Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- :logaccept - [0:0]
- :logdrop - [0:0]
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -m state --state INVALID -j DROP
- -A INPUT -i lo -m state --state NEW -j ACCEPT
- -A INPUT -i br0 -m state --state NEW -j ACCEPT
- -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A FORWARD -i br0 -o br0 -j ACCEPT
- -A FORWARD -i lo -o lo -j ACCEPT
- -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
- -A logaccept -j ACCEPT
- -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
- -A logdrop -j DROP
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement