Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /sbin/iptables -P INPUT DROP
- /sbin/iptables -A INPUT -i lo -j ACCEPT
- /sbin/iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- /sbin/iptables -A INPUT -i eth0 -s 192.168.1.0/24 -j ACCEPT
- /sbin/iptables -A INPUT -i eth0 -s 192.168.10.0/24 -j ACCEPT
- /sbin/iptables -A OUTPUT -o eth0 -d 192.168.1.0/24 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- /sbin/iptables -A OUTPUT -o eth0 -d 192.168.10.0/24 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- /sbin/iptables -A OUTPUT -o eth0 -d 192.168.1.0/24 -p udp --sport 68 --dport 67 -j ACCEPT
- /bin/grep -h '^remote ' /etc/openvpn/*.conf | /usr/bin/cut -d ' ' -f 2 | /usr/bin/sort -du | /usr/bin/xargs -I @ /sbin/iptables -A OUTPUT -d @ -j ACCEPT
- /sbin/iptables -A OUTPUT -o eth0 -j REJECT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement