Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:16:12 2014
- *nat
- :PREROUTING ACCEPT [35743:5752625]
- :INPUT ACCEPT [1396:535696]
- :OUTPUT ACCEPT [4150:569216]
- :POSTROUTING ACCEPT [4150:569216]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_external - [0:0]
- :POST_external_allow - [0:0]
- :POST_external_deny - [0:0]
- :POST_external_log - [0:0]
- :POST_internal - [0:0]
- :POST_internal_allow - [0:0]
- :POST_internal_deny - [0:0]
- :POST_internal_log - [0:0]
- :POST_public - [0:0]
- :POST_public_allow - [0:0]
- :POST_public_deny - [0:0]
- :POST_public_log - [0:0]
- :POST_tor - [0:0]
- :POST_tor_allow - [0:0]
- :POST_tor_deny - [0:0]
- :POST_tor_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_external - [0:0]
- :PRE_external_allow - [0:0]
- :PRE_external_deny - [0:0]
- :PRE_external_log - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- :PRE_tor - [0:0]
- :PRE_tor_allow - [0:0]
- :PRE_tor_deny - [0:0]
- :PRE_tor_log - [0:0]
- [36646:6093963] -A PREROUTING -j PREROUTING_direct
- [36644:6093198] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [36644:6093198] -A PREROUTING -j PREROUTING_ZONES
- [4182:583067] -A OUTPUT -j OUTPUT_direct
- [0:0] -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j SNAT --to-source 23.92.76.239
- [4184:583722] -A POSTROUTING -j POSTROUTING_direct
- [4183:583662] -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- [4183:583662] -A POSTROUTING -j POSTROUTING_ZONES
- [0:0] -A POSTROUTING_ZONES -o eth0:1 -g POST_tor
- [4140:571334] -A POSTROUTING_ZONES -o eth0 -g POST_public
- [0:0] -A POSTROUTING_ZONES -o tun0 -g POST_internal
- [0:0] -A POSTROUTING_ZONES -o eth0:0 -g POST_external
- [17:1020] -A POSTROUTING_ZONES -g POST_public
- [0:0] -A POST_external -j POST_external_log
- [0:0] -A POST_external -j POST_external_deny
- [0:0] -A POST_external -j POST_external_allow
- [0:0] -A POST_internal -j POST_internal_log
- [0:0] -A POST_internal -j POST_internal_deny
- [0:0] -A POST_internal -j POST_internal_allow
- [4157:572354] -A POST_public -j POST_public_log
- [4157:572354] -A POST_public -j POST_public_deny
- [4157:572354] -A POST_public -j POST_public_allow
- [0:0] -A POST_tor -j POST_tor_log
- [0:0] -A POST_tor -j POST_tor_deny
- [0:0] -A POST_tor -j POST_tor_allow
- [0:0] -A PREROUTING_ZONES -i eth0:1 -g PRE_tor
- [34644:5743405] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [1303:80757] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [0:0] -A PREROUTING_ZONES -i eth0:0 -g PRE_external
- [0:0] -A PREROUTING_ZONES -g PRE_public
- [0:0] -A PRE_external -j PRE_external_log
- [0:0] -A PRE_external -j PRE_external_deny
- [0:0] -A PRE_external -j PRE_external_allow
- [1303:80757] -A PRE_internal -j PRE_internal_log
- [1303:80757] -A PRE_internal -j PRE_internal_deny
- [1303:80757] -A PRE_internal -j PRE_internal_allow
- [34644:5743405] -A PRE_public -j PRE_public_log
- [34644:5743405] -A PRE_public -j PRE_public_deny
- [34644:5743405] -A PRE_public -j PRE_public_allow
- [0:0] -A PRE_tor -j PRE_tor_log
- [0:0] -A PRE_tor -j PRE_tor_deny
- [0:0] -A PRE_tor -j PRE_tor_allow
- COMMIT
- # Completed on Thu Nov 27 18:16:12 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:16:12 2014
- *mangle
- :PREROUTING ACCEPT [114156:40774964]
- :INPUT ACCEPT [112853:40694134]
- :FORWARD ACCEPT [1293:80114]
- :OUTPUT ACCEPT [111894:61155350]
- :POSTROUTING ACCEPT [111894:61155350]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_external - [0:0]
- :PRE_external_allow - [0:0]
- :PRE_external_deny - [0:0]
- :PRE_external_log - [0:0]
- :PRE_internal - [0:0]
- :PRE_internal_allow - [0:0]
- :PRE_internal_deny - [0:0]
- :PRE_internal_log - [0:0]
- :PRE_public - [0:0]
- :PRE_public_allow - [0:0]
- :PRE_public_deny - [0:0]
- :PRE_public_log - [0:0]
- :PRE_tor - [0:0]
- :PRE_tor_allow - [0:0]
- :PRE_tor_deny - [0:0]
- :PRE_tor_log - [0:0]
- [115654:41266665] -A PREROUTING -j PREROUTING_direct
- [115650:41265808] -A PREROUTING -j PREROUTING_ZONES_SOURCE
- [115649:41265760] -A PREROUTING -j PREROUTING_ZONES
- [114329:41183251] -A INPUT -j INPUT_direct
- [1305:80876] -A FORWARD -j FORWARD_direct
- [113343:61823858] -A OUTPUT -j OUTPUT_direct
- [113349:61825510] -A POSTROUTING -j POSTROUTING_direct
- [0:0] -A PREROUTING_ZONES -i eth0:1 -g PRE_tor
- [113137:40794983] -A PREROUTING_ZONES -i eth0 -g PRE_public
- [1305:80876] -A PREROUTING_ZONES -i tun0 -g PRE_internal
- [0:0] -A PREROUTING_ZONES -i eth0:0 -g PRE_external
- [185:39578] -A PREROUTING_ZONES -g PRE_public
- [0:0] -A PRE_external -j PRE_external_log
- [0:0] -A PRE_external -j PRE_external_deny
- [0:0] -A PRE_external -j PRE_external_allow
- [1305:80876] -A PRE_internal -j PRE_internal_log
- [1305:80876] -A PRE_internal -j PRE_internal_deny
- [1305:80876] -A PRE_internal -j PRE_internal_allow
- [113322:40834561] -A PRE_public -j PRE_public_log
- [113322:40834561] -A PRE_public -j PRE_public_deny
- [113322:40834561] -A PRE_public -j PRE_public_allow
- [0:0] -A PRE_tor -j PRE_tor_log
- [0:0] -A PRE_tor -j PRE_tor_deny
- [0:0] -A PRE_tor -j PRE_tor_allow
- COMMIT
- # Completed on Thu Nov 27 18:16:12 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:16:12 2014
- *security
- :INPUT ACCEPT [79303:35700741]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [113356:61827805]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- [79307:35701488] -A INPUT -j INPUT_direct
- [0:0] -A FORWARD -j FORWARD_direct
- [113360:61832015] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:16:12 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:16:12 2014
- *raw
- :PREROUTING ACCEPT [115671:41270460]
- :OUTPUT ACCEPT [113372:61835054]
- :OUTPUT_direct - [0:0]
- :PREROUTING_direct - [0:0]
- [115672:41271077] -A PREROUTING -j PREROUTING_direct
- [113372:61835054] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Thu Nov 27 18:16:12 2014
- # Generated by iptables-save v1.4.19.1 on Thu Nov 27 18:16:12 2014
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [111901:61157319]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_external - [0:0]
- :FWDI_external_allow - [0:0]
- :FWDI_external_deny - [0:0]
- :FWDI_external_log - [0:0]
- :FWDI_internal - [0:0]
- :FWDI_internal_allow - [0:0]
- :FWDI_internal_deny - [0:0]
- :FWDI_internal_log - [0:0]
- :FWDI_public - [0:0]
- :FWDI_public_allow - [0:0]
- :FWDI_public_deny - [0:0]
- :FWDI_public_log - [0:0]
- :FWDI_tor - [0:0]
- :FWDI_tor_allow - [0:0]
- :FWDI_tor_deny - [0:0]
- :FWDI_tor_log - [0:0]
- :FWDO_external - [0:0]
- :FWDO_external_allow - [0:0]
- :FWDO_external_deny - [0:0]
- :FWDO_external_log - [0:0]
- :FWDO_internal - [0:0]
- :FWDO_internal_allow - [0:0]
- :FWDO_internal_deny - [0:0]
- :FWDO_internal_log - [0:0]
- :FWDO_public - [0:0]
- :FWDO_public_allow - [0:0]
- :FWDO_public_deny - [0:0]
- :FWDO_public_log - [0:0]
- :FWDO_tor - [0:0]
- :FWDO_tor_allow - [0:0]
- :FWDO_tor_deny - [0:0]
- :FWDO_tor_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_external - [0:0]
- :IN_external_allow - [0:0]
- :IN_external_deny - [0:0]
- :IN_external_log - [0:0]
- :IN_internal - [0:0]
- :IN_internal_allow - [0:0]
- :IN_internal_deny - [0:0]
- :IN_internal_log - [0:0]
- :IN_public - [0:0]
- :IN_public_allow - [0:0]
- :IN_public_deny - [0:0]
- :IN_public_log - [0:0]
- :IN_tor - [0:0]
- :IN_tor_allow - [0:0]
- :IN_tor_deny - [0:0]
- :IN_tor_log - [0:0]
- :OUTPUT_direct - [0:0]
- [77786:35107277] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [17:1020] -A INPUT -i lo -j ACCEPT
- [36608:6089163] -A INPUT -j INPUT_direct
- [36607:6089115] -A INPUT -j INPUT_ZONES_SOURCE
- [36606:6088945] -A INPUT -j INPUT_ZONES
- [13:1052] -A INPUT -p icmp -j ACCEPT
- [35066:5490091] -A INPUT -j REJECT --reject-with icmp-host-prohibited
- [0:0] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -i lo -j ACCEPT
- [1305:80876] -A FORWARD -j FORWARD_direct
- [1305:80876] -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- [1305:80876] -A FORWARD -j FORWARD_IN_ZONES
- [1305:80876] -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- [1305:80876] -A FORWARD -j FORWARD_OUT_ZONES
- [0:0] -A FORWARD -p icmp -j ACCEPT
- [1305:80876] -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- [113375:61836067] -A OUTPUT -j OUTPUT_direct
- [0:0] -A FORWARD_IN_ZONES -i eth0:1 -g FWDI_tor
- [0:0] -A FORWARD_IN_ZONES -i eth0 -g FWDI_public
- [1305:80876] -A FORWARD_IN_ZONES -i tun0 -g FWDI_internal
- [0:0] -A FORWARD_IN_ZONES -i eth0:0 -g FWDI_external
- [0:0] -A FORWARD_IN_ZONES -g FWDI_public
- [0:0] -A FORWARD_OUT_ZONES -o eth0:1 -g FWDO_tor
- [1305:80876] -A FORWARD_OUT_ZONES -o eth0 -g FWDO_public
- [0:0] -A FORWARD_OUT_ZONES -o tun0 -g FWDO_internal
- [0:0] -A FORWARD_OUT_ZONES -o eth0:0 -g FWDO_external
- [0:0] -A FORWARD_OUT_ZONES -g FWDO_public
- [0:0] -A FWDI_external -j FWDI_external_log
- [0:0] -A FWDI_external -j FWDI_external_deny
- [0:0] -A FWDI_external -j FWDI_external_allow
- [1305:80876] -A FWDI_internal -j FWDI_internal_log
- [1305:80876] -A FWDI_internal -j FWDI_internal_deny
- [1305:80876] -A FWDI_internal -j FWDI_internal_allow
- [0:0] -A FWDI_public -j FWDI_public_log
- [0:0] -A FWDI_public -j FWDI_public_deny
- [0:0] -A FWDI_public -j FWDI_public_allow
- [0:0] -A FWDI_tor -j FWDI_tor_log
- [0:0] -A FWDI_tor -j FWDI_tor_deny
- [0:0] -A FWDI_tor -j FWDI_tor_allow
- [0:0] -A FWDO_external -j FWDO_external_log
- [0:0] -A FWDO_external -j FWDO_external_deny
- [0:0] -A FWDO_external -j FWDO_external_allow
- [0:0] -A FWDO_internal -j FWDO_internal_log
- [0:0] -A FWDO_internal -j FWDO_internal_deny
- [0:0] -A FWDO_internal -j FWDO_internal_allow
- [1305:80876] -A FWDO_public -j FWDO_public_log
- [1305:80876] -A FWDO_public -j FWDO_public_deny
- [1305:80876] -A FWDO_public -j FWDO_public_allow
- [0:0] -A FWDO_tor -j FWDO_tor_log
- [0:0] -A FWDO_tor -j FWDO_tor_deny
- [0:0] -A FWDO_tor -j FWDO_tor_allow
- [0:0] -A INPUT_ZONES -i eth0:1 -g IN_tor
- [35800:5807692] -A INPUT_ZONES -i eth0 -g IN_public
- [0:0] -A INPUT_ZONES -i tun0 -g IN_internal
- [0:0] -A INPUT_ZONES -i eth0:0 -g IN_external
- [0:0] -A INPUT_ZONES -g IN_public
- [0:0] -A IN_external -j IN_external_log
- [0:0] -A IN_external -j IN_external_deny
- [0:0] -A IN_external -j IN_external_allow
- [0:0] -A IN_external_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_external_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal -j IN_internal_log
- [0:0] -A IN_internal -j IN_internal_deny
- [0:0] -A IN_internal -j IN_internal_allow
- [0:0] -A IN_internal_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_internal_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [35800:5807692] -A IN_public -j IN_public_log
- [35800:5807692] -A IN_public -j IN_public_deny
- [35800:5807692] -A IN_public -j IN_public_allow
- [0:0] -A IN_public_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- [11:588] -A IN_public_allow -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT
- [73:3532] -A IN_public_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- [1425:592510] -A IN_public_allow -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_public_allow -p udp -m udp --dport 1194 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_public_allow -p tcp -m tcp --dport 6379 -m conntrack --ctstate NEW -j ACCEPT
- [16:832] -A IN_public_allow -p tcp -m tcp --dport 8887 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_tor -j IN_tor_log
- [0:0] -A IN_tor -j IN_tor_deny
- [0:0] -A IN_tor -j IN_tor_allow
- [0:0] -A IN_tor_allow -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A IN_tor_allow -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
- # Completed on Thu Nov 27 18:16:12 2014
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement