Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ubnt@AFi-R-HD-02086D:/usr/sbin# iptables -L
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- input_rule all -- anywhere anywhere ID:66773300 /* user chain for input */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate RELATED,ESTABLISHED
- DROP all -- anywhere anywhere ID:66773300 ctstate INVALID
- syn_flood tcp -- anywhere anywhere ID:66773300 tcp flags:FIN,SYN,RST,ACK/SYN
- zone_lan_input all -- anywhere anywhere ID:66773300
- zone_guest_input all -- anywhere anywhere ID:66773300
- zone_guest_input all -- anywhere anywhere ID:66773300
- zone_guest_input all -- anywhere anywhere ID:66773300
- zone_wan_input all -- anywhere anywhere ID:66773300
- Chain FORWARD (policy DROP)
- target prot opt source destination
- forwarding_rule all -- anywhere anywhere ID:66773300 /* user chain for forwarding */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate RELATED,ESTABLISHED
- DROP all -- anywhere anywhere ID:66773300 ctstate INVALID
- zone_lan_forward all -- anywhere anywhere ID:66773300
- zone_guest_forward all -- anywhere anywhere ID:66773300
- zone_guest_forward all -- anywhere anywhere ID:66773300
- zone_guest_forward all -- anywhere anywhere ID:66773300
- zone_wan_forward all -- anywhere anywhere ID:66773300
- reject all -- anywhere anywhere ID:66773300
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- output_rule all -- anywhere anywhere ID:66773300 /* user chain for output */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate RELATED,ESTABLISHED
- DROP all -- anywhere anywhere ID:66773300 ctstate INVALID
- zone_lan_output all -- anywhere anywhere ID:66773300
- zone_guest_output all -- anywhere anywhere ID:66773300
- zone_guest_output all -- anywhere anywhere ID:66773300
- zone_guest_output all -- anywhere anywhere ID:66773300
- zone_wan_output all -- anywhere anywhere ID:66773300
- Chain MINIUPNPD (1 references)
- target prot opt source destination
- Chain forwarding_guest_rule (1 references)
- target prot opt source destination
- Chain forwarding_lan_rule (1 references)
- target prot opt source destination
- Chain forwarding_rule (1 references)
- target prot opt source destination
- Chain forwarding_wan_rule (1 references)
- target prot opt source destination
- Chain input_guest_rule (1 references)
- target prot opt source destination
- Chain input_lan_rule (1 references)
- target prot opt source destination
- Chain input_rule (1 references)
- target prot opt source destination
- Chain input_wan_rule (1 references)
- target prot opt source destination
- Chain output_guest_rule (1 references)
- target prot opt source destination
- Chain output_lan_rule (1 references)
- target prot opt source destination
- Chain output_rule (1 references)
- target prot opt source destination
- Chain output_wan_rule (1 references)
- target prot opt source destination
- Chain reject (6 references)
- target prot opt source destination
- REJECT tcp -- anywhere anywhere ID:66773300 reject-with tcp-reset
- REJECT all -- anywhere anywhere ID:66773300 reject-with icmp-port-unreachable
- Chain syn_flood (1 references)
- target prot opt source destination
- RETURN tcp -- anywhere anywhere ID:66773300 tcp flags:FIN,SYN,RST,ACK/SYN limit: avg 25/sec burst 50
- DROP all -- anywhere anywhere ID:66773300
- Chain zone_guest_dest_ACCEPT (2 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- ACCEPT all -- anywhere anywhere ID:66773300
- ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_guest_forward (3 references)
- target prot opt source destination
- forwarding_guest_rule all -- anywhere anywhere ID:66773300 /* user chain for forwarding */
- zone_wan_dest_ACCEPT all -- anywhere anywhere ID:66773300 /* forwarding guest -> wan */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port forwards */
- zone_guest_dest_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_guest_input (3 references)
- target prot opt source destination
- input_guest_rule all -- anywhere anywhere ID:66773300 /* user chain for input */
- ACCEPT tcp -- anywhere anywhere ID:66773300 tcp dpt:domain /* Allow guest dns */
- ACCEPT udp -- anywhere anywhere ID:66773300 udp dpt:domain /* Allow guest dns */
- ACCEPT udp -- anywhere anywhere ID:66773300 udp dpt:bootps /* Allow guest dhcp */
- ACCEPT udp -- anywhere anywhere ID:66773300 udp dpt:bootpc /* Allow guest dhcp */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port redirections */
- zone_guest_src_REJECT all -- anywhere anywhere ID:66773300
- Chain zone_guest_output (3 references)
- target prot opt source destination
- output_guest_rule all -- anywhere anywhere ID:66773300 /* user chain for output */
- zone_guest_dest_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_guest_src_REJECT (1 references)
- target prot opt source destination
- reject all -- anywhere anywhere ID:66773300
- reject all -- anywhere anywhere ID:66773300
- reject all -- anywhere anywhere ID:66773300
- Chain zone_lan_dest_ACCEPT (4 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_lan_forward (1 references)
- target prot opt source destination
- MINIUPNPD all -- anywhere anywhere
- forwarding_lan_rule all -- anywhere anywhere ID:66773300 /* user chain for forwarding */
- zone_wan_dest_ACCEPT all -- anywhere anywhere ID:66773300 /* forwarding lan -> wan */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port forwards */
- zone_lan_dest_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_lan_input (1 references)
- target prot opt source destination
- input_lan_rule all -- anywhere anywhere ID:66773300 /* user chain for input */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port redirections */
- zone_lan_src_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_lan_output (1 references)
- target prot opt source destination
- output_lan_rule all -- anywhere anywhere ID:66773300 /* user chain for output */
- zone_lan_dest_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_lan_src_ACCEPT (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_wan_dest_ACCEPT (3 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_wan_dest_REJECT (1 references)
- target prot opt source destination
- reject all -- anywhere anywhere ID:66773300
- Chain zone_wan_forward (1 references)
- target prot opt source destination
- forwarding_wan_rule all -- anywhere anywhere ID:66773300 /* user chain for forwarding */
- zone_lan_dest_ACCEPT esp -- anywhere anywhere ID:66773300 /* @rule[9] */
- zone_lan_dest_ACCEPT udp -- anywhere anywhere ID:66773300 udp dpt:isakmp /* @rule[10] */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port forwards */
- zone_wan_dest_REJECT all -- anywhere anywhere ID:66773300
- Chain zone_wan_input (1 references)
- target prot opt source destination
- input_wan_rule all -- anywhere anywhere ID:66773300 /* user chain for input */
- ACCEPT udp -- anywhere anywhere ID:66773300 udp dpt:bootpc /* Allow-DHCP-Renew */
- ACCEPT icmp -- anywhere anywhere ID:66773300 icmp echo-request /* Allow-Ping */
- ACCEPT igmp -- anywhere anywhere ID:66773300 /* Allow-IGMP */
- ACCEPT all -- anywhere anywhere ID:66773300 ctstate DNAT /* Accept port redirections */
- zone_wan_src_REJECT all -- anywhere anywhere ID:66773300
- Chain zone_wan_output (1 references)
- target prot opt source destination
- output_wan_rule all -- anywhere anywhere ID:66773300 /* user chain for output */
- zone_wan_dest_ACCEPT all -- anywhere anywhere ID:66773300
- Chain zone_wan_src_REJECT (1 references)
- target prot opt source destination
- reject all -- anywhere anywhere ID:66773300
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement