Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:30:29 2014
- *nat
- :PREROUTING ACCEPT [8162:1453132]
- :INPUT ACCEPT [693:354931]
- :OUTPUT ACCEPT [1094:191400]
- :POSTROUTING ACCEPT [1094:191400]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_internal - [0:0]
- :POST_internal_allow - [0:0]
- :POST_internal_deny - [0:0]
- :POST_internal_log - [0:0]
- :POST_public - [0:0]
- :POST_public_allow - [0:0]
- :POST_public_deny - [0:0]
- :POST_public_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- [8641:1622784] -A PREROUTING -j PREROUTING_direct
- [8639:1622444] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [8639:1622444] -A PREROUTING -j PREROUTING_ZONES
- [1127:201013] -A OUTPUT -j OUTPUT_direct
- [0:0] -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j SNAT --to-source 23.92.76.239
- [1127:201013] -A POSTROUTING -j POSTROUTING_direct
- [1127:201013] -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- [1127:201013] -A POSTROUTING -j POSTROUTING_ZONES
- [1088:190882] -A POSTROUTING_ZONES -o eth0 -g POST_public
- [0:0] -A POSTROUTING_ZONES -o tun0 -g POST_internal
- [6:518] -A POSTROUTING_ZONES -g POST_public
- [0:0] -A POST_internal -j POST_internal_log
- [0:0] -A POST_internal -j POST_internal_deny
- [0:0] -A POST_internal -j POST_internal_allow
- [1094:191400] -A POST_public -j POST_public_log
- [1094:191400] -A POST_public -j POST_public_deny
- [1094:191400] -A POST_public -j POST_public_allow
- [7909:1444512] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [277:18279] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [0:0] -A PREROUTING_ZONES -g PRE_public
- [277:18279] -A PRE_internal -j PRE_internal_log
- [277:18279] -A PRE_internal -j PRE_internal_deny
- [277:18279] -A PRE_internal -j PRE_internal_allow
- [7909:1444512] -A PRE_public -j PRE_public_log
- [7909:1444512] -A PRE_public -j PRE_public_deny
- [7909:1444512] -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Nov 27 18:30:29 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:30:29 2014
- *mangle
- :PREROUTING ACCEPT [24860:9016558]
- :INPUT ACCEPT [24582:8998211]
- :FORWARD ACCEPT [277:18279]
- :OUTPUT ACCEPT [24174:11796195]
- :POSTROUTING ACCEPT [24174:11796195]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- [25677:9277420] -A PREROUTING -j PREROUTING_direct
- [25672:9275504] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [25663:9267816] -A PREROUTING -j PREROUTING_ZONES
- [25382:9247834] -A INPUT -j INPUT_direct
- [277:18279] -A FORWARD -j FORWARD_direct
- [25011:12343399] -A OUTPUT -j OUTPUT_direct
- [25016:12344754] -A POSTROUTING -j POSTROUTING_direct
- [24570:8985953] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [277:18279] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [55:26733] -A PREROUTING_ZONES -g PRE_public
- [277:18279] -A PRE_internal -j PRE_internal_log
- [277:18279] -A PRE_internal -j PRE_internal_deny
- [277:18279] -A PRE_internal -j PRE_internal_allow
- [24625:9012686] -A PRE_public -j PRE_public_log
- [24625:9012686] -A PRE_public -j PRE_public_deny
- [24625:9012686] -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Nov 27 18:30:29 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:30:29 2014
- *security
- :INPUT ACCEPT [16779:7972129]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [25037:12355693]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- [16790:7982137] -A INPUT -j INPUT_direct
- [0:0] -A FORWARD -j FORWARD_direct
- [25042:12357142] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:30:29 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:30:29 2014
- *raw
- :PREROUTING ACCEPT [25701:9292040]
- :OUTPUT ACCEPT [25050:12361967]
- :OUTPUT_direct - [0:0]
- :PREROUTING_direct - [0:0]
- [25707:9296826] -A PREROUTING -j PREROUTING_direct
- [25050:12361967] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:30:29 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:30:29 2014
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [24187:11802492]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_internal - [0:0]
- :FWDI_internal_allow - [0:0]
- :FWDI_internal_deny - [0:0]
- :FWDI_internal_log - [0:0]
- :FWDI_public - [0:0]
- :FWDI_public_allow - [0:0]
- :FWDI_public_deny - [0:0]
- :FWDI_public_log - [0:0]
- :FWDO_internal - [0:0]
- :FWDO_internal_allow - [0:0]
- :FWDO_internal_deny - [0:0]
- :FWDO_internal_log - [0:0]
- :FWDO_public - [0:0]
- :FWDO_public_allow - [0:0]
- :FWDO_public_deny - [0:0]
- :FWDO_public_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_internal - [0:0]
- :IN_internal_allow - [0:0]
- :IN_internal_deny - [0:0]
- :IN_internal_log - [0:0]
- :IN_public - [0:0]
- :IN_public_allow - [0:0]
- :IN_public_deny - [0:0]
- :IN_public_log - [0:0]
- :OUTPUT_direct - [0:0]
- [16141:7729513] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [6:518] -A INPUT -i lo -j ACCEPT
- [9385:1664313] -A INPUT -j INPUT_direct
- [9385:1664313] -A INPUT -j INPUT_ZONES_SOURCE
- [9385:1664313] -A INPUT -j INPUT_ZONES
- [1:104] -A INPUT -p icmp -j ACCEPT
- [8655:1295098] -A INPUT -j REJECT --reject-with icmp-host-prohibited
- [0:0] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -i lo -j ACCEPT
- [277:18279] -A FORWARD -j FORWARD_direct
- [277:18279] -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- [277:18279] -A FORWARD -j FORWARD_IN_ZONES
- [277:18279] -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- [277:18279] -A FORWARD -j FORWARD_OUT_ZONES
- [0:0] -A FORWARD -p icmp -j ACCEPT
- [277:18279] -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- [25067:12368002] -A OUTPUT -j OUTPUT_direct
- [0:0] -A FORWARD_IN_ZONES -i eth0 -g FWDI_public
- [277:18279] -A FORWARD_IN_ZONES -i tun0 -g FWDI_internal
- [0:0] -A FORWARD_IN_ZONES -g FWDI_public
- [277:18279] -A FORWARD_OUT_ZONES -o eth0 -g FWDO_public
- [0:0] -A FORWARD_OUT_ZONES -o tun0 -g FWDO_internal
- [0:0] -A FORWARD_OUT_ZONES -g FWDO_public
- [277:18279] -A FWDI_internal -j FWDI_internal_log
- [277:18279] -A FWDI_internal -j FWDI_internal_deny
- [277:18279] -A FWDI_internal -j FWDI_internal_allow
- [0:0] -A FWDI_public -j FWDI_public_log
- [0:0] -A FWDI_public -j FWDI_public_deny
- [0:0] -A FWDI_public -j FWDI_public_allow
- [0:0] -A FWDO_internal -j FWDO_internal_log
- [0:0] -A FWDO_internal -j FWDO_internal_deny
- [0:0] -A FWDO_internal -j FWDO_internal_allow
- [277:18279] -A FWDO_public -j FWDO_public_log
- [277:18279] -A FWDO_public -j FWDO_public_deny
- [277:18279] -A FWDO_public -j FWDO_public_allow
- [8843:1497343] -A INPUT_ZONES -i eth0 -g IN_public
- [0:0] -A INPUT_ZONES -i tun0 -g IN_internal
- [0:0] -A INPUT_ZONES -g IN_public
- [0:0] -A IN_internal -j IN_internal_log
- [0:0] -A IN_internal -j IN_internal_deny
- [0:0] -A IN_internal -j IN_internal_allow
- [0:0] -A IN_internal_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [8843:1497343] -A IN_public -j IN_public_log
- [8843:1497343] -A IN_public -j IN_public_deny
- [8843:1497343] -A IN_public -j IN_public_allow
- [0:0] -A IN_public_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [8:440] -A IN_public_allow -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT
- [14:700] -A IN_public_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [698:366734] -A IN_public_allow -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
- [1:42] -A IN_public_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_public_allow -p tcp -m tcp --dport 6379 -m conntrack --ctstate NEW -j ACCEPT
- [5:260] -A IN_public_allow -p tcp -m tcp --dport 8887 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
- # Completed on Thu Nov 27 18:30:29 2014
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement