Don't like ads? PRO users don't see any ads ;-)
Guest

Untitled

By: a guest on Jul 21st, 2011  |  syntax: None  |  size: 9.76 KB  |  hits: 60  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. Offline.....
  2.  
  3. IP R
  4. -------
  5.  
  6. root@slackware:/etc/shorewall#  ip r
  7. 80.74.157.215 via 192.168.1.1 dev eth0
  8. 192.168.1.0/24 dev eth0  proto kernel  scope link  src 192.168.1.8  metric 202
  9. 10.203.0.0/16 dev tun0  proto kernel  scope link  src 10.203.0.228
  10. 127.0.0.0/8 dev lo  scope link
  11. 0.0.0.0/1 via 10.203.0.1 dev tun0
  12. 128.0.0.0/1 via 10.203.0.1 dev tun0
  13. default via 192.168.1.1 dev eth0  metric 202
  14.  
  15.  
  16. IFCONFIG
  17. -----------
  18.  
  19.  
  20. root@slackware:/etc/shorewall# ifconfig
  21. eth0      Link encap:Ethernet  HWaddr 00:07:03:1B:D2:1D  
  22.           inet addr:192.168.1.8  Bcast:192.168.1.255  Mask:255.255.255.0
  23.           inet6 addr: fe80::207:3ff:fe1b:d21d/64 Scope:Link
  24.           UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
  25.           RX packets:121577 errors:0 dropped:0 overruns:0 frame:0
  26.           TX packets:77160 errors:0 dropped:0 overruns:0 carrier:1
  27.           collisions:0 txqueuelen:1000
  28.           RX bytes:163289735 (155.7 Mb)  TX bytes:13798270 (13.1 Mb)
  29.           Interrupt:41
  30.  
  31. lo        Link encap:Local Loopback  
  32.           inet addr:127.0.0.1  Mask:255.0.0.0
  33.           inet6 addr: ::1/128 Scope:Host
  34.           UP LOOPBACK RUNNING  MTU:16436  Metric:1
  35.           RX packets:65 errors:0 dropped:0 overruns:0 frame:0
  36.           TX packets:65 errors:0 dropped:0 overruns:0 carrier:0
  37.           collisions:0 txqueuelen:0
  38.           RX bytes:6628 (6.4 Kb)  TX bytes:6628 (6.4 Kb)
  39.  
  40. tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00  
  41.           inet addr:10.203.0.228  P-t-P:10.203.0.228  Mask:255.255.0.0
  42.           UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
  43.           RX packets:117631 errors:0 dropped:0 overruns:0 frame:0
  44.           TX packets:73583 errors:0 dropped:0 overruns:0 carrier:0
  45.           collisions:0 txqueuelen:100
  46.           RX bytes:151584576 (144.5 Mb)  TX bytes:6783662 (6.4 Mb)
  47.  
  48. wlan0     Link encap:Ethernet  HWaddr 0C:60:76:51:82:C2  
  49.           UP BROADCAST MULTICAST  MTU:1500  Metric:1
  50.           RX packets:0 errors:0 dropped:0 overruns:0 frame:0
  51.           TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
  52.           collisions:0 txqueuelen:1000
  53.           RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)
  54.  
  55.  
  56. IPTABLES-SAVE
  57. ---------------
  58.  
  59. # Generated by iptables-save v1.4.10 on Thu Jul 21 14:37:52 2011
  60. *nat
  61. :PREROUTING ACCEPT [5:528]
  62. :INPUT ACCEPT [1:328]
  63. :OUTPUT ACCEPT [323:20127]
  64. :POSTROUTING ACCEPT [323:20127]
  65. COMMIT
  66. # Completed on Thu Jul 21 14:37:52 2011
  67. # Generated by iptables-save v1.4.10 on Thu Jul 21 14:37:52 2011
  68. *raw
  69. :PREROUTING ACCEPT [5395:4161995]
  70. :OUTPUT ACCEPT [5433:1031313]
  71. COMMIT
  72. # Completed on Thu Jul 21 14:37:52 2011
  73. # Generated by iptables-save v1.4.10 on Thu Jul 21 14:37:52 2011
  74. *mangle
  75. :PREROUTING ACCEPT [5395:4161995]
  76. :INPUT ACCEPT [5391:4161795]
  77. :FORWARD ACCEPT [0:0]
  78. :OUTPUT ACCEPT [5433:1031313]
  79. :POSTROUTING ACCEPT [5433:1031313]
  80. :tcfor - [0:0]
  81. :tcin - [0:0]
  82. :tcout - [0:0]
  83. :tcpost - [0:0]
  84. :tcpre - [0:0]
  85. -A PREROUTING -j tcpre
  86. -A INPUT -j tcin
  87. -A FORWARD -j MARK --set-xmark 0x0/0xff
  88. -A FORWARD -j tcfor
  89. -A OUTPUT -j tcout
  90. -A POSTROUTING -j tcpost
  91. COMMIT
  92. # Completed on Thu Jul 21 14:37:52 2011
  93. # Generated by iptables-save v1.4.10 on Thu Jul 21 14:37:52 2011
  94. *filter
  95. :INPUT DROP [0:0]
  96. :FORWARD DROP [0:0]
  97. :OUTPUT DROP [0:0]
  98. :Drop - [0:0]
  99. :Reject - [0:0]
  100. :dropBcast - [0:0]
  101. :dropInvalid - [0:0]
  102. :dropNotSyn - [0:0]
  103. :dynamic - [0:0]
  104. :eth0_fwd - [0:0]
  105. :eth0_in - [0:0]
  106. :fw2net - [0:0]
  107. :fw2vpn - [0:0]
  108. :logdrop - [0:0]
  109. :logflags - [0:0]
  110. :logreject - [0:0]
  111. :net2fw - [0:0]
  112. :net2vpn - [0:0]
  113. :net_frwd - [0:0]
  114. :reject - [0:0]
  115. :sfilter - [0:0]
  116. :shorewall - [0:0]
  117. :smurflog - [0:0]
  118. :smurfs - [0:0]
  119. :tcpflags - [0:0]
  120. :vpn2fw - [0:0]
  121. :vpn2net - [0:0]
  122. :vpn_frwd - [0:0]
  123. :wlan0_fwd - [0:0]
  124. :wlan0_in - [0:0]
  125. -A INPUT -m conntrack --ctstate INVALID,NEW -j dynamic
  126. -A INPUT -i eth0 -j eth0_in
  127. -A INPUT -i wlan0 -j wlan0_in
  128. -A INPUT -i tun0 -j vpn2fw
  129. -A INPUT -i tap0 -j vpn2fw
  130. -A INPUT -i lo -j ACCEPT
  131. -A INPUT -j Reject
  132. -A INPUT -j ULOG --ulog-prefix "Shorewall:INPUT:REJECT:"
  133. -A INPUT -g reject
  134. -A FORWARD -i eth0 -j eth0_fwd
  135. -A FORWARD -i wlan0 -j wlan0_fwd
  136. -A FORWARD -i tun0 -j vpn_frwd
  137. -A FORWARD -i tap0 -j vpn_frwd
  138. -A FORWARD -j Reject
  139. -A FORWARD -j ULOG --ulog-prefix "Shorewall:FORWARD:REJECT:"
  140. -A FORWARD -g reject
  141. -A OUTPUT -o eth0 -j fw2net
  142. -A OUTPUT -o wlan0 -j fw2net
  143. -A OUTPUT -o tun0 -j fw2vpn
  144. -A OUTPUT -o tap0 -j fw2vpn
  145. -A OUTPUT -o lo -j ACCEPT
  146. -A OUTPUT -j Reject
  147. -A OUTPUT -j ULOG --ulog-prefix "Shorewall:OUTPUT:REJECT:"
  148. -A OUTPUT -g reject
  149. -A Drop
  150. -A Drop -p tcp -m tcp --dport 113 -m comment --comment "Auth" -j reject
  151. -A Drop -j dropBcast
  152. -A Drop -p icmp -m icmp --icmp-type 3/4 -m comment --comment "Needed ICMP types" -j ACCEPT
  153. -A Drop -p icmp -m icmp --icmp-type 11 -m comment --comment "Needed ICMP types" -j ACCEPT
  154. -A Drop -j dropInvalid
  155. -A Drop -p udp -m multiport --dports 135,445 -m comment --comment "SMB" -j DROP
  156. -A Drop -p udp -m udp --dport 137:139 -m comment --comment "SMB" -j DROP
  157. -A Drop -p udp -m udp --sport 137 --dport 1024:65535 -m comment --comment "SMB" -j DROP
  158. -A Drop -p tcp -m multiport --dports 135,139,445 -m comment --comment "SMB" -j DROP
  159. -A Drop -p udp -m udp --dport 1900 -m comment --comment "UPnP" -j DROP
  160. -A Drop -p tcp -j dropNotSyn
  161. -A Drop -p udp -m udp --sport 53 -m comment --comment "Late DNS Replies" -j DROP
  162. -A Reject
  163. -A Reject -p tcp -m tcp --dport 113 -m comment --comment "Auth" -j reject
  164. -A Reject -j dropBcast
  165. -A Reject -p icmp -m icmp --icmp-type 3/4 -m comment --comment "Needed ICMP types" -j ACCEPT
  166. -A Reject -p icmp -m icmp --icmp-type 11 -m comment --comment "Needed ICMP types" -j ACCEPT
  167. -A Reject -j dropInvalid
  168. -A Reject -p udp -m multiport --dports 135,445 -m comment --comment "SMB" -j reject
  169. -A Reject -p udp -m udp --dport 137:139 -m comment --comment "SMB" -j reject
  170. -A Reject -p udp -m udp --sport 137 --dport 1024:65535 -m comment --comment "SMB" -j reject
  171. -A Reject -p tcp -m multiport --dports 135,139,445 -m comment --comment "SMB" -j reject
  172. -A Reject -p udp -m udp --dport 1900 -m comment --comment "UPnP" -j DROP
  173. -A Reject -p tcp -j dropNotSyn
  174. -A Reject -p udp -m udp --sport 53 -m comment --comment "Late DNS Replies" -j DROP
  175. -A dropBcast -m addrtype --dst-type BROADCAST -j DROP
  176. -A dropBcast -d 224.0.0.0/4 -j DROP
  177. -A dropInvalid -m conntrack --ctstate INVALID -j DROP
  178. -A dropNotSyn -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
  179. -A eth0_fwd -o eth0 -g sfilter
  180. -A eth0_fwd -m conntrack --ctstate INVALID,NEW -j dynamic
  181. -A eth0_fwd -m conntrack --ctstate INVALID,NEW -j smurfs
  182. -A eth0_fwd -p tcp -j tcpflags
  183. -A eth0_fwd -j net_frwd
  184. -A eth0_in -m conntrack --ctstate INVALID,NEW -j dynamic
  185. -A eth0_in -m conntrack --ctstate INVALID,NEW -j smurfs
  186. -A eth0_in -p udp -m udp --dport 67:68 -j ACCEPT
  187. -A eth0_in -p tcp -j tcpflags
  188. -A eth0_in -j net2fw
  189. -A fw2net -p udp -m udp --dport 67:68 -j ACCEPT
  190. -A fw2net -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  191. -A fw2net -j ACCEPT
  192. -A fw2vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  193. -A fw2vpn -j ACCEPT
  194. -A logdrop -j DROP
  195. -A logflags -j ULOG --ulog-prefix "Shorewall:logflags:DROP:"
  196. -A logflags -j DROP
  197. -A logreject -j reject
  198. -A net2fw -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  199. -A net2fw -p tcp -m tcp --dport 113 -j DROP
  200. -A net2fw -j Drop
  201. -A net2fw -j ULOG --ulog-prefix "Shorewall:net2fw:DROP:"
  202. -A net2fw -j DROP
  203. -A net2vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  204. -A net2vpn -j Drop
  205. -A net2vpn -j ULOG --ulog-prefix "Shorewall:net2vpn:DROP:"
  206. -A net2vpn -j DROP
  207. -A net_frwd -o tun0 -j net2vpn
  208. -A net_frwd -o tap0 -j net2vpn
  209. -A reject -m addrtype --src-type BROADCAST -j DROP
  210. -A reject -s 224.0.0.0/4 -j DROP
  211. -A reject -p igmp -j DROP
  212. -A reject -p tcp -j REJECT --reject-with tcp-reset
  213. -A reject -p udp -j REJECT --reject-with icmp-port-unreachable
  214. -A reject -p icmp -j REJECT --reject-with icmp-host-unreachable
  215. -A reject -j REJECT --reject-with icmp-host-prohibited
  216. -A sfilter -j ULOG --ulog-prefix "Shorewall:sfilter:DROP:"
  217. -A sfilter -j DROP
  218. -A smurflog -j ULOG --ulog-prefix "Shorewall:smurfs:DROP:"
  219. -A smurflog -j DROP
  220. -A smurfs -s 0.0.0.0/32 -j RETURN
  221. -A smurfs -m addrtype --src-type BROADCAST -g smurflog
  222. -A smurfs -s 224.0.0.0/4 -g smurflog
  223. -A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g logflags
  224. -A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g logflags
  225. -A tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g logflags
  226. -A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g logflags
  227. -A tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g logflags
  228. -A vpn2fw -m conntrack --ctstate INVALID,NEW -j dynamic
  229. -A vpn2fw -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  230. -A vpn2fw -j Reject
  231. -A vpn2fw -j ULOG --ulog-prefix "Shorewall:vpn2fw:REJECT:"
  232. -A vpn2fw -g reject
  233. -A vpn2net -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  234. -A vpn2net -j Reject
  235. -A vpn2net -j ULOG --ulog-prefix "Shorewall:vpn2net:REJECT:"
  236. -A vpn2net -g reject
  237. -A vpn_frwd -o tun0 -g sfilter
  238. -A vpn_frwd -o tap0 -g sfilter
  239. -A vpn_frwd -m conntrack --ctstate INVALID,NEW -j dynamic
  240. -A vpn_frwd -o eth0 -j vpn2net
  241. -A vpn_frwd -o wlan0 -j vpn2net
  242. -A vpn_frwd -o tun0 -j ACCEPT
  243. -A vpn_frwd -o tap0 -j ACCEPT
  244. -A wlan0_fwd -o wlan0 -g sfilter
  245. -A wlan0_fwd -m conntrack --ctstate INVALID,NEW -j dynamic
  246. -A wlan0_fwd -m conntrack --ctstate INVALID,NEW -j smurfs
  247. -A wlan0_fwd -p tcp -j tcpflags
  248. -A wlan0_fwd -j net_frwd
  249. -A wlan0_in -m conntrack --ctstate INVALID,NEW -j dynamic
  250. -A wlan0_in -m conntrack --ctstate INVALID,NEW -j smurfs
  251. -A wlan0_in -p udp -m udp --dport 67:68 -j ACCEPT
  252. -A wlan0_in -p tcp -j tcpflags
  253. -A wlan0_in -j net2fw
  254. COMMIT
  255. # Completed on Thu Jul 21 14:37:52 2011