Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@fst sysconfig]# cat /etc/sysconfig/iptables
- # Generated by iptables-save v1.4.7 on Wed Jul 17 03:27:43 2013
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [1354:358976]
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -m icmp --icmp-type 8 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp -m multiport --dports 22,80,8080,443,25,143,587,993,465 -j ACCEPT
- -A INPUT -p tcp -m tcp -m multiport --dports 25565,35565,8123 -j ACCEPT
- -A INPUT -p tcp -m tcp -m multiport --dports 10000,7070 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT
- -A INPUT -j DROP
- COMMIT
- # Completed on Wed Jul 17 03:27:43 2013
- # Generated by iptables-save v1.4.7 on Wed Jul 17 03:27:43 2013
- *mangle
- :PREROUTING ACCEPT [1419:342372]
- :INPUT ACCEPT [1415:341909]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [1354:358976]
- :POSTROUTING ACCEPT [1354:358976]
- COMMIT
- # Completed on Wed Jul 17 03:27:43 2013
- # Generated by iptables-save v1.4.7 on Wed Jul 17 03:27:43 2013
- *nat
- :PREROUTING ACCEPT [63:10062]
- :POSTROUTING ACCEPT [37:2306]
- :OUTPUT ACCEPT [37:2306]
- COMMIT
- # Completed on Wed Jul 17 03:27:43 2013
- [root@fst sysconfig]# cat /etc/sysconfig/iptables.save
- # Generated by iptables-save v1.4.7 on Tue Jul 16 02:10:33 2013
- *nat
- :PREROUTING ACCEPT [210:10758]
- :POSTROUTING ACCEPT [20:1470]
- :OUTPUT ACCEPT [20:1470]
- COMMIT
- # Completed on Tue Jul 16 02:10:33 2013
- # Generated by iptables-save v1.4.7 on Tue Jul 16 02:10:33 2013
- *mangle
- :PREROUTING ACCEPT [14630:5594148]
- :INPUT ACCEPT [14630:5594148]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [14630:5594281]
- :POSTROUTING ACCEPT [14630:5594281]
- COMMIT
- # Completed on Tue Jul 16 02:10:33 2013
- # Generated by iptables-save v1.4.7 on Tue Jul 16 02:10:33 2013
- *filter
- :FORWARD ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -p icmp -m icmp -m state --icmp-type echo-reply --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -p icmp -m icmp -m state --icmp-type echo-request --state NEW,ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -p tcp -m tcp -m multiport -j ACCEPT --dports 22,80,8080,443,25,143,587,993,465
- # minecraft
- -A INPUT -p tcp -m tcp -m multiport -j ACCEPT --dports 25565,35565,8123
- # webmin
- -A INPUT -p tcp -m tcp -m multiport -j ACCEPT --dports 10000,7070
- # mysql
- -A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT
- -A INPUT -j DROP
- COMMIT
- # Completed on Tue Jul 16 02:10:33 2013
- [root@fst sysconfig]# cat /etc/sysconfig/iptables-config
- # Load additional iptables modules (nat helpers)
- # Default: -none-
- # Space separated list of nat helpers (e.g. 'ip_nat_ftp ip_nat_irc'), which
- # are loaded after the firewall rules are applied. Options for the helpers are
- # stored in /etc/modprobe.conf.
- IPTABLES_MODULES=""
- # Unload modules on restart and stop
- # Value: yes|no, default: yes
- # This option has to be 'yes' to get to a sane state for a firewall
- # restart or stop. Only set to 'no' if there are problems unloading netfilter
- # modules.
- IPTABLES_MODULES_UNLOAD="yes"
- # Save current firewall rules on stop.
- # Value: yes|no, default: no
- # Saves all firewall rules to /etc/sysconfig/iptables if firewall gets stopped
- # (e.g. on system shutdown).
- IPTABLES_SAVE_ON_STOP="no"
- # Save current firewall rules on restart.
- # Value: yes|no, default: no
- # Saves all firewall rules to /etc/sysconfig/iptables if firewall gets
- # restarted.
- IPTABLES_SAVE_ON_RESTART="no"
- # Save (and restore) rule and chain counter.
- # Value: yes|no, default: no
- # Save counters for rules and chains to /etc/sysconfig/iptables if
- # 'service iptables save' is called or on stop or restart if SAVE_ON_STOP or
- # SAVE_ON_RESTART is enabled.
- IPTABLES_SAVE_COUNTER="no"
- # Numeric status output
- # Value: yes|no, default: yes
- # Print IP addresses and port numbers in numeric format in the status output.
- IPTABLES_STATUS_NUMERIC="yes"
- # Verbose status output
- # Value: yes|no, default: yes
- # Print info about the number of packets and bytes plus the "input-" and
- # "outputdevice" in the status output.
- IPTABLES_STATUS_VERBOSE="no"
- # Status output with numbered lines
- # Value: yes|no, default: yes
- # Print a counter/number for every rule in the status output.
- IPTABLES_STATUS_LINENUMBERS="yes"
- # Reload sysctl settings on start and restart
- # Default: -none-
- # Space separated list of sysctl items which are to be reloaded on start.
- # List items will be matched by fgrep.
- #IPTABLES_SYSCTL_LOAD_LIST=".nf_conntrack .bridge-nf"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement