Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@slackware:~# iptables-save
- # Generated by iptables-save v1.4.14 on Fri Jul 31 18:12:25 2015
- *mangle
- :PREROUTING ACCEPT [39905668:18637358453]
- :INPUT ACCEPT [33360816:13600868199]
- :FORWARD ACCEPT [6544103:5036446390]
- :OUTPUT ACCEPT [32618463:8594967900]
- :POSTROUTING ACCEPT [39170440:13633301440]
- COMMIT
- # Completed on Fri Jul 31 18:12:25 2015
- # Generated by iptables-save v1.4.14 on Fri Jul 31 18:12:25 2015
- *nat
- :PREROUTING ACCEPT [177986:11802394]
- :INPUT ACCEPT [121312:7648472]
- :OUTPUT ACCEPT [325933:21787914]
- :POSTROUTING ACCEPT [233191:15008715]
- :tcp_prebound - [0:0]
- :udp_prebound - [0:0]
- -A PREROUTING -i eth1 -p udp -j udp_prebound
- -A PREROUTING -i eth1 -p tcp -j tcp_prebound
- -A POSTROUTING -o eth1 -j MASQUERADE
- -A tcp_prebound -p tcp -j RETURN
- -A udp_prebound -p udp -j RETURN
- COMMIT
- # Completed on Fri Jul 31 18:12:25 2015
- # Generated by iptables-save v1.4.14 on Fri Jul 31 18:12:25 2015
- *filter
- :INPUT DROP [9497:736209]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :bad_packets - [0:0]
- :bad_tcp_packets - [0:0]
- :icmp_packets - [0:0]
- :tcp_fwdbound - [0:0]
- :tcp_inbound - [0:0]
- :tcp_infwdbound - [0:0]
- :tcp_vpnbound - [0:0]
- :udp_fwdbound - [0:0]
- :udp_inbound - [0:0]
- :udp_infwdbound - [0:0]
- :udp_vpnbound - [0:0]
- -A INPUT -i lo -j ACCEPT
- -A INPUT -j bad_packets
- -A INPUT -d 224.0.0.1/32 -j DROP
- -A INPUT -i eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -s 192.168.112.0/24 -i eth0 -j ACCEPT
- -A INPUT -d 192.168.112.255/32 -i eth0 -j ACCEPT
- -A INPUT -i eth0 -p icmp -j icmp_packets
- -A INPUT -i eth2 -j ACCEPT
- -A INPUT -s 192.168.26.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A INPUT -s 192.168.114.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A INPUT -s 192.168.18.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A INPUT -s 192.168.26.0/24 -i tun+ -p udp -j udp_vpnbound
- -A INPUT -s 192.168.114.0/24 -i tun+ -p udp -j udp_vpnbound
- -A INPUT -s 192.168.18.0/24 -i tun+ -p udp -j udp_vpnbound
- -A INPUT -d 192.168.26.255/32 -i tun+ -j ACCEPT
- -A INPUT -i tun+ -p icmp -j ACCEPT
- -A INPUT -i eth1 -p tcp -j tcp_inbound
- -A INPUT -i eth1 -p udp -j udp_inbound
- -A INPUT -i eth1 -p icmp -j icmp_packets
- -A INPUT -m pkttype --pkt-type broadcast -j DROP
- -A INPUT -m limit --limit 3/min --limit-burst 3 -j ULOG --ulog-prefix "INPUT packet died: "
- -A FORWARD -i eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i eth0 -p tcp -j tcp_fwdbound
- -A FORWARD -i eth2 -j ACCEPT
- -A FORWARD -i eth0 -p udp -j udp_fwdbound
- -A FORWARD -i eth0 -j ACCEPT
- -A FORWARD -s 192.168.26.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A FORWARD -s 192.168.114.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A FORWARD -s 192.168.18.0/24 -i tun+ -p tcp -j tcp_vpnbound
- -A FORWARD -s 192.168.26.0/24 -i tun+ -p udp -j udp_vpnbound
- -A FORWARD -s 192.168.114.0/24 -i tun+ -p udp -j udp_vpnbound
- -A FORWARD -s 192.168.18.0/24 -i tun+ -p udp -j udp_vpnbound
- -A FORWARD -i tun+ -p icmp -j icmp_packets
- -A FORWARD -i eth1 -p tcp -j tcp_infwdbound
- -A FORWARD -i eth1 -p udp -j udp_infwdbound
- -A FORWARD -i eth1 -p icmp -j icmp_packets
- -A FORWARD -m limit --limit 3/min --limit-burst 3 -j ULOG --ulog-prefix "FORWARD packet died: "
- -A OUTPUT -p icmp -m state --state INVALID -j DROP
- -A OUTPUT -s 127.0.0.1/32 -j ACCEPT
- -A OUTPUT -o lo -j ACCEPT
- -A OUTPUT -s 192.168.112.112/32 -j ACCEPT
- -A OUTPUT -o eth0 -j ACCEPT
- -A OUTPUT -o eth2 -j ACCEPT
- -A OUTPUT -o tun+ -j ACCEPT
- -A OUTPUT -o eth1 -j ACCEPT
- -A OUTPUT -m limit --limit 3/min --limit-burst 3 -j ULOG --ulog-prefix "OUTPUT packet died: "
- -A bad_packets -s 192.168.112.0/24 -i eth1 -j ULOG --ulog-prefix "Illegal source: "
- -A bad_packets -s 192.168.112.0/24 -i eth1 -j DROP
- -A bad_packets -m state --state INVALID -j ULOG --ulog-prefix "Invalid packet: "
- -A bad_packets -m state --state INVALID -j DROP
- -A bad_packets -p tcp -j bad_tcp_packets
- -A bad_packets -j RETURN
- -A bad_tcp_packets -i eth0 -p tcp -j RETURN
- -A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j ULOG --ulog-prefix "New not syn: "
- -A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j ULOG --ulog-prefix "Stealth scan: "
- -A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
- -A bad_tcp_packets -p tcp -j RETURN
- -A icmp_packets -p icmp -f -j ULOG --ulog-prefix "ICMP Fragment: "
- -A icmp_packets -p icmp -m icmp --icmp-type 3 -j ACCEPT
- -A icmp_packets -p icmp -f -j DROP
- -A icmp_packets -p icmp -m icmp --icmp-type 0 -j ACCEPT
- -A icmp_packets -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A icmp_packets -p icmp -m icmp --icmp-type 11 -j ACCEPT
- -A icmp_packets -p icmp -j RETURN
- -A tcp_fwdbound -p tcp -j RETURN
- -A tcp_inbound -p tcp -m tcp --dport 113 -j REJECT --reject-with icmp-port-unreachable
- -A tcp_inbound -p tcp -m tcp --dport 51237 -j ACCEPT
- -A tcp_inbound -p tcp -m tcp --dport 34567 -j ACCEPT
- -A tcp_inbound -p tcp -m tcp --dport 3551 -j ACCEPT
- -A tcp_inbound -p tcp -j RETURN
- -A tcp_infwdbound -p tcp -m tcp --dport 12321 -j ACCEPT
- -A tcp_infwdbound -p tcp -j RETURN
- -A tcp_vpnbound -p tcp -m tcp --dport 80 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 3389:3391 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 3395 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 5901 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 5801 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 8080 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 6600 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 10000 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 38000 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 22 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 51237 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 139 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 445 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 53 -j ACCEPT
- -A tcp_vpnbound -p tcp -m tcp --dport 34122:34128 -j ACCEPT
- -A tcp_vpnbound -j RETURN
- -A udp_fwdbound -p udp -j RETURN
- -A udp_inbound -p udp -m udp --dport 113 -j REJECT --reject-with icmp-port-unreachable
- -A udp_inbound -p udp -m udp --dport 137 -j DROP
- -A udp_inbound -p udp -m udp --dport 138 -j DROP
- -A udp_inbound -p udp -m udp --dport 34567 -j ACCEPT
- -A udp_inbound -p udp -m udp --dport 34568 -j ACCEPT
- -A udp_inbound -p udp -m udp --dport 34569 -j ACCEPT
- -A udp_inbound -p udp -m udp --dport 32386 -j ACCEPT
- -A udp_inbound -s 192.168.231.117/32 -p udp -m udp --dport 123 -j ACCEPT
- -A udp_inbound -p udp -j RETURN
- -A udp_inbound -p tcp -m tcp --dport 34568 -j ACCEPT
- -A udp_infwdbound -p udp -j RETURN
- -A udp_vpnbound -p udp -m udp --dport 53 -j ACCEPT
- -A udp_vpnbound -p udp -m udp --dport 137:139 -j ACCEPT
- -A udp_vpnbound -p udp -m udp --dport 445 -j ACCEPT
- -A udp_vpnbound -p udp -j RETURN
- COMMIT
- # Completed on Fri Jul 31 18:12:25 2015
- root@slackware:~#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement