Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- └─[0] <> sudo iptables -S
- -P INPUT ACCEPT
- -P FORWARD ACCEPT
- -P OUTPUT ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -s 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -p icmp -m state --state NEW -m icmp --icmp-type 8 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -m state --state NEW -j ACCEPT
- -A INPUT -s 96.126.119.66/32 -m state --state NEW -j ACCEPT
- -A INPUT -s 192.168.255.0/24 -m state --state NEW -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables_INPUT_denied: " --log-level 7
- -A INPUT -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
- -A INPUT -p udp -m udp --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 5000 -j ACCEPT
- -A INPUT -p udp -m udp --dport 5000 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 25 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 25 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 993 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 110 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 995 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A FORWARD -m limit --limit 5/min -j LOG --log-prefix "iptables_FORWARD_denied: " --log-level 7
- -A FORWARD -j REJECT --reject-with icmp-port-unreachable
- -A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT
- -A OUTPUT -p udp -m udp --dport 25 -j ACCEPT
- -A OUTPUT -p tcp -m tcp --dport 5000 -j ACCEPT
- -A OUTPUT -p udp -m udp --dport 5000 -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 25 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --dport 993 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --dport 110 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --dport 995 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement