Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- pdc:~ # iptables -L
- Chain INPUT (policy DROP)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- input_int all -- anywhere anywhere
- input_ext all -- anywhere anywhere
- input_ext all -- anywhere anywhere
- input_ext all -- anywhere anywhere
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-IN-ILL-TARGET '
- DROP all -- anywhere anywhere
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
- forward_int all -- anywhere anywhere
- forward_ext all -- anywhere anywhere
- forward_ext all -- anywhere anywhere
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWD-ILL-ROUTING '
- DROP all -- anywhere anywhere
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-OUT-ERROR '
- Chain forward_ext (2 references)
- target prot opt source destination
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp echo-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp destination-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp time-exceeded
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp parameter-problem
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp timestamp-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp address-mask-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp protocol-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp redirect
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:smtp state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDext-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:smtp
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere 192.168.10.5 limit: avg 3/min burst 5 tcp dpt:d2k-tapestry2 state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDext-ACC-REVMASQ '
- ACCEPT tcp -- anywhere 192.168.10.5 tcp dpt:d2k-tapestry2
- ACCEPT tcp -- 192.168.10.5 anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere 192.168.10.83 limit: avg 3/min burst 5 tcp dpt:dyna-lm state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDext-ACC-REVMASQ '
- ACCEPT tcp -- anywhere 192.168.10.83 tcp dpt:dyna-lm
- ACCEPT tcp -- 192.168.10.83 anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:pptp state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDext-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:pptp
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:http state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDext-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:http
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2-FWDext-DROP-DEFLT '
- DROP all -- anywhere anywhere PKTTYPE = multicast
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-FWDext-DROP-DEFLT '
- LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDext-DROP-DEFLT '
- LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDext-DROP-DEFLT '
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-FWDext-DROP-DEFLT-INV '
- DROP all -- anywhere anywhere
- Chain forward_int (1 references)
- target prot opt source destination
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp echo-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp destination-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp time-exceeded
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp parameter-problem
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp timestamp-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp address-mask-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp protocol-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp redirect
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:smtp state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDint-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:smtp
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere 192.168.10.5 limit: avg 3/min burst 5 tcp dpt:d2k-tapestry2 state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDint-ACC-REVMASQ '
- ACCEPT tcp -- anywhere 192.168.10.5 tcp dpt:d2k-tapestry2
- ACCEPT tcp -- 192.168.10.5 anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere 192.168.10.83 limit: avg 3/min burst 5 tcp dpt:dyna-lm state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDint-ACC-REVMASQ '
- ACCEPT tcp -- anywhere 192.168.10.83 tcp dpt:dyna-lm
- ACCEPT tcp -- 192.168.10.83 anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:pptp state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDint-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:pptp
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG tcp -- anywhere ext_domain_name limit: avg 3/min burst 5 tcp dpt:http state NEW LOG level warning tcp-options ip-options prefix `SFW2-FWDint-ACC-REVMASQ '
- ACCEPT tcp -- anywhere ext_domain_name tcp dpt:http
- ACCEPT tcp -- ext_domain_name anywhere state RELATED,ESTABLISHED
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
- DROP all -- anywhere anywhere PKTTYPE = multicast
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
- LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
- LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT-INV '
- DROP all -- anywhere anywhere
- Chain input_ext (3 references)
- target prot opt source destination
- DROP all -- anywhere anywhere PKTTYPE = broadcast
- ACCEPT icmp -- anywhere anywhere icmp source-quench
- ACCEPT icmp -- anywhere anywhere icmp echo-request
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp echo-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp destination-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp time-exceeded
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp parameter-problem
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp timestamp-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp address-mask-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp protocol-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp redirect
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:d2k-tapestry2 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:d2k-tapestry2
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:dyna-lm flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:dyna-lm
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:wwiotalk flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:wwiotalk
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:http flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:http
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:smtp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:smtp
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:ssh flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:ssh
- ACCEPT udp -- anywhere anywhere udp dpt:wwiotalk
- reject_func tcp -- anywhere anywhere tcp dpt:ident state NEW
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- DROP all -- anywhere anywhere PKTTYPE = multicast
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT-INV '
- DROP all -- anywhere anywhere
- Chain input_int (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- Chain reject_func (1 references)
- target prot opt source destination
- REJECT tcp -- anywhere anywhere reject-with tcp-reset
- REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
- REJECT all -- anywhere anywhere reject-with icmp-proto-unreachable
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement