Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:33:01 2014
- *nat
- :PREROUTING ACCEPT [1262:196882]
- :INPUT ACCEPT [64:17328]
- :OUTPUT ACCEPT [286:34349]
- :POSTROUTING ACCEPT [1:60]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_internal - [0:0]
- :POST_internal_allow - [0:0]
- :POST_internal_deny - [0:0]
- :POST_internal_log - [0:0]
- :POST_public - [0:0]
- :POST_public_allow - [0:0]
- :POST_public_deny - [0:0]
- :POST_public_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- [17264:3046235] -A PREROUTING -j PREROUTING_direct
- [17262:3045895] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [17262:3045895] -A PREROUTING -j PREROUTING_ZONES
- [3044:463500] -A OUTPUT -j OUTPUT_direct
- [28:1633] -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j SNAT --to-source 23.92.76.239
- [3044:463500] -A POSTROUTING -j POSTROUTING_direct
- [3044:463500] -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- [3044:463500] -A POSTROUTING -j POSTROUTING_ZONES
- [3002:453189] -A POSTROUTING_ZONES -o eth0 -g POST_public
- [0:0] -A POSTROUTING_ZONES -o tun0 -g POST_internal
- [9:698] -A POSTROUTING_ZONES -g POST_public
- [0:0] -A POST_internal -j POST_internal_log
- [0:0] -A POST_internal -j POST_internal_deny
- [0:0] -A POST_internal -j POST_internal_allow
- [3011:453887] -A POST_public -j POST_public_log
- [3011:453887] -A POST_public -j POST_public_deny
- [3011:453887] -A POST_public -j POST_public_allow
- [285:34289] -A POST_public_allow ! -i lo -j MASQUERADE
- [16504:2866330] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [305:19912] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [0:0] -A PREROUTING_ZONES -g PRE_public
- [305:19912] -A PRE_internal -j PRE_internal_log
- [305:19912] -A PRE_internal -j PRE_internal_deny
- [305:19912] -A PRE_internal -j PRE_internal_allow
- [16504:2866330] -A PRE_public -j PRE_public_log
- [16504:2866330] -A PRE_public -j PRE_public_deny
- [16504:2866330] -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Nov 27 18:33:01 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:33:01 2014
- *mangle
- :PREROUTING ACCEPT [62542:28247591]
- :INPUT ACCEPT [62045:28165024]
- :FORWARD ACCEPT [494:82377]
- :OUTPUT ACCEPT [62520:34948561]
- :POSTROUTING ACCEPT [62737:35012659]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- [63359:28508453] -A PREROUTING -j PREROUTING_direct
- [63354:28506537] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [63345:28498849] -A PREROUTING -j PREROUTING_ZONES
- [62845:28414647] -A INPUT -j INPUT_direct
- [494:82377] -A FORWARD -j FORWARD_direct
- [63357:35495765] -A OUTPUT -j OUTPUT_direct
- [63579:35561218] -A POSTROUTING -j POSTROUTING_direct
- [62087:28195727] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [409:36362] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [88:29909] -A PREROUTING_ZONES -g PRE_public
- [409:36362] -A PRE_internal -j PRE_internal_log
- [409:36362] -A PRE_internal -j PRE_internal_deny
- [409:36362] -A PRE_internal -j PRE_internal_allow
- [62175:28225636] -A PRE_public -j PRE_public_log
- [62175:28225636] -A PRE_public -j PRE_public_deny
- [62175:28225636] -A PRE_public -j PRE_public_allow
- COMMIT
- # Completed on Thu Nov 27 18:33:01 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:33:01 2014
- *security
- :INPUT ACCEPT [45821:25876296]
- :FORWARD ACCEPT [218:64138]
- :OUTPUT ACCEPT [63384:35508180]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- [45832:25886304] -A INPUT -j INPUT_direct
- [218:64138] -A FORWARD -j FORWARD_direct
- [63389:35509629] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:33:01 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:33:01 2014
- *raw
- :PREROUTING ACCEPT [63385:28523218]
- :OUTPUT ACCEPT [63397:35514454]
- :OUTPUT_direct - [0:0]
- :PREROUTING_direct - [0:0]
- [63391:28528004] -A PREROUTING -j PREROUTING_direct
- [63397:35514454] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:33:01 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:33:01 2014
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [5878:3558558]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_internal - [0:0]
- :FWDI_internal_allow - [0:0]
- :FWDI_internal_deny - [0:0]
- :FWDI_internal_log - [0:0]
- :FWDI_public - [0:0]
- :FWDI_public_allow - [0:0]
- :FWDI_public_deny - [0:0]
- :FWDI_public_log - [0:0]
- :FWDO_internal - [0:0]
- :FWDO_internal_allow - [0:0]
- :FWDO_internal_deny - [0:0]
- :FWDO_internal_log - [0:0]
- :FWDO_public - [0:0]
- :FWDO_public_allow - [0:0]
- :FWDO_public_deny - [0:0]
- :FWDO_public_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_internal - [0:0]
- :IN_internal_allow - [0:0]
- :IN_internal_deny - [0:0]
- :IN_internal_log - [0:0]
- :IN_public - [0:0]
- :IN_public_allow - [0:0]
- :IN_public_deny - [0:0]
- :IN_public_log - [0:0]
- :OUTPUT_direct - [0:0]
- [44701:25448510] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [9:698] -A INPUT -i lo -j ACCEPT
- [18286:3112054] -A INPUT -j INPUT_direct
- [18286:3112054] -A INPUT -j INPUT_ZONES_SOURCE
- [18286:3112054] -A INPUT -j INPUT_ZONES
- [12:988] -A INPUT -p icmp -j ACCEPT
- [17077:2557849] -A INPUT -j REJECT --reject-with icmp-host-prohibited
- [157:59857] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -i lo -j ACCEPT
- [338:22560] -A FORWARD -j FORWARD_direct
- [338:22560] -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- [338:22560] -A FORWARD -j FORWARD_IN_ZONES
- [338:22560] -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- [338:22560] -A FORWARD -j FORWARD_OUT_ZONES
- [0:0] -A FORWARD -p icmp -j ACCEPT
- [277:18279] -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- [63414:35520489] -A OUTPUT -j OUTPUT_direct
- [0:0] -A FORWARD_IN_ZONES -i eth0 -g FWDI_public
- [338:22560] -A FORWARD_IN_ZONES -i tun0 -g FWDI_internal
- [0:0] -A FORWARD_IN_ZONES -g FWDI_public
- [338:22560] -A FORWARD_OUT_ZONES -o eth0 -g FWDO_public
- [0:0] -A FORWARD_OUT_ZONES -o tun0 -g FWDO_internal
- [0:0] -A FORWARD_OUT_ZONES -g FWDO_public
- [338:22560] -A FWDI_internal -j FWDI_internal_log
- [338:22560] -A FWDI_internal -j FWDI_internal_deny
- [338:22560] -A FWDI_internal -j FWDI_internal_allow
- [0:0] -A FWDI_public -j FWDI_public_log
- [0:0] -A FWDI_public -j FWDI_public_deny
- [0:0] -A FWDI_public -j FWDI_public_allow
- [0:0] -A FWDO_internal -j FWDO_internal_log
- [0:0] -A FWDO_internal -j FWDO_internal_deny
- [0:0] -A FWDO_internal -j FWDO_internal_allow
- [338:22560] -A FWDO_public -j FWDO_public_log
- [338:22560] -A FWDO_public -j FWDO_public_deny
- [338:22560] -A FWDO_public -j FWDO_public_allow
- [61:4281] -A FWDO_public_allow -j ACCEPT
- [17744:2945084] -A INPUT_ZONES -i eth0 -g IN_public
- [0:0] -A INPUT_ZONES -i tun0 -g IN_internal
- [0:0] -A INPUT_ZONES -g IN_public
- [0:0] -A IN_internal -j IN_internal_log
- [0:0] -A IN_internal -j IN_internal_deny
- [0:0] -A IN_internal -j IN_internal_allow
- [0:0] -A IN_internal_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [17744:2945084] -A IN_public -j IN_public_log
- [17744:2945084] -A IN_public -j IN_public_deny
- [17744:2945084] -A IN_public -j IN_public_allow
- [0:0] -A IN_public_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [20:1160] -A IN_public_allow -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT
- [32:1540] -A IN_public_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [1131:549030] -A IN_public_allow -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
- [2:84] -A IN_public_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_public_allow -p tcp -m tcp --dport 6379 -m conntrack --ctstate NEW -j ACCEPT
- [9:468] -A IN_public_allow -p tcp -m tcp --dport 8887 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
- # Completed on Thu Nov 27 18:33:01 2014
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement