Advertisement
ShapeShifter499

/etc/default/iptables

Jun 6th, 2013
92
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.52 KB | None | 0 0
  1.  
  2. *nat
  3. :PREROUTING ACCEPT [249:15581]
  4. :INPUT ACCEPT [9:571]
  5. :OUTPUT ACCEPT [38:2445]
  6. :POSTROUTING ACCEPT [15:1005]
  7.  
  8. # REQUIRED IPTABLES RULES FOR ETH0 IP MASQUERADING (enable only if not using a vpn)
  9.  
  10. -A POSTROUTING -o eth0 -j MASQUERADE
  11.  
  12. COMMIT
  13.  
  14. *filter
  15. :INPUT DROP [0:0]
  16. :FORWARD DROP [0:0]
  17. :OUTPUT ACCEPT [0:0]
  18.  
  19. # REQIRED IPTABLES RULES FOR IODINE (enable only if not using a vpn)
  20.  
  21. -A FORWARD -i eth0 -o dns+ -m state --state RELATED,ESTABLISHED -j ACCEPT
  22. -A FORWARD -i dns+ -o eth0 -j ACCEPT
  23.  
  24. # REQUIRED IPTABLES RULES FOR WIFI ROUTER
  25.  
  26. -A FORWARD -i wlan0 -j ACCEPT
  27.  
  28. # Keep state.
  29. -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
  30.  
  31. # Loop device.
  32. -A INPUT -i lo -j ACCEPT
  33.  
  34. # http, https
  35. -A INPUT -p tcp --dport 80 -j ACCEPT
  36. -A INPUT -p tcp --dport 443 -j ACCEPT
  37.  
  38. # smtp, submission
  39. -A INPUT -p tcp --dport 25 -j ACCEPT
  40. -A INPUT -p tcp --dport 587 -j ACCEPT
  41.  
  42. # pop3, pop3s
  43. -A INPUT -p tcp --dport 110 -j ACCEPT
  44. -A INPUT -p tcp --dport 995 -j ACCEPT
  45.  
  46. # imap, imaps
  47. -A INPUT -p tcp --dport 143 -j ACCEPT
  48. -A INPUT -p tcp --dport 993 -j ACCEPT
  49.  
  50. # ssh
  51. -A INPUT -p tcp --dport 22 -j ACCEPT
  52.  
  53. # Allow PING from remote hosts.
  54. -A INPUT -p icmp --icmp-type echo-request -j ACCEPT
  55.  
  56. # ejabberd
  57. #-A INPUT -p tcp --dport 5222 -j ACCEPT
  58. #-A INPUT -p tcp --dport 5223 -j ACCEPT
  59. #-A INPUT -p tcp --dport 5280 -j ACCEPT
  60.  
  61. # ldap/ldaps
  62. #-A INPUT -p tcp --dport 389 -j ACCEPT
  63. #-A INPUT -p tcp --dport 636 -j ACCEPT
  64.  
  65. # ftp.
  66. #-A INPUT -p tcp --dport 20 -j ACCEPT
  67. #-A INPUT -p tcp --dport 21 -j ACCEPT
  68.  
  69. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement