Advertisement
casaper

filter_ipv6.default

Jan 22nd, 2015
248
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 0.70 KB | None | 0 0
  1. *filter
  2. :INPUT DROP [0:0]
  3. :FORWARD DROP [0:0]
  4. :OUTPUT ACCEPT [0:0]
  5. :logaccept - [0:0]
  6. :logdrop - [0:0]
  7. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  8. -A INPUT -m state --state INVALID -j DROP
  9. -A INPUT -i lo -m state --state NEW -j ACCEPT
  10. -A INPUT -i br0 -m state --state NEW -j ACCEPT
  11. -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
  12. -A FORWARD -i br0 -o br0 -j ACCEPT
  13. -A FORWARD -i lo -o lo -j ACCEPT
  14. -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
  15. -A logaccept -j ACCEPT
  16. -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
  17. -A logdrop -j DROP
  18. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement