Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/sh
- # IPS OF SYSTEM
- IP_MOFUKKA="23xxxxx8"
- IP_FRIZZLEFRIED="2xxx2"
- IP_TOMBERGCPA="23xxx"
- IP_THEWEEDNEXTDOOR="23xxx"
- IP_MOFUKKALAN="1xxx.1"
- #FLUSH ALL RULES
- iptables -F
- iptables -X
- #DEFAULT FILTER
- iptables -P INPUT DROP
- iptables -P OUTPUT DROP
- iptables -P FORWARD DROP
- #ALLOW ALL ON LO
- iptables -A INPUT -i lo -j ACCEPT
- iptables -A OUTPUT -o lo -j ACCEPT
- #ALLOW SSH
- #MOFUKKA
- iptables -A INPUT -p tcp -s 0/0 -d $IP_MOFUKKA --sport 513:65535 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -s $IP_MOFUKKA -d 0/0 --sport 22 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- #MOFUKKALAN
- iptables -A INPUT -p tcp -s 0/0 -d $IP_MOFUKKALAN --sport 513:65535 --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -s $IP_MOFUKKALAN -d 0/0 --sport 22 --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- #ALLOW DNS
- #MOFUKKA
- iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $IP_MOFUKKA --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_MOFUKKA --sport 53 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
- iptables -A INPUT -p udp -s 0/0 --sport 53 -d $IP_MOFUKKA --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_MOFUKKA --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT
- #FRIZZLEFRIED
- iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $IP_FRIZZLEFRIED --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_FRIZZLEFRIED --sport 53 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
- iptables -A INPUT -p udp -s 0/0 --sport 53 -d $IP_FRIZZLEFRIED --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_FRIZZLEFRIED --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT
- #MOFUKKALAN
- iptables -A INPUT -p udp -s 0/0 --sport 1024:65535 -d $IP_MOFUKKALAN --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_MOFUKKALAN --sport 53 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
- iptables -A INPUT -p udp -s 0/0 --sport 53 -d $IP_MOFUKKALAN --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p udp -s $IP_MOFUKKALAN --sport 53 -d 0/0 --dport 53 -m state --state ESTABLISHED -j ACCEPT
- #ALLOW ZENTYAL WEB ADMIN
- #MOFUKKA
- iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d $IP_MOFUKKA --dport 33137 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -s $IP_MOFUKKA --sport 31337 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
- #ALLOW MINECRAFT
- #THESHED
- iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d $IP_THEWEEDNEXTDOOR --dport 25565:25566 -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -s $IP_THEWEEDNEXTDOOR --sport 25565:25566 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT
- #PERMIT ALL ESTABLISHED AND RELATED
- iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
- #DROP REST
- iptables -A INPUT -j DROP
- iptables -A OUTPUT -j DROP
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement