Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- *nat
- :PREROUTING ACCEPT [7:931]
- :INPUT ACCEPT [7:931]
- :OUTPUT ACCEPT [17:1300]
- :POSTROUTING ACCEPT [17:1300]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_FedoraWorkstation - [0:0]
- :POST_FedoraWorkstation_allow - [0:0]
- :POST_FedoraWorkstation_deny - [0:0]
- :POST_FedoraWorkstation_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraWorkstation - [0:0]
- :PRE_FedoraWorkstation_allow - [0:0]
- :PRE_FedoraWorkstation_deny - [0:0]
- :PRE_FedoraWorkstation_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- -A POSTROUTING -j POSTROUTING_direct
- -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- -A POSTROUTING -j POSTROUTING_ZONES
- -A POSTROUTING_ZONES -o virbr0 -g POST_FedoraWorkstation
- -A POSTROUTING_ZONES -o eno16777736 -g POST_FedoraWorkstation
- -A POSTROUTING_ZONES -g POST_FedoraWorkstation
- -A POST_FedoraWorkstation -j POST_FedoraWorkstation_log
- -A POST_FedoraWorkstation -j POST_FedoraWorkstation_deny
- -A POST_FedoraWorkstation -j POST_FedoraWorkstation_allow
- -A PREROUTING_ZONES -i virbr0 -g PRE_FedoraWorkstation
- -A PREROUTING_ZONES -i eno16777736 -g PRE_FedoraWorkstation
- -A PREROUTING_ZONES -g PRE_FedoraWorkstation
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_log
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_deny
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_allow
- COMMIT
- # Completed on Tue Mar 31 21:10:51 2015
- # Generated by iptables-save v1.4.21 on Tue Mar 31 21:10:51 2015
- *mangle
- :PREROUTING ACCEPT [120:10097]
- :INPUT ACCEPT [120:10097]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [75:5866]
- :POSTROUTING ACCEPT [81:6544]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraWorkstation - [0:0]
- :PRE_FedoraWorkstation_allow - [0:0]
- :PRE_FedoraWorkstation_deny - [0:0]
- :PRE_FedoraWorkstation_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A POSTROUTING -j POSTROUTING_direct
- -A PREROUTING_ZONES -i virbr0 -g PRE_FedoraWorkstation
- -A PREROUTING_ZONES -i eno16777736 -g PRE_FedoraWorkstation
- -A PREROUTING_ZONES -g PRE_FedoraWorkstation
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_log
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_deny
- -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_allow
- COMMIT
- # Completed on Tue Mar 31 21:10:51 2015
- # Generated by iptables-save v1.4.21 on Tue Mar 31 21:10:51 2015
- *security
- :INPUT ACCEPT [140:12649]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [102:8698]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Tue Mar 31 21:10:51 2015
- # Generated by iptables-save v1.4.21 on Tue Mar 31 21:10:51 2015
- *raw
- :PREROUTING ACCEPT [141:12977]
- :OUTPUT ACCEPT [102:8698]
- :OUTPUT_direct - [0:0]
- :PREROUTING_direct - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Tue Mar 31 21:10:51 2015
- # Generated by iptables-save v1.4.21 on Tue Mar 31 21:10:51 2015
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [75:5866]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_FedoraWorkstation - [0:0]
- :FWDI_FedoraWorkstation_allow - [0:0]
- :FWDI_FedoraWorkstation_deny - [0:0]
- :FWDI_FedoraWorkstation_log - [0:0]
- :FWDO_FedoraWorkstation - [0:0]
- :FWDO_FedoraWorkstation_allow - [0:0]
- :FWDO_FedoraWorkstation_deny - [0:0]
- :FWDO_FedoraWorkstation_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_FedoraWorkstation - [0:0]
- :IN_FedoraWorkstation_allow - [0:0]
- :IN_FedoraWorkstation_deny - [0:0]
- :IN_FedoraWorkstation_log - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -j INPUT_direct
- -A INPUT -j INPUT_ZONES_SOURCE
- -A INPUT -j INPUT_ZONES
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -m conntrack --ctstate INVALID -j DROP
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
- -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i lo -j ACCEPT
- -A FORWARD -j FORWARD_direct
- -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- -A FORWARD -j FORWARD_IN_ZONES
- -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- -A FORWARD -j FORWARD_OUT_ZONES
- -A FORWARD -p icmp -j ACCEPT
- -A FORWARD -m conntrack --ctstate INVALID -j DROP
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
- -A OUTPUT -j OUTPUT_direct
- -A FORWARD_IN_ZONES -i virbr0 -g FWDI_FedoraWorkstation
- -A FORWARD_IN_ZONES -i eno16777736 -g FWDI_FedoraWorkstation
- -A FORWARD_IN_ZONES -g FWDI_FedoraWorkstation
- -A FORWARD_OUT_ZONES -o virbr0 -g FWDO_FedoraWorkstation
- -A FORWARD_OUT_ZONES -o eno16777736 -g FWDO_FedoraWorkstation
- -A FORWARD_OUT_ZONES -g FWDO_FedoraWorkstation
- -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_log
- -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_deny
- -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_allow
- -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_log
- -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_deny
- -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_allow
- -A INPUT_ZONES -i virbr0 -g IN_FedoraWorkstation
- -A INPUT_ZONES -i eno16777736 -g IN_FedoraWorkstation
- -A INPUT_ZONES -g IN_FedoraWorkstation
- -A IN_FedoraWorkstation -j IN_FedoraWorkstation_log
- -A IN_FedoraWorkstation -j IN_FedoraWorkstation_deny
- -A IN_FedoraWorkstation -j IN_FedoraWorkstation_allow
- -A IN_FedoraWorkstation_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraWorkstation_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraWorkstation_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraWorkstation_allow -p udp -m udp --dport 1025:65535 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 1025:65535 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement