Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- IF=eth0
- _IPTABLES=iptables
- $_IPTABLES -P INPUT DROP
- $_IPTABLES -P FORWARD DROP
- $_IPTABLES -P OUTPUT DROP
- $_IPTABLES -A INPUT -i $IF -p tcp -m multiport --dports 22,53,80,443,953 -m state --state NEW,ESTABLISHED -j ACCEPT
- $_IPTABLES -A OUTPUT -o $IF -p tcp -m multiport --sports 22,53,80,443,953 -m state --state ESTABLISHED -j ACCEPT
- $_IPTABLES -A INPUT -i $IF -p udp -m multiport --dports 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- $_IPTABLES -A OUTPUT -o $IF -p udp -m multiport --sports 53 -m state --state ESTABLISHED -j ACCEPT
- $_IPTABLES -A INPUT -i $IF -p tcp -m multiport --sports 53,953 -m state --state ESTABLISHED -j ACCEPT
- $_IPTABLES -A OUTPUT -o $IF -p tcp -m multiport --dports 53,953 -m state --state NEW,ESTABLISHED -j ACCEPT
- $_IPTABLES -A INPUT -i $IF -p udp -m multiport --sports 53 -m state --state ESTABLISHED -j ACCEPT
- $_IPTABLES -A OUTPUT -o $IF -p udp -m multiport --dports 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- root@ganymede:~/linux/iptables# cat /etc/network/interfaces
- # The loopback network interface
- auto lo
- iface lo inet loopback
- # The bridge we're building over eth0
- auto br0
- iface br0 inet static
- bridge_ports eth0
- bridge_fd 0
- bridge_maxwait 0
- # this should be in eth0 w/o br0
- address xx.xx.xx.xx
- netmask 255.255.255.0
- network xx.xx.xx.0
- broadcast xx.xx.xx.255
- gateway xx.xx.xx.1
- # dns-* options are implemented by the resolvconf package, if installed
- dns-nameservers 217.11.48.200 217.11.49.200 8.8.8.8 8.8.4.4
- auto br0:0
- iface br0:0 inet static
- # this should be in eth0 w/o br0
- address xx.xx.xx.xx
- netmask 255.255.255.248
- network xx.xx.xx.xx
- broadcast xx.xx.xx.xx
- # gateway xx.xx.xx.xx
- # dns-* options are implemented by the resolvconf package, if installed
- # dns-nameservers 217.11.48.200 217.11.49.200 8.8.8.8 8.8.4.4
- root@ganymede:~/linux/iptables# cat /var/lib/lxc/callisto/config
- # Template used to create this container: /usr/share/lxc/templates/lxc-ubuntu
- # Parameters passed to the template:
- # For additional config options, please look at lxc.conf(5)
- # Common configuration
- lxc.include = /usr/share/lxc/config/ubuntu.common.conf
- # Container specific configuration
- lxc.rootfs = /var/lib/lxc/callisto/rootfs
- lxc.mount = /var/lib/lxc/callisto/fstab
- lxc.utsname = callisto
- lxc.arch = amd64
- # Network configuration
- lxc.network.type = veth
- lxc.network.flags = up
- #lxc.network.link = lxcbr0
- # uncoment above and comment below line to move back to local bridge
- lxc.network.link = br0
- lxc.network.hwaddr = 00:16:3e:39:04:35
- lxc.network.ipv4 = yy.yy.yy.yy/29
- # comment this line for local bridge
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement