Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@openvpn ~]# iptables-save -c
- # Generated by iptables-save v1.4.7 on Thu Jul 20 11:48:36 2017
- *filter
- :INPUT DROP [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [225972:122395062]
- [286624:138125884] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- [7:496] -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- [35:2020] -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- [812:50996] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --dport 53 -j ACCEPT
- [1:65] -A INPUT -p udp -m udp --dport 53 -j ACCEPT
- [1:76] -A INPUT -p udp -m udp --dport 123 -j ACCEPT
- [7:400] -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --dport 465 -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --dport 1194 -j ACCEPT
- [0:0] -A INPUT -p udp -m udp --dport 1194 -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --dport 1195 -j ACCEPT
- [2:140] -A INPUT -p udp -m udp --dport 1195 -j ACCEPT
- [66552:4014836] -A INPUT -p tcp -m tcp --dport 3128 -j ACCEPT
- [50:3133] -A INPUT -p tcp -m tcp --dport 10000 -j ACCEPT
- [0:0] -A INPUT -i lo -j ACCEPT
- [0:0] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
- [0:0] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
- [0:0] -A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
- [924:55934] -A INPUT -j DROP
- [0:0] -A FORWARD -s 172.8.0.0/24 -i tun0 -o eth0 -m conntrack --ctstate NEW -j ACCEPT
- [0:0] -A FORWARD -s 172.8.0.0/24 -i eth0 -o tun1 -m conntrack --ctstate NEW -j ACCEPT
- [48653:5418780] -A FORWARD -i tun1 -j ACCEPT
- [83876:101056349] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [2:100] -A OUTPUT -o lo -j ACCEPT
- COMMIT
- # Completed on Thu Jul 20 11:48:37 2017
- # Generated by iptables-save v1.4.7 on Thu Jul 20 11:48:37 2017
- *nat
- :PREROUTING ACCEPT [34658:1997213]
- :POSTROUTING ACCEPT [1221:96647]
- :OUTPUT ACCEPT [1244:153046]
- [572:34624] -A POSTROUTING -s 172.8.0.0/24 -o tun0 -j MASQUERADE
- [0:0] -A POSTROUTING -s 172.8.0.0/24 -o eth0 -j MASQUERADE
- [23:56399] -A POSTROUTING -o eth0 -j MASQUERADE
- COMMIT
- # Completed on Thu Jul 20 11:48:37 2017
- # Generated by iptables-save v1.4.7 on Thu Jul 20 11:48:37 2017
- *mangle
- :PREROUTING ACCEPT [487639:248746161]
- :INPUT ACCEPT [355093:142266189]
- :FORWARD ACCEPT [132546:106479972]
- :OUTPUT ACCEPT [226026:122405357]
- :POSTROUTING ACCEPT [358572:228885329]
- COMMIT
- # Completed on Thu Jul 20 11:48:37 2017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement