bootscreen

Untitled

Mar 13th, 2012
52
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.51 KB | None | 0 0
  1. #!/bin/sh
  2.  
  3. # Flushing all rules
  4. iptables -F
  5. iptables -X
  6. # Setting default filter policy
  7. iptables -P INPUT DROP
  8. iptables -P OUTPUT DROP
  9. iptables -P FORWARD DROP
  10. # Allow unlimited traffic on loopback
  11. iptables -A INPUT -i lo -j ACCEPT
  12. iptables -A OUTPUT -o lo -j ACCEPT
  13.  
  14. # Allow incoming ssh only
  15. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
  16. iptables -A OUTPUT -p tcp -i eth0 --sport 22 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  17. # Allow incoming http only
  18. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
  19. iptables -A OUTPUT -p tcp -i eth0 --sport 80 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  20. # Allow incoming https only
  21. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
  22. iptables -A OUTPUT -p tcp -i eth0 --sport 443 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  23. # Allow incoming plesk only ???????????????????
  24. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 8443 -m state --state NEW,ESTABLISHED -j ACCEPT
  25. iptables -A OUTPUT -p tcp -i eth0 --sport 8443 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  26. # Allow incoming ftp only
  27. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 21 -m state --state NEW,ESTABLISHED -j ACCEPT
  28. iptables -A OUTPUT -p tcp -i eth0 --sport 21 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  29. # Allow incoming mysql only
  30. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 3306 -m state --state NEW,ESTABLISHED -j ACCEPT
  31. iptables -A OUTPUT -p tcp -i eth0 --sport 3306 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  32. # Allow incoming teamspeak only 9987 udp / 30033 tcp
  33. iptables -A INPUT -p udp -i eth0 --sport 513:65535 --dport 9987 -m state --state NEW,ESTABLISHED -j ACCEPT
  34. iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 30033 -m state --state NEW,ESTABLISHED -j ACCEPT
  35. iptables -A OUTPUT -p udp -i eth0 --sport 9987 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  36. iptables -A OUTPUT -p tcp -i eth0 --sport 30033 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  37. # Allow incoming bukkit only
  38. iptables -A INPUT -p udp -i eth0 --sport 513:65535 --dport 25565 -m state --state NEW,ESTABLISHED -j ACCEPT
  39. iptables -A OUTPUT -p udp -i eth0 --sport 25565 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
  40.  
  41. # make sure nothing comes or goes out of this box
  42. iptables -A INPUT -j DROP
  43. iptables -A OUTPUT -j DROP
Advertisement
Add Comment
Please, Sign In to add comment