Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@virl:~# iptables-save
- # Generated by iptables-save v1.4.21 on Sat Jun 4 14:26:58 2016
- *raw
- :PREROUTING ACCEPT [2669008:2316472374]
- :OUTPUT ACCEPT [2678654:2318562649]
- COMMIT
- # Completed on Sat Jun 4 14:26:58 2016
- # Generated by iptables-save v1.4.21 on Sat Jun 4 14:26:58 2016
- *mangle
- :PREROUTING ACCEPT [2674864:2318565463]
- :INPUT ACCEPT [2669891:2318282287]
- :FORWARD ACCEPT [4973:283176]
- :OUTPUT ACCEPT [2686101:2320951372]
- :POSTROUTING ACCEPT [2691074:2321234548]
- :nova-api-POSTROUTING - [0:0]
- -A POSTROUTING -j nova-api-POSTROUTING
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- COMMIT
- # Completed on Sat Jun 4 14:26:58 2016
- # Generated by iptables-save v1.4.21 on Sat Jun 4 14:26:58 2016
- *nat
- :PREROUTING ACCEPT [1022:52204]
- :INPUT ACCEPT [5:284]
- :OUTPUT ACCEPT [318:25914]
- :POSTROUTING ACCEPT [321:26070]
- :nova-api-OUTPUT - [0:0]
- :nova-api-POSTROUTING - [0:0]
- :nova-api-PREROUTING - [0:0]
- :nova-api-float-snat - [0:0]
- :nova-api-snat - [0:0]
- :nova-postrouting-bottom - [0:0]
- -A PREROUTING -j nova-api-PREROUTING
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11001 -j DNAT --to-destination 172.16.11.101:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11002 -j DNAT --to-destination 172.16.11.102:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11003 -j DNAT --to-destination 172.16.11.103:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11004 -j DNAT --to-destination 172.16.11.104:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11005 -j DNAT --to-destination 172.16.11.105:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11006 -j DNAT --to-destination 172.16.11.106:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11007 -j DNAT --to-destination 172.16.11.107:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11008 -j DNAT --to-destination 172.16.11.108:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11009 -j DNAT --to-destination 172.16.11.109:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11010 -j DNAT --to-destination 172.16.11.110:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11011 -j DNAT --to-destination 172.16.11.111:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11012 -j DNAT --to-destination 172.16.11.112:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11013 -j DNAT --to-destination 172.16.11.113:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11014 -j DNAT --to-destination 172.16.11.114:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11015 -j DNAT --to-destination 172.16.11.115:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11016 -j DNAT --to-destination 172.16.11.116:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11017 -j DNAT --to-destination 172.16.11.117:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11018 -j DNAT --to-destination 172.16.11.118:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11019 -j DNAT --to-destination 172.16.11.119:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11020 -j DNAT --to-destination 172.16.11.120:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11021 -j DNAT --to-destination 172.16.11.121:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11022 -j DNAT --to-destination 172.16.11.122:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11023 -j DNAT --to-destination 172.16.11.123:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11024 -j DNAT --to-destination 172.16.11.124:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11025 -j DNAT --to-destination 172.16.11.125:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11026 -j DNAT --to-destination 172.16.11.126:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11027 -j DNAT --to-destination 172.16.11.127:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11028 -j DNAT --to-destination 172.16.11.128:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11029 -j DNAT --to-destination 172.16.11.129:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 11030 -j DNAT --to-destination 172.16.11.130:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12001 -j DNAT --to-destination 172.16.11.201:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12002 -j DNAT --to-destination 172.16.11.202:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12003 -j DNAT --to-destination 172.16.11.203:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12004 -j DNAT --to-destination 172.16.11.204:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12005 -j DNAT --to-destination 172.16.11.205:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12006 -j DNAT --to-destination 172.16.11.206:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12007 -j DNAT --to-destination 172.16.11.207:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12008 -j DNAT --to-destination 172.16.11.208:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12009 -j DNAT --to-destination 172.16.11.209:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12010 -j DNAT --to-destination 172.16.11.210:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12011 -j DNAT --to-destination 172.16.11.211:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12012 -j DNAT --to-destination 172.16.11.212:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12013 -j DNAT --to-destination 172.16.11.213:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12014 -j DNAT --to-destination 172.16.11.214:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12015 -j DNAT --to-destination 172.16.11.215:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12016 -j DNAT --to-destination 172.16.11.216:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12017 -j DNAT --to-destination 172.16.11.217:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12018 -j DNAT --to-destination 172.16.11.218:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12019 -j DNAT --to-destination 172.16.11.219:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12020 -j DNAT --to-destination 172.16.11.220:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12021 -j DNAT --to-destination 172.16.11.221:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12022 -j DNAT --to-destination 172.16.11.222:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12023 -j DNAT --to-destination 172.16.11.223:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12024 -j DNAT --to-destination 172.16.11.224:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12025 -j DNAT --to-destination 172.16.11.225:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12026 -j DNAT --to-destination 172.16.11.226:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12027 -j DNAT --to-destination 172.16.11.227:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12028 -j DNAT --to-destination 172.16.11.228:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12029 -j DNAT --to-destination 172.16.11.229:7023
- -A PREROUTING -i bond0 -p tcp -m tcp --dport 12030 -j DNAT --to-destination 172.16.11.230:7023
- -A OUTPUT -j nova-api-OUTPUT
- -A POSTROUTING -j nova-api-POSTROUTING
- -A POSTROUTING -j nova-postrouting-bottom
- -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- -A POSTROUTING -s 172.16.0.0/19 -o bond0 -j MASQUERADE
- -A POSTROUTING -s 172.16.0.0/19 -o bond0 -j MASQUERADE
- -A nova-api-snat -j nova-api-float-snat
- -A nova-postrouting-bottom -j nova-api-snat
- COMMIT
- # Completed on Sat Jun 4 14:26:58 2016
- # Generated by iptables-save v1.4.21 on Sat Jun 4 14:26:58 2016
- *filter
- :INPUT DROP [0:0]
- :FORWARD ACCEPT [21:840]
- :OUTPUT ACCEPT [0:0]
- :nova-api-FORWARD - [0:0]
- :nova-api-INPUT - [0:0]
- :nova-api-OUTPUT - [0:0]
- :nova-api-local - [0:0]
- :nova-filter-top - [0:0]
- :ufw-after-forward - [0:0]
- :ufw-after-input - [0:0]
- :ufw-after-logging-forward - [0:0]
- :ufw-after-logging-input - [0:0]
- :ufw-after-logging-output - [0:0]
- :ufw-after-output - [0:0]
- :ufw-before-forward - [0:0]
- :ufw-before-input - [0:0]
- :ufw-before-logging-forward - [0:0]
- :ufw-before-logging-input - [0:0]
- :ufw-before-logging-output - [0:0]
- :ufw-before-output - [0:0]
- :ufw-logging-allow - [0:0]
- :ufw-logging-deny - [0:0]
- :ufw-not-local - [0:0]
- :ufw-reject-forward - [0:0]
- :ufw-reject-input - [0:0]
- :ufw-reject-output - [0:0]
- :ufw-skip-to-policy-forward - [0:0]
- :ufw-skip-to-policy-input - [0:0]
- :ufw-skip-to-policy-output - [0:0]
- :ufw-track-forward - [0:0]
- :ufw-track-input - [0:0]
- :ufw-track-output - [0:0]
- :ufw-user-forward - [0:0]
- :ufw-user-input - [0:0]
- :ufw-user-limit - [0:0]
- :ufw-user-limit-accept - [0:0]
- :ufw-user-logging-forward - [0:0]
- :ufw-user-logging-input - [0:0]
- :ufw-user-logging-output - [0:0]
- :ufw-user-output - [0:0]
- -A INPUT -j nova-api-INPUT
- -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
- -A INPUT -j ufw-before-logging-input
- -A INPUT -j ufw-before-input
- -A INPUT -j ufw-after-input
- -A INPUT -j ufw-after-logging-input
- -A INPUT -j ufw-reject-input
- -A INPUT -j ufw-track-input
- -A FORWARD -j nova-filter-top
- -A FORWARD -j nova-api-FORWARD
- -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
- -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -j ufw-before-logging-forward
- -A FORWARD -j ufw-before-forward
- -A FORWARD -j ufw-after-forward
- -A FORWARD -j ufw-after-logging-forward
- -A FORWARD -j ufw-reject-forward
- -A FORWARD -j ufw-track-forward
- -A OUTPUT -j nova-filter-top
- -A OUTPUT -j nova-api-OUTPUT
- -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
- -A OUTPUT -j ufw-before-logging-output
- -A OUTPUT -j ufw-before-output
- -A OUTPUT -j ufw-after-output
- -A OUTPUT -j ufw-after-logging-output
- -A OUTPUT -j ufw-reject-output
- -A OUTPUT -j ufw-track-output
- -A nova-api-INPUT -p tcp -m tcp --dport 8775 -m addrtype --dst-type LOCAL -j ACCEPT
- -A nova-filter-top -j nova-api-local
- -A ufw-after-input -p udp -m udp --dport 137 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 138 -j ufw-skip-to-policy-input
- -A ufw-after-input -p tcp -m tcp --dport 139 -j ufw-skip-to-policy-input
- -A ufw-after-input -p tcp -m tcp --dport 445 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 67 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 68 -j ufw-skip-to-policy-input
- -A ufw-after-input -m addrtype --dst-type BROADCAST -j ufw-skip-to-policy-input
- -A ufw-after-logging-input -m limit --limit 3/min --limit-burst 10 -j LOG --log-prefix "[UFW BLOCK] "
- -A ufw-before-forward -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 3 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 4 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 11 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 12 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A ufw-before-forward -j ufw-user-forward
- -A ufw-before-input -i lo -j ACCEPT
- -A ufw-before-input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A ufw-before-input -m conntrack --ctstate INVALID -j ufw-logging-deny
- -A ufw-before-input -m conntrack --ctstate INVALID -j DROP
- -A ufw-before-input -p icmp -m icmp --icmp-type 3 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 4 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 11 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 12 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A ufw-before-input -p udp -m udp --sport 67 --dport 68 -j ACCEPT
- -A ufw-before-input -j ufw-not-local
- -A ufw-before-input -d 224.0.0.251/32 -p udp -m udp --dport 5353 -j ACCEPT
- -A ufw-before-input -d 239.255.255.250/32 -p udp -m udp --dport 1900 -j ACCEPT
- -A ufw-before-input -j ufw-user-input
- -A ufw-before-output -o lo -j ACCEPT
- -A ufw-before-output -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A ufw-before-output -j ufw-user-output
- -A ufw-logging-allow -m limit --limit 3/min --limit-burst 10 -j LOG --log-prefix "[UFW ALLOW] "
- -A ufw-logging-deny -m conntrack --ctstate INVALID -m limit --limit 3/min --limit-burst 10 -j RETURN
- -A ufw-logging-deny -m limit --limit 3/min --limit-burst 10 -j LOG --log-prefix "[UFW BLOCK] "
- -A ufw-not-local -m addrtype --dst-type LOCAL -j RETURN
- -A ufw-not-local -m addrtype --dst-type MULTICAST -j RETURN
- -A ufw-not-local -m addrtype --dst-type BROADCAST -j RETURN
- -A ufw-not-local -m limit --limit 3/min --limit-burst 10 -j ufw-logging-deny
- -A ufw-not-local -j DROP
- -A ufw-skip-to-policy-forward -j ACCEPT
- -A ufw-skip-to-policy-input -j DROP
- -A ufw-skip-to-policy-output -j ACCEPT
- -A ufw-track-forward -p tcp -m conntrack --ctstate NEW -j ACCEPT
- -A ufw-track-forward -p udp -m conntrack --ctstate NEW -j ACCEPT
- -A ufw-track-output -p tcp -m conntrack --ctstate NEW -j ACCEPT
- -A ufw-track-output -p udp -m conntrack --ctstate NEW -j ACCEPT
- -A ufw-user-input -i bond0 -p tcp -m multiport --dports 11001:11030 -j DROP
- -A ufw-user-input -i bond0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A ufw-user-input -s 10.0.0.0/8 -j ACCEPT
- -A ufw-user-input -i bond0 -p tcp -m tcp --dport 4506 -j ACCEPT
- -A ufw-user-input -i bond0 -p tcp -m tcp --dport 4505 -j ACCEPT
- -A ufw-user-input -i bond0 -p tcp -m tcp --dport 1194 -j ACCEPT
- -A ufw-user-input -i bond0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A ufw-user-input -i bond0 -j DROP
- -A ufw-user-input -j ACCEPT
- -A ufw-user-limit -m limit --limit 3/min -j LOG --log-prefix "[UFW LIMIT BLOCK] "
- -A ufw-user-limit -j REJECT --reject-with icmp-port-unreachable
- -A ufw-user-limit-accept -j ACCEPT
- COMMIT
- # Completed on Sat Jun 4 14:26:58 2016
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement