natbox-spec-surge.rcS revision 1362:88a3afa44545
1#!/bin/sh
2EXTIF=192.168.0.7
3INTIF=10.0.0.1
4CLIENT=10.0.0.2
5
6echo "setting up network..."
7ifconfig lo 127.0.0.1
8ifconfig eth0 $EXTIF txqueuelen 1000
9ifconfig eth1 $INTIF txqueuelen 1000
10
11echo "0" > /proc/sys/net/ipv4/tcp_timestamps
12echo "0" > /proc/sys/net/ipv4/tcp_sack
13echo "1" > /proc/sys/net/ipv4/tcp_vegas_cong_avoid
14echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_rmem
15echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_wmem
16echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_mem
17echo "262143" > /proc/sys/net/core/rmem_max
18echo "262143" > /proc/sys/net/core/wmem_max
19echo "262143" > /proc/sys/net/core/rmem_default
20echo "262143" > /proc/sys/net/core/wmem_default
21echo "262143" > /proc/sys/net/core/optmem_max
22echo "100000" > /proc/sys/net/core/netdev_max_backlog
23
24echo "1" > /proc/sys/net/ipv4/ip_forward
25
26echo "waiting for netserver..."
27/usr/bin/netcat -c -l -p 8000
28
29echo "setting up iptables..."
30IPTABLES=/sbin/iptables
31EXTIF=eth0
32INTIF=eth1
33
34$IPTABLES -P INPUT ACCEPT
35$IPTABLES -F INPUT
36$IPTABLES -P OUTPUT ACCEPT
37$IPTABLES -F OUTPUT
38$IPTABLES -P FORWARD DROP
39$IPTABLES -F FORWARD
40$IPTABLES -t nat -F
41
42$IPTABLES -A FORWARD -i $EXTIF -o $INTIF -m state --state ESTABLISHED,RELATED -j ACCEPT
43$IPTABLES -A FORWARD -i $INTIF -o $EXTIF -j ACCEPT
44$IPTABLES -A FORWARD -j LOG
45
46$IPTABLES -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
47
48echo "informing client..."
49echo "server ready" | /usr/bin/netcat -c $CLIENT 8000
50
51echo "starting bash..."
52exec /bin/bash
53