Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -P INPUT DROP
- -P FORWARD DROP
- -P OUTPUT ACCEPT
- -N fail2ban-dovecot
- -N fail2ban-postfix
- -N fail2ban-roundcube
- -N fail2ban-ssh
- -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-postfix
- -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-dovecot
- -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,4190 -j fail2ban-roundcube
- -A INPUT -p tcp -m tcp --dport 22 -j fail2ban-ssh
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 587 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 110 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 995 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 143 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 993 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -p udp -m udp --dport 1194 -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 10.0.2.0/25 -i tun0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 10.0.2.0/25 -d 10.0.0.0/24 -i tun0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 10.0.2.0/25 -d 192.168.2.0/24 -i tun0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i dns0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i dns1 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 172.16.0.0/27 -d 10.0.0.0/24 -i dns0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 172.16.2.0/27 -d 10.0.0.0/24 -i dns1 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 172.16.0.0/27 -d 192.168.2.0/24 -i dns0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 172.16.2.0/27 -d 192.168.2.0/24 -i dns1 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 53 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 8080 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o wlan0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o wlan0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 5060:5080 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 65535 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 5228 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 5228 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 14259 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 14259 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 80 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 6969 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 1337 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 465 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 587 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 7070 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 1338 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 6667 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 6697 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 2000 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 1843 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 843 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m udp --dport 1194 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 3478:3487 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p tcp -m tcp --dport 5223 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 16384:16387 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p udp -m multiport --dports 16393:16402 -j ACCEPT
- -A FORWARD -i wlan0 -o eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 53 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 53 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 8080 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 8080 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o dns0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o dns0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o dns1 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o dns1 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 5060:5080 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 65535 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 5060:5080 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 65535 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 5228 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 5228 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 14259 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 14259 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 5228 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 5228 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 14259 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 14259 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 80 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 6969 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 1337 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 80 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 6969 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 1337 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i dns1 -o eth -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 465 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 465 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 587 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 587 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 7070 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 1338 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 6667 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 6697 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 7070 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 1338 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 6667 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 6697 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 2000 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 1843 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 843 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 2000 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 1843 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 843 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m udp --dport 1194 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m udp --dport 1194 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 3478:3487 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p tcp -m tcp --dport 5223 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 16384:16387 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p udp -m multiport --dports 16393:16402 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 3478:3487 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p tcp -m tcp --dport 5223 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 16384:16387 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p udp -m multiport --dports 16393:16402 -j ACCEPT
- -A FORWARD -i dns0 -o eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A FORWARD -i dns1 -o eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 53 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 8080 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o tun0 -p udp -m udp --dport 29304 -j ACCEPT
- -A FORWARD -i eth0 -o tun0 -p tcp -m tcp --dport 29304 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 6783:6785 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 5060:5080 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 65535 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m multiport --dports 19305:19309 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 5228 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 5228 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 14259 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 14259 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 80 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 6969 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 1337 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 465 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 587 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m multiport --dports 993:995 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 7070 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 1338 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 6667 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 6697 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 2000 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 1843 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 843 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m udp --dport 1194 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 3478:3487 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p tcp -m tcp --dport 5223 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 16384:16387 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p udp -m multiport --dports 16393:16402 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A fail2ban-dovecot -j RETURN
- -A fail2ban-postfix -j RETURN
- -A fail2ban-roundcube -j RETURN
- -A fail2ban-ssh -j RETURN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement