Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
- *security
- :INPUT ACCEPT [325023:104284201]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [340080:196993969]
- COMMIT
- # Completed on Sun Sep 23 23:48:33 2018
- # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
- *raw
- :PREROUTING ACCEPT [341193:105156430]
- :OUTPUT ACCEPT [340080:196993969]
- COMMIT
- # Completed on Sun Sep 23 23:48:33 2018
- # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
- *nat
- :PREROUTING ACCEPT [24144:1314529]
- :INPUT ACCEPT [8143:452552]
- :OUTPUT ACCEPT [20658:1438999]
- :POSTROUTING ACCEPT [20658:1438999]
- COMMIT
- # Completed on Sun Sep 23 23:48:33 2018
- # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
- *mangle
- :PREROUTING ACCEPT [341193:105156430]
- :INPUT ACCEPT [341193:105156430]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [340080:196993969]
- :POSTROUTING ACCEPT [340080:196993969]
- COMMIT
- # Completed on Sun Sep 23 23:48:33 2018
- # Generated by iptables-save v1.4.21 on Sun Sep 23 23:48:33 2018
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [7132:9671792]
- :INBOUND - [0:0]
- -A INPUT -m state --state NEW -j LOG --log-prefix "New Connection: "
- -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -s 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -p icmp -m state --state NEW -m icmp --icmp-type 8 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 3306 -m state --state NEW -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables_INPUT_denied: " --log-level 7
- -A INPUT -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -p tcp -m tcp --dport 993 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 110 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 995 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 143 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
- -A INPUT -j LOG
- -A INPUT -j LOG --log-prefix "BAD_INPUT: "
- -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
- -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
- -A INPUT -j LOG --log-prefix "BAD_INPUT: "
- -A INPUT -p tcp -j LOG --log-prefix " INPUT TCP "
- -A INPUT -i eth0 -p tcp -m state --state RELATED,ESTABLISHED -j INBOUND
- -A FORWARD -m limit --limit 5/min -j LOG --log-prefix "iptables_FORWARD_denied: " --log-level 7
- -A FORWARD -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -j LOG --log-prefix "BAD_FORWARD: "
- -A FORWARD -j LOG --log-prefix "BAD_FORWARD: " --log-level 7
- -A OUTPUT -p tcp -m tcp --sport 993 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 110 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 995 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 143 -m conntrack --ctstate ESTABLISHED -j ACCEPT
- -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: "
- -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: " --log-level 7
- -A INBOUND -p tcp -j LOG --log-prefix " INBOUND TCP "
- -A INBOUND -p tcp -j ACCEPT
- COMMIT
- # Completed on Sun Sep 23 23:48:33 2018
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement