natbox-spec-surge.rcS revision 1645
1#!/bin/sh
2EXTIF=192.168.0.7
3INTIF=10.0.0.1
4CLIENT=10.0.0.2
5
6echo "setting up network..."
7ifconfig lo 127.0.0.1
8ifconfig eth0 $EXTIF txqueuelen 1000
9ifconfig eth1 $INTIF txqueuelen 1000
10
11echo "0" > /proc/sys/net/ipv4/tcp_timestamps
12echo "0" > /proc/sys/net/ipv4/tcp_sack
13echo "1" > /proc/sys/net/ipv4/tcp_vegas_cong_avoid
14echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_rmem
15echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_wmem
16echo "5000000 5000000 5000000" > /proc/sys/net/ipv4/tcp_mem
17echo "262143" > /proc/sys/net/core/rmem_max
18echo "262143" > /proc/sys/net/core/wmem_max
19echo "262143" > /proc/sys/net/core/rmem_default
20echo "262143" > /proc/sys/net/core/wmem_default
21echo "262143" > /proc/sys/net/core/optmem_max
22echo "100000" > /proc/sys/net/core/netdev_max_backlog
23
24echo "1" > /proc/sys/net/ipv4/ip_forward
25
26echo "262144" > /proc/sys/net/ipv4/ip_conntrack_max
27
28echo "waiting for netserver..."
29/usr/bin/netcat -c -l -p 8000
30
31echo "setting up iptables..."
32IPTABLES=/sbin/iptables
33EXTIF=eth0
34INTIF=eth1
35
36$IPTABLES -P INPUT ACCEPT
37$IPTABLES -F INPUT
38$IPTABLES -P OUTPUT ACCEPT
39$IPTABLES -F OUTPUT
40$IPTABLES -P FORWARD DROP
41$IPTABLES -F FORWARD
42$IPTABLES -t nat -F
43
44$IPTABLES -A FORWARD -i $EXTIF -o $INTIF -m state --state ESTABLISHED,RELATED -j ACCEPT
45$IPTABLES -A FORWARD -i $INTIF -o $EXTIF -j ACCEPT
46$IPTABLES -A FORWARD -j LOG
47
48$IPTABLES -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
49
50echo "informing client..."
51echo "server ready" | /usr/bin/netcat -c $CLIENT 8000
52
53echo "starting bash..."
54exec /bin/bash
55