Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/sh
- # Flushing all rules
- iptables -F
- iptables -X
- # Setting default filter policy
- iptables -P INPUT DROP
- iptables -P OUTPUT DROP
- iptables -P FORWARD DROP
- # Allow unlimited traffic on loopback
- iptables -A INPUT -i lo -j ACCEPT
- iptables -A OUTPUT -o lo -j ACCEPT
- # Allow incoming ssh only
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 22 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming http only
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 80 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming https only
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 443 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming plesk only ???????????????????
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 8443 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 8443 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming ftp only
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 21 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 21 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming mysql only
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 3306 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 3306 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming teamspeak only 9987 udp / 30033 tcp
- iptables -A INPUT -p udp -i eth0 --sport 513:65535 --dport 9987 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A INPUT -p tcp -i eth0 --sport 513:65535 --dport 30033 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -i eth0 --sport 9987 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -i eth0 --sport 30033 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # Allow incoming bukkit only
- iptables -A INPUT -p udp -i eth0 --sport 513:65535 --dport 25565 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -i eth0 --sport 25565 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- # make sure nothing comes or goes out of this box
- iptables -A INPUT -j DROP
- iptables -A OUTPUT -j DROP
Advertisement
Add Comment
Please, Sign In to add comment