Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@deor:/etc/firehol# iptables -L
- Chain INPUT (policy DROP)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- in_world all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'IN-unknown:''
- DROP all -- anywhere anywhere
- Chain FORWARD (policy DROP)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere state RELATED
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'PASS-unknown:''
- DROP all -- anywhere anywhere
- Chain OUTPUT (policy DROP)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- out_world all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'OUT-unknown:''
- DROP all -- anywhere anywhere
- Chain in_world (1 references)
- target prot opt source destination
- pr_world_fragments all -f anywhere anywhere
- pr_world_nosyn tcp -- anywhere anywhere state NEW tcp flags:!FIN,SYN,RST,ACK/SYN
- pr_world_icmpflood icmp -- anywhere anywhere icmp echo-request
- pr_world_synflood tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN
- pr_world_malxmas tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,PSH,ACK,URG
- pr_world_malnull tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE
- pr_world_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN
- pr_world_malbad tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST
- pr_world_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,ACK,URG
- pr_world_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,PSH,URG
- DROP all -- anywhere anywhere state INVALID
- in_world_all_c1 all -- anywhere anywhere
- in_world_irc_c2 all -- anywhere anywhere
- in_world_ftp_c3 all -- anywhere anywhere
- in_world_ssh_s4 all -- anywhere anywhere
- in_world_http_s5 all -- anywhere anywhere
- in_world_minecraft_s6 all -- anywhere anywhere
- in_world_mcadmin_s7 all -- anywhere anywhere
- in_world_ts3_s8 all -- anywhere anywhere
- in_world_ts3ft_s9 all -- anywhere anywhere
- in_world_ts3sq_s10 all -- anywhere anywhere
- in_world_pptp_s11 all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `''IN-world':''
- DROP all -- anywhere anywhere
- Chain in_world_all_c1 (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere state ESTABLISHED
- Chain in_world_ftp_c3 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:ftp dpts:32768:61000 state ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spt:ftp-data dpts:32768:61000 state RELATED,ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:32768:61000 state ESTABLISHED
- Chain in_world_http_s5 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:www state NEW,ESTABLISHED
- Chain in_world_irc_c2 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:ircd dpts:32768:61000 state ESTABLISHED
- Chain in_world_mcadmin_s7 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:http-alt state NEW,ESTABLISHED
- Chain in_world_minecraft_s6 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:25565 state NEW,ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spt:25565 dpt:25565 state NEW,ESTABLISHED
- ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpt:25565 state NEW,ESTABLISHED
- ACCEPT udp -- anywhere anywhere udp spt:25565 dpt:25565 state NEW,ESTABLISHED
- Chain in_world_pptp_s11 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:1723 state NEW,ESTABLISHED
- ACCEPT gre -- anywhere anywhere
- Chain in_world_ssh_s4 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ssh state NEW,ESTABLISHED
- Chain in_world_ts3_s8 (1 references)
- target prot opt source destination
- ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpts:9987:9988 state NEW,ESTABLISHED
- Chain in_world_ts3ft_s9 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:30033 state NEW,ESTABLISHED
- Chain in_world_ts3sq_s10 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:10011 state NEW,ESTABLISHED
- Chain out_world (1 references)
- target prot opt source destination
- out_world_all_c1 all -- anywhere anywhere
- out_world_irc_c2 all -- anywhere anywhere
- out_world_ftp_c3 all -- anywhere anywhere
- out_world_ssh_s4 all -- anywhere anywhere
- out_world_http_s5 all -- anywhere anywhere
- out_world_minecraft_s6 all -- anywhere anywhere
- out_world_mcadmin_s7 all -- anywhere anywhere
- out_world_ts3_s8 all -- anywhere anywhere
- out_world_ts3ft_s9 all -- anywhere anywhere
- out_world_ts3sq_s10 all -- anywhere anywhere
- out_world_pptp_s11 all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `''OUT-world':''
- DROP all -- anywhere anywhere
- Chain out_world_all_c1 (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere state NEW,ESTABLISHED
- Chain out_world_ftp_c3 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ftp state NEW,ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ftp-data state ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpts:1024:65535 state RELATED,ESTABLISHED
- Chain out_world_http_s5 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:www dpts:1024:65535 state ESTABLISHED
- Chain out_world_irc_c2 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ircd state NEW,ESTABLISHED
- Chain out_world_mcadmin_s7 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:http-alt dpts:1024:65535 state ESTABLISHED
- Chain out_world_minecraft_s6 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:25565 dpts:1024:65535 state ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spt:25565 dpt:25565 state ESTABLISHED
- ACCEPT udp -- anywhere anywhere udp spt:25565 dpts:1024:65535 state ESTABLISHED
- ACCEPT udp -- anywhere anywhere udp spt:25565 dpt:25565 state ESTABLISHED
- Chain out_world_pptp_s11 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:1723 dpts:1024:65535 state ESTABLISHED
- ACCEPT gre -- anywhere anywhere
- Chain out_world_ssh_s4 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:ssh dpts:1024:65535 state ESTABLISHED
- Chain out_world_ts3_s8 (1 references)
- target prot opt source destination
- ACCEPT udp -- anywhere anywhere udp spts:9987:9988 dpts:1024:65535 state ESTABLISHED
- Chain out_world_ts3ft_s9 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:30033 dpts:1024:65535 state ESTABLISHED
- Chain out_world_ts3sq_s10 (1 references)
- target prot opt source destination
- ACCEPT tcp -- anywhere anywhere tcp spt:10011 dpts:1024:65535 state ESTABLISHED
- Chain pr_world_fragments (1 references)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'PACKET FRAGMENTS:''
- DROP all -- anywhere anywhere
- Chain pr_world_icmpflood (1 references)
- target prot opt source destination
- RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'ICMP FLOOD:''
- DROP all -- anywhere anywhere
- Chain pr_world_malbad (4 references)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED BAD:''
- DROP all -- anywhere anywhere
- Chain pr_world_malnull (1 references)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED NULL:''
- DROP all -- anywhere anywhere
- Chain pr_world_malxmas (1 references)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED XMAS:''
- DROP all -- anywhere anywhere
- Chain pr_world_nosyn (1 references)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'NEW TCP w/o SYN:''
- DROP all -- anywhere anywhere
- Chain pr_world_synflood (1 references)
- target prot opt source destination
- RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
- LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'SYN FLOOD:''
- DROP all -- anywhere anywhere
- root@deor:/etc/firehol# iptables -t nat -n -L
- Chain PREROUTING (policy ACCEPT)
- target prot opt source destination
- Chain POSTROUTING (policy ACCEPT)
- target prot opt source destination
- SNAT all -- 0.0.0.0/0 0.0.0.0/0 to:11.22.33.44
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- root@deor:/etc/firehol#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement