Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- utm:/var/mdw/etc/iptables # cat ip6table.filter
- # Generated by ip6tables-save v1.4.4 on Mon Feb 1 14:28:25 2010
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :GEOIP_REJECT - [0:0]
- :GEOIP_OUT - [0:0]
- :AUTO_FORWARD - [0:0]
- :AUTO_INPUT - [0:0]
- :AUTO_OUTPUT - [0:0]
- :HA_OUT - [0:0]
- :LOCKOUT - [0:0]
- :INVALID_PKT - [0:0]
- :LOGACCEPT - [0:0]
- :LOGDROP - [0:0]
- :LOGREJECT - [0:0]
- :PSD_ACTION - [0:0]
- :PSD_MATCH - [0:0]
- :RELATED_FWD - [0:0]
- :SANITY_CHECKS - [0:0]
- :STRICT_TCP_DROP - [0:0]
- :STRICT_TCP_STATE - [0:0]
- :USR_FORWARD - [0:0]
- :USR_INPUT - [0:0]
- :USR_OUTPUT - [0:0]
- -A INPUT -i lo -j ACCEPT
- -A INPUT -m confirmed ! -d ff00::/8 -j ACCEPT
- -A INPUT -m conntrack --ctstate RELATED -j CONFIRMED
- -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type 135/0 -j ACCEPT
- -A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type 136/0 -j ACCEPT
- -A INPUT -j LOCKOUT
- -A INPUT -j PSD_MATCH
- -A INPUT -j SANITY_CHECKS
- -A INPUT -j AUTO_INPUT
- -A INPUT -j USR_INPUT
- -A INPUT -m logmark --logmark 60001 -j LOGDROP
- -A FORWARD -m confirmed ! -d ff00::/8 -j ACCEPT
- -A FORWARD -m conntrack --ctstate RELATED -j RELATED_FWD
- -A FORWARD -j PSD_MATCH
- -A FORWARD -j SANITY_CHECKS
- -A FORWARD -j AUTO_FORWARD
- -A FORWARD -j USR_FORWARD
- -A FORWARD ! -o eth2 -p tcp --tcp-flags SYN,ACK,FIN ACK,FIN -j DROP
- -A FORWARD ! -o eth2 -p tcp --tcp-flags SYN,RST RST -j DROP
- -A FORWARD -m logmark --logmark 60002 -j LOGDROP
- -A OUTPUT -o lo -j ACCEPT
- -A OUTPUT -m confirmed ! -d ff00::/8 -j ACCEPT
- -A OUTPUT -j HA_OUT
- -A OUTPUT -m conntrack --ctstate RELATED -j CONFIRMED
- -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type 135/0 -j ACCEPT
- -A OUTPUT -p ipv6-icmp -m icmp6 --icmpv6-type 136/0 -j ACCEPT
- # NUTM-10626: The dehydrated output rules are unconditional because Middleware would try to connect outbound before creating the rules
- -A OUTPUT -p tcp -m tcp --sport 1:65535 --dport 443 -m owner --uid-owner dehydrated --gid-owner dehydrated -j CONFIRMED
- -A OUTPUT -j SANITY_CHECKS
- -A OUTPUT -j AUTO_OUTPUT
- -A OUTPUT -j USR_OUTPUT
- -A OUTPUT -m logmark --logmark 60003 -j LOGDROP
- -A INVALID_PKT -m logmark --logmark 60007 -j NFLOG --nflog-prefix "INVALID_PKT: "
- -A INVALID_PKT -j DROP
- -A STRICT_TCP_DROP -j DROP
- -A LOGACCEPT -j NFLOG --nflog-prefix "ACCEPT: "
- -A LOGACCEPT -j CONFIRMED
- -A LOGDROP -j NFLOG --nflog-prefix "DROP: "
- -A LOGDROP -j DROP
- -A LOGREJECT -j NFLOG --nflog-prefix "REJECT: "
- -A LOGREJECT -j REJECT --reject-with icmp6-port-unreachable
- -A GEOIP_REJECT -p tcp -j REJECT --reject-with tcp-reset
- -A GEOIP_REJECT -j REJECT --reject-with icmp6-port-unreachable
- -A RELATED_FWD -j CONFIRMED
- COMMIT
- # Completed on Mon Feb 1 14:28:25 2010
Advertisement
Add Comment
Please, Sign In to add comment