Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.1 on Wed Jul 24 21:56:42 2019
- *nat
- :PREROUTING ACCEPT [377994:19702094]
- :INPUT ACCEPT [148170:8556315]
- :OUTPUT ACCEPT [937254:66470683]
- :POSTROUTING ACCEPT [937254:66470683]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_ZONES_SOURCE - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_FedoraServer - [0:0]
- :POST_FedoraServer_allow - [0:0]
- :POST_FedoraServer_deny - [0:0]
- :POST_FedoraServer_log - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraServer - [0:0]
- :PRE_FedoraServer_allow - [0:0]
- :PRE_FedoraServer_deny - [0:0]
- :PRE_FedoraServer_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -j POSTROUTING_direct
- -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
- -A POSTROUTING -j POSTROUTING_ZONES
- -A POSTROUTING_ZONES -o eth0 -g POST_FedoraServer
- -A POSTROUTING_ZONES -g POST_FedoraServer
- -A POST_FedoraServer -j POST_FedoraServer_log
- -A POST_FedoraServer -j POST_FedoraServer_deny
- -A POST_FedoraServer -j POST_FedoraServer_allow
- -A PREROUTING_ZONES -i eth0 -g PRE_FedoraServer
- -A PREROUTING_ZONES -g PRE_FedoraServer
- -A PRE_FedoraServer -j PRE_FedoraServer_log
- -A PRE_FedoraServer -j PRE_FedoraServer_deny
- -A PRE_FedoraServer -j PRE_FedoraServer_allow
- COMMIT
- # Completed on Wed Jul 24 21:56:42 2019
- # Generated by iptables-save v1.6.1 on Wed Jul 24 21:56:42 2019
- *mangle
- :PREROUTING ACCEPT [10607725:1606157929]
- :INPUT ACCEPT [10607724:1606157853]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [11282494:28313847804]
- :POSTROUTING ACCEPT [11282494:28313847804]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraServer - [0:0]
- :PRE_FedoraServer_allow - [0:0]
- :PRE_FedoraServer_deny - [0:0]
- :PRE_FedoraServer_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- -A POSTROUTING -j POSTROUTING_direct
- -A PREROUTING_ZONES -i eth0 -g PRE_FedoraServer
- -A PREROUTING_ZONES -g PRE_FedoraServer
- -A PRE_FedoraServer -j PRE_FedoraServer_log
- -A PRE_FedoraServer -j PRE_FedoraServer_deny
- -A PRE_FedoraServer -j PRE_FedoraServer_allow
- COMMIT
- # Completed on Wed Jul 24 21:56:42 2019
- # Generated by iptables-save v1.6.1 on Wed Jul 24 21:56:42 2019
- *raw
- :PREROUTING ACCEPT [10607725:1606157929]
- :OUTPUT ACCEPT [11282494:28313847804]
- :OUTPUT_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_ZONES_SOURCE - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraServer - [0:0]
- :PRE_FedoraServer_allow - [0:0]
- :PRE_FedoraServer_deny - [0:0]
- :PRE_FedoraServer_log - [0:0]
- -A PREROUTING -j PREROUTING_direct
- -A PREROUTING -j PREROUTING_ZONES_SOURCE
- -A PREROUTING -j PREROUTING_ZONES
- -A OUTPUT -j OUTPUT_direct
- -A PREROUTING_ZONES -i eth0 -g PRE_FedoraServer
- -A PREROUTING_ZONES -g PRE_FedoraServer
- -A PRE_FedoraServer -j PRE_FedoraServer_log
- -A PRE_FedoraServer -j PRE_FedoraServer_deny
- -A PRE_FedoraServer -j PRE_FedoraServer_allow
- COMMIT
- # Completed on Wed Jul 24 21:56:42 2019
- # Generated by iptables-save v1.6.1 on Wed Jul 24 21:56:42 2019
- *security
- :INPUT ACCEPT [10343291:1593154054]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [11282494:28313847804]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -j INPUT_direct
- -A FORWARD -j FORWARD_direct
- -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Wed Jul 24 21:56:42 2019
- # Generated by iptables-save v1.6.1 on Wed Jul 24 21:56:42 2019
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [11282494:28313847804]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_IN_ZONES_SOURCE - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_OUT_ZONES_SOURCE - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_FedoraServer - [0:0]
- :FWDI_FedoraServer_allow - [0:0]
- :FWDI_FedoraServer_deny - [0:0]
- :FWDI_FedoraServer_log - [0:0]
- :FWDO_FedoraServer - [0:0]
- :FWDO_FedoraServer_allow - [0:0]
- :FWDO_FedoraServer_deny - [0:0]
- :FWDO_FedoraServer_log - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_ZONES_SOURCE - [0:0]
- :INPUT_direct - [0:0]
- :IN_FedoraServer - [0:0]
- :IN_FedoraServer_allow - [0:0]
- :IN_FedoraServer_deny - [0:0]
- :IN_FedoraServer_log - [0:0]
- :OUTPUT_direct - [0:0]
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -j INPUT_direct
- -A INPUT -j INPUT_ZONES_SOURCE
- -A INPUT -j INPUT_ZONES
- -A INPUT -m conntrack --ctstate INVALID -j DROP
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i lo -j ACCEPT
- -A FORWARD -j FORWARD_direct
- -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- -A FORWARD -j FORWARD_IN_ZONES
- -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- -A FORWARD -j FORWARD_OUT_ZONES
- -A FORWARD -m conntrack --ctstate INVALID -j DROP
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A OUTPUT -j OUTPUT_direct
- -A FORWARD_IN_ZONES -i eth0 -g FWDI_FedoraServer
- -A FORWARD_IN_ZONES -g FWDI_FedoraServer
- -A FORWARD_OUT_ZONES -o eth0 -g FWDO_FedoraServer
- -A FORWARD_OUT_ZONES -g FWDO_FedoraServer
- -A FWDI_FedoraServer -j FWDI_FedoraServer_log
- -A FWDI_FedoraServer -j FWDI_FedoraServer_deny
- -A FWDI_FedoraServer -j FWDI_FedoraServer_allow
- -A FWDI_FedoraServer -p icmp -j ACCEPT
- -A FWDO_FedoraServer -j FWDO_FedoraServer_log
- -A FWDO_FedoraServer -j FWDO_FedoraServer_deny
- -A FWDO_FedoraServer -j FWDO_FedoraServer_allow
- -A INPUT_ZONES -i eth0 -g IN_FedoraServer
- -A INPUT_ZONES -g IN_FedoraServer
- -A IN_FedoraServer -j IN_FedoraServer_log
- -A IN_FedoraServer -j IN_FedoraServer_deny
- -A IN_FedoraServer -j IN_FedoraServer_allow
- -A IN_FedoraServer -p icmp -j ACCEPT
- -A IN_FedoraServer_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraServer_allow -p tcp -m tcp --dport 9090 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_FedoraServer_allow -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
- COMMIT
- # Completed on Wed Jul 24 21:56:42 2019
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement