Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.21 on Tue Apr 26 11:03:25 2016
- *mangle
- :PREROUTING ACCEPT [1147859:702009071]
- :INPUT ACCEPT [43517:8752924]
- :FORWARD ACCEPT [1103788:693068380]
- :OUTPUT ACCEPT [42851:5481746]
- :POSTROUTING ACCEPT [1146112:698518562]
- :NAT_DESTINATION - [0:0]
- [27388545:18692468907] -A PREROUTING -j NAT_DESTINATION
- ....
- [237:14164] -A NAT_DESTINATION -s 192.168.5.0/24 -d EXT_IP/32 -p tcp -m tcp --dport 6000 -j MARK --set-xmark 0x1/0xffffffff
- [0:0] -A NAT_DESTINATION -s 10.10.20.0/24 -d EXT_IP/32 -p tcp -m tcp --dport 6000 -j MARK --set-xmark 0x2/0xffffffff
- [0:0] -A NAT_DESTINATION -s 172.16.10.0/24 -d EXT_IP/32 -p tcp -m tcp --dport 6000 -j MARK --set-xmark 0x3/0xffffffff
- ....
- COMMIT
- # Completed on Tue Apr 26 11:03:25 2016
- # Generated by iptables-save v1.4.21 on Tue Apr 26 11:03:25 2016
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- :BADTCP - [0:0]
- :CONNTRACK - [0:0]
- :CUSTOMFORWARD - [0:0]
- :CUSTOMINPUT - [0:0]
- :CUSTOMOUTPUT - [0:0]
- :DHCPBLUEINPUT - [0:0]
- :DHCPBLUEOUTPUT - [0:0]
- :DHCPGREENINPUT - [0:0]
- :DHCPGREENOUTPUT - [0:0]
- :DHCPINPUT - [0:0]
- :DHCPOUTPUT - [0:0]
- :FORWARDFW - [0:0]
- :GEOIPBLOCK - [0:0]
- :GUARDIAN - [0:0]
- :GUIINPUT - [0:0]
- :ICMPINPUT - [0:0]
- :INPUTFW - [0:0]
- :IPSECBLOCK - [0:0]
- :IPSECFORWARD - [0:0]
- :IPSECINPUT - [0:0]
- :IPSECOUTPUT - [0:0]
- :IPTVFORWARD - [0:0]
- :IPTVINPUT - [0:0]
- :LOG_DROP - [0:0]
- :LOG_REJECT - [0:0]
- :LOOPBACK - [0:0]
- :NEWNOTSYN - [0:0]
- :OUTGOINGFW - [0:0]
- :OVPNBLOCK - [0:0]
- :OVPNINPUT - [0:0]
- :P2PBLOCK - [0:0]
- :POLICYFWD - [0:0]
- :POLICYIN - [0:0]
- :POLICYOUT - [0:0]
- :PSCAN - [0:0]
- :REDFORWARD - [0:0]
- :REDINPUT - [0:0]
- :TOR_INPUT - [0:0]
- :UPNPFW - [0:0]
- :WIRELESSFORWARD - [0:0]
- :WIRELESSINPUT - [0:0]
- [924652:283049825] -A INPUT -p tcp -j BADTCP
- [1797061:854638094] -A INPUT -j CUSTOMINPUT
- [1797061:854638094] -A INPUT -j P2PBLOCK
- [1797061:854638094] -A INPUT -j GUARDIAN
- [0:0] -A INPUT -i tun+ -j OVPNBLOCK
- [1797061:854638094] -A INPUT -j IPTVINPUT
- [1797061:854638094] -A INPUT -j ICMPINPUT
- [1794329:854363932] -A INPUT -j LOOPBACK
- [1791810:854108985] -A INPUT -j CONNTRACK
- [117095:9133935] -A INPUT -j GEOIPBLOCK
- [117095:9133935] -A INPUT -j IPSECINPUT
- [117069:9129015] -A INPUT -j GUIINPUT
- [117069:9129015] -A INPUT -m conntrack --ctstate NEW -j WIRELESSINPUT
- [116556:9095271] -A INPUT -j OVPNINPUT
- [116550:9094943] -A INPUT -j TOR_INPUT
- [116550:9094943] -A INPUT -j INPUTFW
- [116550:9094943] -A INPUT -j REDINPUT
- [116550:9094943] -A INPUT -j POLICYIN
- [83:4017] -A FORWARD -d 10.5.1.29/32 -j ACCEPT
- [88:21680] -A FORWARD -s 10.5.1.29/32 -j ACCEPT
- [0:0] -A FORWARD -d 10.10.20.0/24 -j ACCEPT
- [0:0] -A FORWARD -s 10.10.20.0/24 -j ACCEPT
- [5081:293317] -A FORWARD -d 192.168.80.99/32 -j ACCEPT
- [15874:855894] -A FORWARD -d 192.168.80.98/32 -j ACCEPT
- [4096:244737] -A FORWARD -s 192.168.80.99/32 -j ACCEPT
- [15381:4717024] -A FORWARD -s 192.168.80.98/32 -j ACCEPT
- [22545772:16630556002] -A FORWARD -p tcp -j BADTCP
- [1232892:71919592] -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- [24025978:17226142777] -A FORWARD -j CUSTOMFORWARD
- [24025978:17226142777] -A FORWARD -j P2PBLOCK
- [24025978:17226142777] -A FORWARD -j GUARDIAN
- [24025978:17226142777] -A FORWARD -m policy --dir out --pol none -j IPSECBLOCK
- [304633:21370826] -A FORWARD -i tun+ -j OVPNBLOCK
- [277768:180074627] -A FORWARD -o tun+ -j OVPNBLOCK
- [24025976:17226142595] -A FORWARD -j IPTVFORWARD
- [24025976:17226142595] -A FORWARD -j LOOPBACK
- [24025976:17226142595] -A FORWARD -j CONNTRACK
- [674885:45234435] -A FORWARD -j GEOIPBLOCK
- [674885:45234435] -A FORWARD -j IPSECFORWARD
- [674885:45234435] -A FORWARD -m conntrack --ctstate NEW -j WIRELESSFORWARD
- [674885:45234435] -A FORWARD -j FORWARDFW
- [665239:44531502] -A FORWARD -m conntrack --ctstate NEW -j UPNPFW
- [665239:44531502] -A FORWARD -j REDFORWARD
- [665154:44525551] -A FORWARD -j POLICYFWD
- [1711520:432627335] -A OUTPUT -j CUSTOMOUTPUT
- [1711520:432627335] -A OUTPUT -j P2PBLOCK
- [1711520:432627335] -A OUTPUT -m policy --dir out --pol none -j IPSECBLOCK
- [1711008:432584327] -A OUTPUT -j LOOPBACK
- [1699674:431498471] -A OUTPUT -j CONNTRACK
- [3880:379330] -A OUTPUT -j IPSECOUTPUT
- [3880:379330] -A OUTPUT -j OUTGOINGFW
- [3880:379330] -A OUTPUT -j POLICYOUT
- [2:100] -A BADTCP -i lo -j RETURN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j PSCAN
- [0:0] -A BADTCP -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j PSCAN
- [2295:281062] -A BADTCP -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m conntrack --ctstate NEW -j NEWNOTSYN
- [26715754:18456709871] -A CONNTRACK -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [5846:292480] -A CONNTRACK -m conntrack --ctstate INVALID -j DROP
- [0:0] -A DHCPINPUT -p udp -m udp --sport 68 --dport 67 -j ACCEPT
- [0:0] -A DHCPINPUT -p tcp -m tcp --sport 68 --dport 67 -j ACCEPT
- [0:0] -A DHCPOUTPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
- [0:0] -A DHCPOUTPUT -p tcp -m tcp --sport 67 --dport 68 -j ACCEPT
- ......................
- [0:0] -A FORWARDFW -s 192.168.5.253/32 -p tcp -m tcp --dport 6000 -j ACCEPT
- [240:14344] -A FORWARDFW -d 192.168.5.253/32 -p tcp -m tcp --dport 6000 -j ACCEPT
- .....................
- [0:0] -A LOG_DROP -m limit --limit 10/min -j LOG
- [0:0] -A LOG_DROP -j DROP
- [0:0] -A LOG_REJECT -m limit --limit 10/min -j LOG
- [0:0] -A LOG_REJECT -j REJECT --reject-with icmp-port-unreachable
- [2519:254947] -A LOOPBACK -i lo -j ACCEPT
- [11334:1085856] -A LOOPBACK -o lo -j ACCEPT
- [0:0] -A LOOPBACK -s 127.0.0.0/8 -j DROP
- [0:0] -A LOOPBACK -d 127.0.0.0/8 -j DROP
- [812:85565] -A NEWNOTSYN -m limit --limit 10/min -j LOG --log-prefix "DROP_NEWNOTSYN "
- [2295:281062] -A NEWNOTSYN -m comment --comment DROP_NEWNOTSYN -j DROP
- [0:0] -A OVPNBLOCK -p icmp -m conntrack --ctstate RELATED -j RETURN
- [6:328] -A OVPNINPUT -i red0 -p tcp -m tcp --dport 1194 -j ACCEPT
- [0:0] -A OVPNINPUT -i blue0 -p tcp -m tcp --dport 1194 -j ACCEPT
- [0:0] -A P2PBLOCK -m ipp2p --edk --dc --gnu --kazaa --bit --apple --soul --winmx --ares -j DROP
- [33803:2250572] -A POLICYFWD -s 192.168.5.0/24 -i green0 -j ACCEPT
- [1:78] -A POLICYFWD -m policy --dir in --pol ipsec -j ACCEPT
- [30:2127] -A POLICYFWD -i tun+ -j ACCEPT
- [0:0] -A POLICYFWD -s 10.10.20.0/24 -i blue0 -o red0 -j ACCEPT
- [0:0] -A POLICYFWD -s 172.16.10.0/24 -i orange0 -o red0 -j ACCEPT
- [0:0] -A POLICYFWD -m limit --limit 10/min -j LOG --log-prefix "DROP_FORWARD "
- [0:0] -A POLICYFWD -m comment --comment DROP_FORWARD -j DROP
- [5067:403340] -A POLICYIN -i green0 -j ACCEPT
- [0:0] -A POLICYIN -m policy --dir in --pol ipsec -j ACCEPT
- [0:0] -A POLICYIN -i tun+ -j ACCEPT
- [132:10028] -A POLICYIN -m limit --limit 10/min -j LOG --log-prefix "DROP_INPUT "
- [136:10264] -A POLICYIN -m comment --comment DROP_INPUT -j DROP
- [112:10480] -A POLICYOUT -j ACCEPT
- [0:0] -A POLICYOUT -m comment --comment DROP_OUTPUT -j DROP
- [0:0] -A PSCAN -p tcp -m limit --limit 10/min -m comment --comment "DROP_TCP PScan" -j LOG --log-prefix "DROP_TCP Scan "
- [0:0] -A PSCAN -p udp -m limit --limit 10/min -m comment --comment "DROP_UDP PScan" -j LOG --log-prefix "DROP_UDP Scan "
- [0:0] -A PSCAN -p icmp -m limit --limit 10/min -m comment --comment "DROP_ICMP PScan" -j LOG --log-prefix "DROP_ICMP Scan "
- [0:0] -A PSCAN -f -m limit --limit 10/min -m comment --comment "DROP_FRAG PScan" -j LOG --log-prefix "DROP_FRAG Scan "
- [0:0] -A PSCAN -m comment --comment DROP_PScan -j DROP
- [0:0] -A REDFORWARD -i orange0 -o red0 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d EXT_IP/32 -p tcp -m tcp --dport 1194 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [73:4802] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [4:251] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [116:7703] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [318:20857] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [2:131] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- [0:0] -A WIRELESSINPUT -s 10.10.20.0/24 -d 10.10.20.1/32 -j ACCEPT
- COMMIT
- # Completed on Tue Apr 26 11:03:25 2016
- # Generated by iptables-save v1.4.21 on Tue Apr 26 11:03:25 2016
- *nat
- :PREROUTING ACCEPT [40352:2816830]
- :INPUT ACCEPT [3673:280785]
- :OUTPUT ACCEPT [118:10861]
- :POSTROUTING ACCEPT [309:18374]
- :CUSTOMPOSTROUTING - [0:0]
- :CUSTOMPREROUTING - [0:0]
- :IPSECNAT - [0:0]
- :NAT_DESTINATION - [0:0]
- :NAT_DESTINATION_FIX - [0:0]
- :NAT_SOURCE - [0:0]
- :OVPNNAT - [0:0]
- :REDNAT - [0:0]
- :SQUID - [0:0]
- :UPNPFW - [0:0]
- [832818:56380040] -A PREROUTING -j CUSTOMPREROUTING
- [832818:56380040] -A PREROUTING -j SQUID
- [832818:56380040] -A PREROUTING -j NAT_DESTINATION
- [828148:56093813] -A PREROUTING -j UPNPFW
- [0:0] -A PREROUTING -d 172.16.10.254/32 -p tcp -m tcp --dport 27017 -j DNAT --to-destination 192.168.5.237:27017
- [52:2704] -A PREROUTING -d 172.16.10.254/32 -p tcp -m tcp --dport 10051 -j DNAT --to-destination 192.168.5.232:10051
- [4374:393256] -A OUTPUT -j NAT_DESTINATION
- [3:144] -A POSTROUTING -d 10.5.1.0/24 -j SNAT --to-source 172.5.0.254
- [2568:154032] -A POSTROUTING -d 192.168.80.0/24 -j SNAT --to-source 172.16.10.254
- [675392:44682188] -A POSTROUTING -j CUSTOMPOSTROUTING
- [675392:44682188] -A POSTROUTING -j OVPNNAT
- [675392:44682188] -A POSTROUTING -j IPSECNAT
- [675392:44682188] -A POSTROUTING -j NAT_SOURCE
- [675392:44682188] -A POSTROUTING -j NAT_DESTINATION_FIX
- [675392:44682188] -A POSTROUTING -j REDNAT
- [0:0] -A REDNAT -o red0 -m mark --mark 0x32 -j RETURN
- [596955:39326218] -A REDNAT -o red0 -j MASQUERADE
- COMMIT
- # Completed on Tue Apr 26 11:03:25 2016
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement