Advertisement
Guest User

Untitled

a guest
Feb 11th, 2016
54
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.99 KB | None | 0 0
  1. -P INPUT ACCEPT
  2. -P FORWARD ACCEPT
  3. -P OUTPUT ACCEPT
  4. -N nova-api-FORWARD
  5. -N nova-api-INPUT
  6. -N nova-api-OUTPUT
  7. -N nova-api-local
  8. -N nova-filter-top
  9. -A INPUT -j nova-api-INPUT
  10. -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
  11. -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
  12. -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
  13. -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
  14. -A FORWARD -j nova-filter-top
  15. -A FORWARD -j nova-api-FORWARD
  16. -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  17. -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
  18. -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
  19. -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
  20. -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
  21. -A OUTPUT -j nova-filter-top
  22. -A OUTPUT -j nova-api-OUTPUT
  23. -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
  24. -A nova-api-INPUT -d 10.0.2.15/32 -p tcp -m tcp --dport 8775 -j ACCEPT
  25. -A nova-filter-top -j nova-api-local
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement