Advertisement
Guest User

Untitled

a guest
Jun 18th, 2013
43
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.64 KB | None | 0 0
  1. *filter
  2. :INPUT ACCEPT [0:0]
  3. :FORWARD ACCEPT [0:0]
  4. :OUTPUT ACCEPT [0:0]
  5. -A INPUT -i lo -j ACCEPT
  6. -A INPUT -d 127.0.0.0/8 -i lo -j REJECT --reject-with icmp-port-unreachable
  7. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  8. {% if grains['id'].startswith('web') %}
  9. #HTTP
  10. -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
  11. #HTTPS
  12. -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
  13. {% elif grains['id'].startswith('chat') %}
  14. #CHAT
  15. -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 2424
  16. {% else %}{% endif %}
  17. -A INPUT -j REJECT --reject-with icmp-port-unreachable
  18. -A FORWARD -j REJECT --reject-with icmp-port-unreachable
  19. -A OUTPUT -j ACCEPT
  20. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement