Advertisement
Guest User

Untitled

a guest
Sep 23rd, 2018
91
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.44 KB | None | 0 0
  1. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
  2. *security
  3. :INPUT ACCEPT [325023:104284201]
  4. :FORWARD ACCEPT [0:0]
  5. :OUTPUT ACCEPT [340080:196993969]
  6. COMMIT
  7. # Completed on Sun Sep 23 23:48:33 2018
  8. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
  9. *raw
  10. :PREROUTING ACCEPT [341193:105156430]
  11. :OUTPUT ACCEPT [340080:196993969]
  12. COMMIT
  13. # Completed on Sun Sep 23 23:48:33 2018
  14. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
  15. *nat
  16. :PREROUTING ACCEPT [24144:1314529]
  17. :INPUT ACCEPT [8143:452552]
  18. :OUTPUT ACCEPT [20658:1438999]
  19. :POSTROUTING ACCEPT [20658:1438999]
  20. COMMIT
  21. # Completed on Sun Sep 23 23:48:33 2018
  22. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
  23. *mangle
  24. :PREROUTING ACCEPT [341193:105156430]
  25. :INPUT ACCEPT [341193:105156430]
  26. :FORWARD ACCEPT [0:0]
  27. :OUTPUT ACCEPT [340080:196993969]
  28. :POSTROUTING ACCEPT [340080:196993969]
  29. COMMIT
  30. # Completed on Sun Sep 23 23:48:33 2018
  31. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
  32. *filter
  33. :INPUT ACCEPT [0:0]
  34. :FORWARD ACCEPT [0:0]
  35. :OUTPUT ACCEPT [7132:9671792]
  36. :INBOUND - [0:0]
  37. -A INPUT -m state --state NEW -j LOG --log-prefix "New Connection: "
  38. -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
  39. -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
  40. -A INPUT -i lo -j ACCEPT
  41. -A INPUT -s 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable
  42. -A INPUT -p icmp -m state --state NEW -m icmp --icmp-type 8 -j ACCEPT
  43. -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
  44. -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
  45. -A INPUT -p tcp -m tcp --dport 443 -m state --state NEW -j ACCEPT
  46. -A INPUT -p tcp -m tcp --dport 3306 -m state --state NEW -j ACCEPT
  47. -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j ACCEPT
  48. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  49. -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables_INPUT_denied: " --log-level 7
  50. -A INPUT -j REJECT --reject-with icmp-port-unreachable
  51. -A INPUT -p tcp -m tcp --dport 993 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  52. -A INPUT -p tcp -m tcp --dport 110 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  53. -A INPUT -p tcp -m tcp --dport 995 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  54. -A INPUT -p tcp -m tcp --dport 143 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  55. -A INPUT -j LOG
  56. -A INPUT -j LOG --log-prefix "BAD_INPUT: "
  57. -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
  58. -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
  59. -A INPUT -j LOG --log-prefix "BAD_INPUT: "
  60. -A INPUT -p tcp -j LOG --log-prefix " INPUT TCP "
  61. -A INPUT -i eth0 -p tcp -m state --state RELATED,ESTABLISHED -j INBOUND
  62. -A FORWARD -m limit --limit 5/min -j LOG --log-prefix "iptables_FORWARD_denied: " --log-level 7
  63. -A FORWARD -j REJECT --reject-with icmp-port-unreachable
  64. -A FORWARD -j LOG --log-prefix "BAD_FORWARD: "
  65. -A FORWARD -j LOG --log-prefix "BAD_FORWARD: " --log-level 7
  66. -A OUTPUT -p tcp -m tcp --sport 993 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  67. -A OUTPUT -p tcp -m tcp --sport 110 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  68. -A OUTPUT -p tcp -m tcp --sport 995 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  69. -A OUTPUT -p tcp -m tcp --sport 143 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  70. -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: "
  71. -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: " --log-level 7
  72. -A INBOUND -p tcp -j LOG --log-prefix " INBOUND TCP "
  73. -A INBOUND -p tcp -j ACCEPT
  74. COMMIT
  75. # Completed on Sun Sep 23 23:48:33 2018
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement