Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- linux-w43c:~ # SuSEfirewall2 status
- ### iptables filter ###
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- 9 612 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate ESTABLISHED
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED
- 0 0 input_int all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 1 28 input_ext all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-IN-ILL-TARGET "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 TCPMSS tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 TCPMSS clamp to PMTU
- 0 0 forward_int all -- eth1 * 0.0.0.0/0 0.0.0.0/0
- 0 0 forward_ext all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 forward_ext all -- eth2 * 0.0.0.0/0 0.0.0.0/0
- 0 0 forward_ext all -- eth3 * 0.0.0.0/0 0.0.0.0/0
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWD-ILL-ROUTING "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 6 packets, 696 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
- Chain forward_ext (3 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 3
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 11
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 12
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 14
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 18
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 3 code 2
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 5
- 0 0 ACCEPT all -- eth0 eth1 0.0.0.0/0 192.168.10.2 ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT all -- eth2 eth1 0.0.0.0/0 192.168.10.2 ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT all -- eth3 eth1 0.0.0.0/0 192.168.10.2 ctstate RELATED,ESTABLISHED
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = multicast
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain forward_int (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 0
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 3
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 11
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 12
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 14
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 18
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 3 code 2
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED icmptype 5
- 0 0 ACCEPT all -- eth1 eth0 192.168.10.2 0.0.0.0/0 ctstate NEW,RELATED,ESTABLISHED
- 0 0 ACCEPT all -- eth1 eth2 192.168.10.2 0.0.0.0/0 ctstate NEW,RELATED,ESTABLISHED
- 0 0 ACCEPT all -- eth1 eth3 192.168.10.2 0.0.0.0/0 ctstate NEW,RELATED,ESTABLISHED
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = multicast
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 reject_func all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain input_ext (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 4
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:1028 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1028
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:80 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:443 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp dpt:22 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:80
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:443
- 1 28 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = multicast
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 PKTTYPE = broadcast
- 0 0 LOG tcp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 LOG icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 LOG udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain input_int (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain reject_func (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
- 0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-proto-unreachable
- ### iptables nat ###
- Chain PREROUTING (policy ACCEPT 1 packets, 28 bytes)
- pkts bytes target prot opt in out source destination
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy ACCEPT 1 packets, 148 bytes)
- pkts bytes target prot opt in out source destination
- Chain POSTROUTING (policy ACCEPT 1 packets, 148 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 MASQUERADE all -- * eth0 192.168.10.2 0.0.0.0/0
- 0 0 MASQUERADE all -- * eth2 192.168.10.2 0.0.0.0/0
- 0 0 MASQUERADE all -- * eth3 192.168.10.2 0.0.0.0/0
- ### iptables raw ###
- Chain PREROUTING (policy ACCEPT 55 packets, 2980 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 CT all -- lo * 0.0.0.0/0 0.0.0.0/0 CT notrack
- Chain OUTPUT (policy ACCEPT 53 packets, 15972 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 CT all -- * lo 0.0.0.0/0 0.0.0.0/0 CT notrack
- ### ip6tables filter ###
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all lo * ::/0 ::/0
- 0 0 ACCEPT all * * ::/0 ::/0 ctstate ESTABLISHED
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED
- 0 0 input_int all eth1 * ::/0 ::/0
- 0 0 input_ext all * * ::/0 ::/0
- 0 0 LOG all * * ::/0 ::/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-IN-ILL-TARGET "
- 0 0 DROP all * * ::/0 ::/0
- Chain FORWARD (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 forward_int all eth1 * ::/0 ::/0
- 0 0 forward_ext all eth0 * ::/0 ::/0
- 0 0 forward_ext all eth2 * ::/0 ::/0
- 0 0 forward_ext all eth3 * ::/0 ::/0
- 0 0 LOG all * * ::/0 ::/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWD-ILL-ROUTING "
- 0 0 DROP all * * ::/0 ::/0
- Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all * lo ::/0 ::/0
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0
- Chain forward_ext (3 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 129
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 1
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 2
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 3
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 4
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 LOG icmpv6 * * ::/0 ::/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 LOG udp * * ::/0 ::/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-FWDext-DROP-DEFLT "
- 0 0 DROP all * * ::/0 ::/0
- Chain forward_int (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 129
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 1
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 2
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 3
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ctstate RELATED,ESTABLISHED ipv6-icmptype 4
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 LOG icmpv6 * * ::/0 ::/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 LOG udp * * ::/0 ::/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-FWDint-DROP-DEFLT "
- 0 0 reject_func all * * ::/0 ::/0
- Chain input_ext (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 128
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 133
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 134
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 135
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 136
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 137
- 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 130
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp dpt:1028 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:1028
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp dpt:80 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:80
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp dpt:443 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:443
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp dpt:22 flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-ACC-TCP "
- 0 0 ACCEPT tcp * * ::/0 ::/0 tcp dpt:22
- 0 0 ACCEPT udp * * ::/0 ::/0 udp dpt:80
- 0 0 ACCEPT udp * * ::/0 ::/0 udp dpt:443
- 0 0 LOG tcp * * ::/0 ::/0 limit: avg 3/min burst 5 tcp flags:0x17/0x02 LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 LOG icmpv6 * * ::/0 ::/0 limit: avg 3/min burst 5 LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 LOG udp * * ::/0 ::/0 limit: avg 3/min burst 5 ctstate NEW LOG flags 6 level 4 prefix "SFW2-INext-DROP-DEFLT "
- 0 0 DROP all * * ::/0 ::/0
- Chain input_int (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all * * ::/0 ::/0
- Chain reject_func (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 REJECT tcp * * ::/0 ::/0 reject-with tcp-reset
- 0 0 REJECT udp * * ::/0 ::/0 reject-with icmp6-port-unreachable
- 0 0 REJECT all * * ::/0 ::/0 reject-with icmp6-addr-unreachable
- 0 0 DROP all * * ::/0 ::/0
- ### ip6tables mangle ###
- Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- ### ip6tables raw ###
- Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 CT all lo * ::/0 ::/0 CT notrack
- Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 CT all * lo ::/0 ::/0 CT notrack
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement