Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 95 13582 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
- 0 0 ovpn2fw all -- tun+ * 0.0.0.0/0 0.0.0.0/0
- 903 133K loc2fw all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 57 4652 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:INPUT:DROP:' queue_threshold 1
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
- 0 0 ovpn2loc all -- tun+ eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 loc2ovpn all -- eth0 tun+ 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:FORWARD:DROP:' queue_threshold 1
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 fw2ovpn all -- * tun+ 0.0.0.0/0 0.0.0.0/0
- 858 136K fw2loc all -- * eth0 0.0.0.0/0 0.0.0.0/0
- 57 4652 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:OUTPUT:DROP:' queue_threshold 1
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain Drop (5 references)
- pkts bytes target prot opt in out source destination
- 0 0 all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:113 /* Auth */
- 0 0 dropBcast all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4 /* Needed ICMP types */
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 11 /* Needed ICMP types */
- 0 0 dropInvalid all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,445 /* SMB */
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:137:139 /* SMB */
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137 dpts:1024:65535 /* SMB */
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,139,445 /* SMB */
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1900 /* UPnP */
- 0 0 dropNotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:53 /* Late DNS Replies */
- Chain Reject (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:113 /* Auth */
- 0 0 dropBcast all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4 /* Needed ICMP types */
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 11 /* Needed ICMP types */
- 0 0 dropInvalid all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,445 /* SMB */
- 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:137:139 /* SMB */
- 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137 dpts:1024:65535 /* SMB */
- 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,139,445 /* SMB */
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1900 /* UPnP */
- 0 0 dropNotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:53 /* Late DNS Replies */
- Chain dropBcast (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
- 0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/4
- Chain dropInvalid (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
- Chain dropNotSyn (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02
- Chain dynamic (2 references)
- pkts bytes target prot opt in out source destination
- Chain fw2loc (1 references)
- pkts bytes target prot opt in out source destination
- 852 135K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 log1 udp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] multiport dports 53,123
- 6 1249 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:fw2loc:ACCEPT:' queue_threshold 1
- 6 1249 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain fw2ovpn (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:fw2ovpn:ACCEPT:' queue_threshold 1
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain loc2fw (1 references)
- pkts bytes target prot opt in out source destination
- 811 120K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
- 2 143 log0 tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] multiport dports 22,80,443,1194
- 0 0 log0 udp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] multiport dports 53,123
- 90 13235 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:loc2fw:ACCEPT:' queue_threshold 1
- 90 13235 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain loc2ovpn (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:loc2ovpn:DROP:' queue_threshold 1
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain log0 (2 references)
- pkts bytes target prot opt in out source destination
- 2 143 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:loc2fw:ACCEPT:' queue_threshold 1
- 2 143 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain log1 (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:fw2loc:ACCEPT:' queue_threshold 1
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain log2 (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:ovpn2fw:ACCEPT:' queue_threshold 1
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain logdrop (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain logreject (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ovpn2fw (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 log2 udp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] multiport dports 53,123
- 0 0 log2 tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] multiport dports 21,22
- 0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:ovpn2fw:REJECT:' queue_threshold 1
- 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
- Chain ovpn2loc (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 Drop all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ULOG all -- * * 0.0.0.0/0 0.0.0.0/0 ULOG copy_range 0 nlgroup 1 prefix `Shorewall:ovpn2loc:DROP:' queue_threshold 1
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain reject (8 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match src-type BROADCAST
- 0 0 DROP all -- * * 224.0.0.0/4 0.0.0.0/0
- 0 0 DROP 2 -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
- 0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT icmp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-unreachable
- 0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement