื” ืขื‘ื•ืจื ื• ืคื•ื ืงืฆื™ื” ืงืจื™ื˜ื™ืช;
  • pfSense - ื›ื‘ื•ื“ ื•ื›ื‘ื•ื“, ื‘ื• ื‘ื–ืžืŸ ืžืฉืขืžื, ืžืชืจื’ืœ ืœืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ื—ื•ืžืช ื”ืืฉ ืฉืœ FreeBSD ื•ืœื ืžืกืคื™ืง ื ื•ื— ืœื ื• (ืื ื™ ื—ื•ืฉื‘ ืฉื–ื” ืขื ื™ื™ืŸ ืฉืœ ื”ืจื’ืœ, ืื‘ืœ ื”ืชื‘ืจืจ ืฉื–ื” ืœื ื ื›ื•ืŸ);
  • ClearOS - ื‘ื—ื•ืžืจื” ืฉืœื ื• ื–ื” ื”ืชื‘ืจืจ ื›ืื™ื˜ื™ ืžืื•ื“, ืœื ื”ืฆืœื—ื ื• ืœื”ื’ื™ืข ืœื‘ื“ื™ืงื•ืช ืจืฆื™ื ื™ื•ืช, ืื– ืœืžื” ืžืžืฉืงื™ื ื›ื‘ื“ื™ื ื›ืœ ื›ืš?
  • Ideco SELECTA. ื”ืžื•ืฆืจ ืฉืœ Ideco ื”ื•ื ืฉื™ื—ื” ื ืคืจื“ืช, ืžื•ืฆืจ ืžืขื ื™ื™ืŸ, ืื‘ืœ ืžืกื™ื‘ื•ืช ืคื•ืœื™ื˜ื™ื•ืช ืœื ื‘ืฉื‘ื™ืœื ื•, ื•ืื ื™ ืจื•ืฆื” ื’ื "ืœื ื’ื•ืก" ืื•ืชื ืœื’ื‘ื™ ื”ืจื™ืฉื™ื•ืŸ ืœืื•ืชื” ืœื™ื ื•ืงืก, ืจืื•ื ื“ืงื™ื•ื‘ ื•ื›ื•'. ืžืื™ืคื” ื”ื ืงื™ื‘ืœื• ืืช ื”ืจืขื™ื•ืŸ ืขืœ ื™ื“ื™ ื—ื™ืชื•ืš ื”ืžืžืฉืง ืœืชื•ืš ืคื™ืชื•ืŸ ื•ืขืœ ื™ื“ื™ ืœืงื™ื—ืช ื–ื›ื•ื™ื•ืช ืžืฉืชืžืฉ-ืขืœ, ื”ื ื™ื›ื•ืœื™ื ืœืžื›ื•ืจ ืžื•ืฆืจ ืžื•ื’ืžืจ ื”ืžื•ืจื›ื‘ ืžืžื•ื“ื•ืœื™ื ืžืคื•ืชื—ื™ื ื•ืžืฉื•ื ื™ื ืžืงื”ื™ืœืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžื•ืคืฆื™ื ืชื—ืช GPL&etc.

ืื ื™ ืžื‘ื™ืŸ ืฉื›ืขืช ื™ื–ืจืžื• ืœื›ื™ื•ื•ื ื™ ืงืจื™ืื•ืช ืฉืœื™ืœื™ื•ืช ืขื ื“ืจื™ืฉื•ืช ืœื‘ืกืก ืืช ื”ืจื’ืฉื•ืช ื”ืกื•ื‘ื™ื™ืงื˜ื™ื‘ื™ื™ื ืฉืœื™ ื‘ืคื™ืจื•ื˜, ืื‘ืœ ืื ื™ ืจื•ืฆื” ืœื•ืžืจ ืฉืฆื•ืžืช ื”ืจืฉืช ื”ื–ื” ื”ื•ื ื’ื ืžืื–ืŸ ืชืขื‘ื•ืจื” ืœ-4 ืขืจื•ืฆื™ื ื—ื™ืฆื•ื ื™ื™ื ืœืื™ื ื˜ืจื ื˜, ื•ืœื›ืœ ืขืจื•ืฅ ื™ืฉ ืžืืคื™ื™ื ื™ื ืžืฉืœื•. . ืื‘ืŸ ื™ืกื•ื“ ื ื•ืกืคืช ื”ื™ื™ืชื” ื”ืฆื•ืจืš ื‘ืื—ื“ ืžื›ืžื” ืžืžืฉืงื™ ืจืฉืช ืฉื™ืคืขืœื• ื‘ืžืจื—ื‘ื™ ื›ืชื•ื‘ื•ืช ืฉื•ื ื™ื, ื•ืื ื™ ะณะพั‚ะพะฒ ืชื•ื“ื• ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-VLAN ื‘ื›ืœ ืžืงื•ื ื”ื™ื›ืŸ ืฉืฆืจื™ืš ื•ืœื ื”ื›ืจื—ื™ ืœื ืžื•ื›ืŸ. ื™ืฉื ื ืžื›ืฉื™ืจื™ื ื‘ืฉื™ืžื•ืฉ ื›ื’ื•ืŸ TP-Link TL-R480T+ - ื”ื ืื™ื ื ืžืชื ื”ื’ื™ื ื‘ืฆื•ืจื” ืžื•ืฉืœืžืช, ื‘ืื•ืคืŸ ื›ืœืœื™, ืขื ื ื™ื•ืื ืกื™ื ืžืฉืœื”ื. ื ื™ืชืŸ ื”ื™ื” ืœื”ื’ื“ื™ืจ ืืช ื”ื—ืœืง ื”ื–ื” ื‘ืœื™ื ื•ืงืก ื”ื•ื“ื•ืช ืœืืชืจ ื”ืจืฉืžื™ ืฉืœ ืื•ื‘ื•ื ื˜ื• ืื™ื–ื•ืŸ IP: ืฉื™ืœื•ื‘ ืžืกืคืจ ืขืจื•ืฆื™ ืื™ื ื˜ืจื ื˜ ืœืื—ื“. ื™ืชืจื” ืžื›ืš, ื›ืœ ืื—ื“ ืžื”ืขืจื•ืฆื™ื ื™ื›ื•ืœ "ืœื™ืคื•ืœ" ื‘ื›ืœ ืจื’ืข, ื›ืžื• ื’ื ืœืขืœื•ืช. ืื ืืชื ืžืขื•ื ื™ื™ื ื™ื ื‘ืชืกืจื™ื˜ ืฉืขื•ื‘ื“ ื›ืจื’ืข (ื•ื–ื” ืฉื•ื•ื” ืคืจืกื•ื ื ืคืจื“), ื›ืชื‘ื• ื‘ืชื’ื•ื‘ื•ืช.

ื”ืคืชืจื•ืŸ ื”ื ื‘ื—ืŸ ืื™ื ื• ืžืชื™ื™ืžืจ ืœื”ื™ื•ืช ื™ื™ื—ื•ื“ื™, ืืš ื‘ืจืฆื•ื ื™ ืœืฉืื•ืœ ืืช ื”ืฉืืœื”: "ืžื“ื•ืข ืืจื’ื•ืŸ ืฆืจื™ืš ืœื”ืชืื™ื ืœืžื•ืฆืจื™ื ืžืคื•ืงืคืงื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืขื ื“ืจื™ืฉื•ืช ื—ื•ืžืจื” ืจืฆื™ื ื™ื•ืช ื›ืืฉืจ ื ื™ืชืŸ ืœืฉืงื•ืœ ืืคืฉืจื•ืช ื—ืœื•ืคื™ืช?"

ืื ื‘ืคื“ืจืฆื™ื” ื”ืจื•ืกื™ืช ื™ืฉ ืจืฉื™ืžื” ืฉืœ Roskomnadzor, ื‘ืื•ืงืจืื™ื ื” ื™ืฉ ื ืกืคื— ืœื”ื—ืœื˜ืช ื”ืžื•ืขืฆื” ืœื‘ื™ื˜ื—ื•ืŸ ืœืื•ืžื™ (ืœืžืฉืœ. ื›ืืŸ), ืื– ื’ื ืžื ื”ื™ื’ื™ื ืžืงื•ืžื™ื™ื ืœื ื™ืฉื ื™ื. ืœืžืฉืœ, ืงื™ื‘ืœื ื• ืจืฉื™ืžื” ืฉืœ ืืชืจื™ื ืืกื•ืจื™ื ืฉืœื“ืขืช ื”ื”ื ื”ืœื” ืคื•ื’ืขื™ื ื‘ืชืคื•ืงื” ื‘ืžืงื•ื ื”ืขื‘ื•ื“ื”.

ื‘ืชืงืฉื•ืจืช ืขื ืขืžื™ืชื™ื ื‘ืžืคืขืœื™ื ืื—ืจื™ื, ืฉื‘ื”ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื›ืœ ื”ืืชืจื™ื ืืกื•ืจื™ื ื•ืจืง ืœืคื™ ื‘ืงืฉื” ื‘ืื™ืฉื•ืจ ื”ื‘ื•ืก ืืชื” ื™ื›ื•ืœ ืœื’ืฉืช ืœืืชืจ ืกืคืฆื™ืคื™, ืžื—ื™ื™ืš ื‘ื›ื‘ื•ื“, ื—ื•ืฉื‘ื™ื ื•"ืžืขืฉื ื™ื ืขืœ ื”ื‘ืขื™ื”", ื”ื’ืขื ื• ืœื”ื‘ื ื” ืฉื”ื—ื™ื™ื ืขื“ื™ื™ืŸ ื˜ื•ื‘ ื•ื”ืชื—ืœื ื• ืืช ื”ื—ื™ืคื•ืฉ ืฉืœื”ื.

ืœืื—ืจ ืฉื”ื™ื™ืชื” ืœื ื• ื”ื–ื“ืžื ื•ืช ืœื ืจืง ืœืจืื•ืช ื‘ืฆื•ืจื” ืื ืœื™ื˜ื™ืช ืืช ืžื” ืฉื”ื ื›ื•ืชื‘ื™ื ื‘"ืกืคืจื™ื ืฉืœ ืขืงืจื•ืช ื‘ื™ืช" ืขืœ ืกื™ื ื•ืŸ ืชื ื•ืขื”, ืืœื ื’ื ืœืจืื•ืช ืžื” ืงื•ืจื” ื‘ืขืจื•ืฆื™ื ืฉืœ ืกืคืงื™ื ืฉื•ื ื™ื, ืฉืžื ื• ืœื‘ ืœืžืชื›ื•ื ื™ื ื”ื‘ืื™ื (ื›ืœ ืฆื™ืœื•ืžื™ ืžืกืš ื—ืชื•ื›ื™ื ืžืขื˜, ื‘ื‘ืงืฉื” ืœื”ื‘ื™ืŸ ื›ืฉืฉื•ืืœื™ื):

ืกืคืง 1
- ืœื ืžืคืจื™ืข ื•ื›ื•ืคื” ืฉืจืชื™ DNS ืžืฉืœื• ื•ืฉืจืช ืคืจื•ืงืกื™ ืฉืงื•ืฃ. ื•ื‘ื›ืŸ?.. ืื‘ืœ ื™ืฉ ืœื ื• ื’ื™ืฉื” ืœืžืงื•ื ืฉืื ื—ื ื• ืฆืจื™ื›ื™ื ืืช ื–ื” (ืื ืื ื—ื ื• ืฆืจื™ื›ื™ื ืืช ื–ื” :))

ืกืคืง 2
- ืžืืžื™ืŸ ืฉื”ืกืคืง ื”ืžื•ื‘ื™ืœ ืฉืœื• ืฆืจื™ืš ืœื—ืฉื•ื‘ ืขืœ ื–ื”, ื”ืชืžื™ื›ื” ื”ื˜ื›ื ื™ืช ืฉืœ ื”ืกืคืง ื”ืขืœื™ื•ืŸ ืืคื™ืœื• ื”ื•ื“ืชื” ืžื“ื•ืข ืœื ื™ื›ื•ืœืชื™ ืœืคืชื•ื— ืืช ื”ืืชืจ ืฉื”ื™ื™ืชื™ ืฆืจื™ืš, ื“ื‘ืจ ืฉืœื ื”ื™ื” ืืกื•ืจ. ืื ื™ ื—ื•ืฉื‘ ืฉื”ืชืžื•ื ื” ืชืฉืขืฉืข ืื•ืชืš :)

Iptables ื•ืกื™ื ื•ืŸ ืชื ื•ืขื” ืฉืœ ืžืชื ื’ื“ื™ื ืขื ื™ื™ื ื•ืขืฆืœื ื™ื

ื›ืคื™ ืฉื”ืชื‘ืจืจ, ื”ื ืžืชืจื’ืžื™ื ืฉืžื•ืช ืฉืœ ืืชืจื™ื ืืกื•ืจื™ื ืœื›ืชื•ื‘ื•ืช IP ื•ื—ื•ืกืžื™ื ืืช ื”-IP ืขืฆืžื• (ื”ื ืœื ืžื•ื˜ืจื“ื™ื ืžื”ืขื•ื‘ื“ื” ืฉื›ืชื•ื‘ืช ื”-IP ื”ื–ื• ื™ื›ื•ืœื” ืœืืจื— 20 ืืชืจื™ื).

ืกืคืง 3
- ืžืืคืฉืจ ืœืชื ื•ืขื” ืœืขื‘ื•ืจ ืœืฉื, ืืš ืื™ื ื• ืžืืคืฉืจ ืœื” ืœื—ื–ื•ืจ ืœืื•ืจืš ื”ืžืกืœื•ืœ.

ืกืคืง 4
- ืื•ืกืจ ืขืœ ื›ืœ ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ืžื ื•ืช ื‘ื›ื™ื•ื•ืŸ ืฉืฆื•ื™ืŸ.

ืžื” ืœืขืฉื•ืช ืขื VPN (ื›ื‘ื•ื“ ืœื“ืคื“ืคืŸ Opera) ื•ืชื•ืกืคื™ ื“ืคื“ืคืŸ? ื›ืฉืฉื™ื—ืงื ื• ืขื ื”ืฆื•ืžืช Mikrotik ื‘ื”ืชื—ืœื”, ืืคื™ืœื• ืงื™ื‘ืœื ื• ืžืชื›ื•ืŸ ืขืชื™ืจ ืžืฉืื‘ื™ื ืขื‘ื•ืจ L7, ืฉืื•ืชื• ื ืืœืฆื ื• ืœื ื˜ื•ืฉ ืžืื•ื—ืจ ื™ื•ืชืจ (ื™ื™ืชื›ืŸ ืฉื™ืฉ ืขื•ื“ ืฉืžื•ืช ืืกื•ืจื™ื, ื–ื” ื”ื•ืคืš ืœื”ื™ื•ืช ืขืฆื•ื‘ ื›ืืฉืจ, ื‘ื ื•ืกืฃ ืœืื—ืจื™ื•ืช ื”ื™ืฉื™ืจื” ืฉืœื• ืœืžืกืœื•ืœื™ื, ืขืœ 3 ืชืจื™ืกืจ ื‘ื™ื˜ื•ื™ื™ื ืขื•ืžืก ื”ืžืขื‘ื“ PPC460GT ืžื’ื™ืข ืœ-100%.

Iptables ื•ืกื™ื ื•ืŸ ืชื ื•ืขื” ืฉืœ ืžืชื ื’ื“ื™ื ืขื ื™ื™ื ื•ืขืฆืœื ื™ื.

ืžื” ืฉื”ืชื‘ืจืจ:
DNS ื‘-127.0.0.1 ื”ื•ื ืžืžืฉ ืœื ืชืจื•ืคืช ืคืœื; ื’ืจืกืื•ืช ืžื•ื“ืจื ื™ื•ืช ืฉืœ ื“ืคื“ืคื ื™ื ืขื“ื™ื™ืŸ ืžืืคืฉืจื•ืช ืœืš ืœืขืงื•ืฃ ื‘ืขื™ื•ืช ื›ืืœื”. ืื™ ืืคืฉืจ ืœื”ื’ื‘ื™ืœ ืืช ื›ืœ ื”ืžืฉืชืžืฉื™ื ืœื–ื›ื•ื™ื•ืช ืžื•ืคื—ืชื•ืช, ื•ืืกื•ืจ ืœื ื• ืœืฉื›ื•ื— ืืช ื”ืžืกืคืจ ื”ืขืฆื•ื ืฉืœ DNS ืืœื˜ืจื ื˜ื™ื‘ื™. ื”ืื™ื ื˜ืจื ื˜ ืื™ื ื• ืกื˜ื˜ื™, ื•ื‘ื ื•ืกืฃ ืœื›ืชื•ื‘ื•ืช DNS ื—ื“ืฉื•ืช, ืืชืจื™ื ืืกื•ืจื™ื ืงื•ื ื™ื ื›ืชื•ื‘ื•ืช ื—ื“ืฉื•ืช, ืžืฉื ื™ื ื“ื•ืžื™ื™ื ื™ื ื‘ืจืžื” ื”ืขืœื™ื•ื ื” ื•ื™ื›ื•ืœื™ื ืœื”ื•ืกื™ืฃ/ืœื”ืกื™ืจ ืชื• ื‘ื›ืชื•ื‘ืช ืฉืœื”ื. ืื‘ืœ ืขื“ื™ื™ืŸ ื™ืฉ ืœื• ืืช ื”ื–ื›ื•ืช ืœื—ื™ื•ืช ืžืฉื”ื• ื›ืžื•:

ip route add blackhole 1.2.3.4

ื–ื” ื™ื”ื™ื” ื“ื™ ื™ืขื™ืœ ืœื”ืฉื™ื’ ืจืฉื™ืžื” ืฉืœ ื›ืชื•ื‘ื•ืช IP ืžืจืฉื™ืžืช ื”ืืชืจื™ื ื”ืืกื•ืจื™ื, ืื‘ืœ ืžื”ืกื™ื‘ื•ืช ืฉืฆื•ื™ื ื• ืœืขื™ืœ, ืขื‘ืจื ื• ืœืฉื™ืงื•ืœื™ื ืœื’ื‘ื™ Iptables. ื›ื‘ืจ ื”ื™ื” ืžืื–ืŸ ื—ื™ ื‘ื’ืจืกื” 7.5.1804 ืฉืœ CentOS Linux.

ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ืžืฉืชืžืฉ ืฆืจื™ืš ืœื”ื™ื•ืช ืžื”ื™ืจ, ื•ื”ื“ืคื“ืคืŸ ืœื ืฆืจื™ืš ืœื”ืžืชื™ืŸ ื—ืฆื™ ื“ืงื”, ืชื•ืš ืžืกืงื ื” ืฉื“ืฃ ื–ื” ืื™ื ื• ื–ืžื™ืŸ. ืœืื—ืจ ื—ื™ืคื•ืฉ ืืจื•ืš ื”ื’ืขื ื• ืœื“ื’ื ื”ื–ื”:
ืงื•ื‘ืฅ 1 -> /script/denied_host, ืจืฉื™ืžื” ืฉืœ ืฉืžื•ืช ืืกื•ืจื™ื:

test.test
blablabla.bubu
torrent
porno

ืงื•ื‘ืฅ 2 -> /script/denied_range, ืจืฉื™ืžื” ืฉืœ ืžืจื—ื‘ื™ ื›ืชื•ื‘ื•ืช ื•ื›ืชื•ื‘ื•ืช ืืกื•ืจื™ื:

192.168.111.0/24
241.242.0.0/16

ืงื•ื‘ืฅ ืกืงืจื™ืคื˜ 3 -> ipt.shืขื•ืฉื” ืืช ื”ืขื‘ื•ื“ื” ืขื ipables:

# ัั‡ะธั‚ั‹ะฒะฐะตะผ ะฟะพะปะตะทะฝัƒัŽ ะธะฝั„ะพั€ะผะฐั†ะธัŽ ะธะท ะฟะตั€ะตั‡ะฝะตะน ั„ะฐะนะปะพะฒ
HOSTS=`cat /script/denied_host | grep -v '^#'`
RANGE=`cat /script/denied_range | grep -v '^#'`
echo "Stopping firewall and allowing everyone..."
# ัะฑั€ะฐัั‹ะฒะฐะตะผ ะฒัะต ะฝะฐัั‚ั€ะพะนะบะธ iptables, ั€ะฐะทั€ะตัˆะฐั ั‚ะพ ั‡ั‚ะพ ะฝะต ะทะฐะฟั€ะตั‰ะตะฝะพ
sudo iptables -F
sudo iptables -X
sudo iptables -t nat -F
sudo iptables -t nat -X
sudo iptables -t mangle -F
sudo iptables -t mangle -X
sudo iptables -P INPUT ACCEPT
sudo iptables -P FORWARD ACCEPT
sudo iptables -P OUTPUT ACCEPT
#ั€ะตัˆะฐะตะผ ะพะฑะฝะพะฒะธั‚ัŒ ะธะฝั„ะพั€ะผะฐั†ะธัŽ ะพ ะผะฐั€ัˆั€ัƒั‚ะฐั… (ะพัะพะฑะตะฝะฝะพัั‚ัŒ ะฝะฐัˆะตะน ะฐั€ั…ะธั‚ะตะบั‚ัƒั€ั‹)
sudo sh rout.sh
# ั†ะธะบะปะธั‡ะตัะบะธ ะพะฑั€ะฐะฑะฐั‚ั‹ะฒะฐั ะบะฐะถะดัƒัŽ ัั‚ั€ะพะบัƒ ั„ะฐะนะปะฐ ะฟั€ะธะผะตะฝัะตะผ ะฟั€ะฐะฒะธะปะพ ะฑะปะพะบะธั€ะพะฒะบะธ ัั‚ั€ะพะบะธ
for i in $HOSTS; do
sudo iptables -I FORWARD -m string --string $i --algo bm --from 1 --to 600 -p tcp -j REJECT --reject-with tcp-reset;
sudo iptables -I FORWARD -m string --string $i --algo bm --from 1 --to 600 -p udp -j DROP;
done
# ั†ะธะบะปะธั‡ะตัะบะธ ะพะฑั€ะฐะฑะฐั‚ั‹ะฒะฐั ะบะฐะถะดัƒัŽ ัั‚ั€ะพะบัƒ ั„ะฐะนะปะฐ ะฟั€ะธะผะตะฝัะตะผ ะฟั€ะฐะฒะธะปะพ ะฑะปะพะบะธั€ะพะฒะบะธ ะฐะดั€ะตัะฐ
for i in $RANGE; do
sudo iptables -I FORWARD -p UDP -d $i -j DROP;
sudo iptables -I FORWARD -p TCP  -d $i -j REJECT --reject-with tcp-reset;
done

ื”ืฉื™ืžื•ืฉ ื‘-sudo ื ื•ื‘ืข ืžื›ืš ืฉื™ืฉ ืœื ื• ืคืจื™ืฆื” ืงื˜ื ื” ืœื ื™ื”ื•ืœ ื“ืจืš ืžืžืฉืง ื”-WEB, ืืš ื›ืคื™ ืฉื”ื•ื›ื™ื— ื”ื ื™ืกื™ื•ืŸ ื‘ืฉื™ืžื•ืฉ ื‘ืžื•ื“ืœ ื›ื–ื” ื‘ืžืฉืš ื™ื•ืชืจ ืžืฉื ื”, WEB ืื™ื ื• ื›ืœ ื›ืš ื”ื›ืจื—ื™. ืœืื—ืจ ื”ื˜ืžืขื” ื ื•ืฆืจ ืจืฆื•ืŸ ืœื”ื•ืกื™ืฃ ืจืฉื™ืžืช ืืชืจื™ื ืœืžืื’ืจ ื•ื›ื•'. ืžืกืคืจ ื”ืžืืจื—ื™ื ื”ื—ืกื•ืžื™ื ื”ื•ื ื™ื•ืชืจ ืž-250 + ืชืจื™ืกืจ ืžืงื•ืžื•ืช ื›ืชื•ื‘ื•ืช. ื‘ืืžืช ื™ืฉ ื‘ืขื™ื” ื›ืฉื ื›ื ืกื™ื ืœืืชืจ ื“ืจืš ื—ื™ื‘ื•ืจ https, ื›ืžื• ืžื ื”ืœ ื”ืžืขืจื›ืช, ื™ืฉ ืœื™ ืชืœื•ื ื•ืช ืขืœ ื“ืคื“ืคื ื™ื :), ืื‘ืœ ืืœื• ืžืงืจื™ื ืžื™ื•ื—ื“ื™ื, ืจื•ื‘ ื”ื˜ืจื™ื’ืจื™ื ืœื—ื•ืกืจ ื’ื™ืฉื” ืœืžืฉืื‘ ืขื“ื™ื™ืŸ ื‘ืฆื“ ืฉืœื ื• , ืื ื• ื’ื ื—ื•ืกืžื™ื ื‘ื”ืฆืœื—ื” ืืช Opera VPN ื•ืชื•ืกืคื™ื ื›ืžื• friGate ื•ื˜ืœืžื˜ืจื™ื” ืžื‘ื™ืช ืžื™ืงืจื•ืกื•ืคื˜.

Iptables ื•ืกื™ื ื•ืŸ ืชื ื•ืขื” ืฉืœ ืžืชื ื’ื“ื™ื ืขื ื™ื™ื ื•ืขืฆืœื ื™ื

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”