Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- iptables -t nat -X
- iptables -t nat -F
- iptables -t mangle -X
- iptables -t mangle -F
- iptables -X
- iptables -F
- iptables -P INPUT DROP
- iptables -P OUTPUT DROP
- iptables -P FORWARD DROP
- iptables -A INPUT -i lo -j ACCEPT
- iptables -A OUTPUT -o lo -j ACCEPT
- iptables -A INPUT -i vlan44 -p udp --dport 67:68 --sport 67:68 -j ACCEPT
- iptables -A OUTPUT -o vlan44 -p udp --dport 67:68 --sport 67:68 -j ACCEPT
- iptables -A INPUT -p udp -m udp --sport 53 -j ACCEPT
- iptables -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT
- iptables -A INPUT -p tcp -m tcp --sport 53 -j ACCEPT
- iptables -A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT
- iptables -A INPUT -i vlan2017 -p icmp --icmp-type 3 -j ACCEPT
- iptables -A INPUT -i vlan2017 -p icmp --icmp-type 8 -j ACCEPT
- iptables -A INPUT -i vlan2017 -p icmp --icmp-type 12 -j ACCEPT
- iptables -A INPUT -i vlan44 -p icmp -j ACCEPT
- iptables -A OUTPUT -p icmp -j ACCEPT
- iptables -A OUTPUT -p TCP --sport 32768:61000 -j ACCEPT
- iptables -A OUTPUT -p UDP --sport 32768:61000 -j ACCEPT
- iptables -A INPUT -p tcp ! --syn -m conntrack --ctstate NEW -j DROP
- iptables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- iptables -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- iptables -A INPUT -i vlan44 -p udp -m udp --dport 161:162 -j ACCEPT
- iptables -A INPUT -i vlan44 -p tcp --dport 22 -j ACCEPT
- iptables -A INPUT -p ipv6 -s 216.66.80.98/32 -j ACCEPT
- iptables -A OUTPUT -p ipv6 -d 216.66.80.98/32 -j ACCEPT
- iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- ip6tables -t nat -X
- ip6tables -t nat -F
- ip6tables -t mangle -X
- ip6tables -t mangle -F
- ip6tables -X
- ip6tables -F
- ip6tables -P INPUT DROP
- ip6tables -P OUTPUT DROP
- ip6tables -P FORWARD DROP
- ip6tables -A INPUT -i lo -j ACCEPT
- ip6tables -A OUTPUT -o lo -j ACCEPT
- ip6tables -A INPUT -i vlan44 -p udp --dport 67:68 --sport 67:68 -j ACCEPT
- ip6tables -A OUTPUT -o vlan44 -p udp --dport 67:68 --sport 67:68 -j ACCEPT
- ip6tables -A INPUT -p udp -m udp --sport 53 -j ACCEPT
- ip6tables -A OUTPUT -p udp -m udp --dport 53 -j ACCEPT
- ip6tables -A INPUT -p tcp -m tcp --sport 53 -j ACCEPT
- ip6tables -A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT
- ip6tables -A INPUT -i vlan2017 -p icmpv6 --icmpv6-type 1 -j ACCEPT
- ip6tables -A INPUT -i vlan2017 -p icmpv6 --icmpv6-type 2 -j ACCEPT
- ip6tables -A INPUT -i vlan2017 -p icmpv6 --icmpv6-type 3 -j ACCEPT
- ip6tables -A INPUT -i vlan2017 -p icmpv6 --icmpv6-type 4 -j ACCEPT
- ip6tables -A INPUT -i vlan2017 -p icmpv6 --icmpv6-type 128 -j ACCEPT
- ip6tables -A INPUT -i vlan44 -p icmpv6 -j ACCEPT
- ip6tables -A OUTPUT -p icmpv6 -j ACCEPT
- ip6tables -A OUTPUT -p TCP --sport 32768:61000 -j ACCEPT
- ip6tables -A OUTPUT -p UDP --sport 32768:61000 -j ACCEPT
- ip6tables -A INPUT -p tcp ! --syn -m conntrack --ctstate NEW -j DROP
- ip6tables -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- ip6tables -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- ip6tables -A INPUT -i vlan44 -p udp -m udp --dport 161:162 -j ACCEPT
- ip6tables -A INPUT -i vlan44 -p tcp --dport 22 -j ACCEPT
- ip6tables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- ip6tables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement