Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Firewall configuration
- # POCR configuration
- #
- # 2018-12-7 hkamrik - added new scadanode
- # 2018-12-11 hkarmik - added http from ws to bond3
- # 2019-01-24 MakarenkoN - added Remote connection from WSs to TS
- # 2019-01-25 MakarenkoN - added Remote connections from NEWS to WSs TightVNC
- #
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :LogDrop - [0:0]
- # Stateful firewall
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- # bond0 - Management 10.6.32.0/24
- # bond1 - Server net 10.6.33.0/24
- # bond2 - VLAN trunk
- # bond2.10 - DMZ1.0 - NFE 10.6.0.0/24
- # bond2.20 - DMZ2.0 - Terminal server 10.6.16.0/26
- # bond2.48 - Workstations control center 0 10.6.48.0/24
- # bond3 - DMZ out
- # Everything allowed inside the device
- -A INPUT -i lo -j ACCEPT
- -A OUTPUT -o lo -j ACCEPT
- # Drop AD's root dns server queries
- -A FORWARD -i bond1 -s 10.6.33.8 -p udp --dport 53 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.9 -p udp --dport 53 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.8 -p udp --sport 53 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.9 -p udp --sport 53 -j ACCEPT
- #
- -A FORWARD -o bond1 -d 10.6.33.8 -p udp --dport 53 -j ACCEPT
- -A FORWARD -o bond1 -d 10.6.33.9 -p udp --dport 53 -j ACCEPT
- # SSH
- -A INPUT -p tcp --dport 22 -j ACCEPT
- -A OUTPUT -p tcp --dport 22 -j ACCEPT
- -A FORWARD -i bond3 -p tcp --dport 22 -j ACCEPT
- # Incoming OpenVPN connections
- #-A INPUT -i bond1 -p udp --dport 1194 -d 192.168.1.76 -j ACCEPT
- #-A OUTPUT -o bond1 -p udp --sport 1194 -s 192.168.1.76 -j ACCEPT
- # NTP
- -A INPUT -p udp --dport 123 -s 10.0.0.0/8 -j ACCEPT
- -A OUTPUT -p udp --sport 123 -d 10.0.0.0/8 -j ACCEPT
- -A OUTPUT -p udp --dport 123 -d 10.0.0.0/8 -j ACCEPT
- -A INPUT -p udp --dport 123 -s 172.20.0.0/8 -j ACCEPT
- -A OUTPUT -p udp --sport 123 -d 172.20.0.0/8 -j ACCEPT
- -A OUTPUT -p udp --dport 123 -d 172.20.0.0/8 -j ACCEPT
- -A INPUT -p udp --dport 123 -s 172.21.0.11/8 -j ACCEPT
- -A OUTPUT -p udp --sport 123 -d 172.21.0.11/8 -j ACCEPT
- -A OUTPUT -p udp --dport 123 -d 172.21.0.11/8 -j ACCEPT
- # SNMP
- -A OUTPUT -o bond0 -p udp --dport 161 -j ACCEPT
- -A OUTPUT -o bond3 -p udp --dport 161 -j ACCEPT
- # HP System management
- -A INPUT -i bond2.20 -p tcp -m multiport --dport 2301,2381 -j ACCEPT
- -A INPUT -i bond2.48 -s 10.6.48.161 -p tcp -m multiport --dport 2301,2381 -j ACCEPT
- # Redundancy
- -A INPUT -i bond1 -s 10.6.33.0/29 -p udp --dport 8500 -j ACCEPT
- -A OUTPUT -o bond1 -d 10.6.33.0/29 -p udp --dport 8500 -j ACCEPT
- -A OUTPUT -o bond1 -s 10.6.33.0/29 -d 224.0.0.18/32 -p vrrp -j ACCEPT
- -A INPUT -i bond1 -s 10.6.33.0/29 -d 224.0.0.18/32 -p vrrp -j ACCEPT
- # DNS to AD's
- -A OUTPUT -o bond1 -p udp --dport 53 -j ACCEPT
- # Telnet to NFE
- -A OUTPUT -o bond2.10 -p tcp --dport 8023 -d 10.6.0.0/24 -j ACCEPT
- # Serverwatch to NFE
- -A OUTPUT -o bond2.10 -d 10.6.0.198 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.198 -p udp --dport 6653 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.208 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.208 -p udp --dport 6653 -j ACCEPT
- # SNMP to NFE
- -A OUTPUT -o bond2.10 -d 10.6.0.199 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.199 -p udp --dport 6653 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.209 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond2.10 -d 10.6.0.209 -p udp --dport 6653 -j ACCEPT
- -A OUTPUT -o bond3 -d 10.6.0.199 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond3 -d 10.6.0.199 -p udp --dport 6653 -j ACCEPT
- -A OUTPUT -o bond3 -d 10.6.0.209 -p udp --dport 6652 -j ACCEPT
- -A OUTPUT -o bond3 -d 10.6.0.209 -p udp --dport 6653 -j ACCEPT
- # GWServer hardware monitoring to scada
- -A OUTPUT -o bond1 -d 10.6.33.32/28 -p tcp --dport 6001 -j ACCEPT
- # IEC-104 and other protocols from NFE to substations
- -A FORWARD -i bond2.10 -o bond3 -s 10.6.0.0/24 -p tcp --dport 2404 -j ACCEPT
- -A FORWARD -i bond2.10 -o bond3 -s 10.6.0.0/24 -p udp --dport 2101:2150 -j ACCEPT
- #
- #-A FORWARD -i bond2.20 -o bond3 -s 10.6.0.0/24 -p tcp --dport 3389 -j ACCEPT
- # Ping
- -A OUTPUT -p icmp --icmp echo-request -j ACCEPT
- -A OUTPUT -p icmp --icmp echo-reply -j ACCEPT
- -A INPUT -p icmp --icmp echo-request -j ACCEPT
- -A INPUT -p icmp --icmp echo-reply -j ACCEPT
- -A FORWARD -p icmp --icmp echo-request -j ACCEPT
- -A FORWARD -p icmp --icmp echo-reply -j ACCEPT
- ### Connections from Engineering WS
- -A FORWARD -i bond2.48 -s 10.6.48.160/29 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A INPUT -i bond2.48 -s 10.6.48.160/29 -p tcp -m multiport --dports 22,1066,8023 -j ACCEPT
- -A FORWARD -i bond2.48 -s 10.6.48.160/29 -p udp -m multiport --dports 137,161 -j ACCEPT
- # connection from ws network to bond3
- -A FORWARD -i bond2.48 -o bond3 -s 10.6.48.0/24 -p tcp -m multiport --dports 80 -j ACCEPT
- ### Connections from NWS07 WS TEMPORARY!!
- #-A FORWARD -i bond2.48 -s 10.6.48.198/32 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- #-A INPUT -i bond2.48 -s 10.6.48.198/32 -p tcp -m multiport --dports 22,1066,8023 -j ACCEPT
- #-A FORWARD -i bond2.48 -s 10.6.48.198/32 -p udp -m multiport --dports 137 -j ACCEPT
- # Workstations to TS
- -A FORWARD -o bond2.20 -i bond2.48 -p tcp --dport 3389 -j ACCEPT
- # Maintenance from TS
- -A FORWARD -i bond2.20 -s 10.6.16.49 -p tcp -m multiport --dport 22,80,443,3389,8023,445 -j ACCEPT
- -A FORWARD -i bond2.20 -s 10.6.16.50 -p tcp -m multiport --dport 22,80,443,3389,8023,445 -j ACCEPT
- #### Vmware vSphere connection
- -A FORWARD -i bond2.48 -o bond0 -d 10.6.32.66 -p tcp -m multiport --dport 80,443,902,5480,9443 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond0 -d 10.6.32.71 -p tcp -m multiport --dport 80,443,902,5480,9443 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond0 -d 10.6.32.72 -p tcp -m multiport --dport 80,443,902,5480,9443 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond0 -s 10.6.32.66 -p tcp -m multiport --sport 443 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond0 -s 10.6.32.71 -p tcp -m multiport --sport 443 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond0 -s 10.6.32.72 -p tcp -m multiport --sport 443 -j ACCEPT
- #### Vmware VCenter Alarms to Scada
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.34 -p tcp --dport 6001 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.35 -p tcp --dport 6001 -j ACCEPT
- #### Scada to NFE
- -A INPUT -i bond1 -s 10.6.33.34 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A INPUT -i bond1 -s 10.6.33.35 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.34 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.35 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A INPUT -i bond1 -s 10.6.33.36 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A INPUT -i bond1 -s 10.6.33.37 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.36 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- -A FORWARD -i bond1 -s 10.6.33.37 -p tcp -m multiport --dport 1066,1719,8023 -j ACCEPT
- #### Domain connection
- #### DNS 53, Kerberos 88, NTP 123, RPC 135, LDAP 389, SMB 445, secure LDAP 686, MS DFS 5722
- # DMZ2.0
- -A FORWARD -i bond2.20 -o bond1 -d 10.6.33.8 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.8 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.8 -p tcp -m multiport --sport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond2.20 -o bond1 -d 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.8 -p udp -m multiport --sport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -i bond2.20 -o bond1 -d 10.6.33.9 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.9 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.9 -p tcp -m multiport --sport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond2.20 -o bond1 -d 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -i bond2.20 -o bond1 -d 10.6.33.9 -p udp -m multiport --sport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -s 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- # Workstations
- -A FORWARD -i bond2.48 -o bond1 -d 10.6.33.8 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.8 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.8 -p tcp -m multiport --sport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond1 -d 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.8 -p udp -m multiport --sport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond1 -d 10.6.33.9 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.9 -p tcp -m multiport --dport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.9 -p tcp -m multiport --sport 53,88,135,139,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond1 -d 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -s 10.6.33.9 -p udp -m multiport --sport 53,88,123,137,138,389,445,5722 -j ACCEPT
- # Management
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.8 -p tcp -m multiport --dport 53,88,135,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond0 -i bond1 -s 10.6.33.8 -p tcp -m multiport --dport 53,88,135,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond0 -i bond1 -s 10.6.33.8 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.9 -p tcp -m multiport --dport 53,88,135,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -o bond0 -i bond1 -s 10.6.33.9 -p tcp -m multiport --dport 53,88,135,389,445,686,3268,5722 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -d 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- -A FORWARD -o bond0 -i bond1 -s 10.6.33.9 -p udp -m multiport --dport 53,88,123,137,138,389,445,5722 -j ACCEPT
- # DomainCtl dynamic ports RPC...
- -A FORWARD -i bond2.20 -o bond1 -p tcp --dport 49152:65535 -j ACCEPT
- -A FORWARD -i bond2.20 -o bond1 -p udp --dport 49152:65535 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond1 -p tcp --dport 49152:65535 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond1 -p udp --dport 49152:65535 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -p tcp --dport 49152:65535 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -p udp --dport 49152:65535 -j ACCEPT
- #### Terminal server to Scada
- -A FORWARD -i bond2.20 -o bond1 -s 10.6.16.0/26 -d 10.6.33.32/27 -p tcp -m multiport --dports 2010,3389,6001,6003,9789,9790,9792,9791 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -d 10.6.16.0/26 -s 10.6.33.32/27 -p tcp -m multiport --sports 2010,3389,6001,6003,9789,9790,9792,9791 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -d 10.6.16.0/26 -s 10.6.33.32/27 -p tcp -m state --state NEW,ESTABLISHED --dport 1521 -j ACCEPT
- # Workstation to Scada
- -A FORWARD -i bond2.48 -o bond1 -s 10.6.48.128/25 -d 10.6.33.32/27 -p tcp -m multiport --dports 2010,3389,6001,6003,9789,9790,9792,9791 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -d 10.6.48.128/25 -s 10.6.33.32/27 -p tcp -m multiport --sports 2010,3389,6001,6003,9789,9790,9792,9791 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -d 10.6.48.128/25 -s 10.6.33.32/27 -p tcp -m state --state NEW,ESTABLISHED --dport 1521 -j ACCEPT
- #### Terminal server to Oracle
- -A FORWARD -i bond2.20 -o bond1 -s 10.6.16.0/26 -d 10.6.33.96/28 -m state --state NEW,ESTABLISHED -p tcp --dport 1521 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond1 -d 10.6.16.0/26 -s 10.6.33.96/28 -p tcp --sport 1521 -j ACCEPT
- # Workstation to Oracle
- -A FORWARD -i bond2.48 -o bond1 -s 10.6.48.128/25 -d 10.6.33.96/28 -m state --state NEW,ESTABLISHED -p tcp --dport 1521 -j ACCEPT
- -A FORWARD -o bond2.48 -i bond1 -d 10.6.48.128/25 -s 10.6.33.96/28 -p tcp --sport 1521 -j ACCEPT
- #### Server net to Terminal server web service
- -A FORWARD -i bond1 -o bond2.20 -s 10.6.33.0/24 -d 10.6.16.49/27 -p tcp --dport 7777 -j ACCEPT
- # Workstation net to terminal server web service
- -A FORWARD -i bond2.48 -o bond2.20 -s 10.6.48.0/24 -d 10.6.16.49/27 -p tcp -m multiport --dports 80,7777 -j ACCEPT
- #### Network drive mount from server net scadas
- #### TCP 139, SMB 445
- # to Terminal Server
- -A FORWARD -o bond2.20 -i bond1 -d 10.6.16.0/26 -s 10.6.33.32/27 -p tcp -m multiport --dport 139,445 -j ACCEPT
- # to Workstation
- -A FORWARD -o bond2.48 -i bond1 -d 10.6.48.128/25 -s 10.6.33.32/27 -p tcp -m multiport --dport 139,445 -j ACCEPT
- # From workstation to Terminal Server
- -A FORWARD -i bond2.48 -o bond2.20 -s 10.6.48.128/25 -d 10.6.16.49/27 -p tcp -m multiport --dport 139,445 -j ACCEPT
- #### NWSUS to windows update, all to NWSUS
- #-A FORWARD -i bond2.20 -o bond3 -s 10.6.16.33/32 -m multiport -p tcp --dport 80,443 -j ACCEPT
- #-A FORWARD -o bond2.20 -s 10.6.0.0/16 -m multiport -p tcp --dport 8530,8531 -j ACCEPT
- #### iFix License server
- #-A FORWARD -i bond2.20 -o bond3 -s 10.6.16.0/26 -d 10.0.199.10/32 -m state --state NEW,ESTABLISHED -p tcp --dport 3333 -j ACCEPT
- #-A FORWARD -o bond2.20 -i bond3 -d 10.6.16.0/26 -s 10.0.199.10/32 -m state --state NEW,ESTABLISHED -p tcp --sport 3333 -j ACCEPT
- #-A FORWARD -i bond1 -o bond3 -s 10.6.33.0/24 -d 10.0.199.10/32 -m state --state NEW,ESTABLISHED -p tcp --dport 3333 -j ACCEPT
- #-A FORWARD -o bond1 -i bond3 -d 10.6.33.0/24 -s 10.0.199.10/32 -m state --state NEW,ESTABLISHED -p tcp --sport 3333 -j ACCEPT
- #### Get status from iLO to Scada (NCHWHealth)
- -A FORWARD -i bond1 -o bond0 -s 10.6.33.34 -p tcp --dport 443 -j ACCEPT
- -A FORWARD -i bond1 -o bond0 -s 10.6.33.35 -p tcp --dport 443 -j ACCEPT
- ## POCR specific
- # From Backupserver to SCADA
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.34 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.34 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.34 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.34 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.35 -p udp -m multiport --dports 137 -j ACCEPT
- # From Backupserver to TS
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.49 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.49 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.49 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.49 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.50 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.50 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.50 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.20 -s 10.6.32.81 -d 10.6.16.50 -p udp -m multiport --dports 137 -j ACCEPT
- # From Backupserver to WS
- -A FORWARD -i bond0 -o bond2.48 -s 10.6.32.81 -d 10.6.48.128/25 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.48 -s 10.6.32.81 -d 10.6.48.128/25 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.48 -s 10.6.32.81 -d 10.6.48.128/25 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.48 -s 10.6.32.81 -d 10.6.48.128/25 -p udp -m multiport --dports 137 -j ACCEPT
- # From Backupserver to DWH
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.98 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.98 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.98 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.98 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.99 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.99 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.99 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.99 -p udp -m multiport --dports 137 -j ACCEPT
- # From Backupserver to NAD
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.8 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.8 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.8 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.8 -p udp -m multiport --dports 137 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.9 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.9 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.9 -p tcp -m multiport --dports 80,443,22,23,1066,8023,3389,445,17990,5480,902,9877 -j ACCEPT
- -A FORWARD -i bond0 -o bond1 -s 10.6.32.81 -d 10.6.33.9 -p udp -m multiport --dports 137 -j ACCEPT
- # From Backupserver to NGW-server and NFE-server
- -A INPUT -i bond0 -s 10.6.32.81 -p tcp --dport 2500:2501 -j ACCEPT
- -A INPUT -i bond0 -s 10.6.32.81 -p tcp --dport 6160:6162 -j ACCEPT
- -A INPUT -i bond0 -s 10.6.32.81 -p tcp --dport 22 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.17 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.17 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.17 -p tcp --dport 22 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.18 -p tcp --dport 2500:5000 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.18 -p tcp --dport 6160:6162 -j ACCEPT
- -A FORWARD -i bond0 -o bond2.10 -s 10.6.32.81 -d 10.6.0.18 -p tcp --dport 22 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.133 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.133 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.50 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.50 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.32 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.32 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.206 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.206 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.35 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.35 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.8 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.8 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.202 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.202 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.205 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.205 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.203 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.203 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.36 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.36 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.34 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.34 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.204 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.204 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.201 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.201 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.51 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.51 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.31 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.31 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.33 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.33 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.49 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.49 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.71 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.71 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.157 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.157 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.41 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.41 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.58 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.58 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.177 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond3 -s 172.21.0.177 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond2.48 -s 10.6.48.150 -d 10.6.16.49 -p tcp --dport 3389 -j ACCEPT
- -A FORWARD -o bond2.20 -i bond2.48 -s 10.6.48.150 -d 10.6.16.50 -p tcp --dport 3389 -j ACCEPT
- #Remote connections from NEWS to WSs TightVNC
- -A FORWARD -i bond2.48 -o bond3 -s 10.6.48.161 -p tcp -m multiport --dport 5900 -j ACCEPT
- -A FORWARD -i bond2.48 -o bond3 -s 10.6.48.162 -p tcp -m multiport --dport 5900 -j ACCEPT
- # Everything else forbidden
- -A INPUT -p udp -d 255.255.255.255 -j DROP
- -A INPUT -p udp --dport 136:139 -j DROP
- -A INPUT -p tcp --dport 136:139 -j DROP
- -A INPUT -p udp --dport 1947 -j DROP
- -A INPUT -j LogDrop
- -A FORWARD -j LogDrop
- -A OUTPUT -j LogDrop
- -A LogDrop -j LOG
- -A LogDrop -j DROP
- COMMIT
- # NAT Rules
- *nat
- :PREROUTING ACCEPT
- :POSTROUTING ACCEPT
- :OUTPUT ACCEPT
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement