Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@controller-0 ~]# cat /etc/sysconfig/iptables
- # sample configuration for iptables service
- # you can edit this manually or use system-config-firewall
- # please do not ask us to add additional ports/services to this default configuration
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 22 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp -s 0.0.0.0/0 --dport 22 -j ACCEPT
- -A INPUT -m state --state NEW -p all -s 192.168.0.0/22 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 5000 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 35357 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 5001 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 9292 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 9393 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 8774 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 6080 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 9696 -j ACCEPT
- -A INPUT -m state --state NEW -m udp -p udp --dport 4789 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 443 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 8004 -j ACCEPT
- -A INPUT -m state --state NEW -m tcp -p tcp --dport 8001 -j ACCEPT
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- COMMIT
- In memory Iptables output: (Just adding Partial output)
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- neutron-linuxbri-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8001 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8004 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:443 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 state NEW
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:4789 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9696 state NEW
- nova-api-INPUT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:6080 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:8774 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9393 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9292 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:5001 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:35357 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:5000 state NEW
- ACCEPT all -- 192.168.0.0/22 0.0.0.0/0 state NEW
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 state NEW
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
- REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- neutron-filter-top all -- 0.0.0.0/0 0.0.0.0/0
- neutron-linuxbri-FORWARD all -- 0.0.0.0/0 0.0.0.0/0
- nova-filter-top all -- 0.0.0.0/0 0.0.0.0/0
- nova-api-FORWARD all -- 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- neutron-filter-top all -- 0.0.0.0/0 0.0.0.0/0
- neutron-linuxbri-OUTPUT all -- 0.0.0.0/0 0.0.0.0/0
- nova-filter-top all -- 0.0.0.0/0 0.0.0.0/0
- nova-api-OUTPUT all -- 0.0.0.0/0 0.0.0.0/0
- Chain neutron-filter-top (2 references)
- target prot opt source destination
- neutron-linuxbri-local all -- 0.0.0.0/0 0.0.0.0/0
- Chain neutron-linuxbri-FORWARD (1 references)
- target prot opt source destination
- Chain neutron-linuxbri-INPUT (1 references)
- target prot opt source destination
- Chain neutron-linuxbri-OUTPUT (1 references)
- target prot opt source destination
- Chain neutron-linuxbri-local (1 references)
- target prot opt source destination
- Chain neutron-linuxbri-sg-chain (0 references)
- :
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement