SHARE
TWEET

Untitled

a guest Oct 23rd, 2019 82 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. # Generated by iptables-save v1.6.0 on Wed Oct 23 08:58:12 2019
  2. *filter
  3. :INPUT DROP [0:0]
  4. :FORWARD DROP [0:0]
  5. :OUTPUT DROP [0:0]
  6. :lan - [0:0]
  7. -A INPUT -m state --state ESTABLISHED -j ACCEPT
  8. -A INPUT -i lo -j ACCEPT
  9. -A OUTPUT -m state --state ESTABLISHED -j ACCEPT
  10. -A OUTPUT -o lo -p icmp -m state --state RELATED -j ACCEPT
  11. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9050 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 104 -j ACCEPT
  12. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9050 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 13 -j ACCEPT
  13. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9050 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 65534 -j ACCEPT
  14. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m multiport --dports 9050,9062,9150 -m owner --uid-owner 1000 -j ACCEPT
  15. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9062 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 116 -j ACCEPT
  16. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9062 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 117 -j ACCEPT
  17. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9062 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 118 -j ACCEPT
  18. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9052 -m owner --uid-owner 0 -j ACCEPT
  19. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9051 -m owner --uid-owner 1000 -j ACCEPT
  20. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9051 -m owner --uid-owner 119 -j ACCEPT
  21. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 9040 -m owner --uid-owner 1000 -j ACCEPT
  22. -A OUTPUT -d 127.0.0.1/32 -o lo -p udp -m udp --dport 53 -m owner --uid-owner 1000 -j ACCEPT
  23. -A OUTPUT -d 127.0.0.1/32 -o lo -p udp -m udp --dport 5353 -m owner --uid-owner 1000 -j ACCEPT
  24. -A OUTPUT -d 127.0.0.1/32 -o lo -p udp -m udp --dport 53 -m owner --uid-owner 104 -j DROP
  25. -A OUTPUT -d 127.0.0.1/32 -o lo -p udp -m udp --dport 5353 -m owner --uid-owner 104 -j DROP
  26. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 4101 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 1000 -j ACCEPT
  27. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 4101 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 113 -j ACCEPT
  28. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 631 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 1000 -j ACCEPT
  29. -A OUTPUT -d 127.0.0.1/32 -o lo -p tcp -m tcp --dport 17600:17650 --tcp-flags FIN,SYN,RST,ACK SYN -m owner --uid-owner 1000 -j ACCEPT
  30. -A OUTPUT ! -o lo -p tcp -m owner --uid-owner 114 -j ACCEPT
  31. -A OUTPUT ! -o lo -p udp -m owner --uid-owner 114 -m udp --dport 53 -j ACCEPT
  32. -A OUTPUT -p tcp -m owner --uid-owner 107 -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j ACCEPT
  33. -A OUTPUT -p udp -m owner --uid-owner 107 -m udp --dport 53 -j ACCEPT
  34. -A OUTPUT -d 10.0.0.0/8 -j lan
  35. -A OUTPUT -d 172.16.0.0/12 -j lan
  36. -A OUTPUT -d 192.168.0.0/16 -j lan
  37. -A OUTPUT -j LOG --log-prefix "Dropped outbound packet: " --log-level 7 --log-uid
  38. -A OUTPUT -j REJECT --reject-with icmp-port-unreachable
  39. -A lan -p tcp -m tcp --dport 53 -j REJECT --reject-with icmp-port-unreachable
  40. -A lan -p udp -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable
  41. -A lan -p tcp -m tcp --dport 137 -j REJECT --reject-with icmp-port-unreachable
  42. -A lan -p udp -m udp --dport 137 -j REJECT --reject-with icmp-port-unreachable
  43. -A lan -j ACCEPT
  44. COMMIT
  45. # Completed on Wed Oct 23 08:58:12 2019
  46. # Generated by iptables-save v1.6.0 on Wed Oct 23 08:58:12 2019
  47. *nat
  48. :PREROUTING ACCEPT [0:0]
  49. :INPUT ACCEPT [0:0]
  50. :OUTPUT ACCEPT [88:4576]
  51. :POSTROUTING ACCEPT [88:4576]
  52. -A OUTPUT -d 127.192.0.0/10 -p tcp -j REDIRECT --to-ports 9040
  53. -A OUTPUT -d 127.0.0.1/32 -p udp -m udp --dport 53 -j REDIRECT --to-ports 5353
  54. COMMIT
  55. # Completed on Wed Oct 23 08:58:12 2019
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top