Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.12.1 on Wed Nov 14 14:00:46 2012
- *filter
- :INPUT DROP [7:2651]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [1015:329997]
- [142:10072] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- [0:0] -A INPUT -d myip/32 -p tcp -m tcp --dport 3389 -j ACCEPT
- [0:0] -A INPUT -p udp -m udp --dport 1194 -m comment --comment "openvpn server" -j ACCEPT
- [0:0] -A INPUT -s 127.0.0.1/32 -d 127.0.0.1/32 -m comment --comment "Vajno loopback" -j ACCEPT
- [373:76200] -A INPUT -d 192.168.137.1/32 -j ACCEPT
- [0:0] -A INPUT -p udp -m udp --dport 1194 -m comment --comment "Virtual connection server" -j ACCEPT
- [0:0] -A INPUT -p tcp -m multiport --dports 25,143,110,993 -m comment --comment Mail -j ACCEPT
- [0:0] -A INPUT -s 192.168.137.0/24 -j ACCEPT
- [389:243554] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -i eth0 -p icmp -j ACCEPT
- [0:0] -A FORWARD -i eth0 -p tcp -m multiport --ports 3389,389 -j ACCEPT
- [0:0] -A FORWARD -i tun+ -p tcp -m multiport --ports 3389,389 -j ACCEPT
- [0:0] -A FORWARD -p tcp -m tcp --dport 445 -j DROP
- [0:0] -A FORWARD -s 10.20.11.0/24 -p tcp -m tcp --dport 3389 -m comment --comment "RDP for openvpn users" -j ACCEPT
- [488:37730] -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- [1:48] -A FORWARD -s 192.168.137.0/24 -p tcp -m multiport --dports 21,20,22,23,25,110,443,995,2802,3389,5190,8108,993 -j ACCEPT
- [0:0] -A FORWARD -s 192.168.137.0/24 -p udp -m multiport --dports 20,21,22,23,25,87,110,443,995,2802,3389,5190,8108 -j ACCEPT
- [16:776] -A FORWARD -s 192.168.137.0/24 -j DROP
- [0:0] -A FORWARD -m state --state INVALID -j DROP
- [0:0] -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- COMMIT
- # Completed on Wed Nov 14 14:00:46 2012
- # Generated by iptables-save v1.4.12.1 on Wed Nov 14 14:00:46 2012
- *nat
- :PREROUTING ACCEPT [103:7515]
- :INPUT ACCEPT [37:1864]
- :OUTPUT ACCEPT [48:3047]
- :POSTROUTING ACCEPT [48:3047]
- [1:48] -A POSTROUTING -s 192.168.137.0/24 -j MASQUERADE
- COMMIT
- # Completed on Wed Nov 14 14:00:46 2012
- # Generated by iptables-save v1.4.12.1 on Wed Nov 14 14:00:46 2012
- *raw
- :PREROUTING ACCEPT [1458:373207]
- :OUTPUT ACCEPT [1015:329997]
- COMMIT
- # Completed on Wed Nov 14 14:00:46 2012
- # Generated by iptables-save v1.4.12.1 on Wed Nov 14 14:00:46 2012
- *mangle
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- COMMIT
- # Completed on Wed Nov 14 14:00:46 2012
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement