Advertisement
spacemanspiff

tmp filters asus

Apr 17th, 2025
28
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.24 KB | None | 0 0
  1. admin@RT-AX86U-79A8:/# more /tmp/filter_rules
  2. *filter
  3. :INPUT ACCEPT [0:0]
  4. :FORWARD ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. :INPUT_PING - [0:0]
  7. :INPUT_ICMP - [0:0]
  8. :FUPNP - [0:0]
  9. :SECURITY - [0:0]
  10. :ACCESS_RESTRICTION - [0:0]
  11. :IControls - [0:0]
  12. :DNSFILTER_DOT - [0:0]
  13. :WGNPControls - [0:0]
  14. :PControls - [0:0]
  15. :default_block - [0:0]
  16. :IPSEC_DROP_SUBNET_ICMP - [0:0]
  17. :IPSEC_STRONGSWAN - [0:0]
  18. :WGSI - [0:0]
  19. :WGSF - [0:0]
  20. :WGCI - [0:0]
  21. :WGCF - [0:0]
  22. :OVPNSI - [0:0]
  23. :OVPNSF - [0:0]
  24. :OVPNCI - [0:0]
  25. :OVPNCF - [0:0]
  26. :VPNCF - [0:0]
  27. :VPNCI - [0:0]
  28. :logaccept - [0:0]
  29. :logdrop - [0:0]
  30. :PTCSRVWAN - [0:0]
  31. :PTCSRVLAN - [0:0]
  32. -A FORWARD -j IPSEC_DROP_SUBNET_ICMP
  33. -A FORWARD -j IPSEC_STRONGSWAN
  34. -A INPUT -p icmp --icmp-type 8 -j INPUT_PING
  35. -A INPUT_PING -p icmp -m policy --dir in --pol ipsec -j RETURN
  36. -A INPUT_PING -i vlan10 -p icmp -j DROP
  37. -A INPUT -p udp -m multiport --dport 500,4500 -j ACCEPT
  38. -A INPUT -p esp -j ACCEPT
  39. -A INPUT -p ah -j ACCEPT
  40. -A INPUT -m state --state RELATED,ESTABLISHED -j logaccept
  41. -A INPUT -m state --state INVALID -j DROP
  42. -A INPUT ! -i br0 -j PTCSRVWAN
  43. -A INPUT -i br0 -j PTCSRVLAN
  44. -A INPUT ! -i lo -p tcp --dport 5152 -j DROP
  45. -A INPUT -i br0 -m state --state NEW -j ACCEPT
  46. -A INPUT -m policy --dir in --pol ipsec -m state --state NEW -j ACCEPT
  47. -A INPUT -i lo -m state --state NEW -j ACCEPT
  48. -A INPUT -p udp --sport 67 --dport 68 -j logaccept
  49. -A INPUT -p icmp -j INPUT_ICMP
  50. -A INPUT_ICMP -p icmp --icmp-type 8 -j RETURN
  51. -A INPUT_ICMP -p icmp --icmp-type 13 -j RETURN
  52. -A INPUT_ICMP -p icmp -j logaccept
  53. -A INPUT -j WGSI
  54. -A INPUT -j WGCI
  55. -A INPUT -j OVPNSI
  56. -A INPUT -j OVPNCI
  57. -A INPUT -j DROP
  58. -A FORWARD -m state --state ESTABLISHED,RELATED -j logaccept
  59. -A FORWARD -m policy --dir in --pol ipsec -j ACCEPT
  60. -A FORWARD -j WGSF
  61. -A FORWARD -j OVPNSF
  62. -A FORWARD -o vlan10 ! -i br0 -j DROP
  63. -A FORWARD -i br0 -o br0 -j logaccept
  64. -A FORWARD -m state --state INVALID -j DROP
  65. -A FORWARD -i vlan10 -j SECURITY
  66. -A FORWARD -m conntrack --ctstate DNAT -j logaccept
  67. -A SECURITY -p tcp --syn -m limit --limit 1/s -j RETURN
  68. -A SECURITY -p tcp --syn -j DROP
  69. -A SECURITY -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j RETURN
  70. -A SECURITY -p tcp --tcp-flags SYN,ACK,FIN,RST RST -j DROP
  71. -A SECURITY -p icmp --icmp-type 8 -m limit --limit 1/s -j RETURN
  72. -A SECURITY -p icmp --icmp-type 8 -j DROP
  73. -A SECURITY -j RETURN
  74. -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
  75. -A logaccept -j ACCEPT
  76. -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
  77. -A logdrop -j DROP
  78. -A FORWARD -j WGCF
  79. -A FORWARD -j OVPNCF
  80. -A FORWARD -j VPNCF
  81. -A FORWARD -i br0 -j ACCEPT
  82. -A FORWARD -j DROP
  83. :logdrop_dns - [0:0]
  84. -A logdrop_dns -j LOG --log-prefix "DROP_DNS " --log-tcp-sequence --log-tcp-options --log-ip-options
  85. -A logdrop_dns -j DROP
  86. :OUTPUT_DNS - [0:0]
  87. :logdrop_ip - [0:0]
  88. -A logdrop_ip -j LOG --log-prefix "DROP_IP " --log-tcp-sequence --log-tcp-options --log-ip-options
  89. -A logdrop_ip -j DROP
  90. :OUTPUT_IP - [0:0]
  91. -A OUTPUT -p udp --dport 53 -m u32 --u32 0>>22&0x3c@8>>15&1=0 -j OUTPUT_DNS
  92. -A OUTPUT -p tcp --dport 53 -m u32 --u32 0>>22&0x3c@12>>26&0x3c@8>>15&1=0 -j OUTPUT_DNS
  93. -A OUTPUT_DNS -m string --icase --hex-string "|10|poiuytyuiopkjfnf|03|com|00|" --algo bm -j logdrop_dns
  94. -A OUTPUT_DNS -m string --icase --hex-string "|0D|rfjejnfjnefje|03|com|00|" --algo bm -j logdrop_dns
  95. -A OUTPUT_DNS -m string --icase --hex-string "|11|10afdmasaxsssaqrk|03|com|00|" --algo bm -j logdrop_dns
  96. -A OUTPUT_DNS -m string --icase --hex-string "|0F|7mfsdfasdmkgmrk|03|com|00|" --algo bm -j logdrop_dns
  97. -A OUTPUT_DNS -m string --icase --hex-string "|0D|8masaxsssaqrk|03|com|00|" --algo bm -j logdrop_dns
  98. -A OUTPUT_DNS -m string --icase --hex-string "|0F|9fdmasaxsssaqrk|03|com|00|" --algo bm -j logdrop_dns
  99. -A OUTPUT_DNS -m string --icase --hex-string "|12|efbthmoiuykmkjkjgt|03|com|00|" --algo bm -j logdrop_dns
  100. -A OUTPUT_DNS -m string --icase --hex-string "|08|hackucdt|03|com|00|" --algo bm -j logdrop_dns
  101. -A OUTPUT_DNS -m string --icase --hex-string "|07|linwudi|05|f3322|03|net|00|" --algo bm -j logdrop_dns
  102. -A OUTPUT_DNS -m string --icase --hex-string "|0F|lkjhgfdsatryuio|03|com|00|" --algo bm -j logdrop_dns
  103. -A OUTPUT_DNS -m string --icase --hex-string "|0B|mnbvcxzzz12|03|com|00|" --algo bm -j logdrop_dns
  104. -A OUTPUT_DNS -m string --icase --hex-string "|07|q111333|03|top|00|" --algo bm -j logdrop_dns
  105. -A OUTPUT_DNS -m string --icase --hex-string "|05|sq520|05|f3322|03|net|00|" --algo bm -j logdrop_dns
  106. -A OUTPUT_DNS -m string --icase --hex-string "|07|uctkone|03|com|00|" --algo bm -j logdrop_dns
  107. -A OUTPUT_DNS -m string --icase --hex-string "|0E|zxcvbmnnfjjfwq|03|com|00|" --algo bm -j logdrop_dns
  108. -A OUTPUT_DNS -m string --icase --hex-string "|0A|eummagvnbp|03|com|00|" --algo bm -j logdrop_dns
  109. -A OUTPUT -j OUTPUT_IP
  110. -A OUTPUT_IP -d 193.201.224.0/24 -j logdrop_ip
  111. -A OUTPUT_IP -d 51.15.120.245 -j logdrop_ip
  112. -A OUTPUT_IP -d 45.33.73.134 -j logdrop_ip
  113. -A OUTPUT_IP -d 190.115.18.28 -j logdrop_ip
  114. -A OUTPUT_IP -d 51.159.52.250 -j logdrop_ip
  115. -A OUTPUT_IP -d 190.115.18.86 -j logdrop_ip
  116. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement