Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- @RT-AC66U-F080:/tmp/home/root$ cat /tmp/filter_rules_ipv6
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :PControls - [0:0]
- :logaccept - [0:0]
- :logdrop - [0:0]
- -A INPUT -m rt --rt-type 0 -j DROP
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -m state --state NEW -j ACCEPT
- -A INPUT -i br0 -m state --state NEW -j ACCEPT
- -A FORWARD -m rt --rt-type 0 -j DROP
- -A FORWARD -o eth0 ! -i br0 -j DROP
- -A FORWARD -m state --state INVALID -j DROP
- -A FORWARD -i br0 -o br0 -j ACCEPT
- -A FORWARD -p ipv6-nonxt -m length --length 40 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 1 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 2 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 3 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 4 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 128 -j ACCEPT
- -A FORWARD -p ipv6-icmp --icmpv6-type 129 -j ACCEPT
- -A INPUT -p ipv6-nonxt -m length --length 40 -j ACCEPT
- -A INPUT -i br0 -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 1 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 2 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 3 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 4 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 128 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 129 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 130 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 131 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 132 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 133 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 134 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 135 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 136 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 141 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 142 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 143 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 148 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 149 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 151 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 152 -j ACCEPT
- -A INPUT -p ipv6-icmp --icmpv6-type 153 -j ACCEPT
- -A INPUT -j DROP
- -A OUTPUT -m rt --rt-type 0 -j DROP
- -A PControls -j ACCEPT
- -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
- -A logaccept -j ACCEPT
- -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
- -A logdrop -j DROP
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement