Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- > iptables --list
- Chain INPUT (policy DROP)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- input_ext all -- anywhere anywhere
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-IN-ILL-TARGET '
- DROP all -- anywhere anywhere
- Chain FORWARD (policy DROP)
- target prot opt source destination
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWD-ILL-ROUTING '
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-OUT-ERROR '
- Chain forward_ext (0 references)
- target prot opt source destination
- Chain input_ext (1 references)
- target prot opt source destination
- DROP all -- anywhere anywhere PKTTYPE = broadcast
- ACCEPT icmp -- anywhere anywhere icmp source-quench
- ACCEPT icmp -- anywhere anywhere icmp echo-request
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp echo-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp destination-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp time-exceeded
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp parameter-problem
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp timestamp-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp address-mask-reply
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp protocol-unreachable
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp redirect
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:http flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC-TCP '
- ACCEPT tcp -- anywhere anywhere tcp dpt:http
- LOG tcp -- charon.pristop.si anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- charon.pristop.si anywhere tcp dpt:ssh
- LOG tcp -- 193.95.196.93 anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- 193.95.196.93 anywhere tcp dpt:ssh
- LOG tcp -- sij.si anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- sij.si anywhere tcp dpt:ssh
- LOG tcp -- 89-212-29-209.dynamic.dsl.t-2.net anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- 89-212-29-209.dynamic.dsl.t-2.net anywhere tcp dpt:ssh
- LOG tcp -- 194.152.23.251 anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- 194.152.23.251 anywhere tcp dpt:ssh
- LOG tcp -- 86.58.16.16 anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- 86.58.16.16 anywhere tcp dpt:ssh
- LOG tcp -- BSN-77-70-145.dsl.siol.net anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- BSN-77-70-145.dsl.siol.net anywhere tcp dpt:ssh
- LOG tcp -- clj29-101.dial-up.arnes.si anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- clj29-101.dial-up.arnes.si anywhere tcp dpt:ssh
- LOG tcp -- lk.84.20.252.48.dc.cable.static.lj-kabel.net anywhere tcp dpt:ssh state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- lk.84.20.252.48.dc.cable.static.lj-kabel.net anywhere tcp dpt:ssh
- LOG tcp -- charon.pristop.si anywhere tcp dpt:10050 state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- charon.pristop.si anywhere tcp dpt:10050
- LOG tcp -- charon.pristop.si anywhere tcp dpt:https state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- charon.pristop.si anywhere tcp dpt:https
- LOG tcp -- 193.95.196.85 anywhere tcp dpt:mysql state NEW limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-ACC '
- ACCEPT tcp -- 193.95.196.85 anywhere tcp dpt:mysql
- reject_func tcp -- anywhere anywhere tcp dpt:ident state NEW
- LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT '
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-INext-DROP-DEFLT-INV '
- DROP all -- anywhere anywhere
- Chain reject_func (1 references)
- target prot opt source destination
- REJECT tcp -- anywhere anywhere reject-with tcp-reset
- REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
- REJECT all -- anywhere anywhere reject-with icmp-proto-unreachable
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement