Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@router ~]# cat /etc/sysconfig/iptables
- # Generated by iptables-save v1.3.5 on Tue Jan 12 12:45:36 2010
- *filter
- :FORWARD DROP [0:0]
- :INPUT DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -p tcp -m tcp -i eth2 --dport 22 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 195.177.73.203 -i eth2 --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 195.177.73.203 -i eth2 --dport 443 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 195.177.73.203 -i eth2 --dport 110 -j ACCEPT
- #------------------ICMP_RULERS-----------------------------------------
- -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- -A INPUT -p all -m state --state ESTABLISHED,RELATED -j ACCEPT
- -A INPUT -s 192.168.0.254 -i lo -j ACCEPT
- #-----------------WEBMIN-----------------------------------------------
- -A INPUT -p tcp -m tcp -d 195.177.73.203 -i eth2 --dport 10000 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 110 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 5190 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 80 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 3128 -j ACCEPT
- -A INPUT -p tcp -m tcp -d 192.168.0.254 -i eth1 --dport 53 -j ACCEPT
- #----------------FORWARDS---------------------------------------------
- -A FORWARD -p tcp -m tcp -i eth1 --dport 25 -j ACCEPT
- -A FORWARD -i eth1 -p all -j ACCEPT
- -A FORWARD -p tcp -m tcp -s 192.168.0.2 --sport 3389 -j ACCEPT
- -A FORWARD -p tcp -m tcp -d 192.168.0.2 --dport 3389 -j ACCEPT
- -A FORWARD -p all -m state --state ESTABLISHED,RELATED -j ACCEPT
- #---------------OUTPUT------------------------------------------------
- -A OUTPUT -p tcp -m tcp --sport 10000 -j ACCEPT
- COMMIT
- # Completed on Tue Jan 12 12:45:36 2010
- # Generated by iptables-save v1.3.5 on Tue Jan 12 12:45:36 2010
- *nat
- :PREROUTING ACCEPT [3287:273942]
- :POSTROUTING ACCEPT [13:4662]
- :OUTPUT ACCEPT [776:50688]
- -A PREROUTING -i eth2 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.0.2
- -A POSTROUTING -o eth2 -j SNAT --to 195.177.73.203
- COMMIT
- # Completed on Tue Jan 12 12:45:36 2010
- # Generated by iptables-save v1.3.5 on Tue Jan 12 12:45:36 2010
- *mangle
- :PREROUTING ACCEPT [1884708:1820524636]
- :INPUT ACCEPT [1876852:1818376990]
- :FORWARD ACCEPT [7508:2113527]
- :OUTPUT ACCEPT [1276258:1781436931]
- :POSTROUTING ACCEPT [1283766:1783550458]
- COMMIT
Add Comment
Please, Sign In to add comment