Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@thor ~]# iptables -L -n -v
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT tcp -- !lo * 8.8.4.4 0.0.0.0/0 tcp dpt:53
- 0 0 ACCEPT udp -- !lo * 8.8.4.4 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- !lo * 8.8.4.4 0.0.0.0/0 tcp spt:53
- 19 2634 ACCEPT udp -- !lo * 8.8.4.4 0.0.0.0/0 udp spt:53
- 0 0 ACCEPT tcp -- !lo * 159.253.0.110 0.0.0.0/0 tcp dpt:53
- 0 0 ACCEPT udp -- !lo * 159.253.0.110 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- !lo * 159.253.0.110 0.0.0.0/0 tcp spt:53
- 4 505 ACCEPT udp -- !lo * 159.253.0.110 0.0.0.0/0 udp spt:53
- 8550 734K LOCALINPUT all -- !lo * 0.0.0.0/0 0.0.0.0/0
- 3203 1393K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- 171 16563 INVALID tcp -- !lo * 0.0.0.0/0 0.0.0.0/0
- 449 68877 ACCEPT all -- !lo * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 1 40 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:20
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:21
- 5 228 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:25
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:53
- 19 1120 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:80
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:110
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:143
- 4 220 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:443
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:465
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:587
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:993
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:995
- 0 0 ACCEPT tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:2222
- 0 0 ACCEPT udp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:20
- 0 0 ACCEPT udp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:21
- 110 7393 ACCEPT udp -- !lo * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:53
- 0 0 ACCEPT icmp -- !lo * 0.0.0.0/0 0.0.0.0/0 icmp type 8 limit: avg 1/sec burst 5
- 0 0 ACCEPT icmp -- !lo * 0.0.0.0/0 0.0.0.0/0 icmp type 0 limit: avg 1/sec burst 5
- 0 0 ACCEPT icmp -- !lo * 0.0.0.0/0 0.0.0.0/0 icmp type 11
- 2 120 ACCEPT icmp -- !lo * 0.0.0.0/0 0.0.0.0/0 icmp type 3
- 14 1428 LOGDROPIN all -- !lo * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy DROP 156 packets, 8134 bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 8.8.4.4 tcp dpt:53
- 19 1177 ACCEPT udp -- * !lo 0.0.0.0/0 8.8.4.4 udp dpt:53
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 8.8.4.4 tcp spt:53
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 8.8.4.4 udp spt:53
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 159.253.0.110 tcp dpt:53
- 4 263 ACCEPT udp -- * !lo 0.0.0.0/0 159.253.0.110 udp dpt:53
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 159.253.0.110 tcp spt:53
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 159.253.0.110 udp spt:53
- 7840 16M LOCALOUTPUT all -- * !lo 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- 54 3994 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 tcp spt:53
- 114 12482 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 udp spt:53
- 0 0 ACCEPT tcp -- * lo 0.0.0.0/0 0.0.0.0/0 tcp dpt:587
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:587 owner GID match 12
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:587 owner UID match 0
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:587
- 0 0 ACCEPT tcp -- * lo 0.0.0.0/0 0.0.0.0/0 tcp dpt:465
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:465 owner GID match 12
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:465 owner UID match 0
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:465
- 0 0 ACCEPT tcp -- * lo 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25 owner GID match 12
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25 owner UID match 0
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
- 3203 1393K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
- 109 31301 INVALID tcp -- * !lo 0.0.0.0/0 0.0.0.0/0
- 166 35717 ACCEPT all -- * !lo 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:20
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:21
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:25
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:53
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:80
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:110
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:113
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:443
- 0 0 ACCEPT tcp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:2222
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:20
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:21
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:53
- 0 0 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:113
- 221 16796 ACCEPT udp -- * !lo 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:123
- 0 0 ACCEPT icmp -- * !lo 0.0.0.0/0 0.0.0.0/0 icmp type 0
- 0 0 ACCEPT icmp -- * !lo 0.0.0.0/0 0.0.0.0/0 icmp type 8
- 0 0 ACCEPT icmp -- * !lo 0.0.0.0/0 0.0.0.0/0 icmp type 11
- 0 0 ACCEPT icmp -- * !lo 0.0.0.0/0 0.0.0.0/0 icmp type 3
- 0 0 LOGDROPOUT all -- * !lo 0.0.0.0/0 0.0.0.0/0
- Chain ALLOWIN (1 references)
- pkts bytes target prot opt in out source destination
- 7920 653K ACCEPT all -- !lo * 77.173.163.18 0.0.0.0/0
- Chain ALLOWOUT (1 references)
- pkts bytes target prot opt in out source destination
- 7285 16M ACCEPT all -- * !lo 0.0.0.0/0 77.173.163.18
- Chain DENYIN (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- !lo * 61.147.116.5 0.0.0.0/0
- 1 40 DROP all -- !lo * 61.160.251.136 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.113.165 0.0.0.0/0
- 0 0 DROP all -- !lo * 58.221.82.14 0.0.0.0/0
- 0 0 DROP all -- !lo * 58.215.133.52 0.0.0.0/0
- 0 0 DROP all -- !lo * 222.175.114.132 0.0.0.0/0
- 0 0 DROP all -- !lo * 222.189.239.126 0.0.0.0/0
- 1 40 DROP all -- !lo * 112.5.118.54 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.107.102 0.0.0.0/0
- 1 40 DROP all -- !lo * 222.189.239.70 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.160.251.139 0.0.0.0/0
- 0 0 DROP all -- !lo * 111.68.107.133 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.116.20 0.0.0.0/0
- 0 0 DROP all -- !lo * 120.194.36.56 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.119.106 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.116.54 0.0.0.0/0
- 0 0 DROP all -- !lo * 202.119.236.121 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.113.85 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.74.149 0.0.0.0/0
- 0 0 DROP all -- !lo * 114.80.217.238 0.0.0.0/0
- 0 0 DROP all -- !lo * 198.50.195.121 0.0.0.0/0
- 0 0 DROP all -- !lo * 203.172.243.36 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.147.116.57 0.0.0.0/0
- 0 0 DROP all -- !lo * 59.152.250.114 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.142.106.34 0.0.0.0/0
- 0 0 DROP all -- !lo * 124.117.249.242 0.0.0.0/0
- 0 0 DROP all -- !lo * 183.224.249.22 0.0.0.0/0
- 1 40 DROP all -- !lo * 114.80.226.94 0.0.0.0/0
- 0 0 DROP all -- !lo * 218.76.86.167 0.0.0.0/0
- 0 0 DROP all -- !lo * 119.147.101.82 0.0.0.0/0
- 0 0 DROP all -- !lo * 119.188.55.56 0.0.0.0/0
- 0 0 DROP all -- !lo * 216.99.158.72 0.0.0.0/0
- 0 0 DROP all -- !lo * 117.21.127.215 0.0.0.0/0
- 0 0 DROP all -- !lo * 59.53.94.9 0.0.0.0/0
- 0 0 DROP all -- !lo * 61.182.170.38 0.0.0.0/0
- 0 0 DROP all -- !lo * 142.54.177.122 0.0.0.0/0
- 0 0 DROP all -- !lo * 222.76.211.140 0.0.0.0/0
- 0 0 DROP all -- !lo * 182.101.206.91 0.0.0.0/0
- 0 0 DROP all -- !lo * 202.85.221.153 0.0.0.0/0
- 0 0 DROP all -- !lo * 1.234.90.192 0.0.0.0/0
- 0 0 DROP all -- !lo * 117.41.184.109 0.0.0.0/0
- 0 0 DROP all -- !lo * 58.215.133.47 0.0.0.0/0
- Chain DENYOUT (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.116.5
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.160.251.136
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.113.165
- 0 0 DROP all -- * !lo 0.0.0.0/0 58.221.82.14
- 0 0 DROP all -- * !lo 0.0.0.0/0 58.215.133.52
- 0 0 DROP all -- * !lo 0.0.0.0/0 222.175.114.132
- 0 0 DROP all -- * !lo 0.0.0.0/0 222.189.239.126
- 0 0 DROP all -- * !lo 0.0.0.0/0 112.5.118.54
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.107.102
- 0 0 DROP all -- * !lo 0.0.0.0/0 222.189.239.70
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.160.251.139
- 0 0 DROP all -- * !lo 0.0.0.0/0 111.68.107.133
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.116.20
- 0 0 DROP all -- * !lo 0.0.0.0/0 120.194.36.56
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.119.106
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.116.54
- 0 0 DROP all -- * !lo 0.0.0.0/0 202.119.236.121
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.113.85
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.74.149
- 0 0 DROP all -- * !lo 0.0.0.0/0 114.80.217.238
- 0 0 DROP all -- * !lo 0.0.0.0/0 198.50.195.121
- 0 0 DROP all -- * !lo 0.0.0.0/0 203.172.243.36
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.147.116.57
- 0 0 DROP all -- * !lo 0.0.0.0/0 59.152.250.114
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.142.106.34
- 0 0 DROP all -- * !lo 0.0.0.0/0 124.117.249.242
- 0 0 DROP all -- * !lo 0.0.0.0/0 183.224.249.22
- 0 0 DROP all -- * !lo 0.0.0.0/0 114.80.226.94
- 0 0 DROP all -- * !lo 0.0.0.0/0 218.76.86.167
- 0 0 DROP all -- * !lo 0.0.0.0/0 119.147.101.82
- 0 0 DROP all -- * !lo 0.0.0.0/0 119.188.55.56
- 0 0 DROP all -- * !lo 0.0.0.0/0 216.99.158.72
- 0 0 DROP all -- * !lo 0.0.0.0/0 117.21.127.215
- 0 0 DROP all -- * !lo 0.0.0.0/0 59.53.94.9
- 0 0 DROP all -- * !lo 0.0.0.0/0 61.182.170.38
- 0 0 DROP all -- * !lo 0.0.0.0/0 142.54.177.122
- 0 0 DROP all -- * !lo 0.0.0.0/0 222.76.211.140
- 0 0 DROP all -- * !lo 0.0.0.0/0 182.101.206.91
- 0 0 DROP all -- * !lo 0.0.0.0/0 202.85.221.153
- 0 0 DROP all -- * !lo 0.0.0.0/0 1.234.90.192
- 0 0 DROP all -- * !lo 0.0.0.0/0 117.41.184.109
- 0 0 DROP all -- * !lo 0.0.0.0/0 58.215.133.47
- Chain INVALID (2 references)
- pkts bytes target prot opt in out source destination
- 22 884 INVDROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x3F
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x03/0x03
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x06
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x05/0x05
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x11/0x01
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x18/0x08
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x30/0x20
- 0 0 INVDROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW
- Chain INVDROP (10 references)
- pkts bytes target prot opt in out source destination
- 22 884 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain LOCALINPUT (1 references)
- pkts bytes target prot opt in out source destination
- 8550 734K ALLOWIN all -- !lo * 0.0.0.0/0 0.0.0.0/0
- 630 80470 DENYIN all -- !lo * 0.0.0.0/0 0.0.0.0/0
- Chain LOCALOUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- 7840 16M ALLOWOUT all -- * !lo 0.0.0.0/0 0.0.0.0/0
- 555 68989 DENYOUT all -- * !lo 0.0.0.0/0 0.0.0.0/0
- Chain LOGDROPIN (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:68
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:111
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:111
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:113
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:113
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:135:139
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:135:139
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:445
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:445
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:500
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:500
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:513
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:513
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:520
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:520
- 3 120 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 30/min burst 5 LOG flags 0 level 4 prefix `Firewall: *TCP_IN Blocked* '
- 11 1308 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 30/min burst 5 LOG flags 0 level 4 prefix `Firewall: *UDP_IN Blocked* '
- 0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 30/min burst 5 LOG flags 0 level 4 prefix `Firewall: *ICMP_IN Blocked* '
- 14 1428 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain LOGDROPOUT (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 30/min burst 5 LOG flags 8 level 4 prefix `Firewall: *TCP_OUT Blocked* '
- 0 0 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 30/min burst 5 LOG flags 8 level 4 prefix `Firewall: *UDP_OUT Blocked* '
- 0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 30/min burst 5 LOG flags 8 level 4 prefix `Firewall: *ICMP_OUT Blocked* '
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement