Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/bash
- # portierbarkeit
- PATH_IPT=/sbin/iptables
- PATH_IPT6=/sbin/ip6tables
- ipSRV=192.168.178.29
- #ipSRV=10.126.244.13
- ipADM=192.168.178.35
- #ipADM=10.126.244.195
- # drop everything by default
- $PATH_IPT -P INPUT DROP
- $PATH_IPT -P FORWARD DROP
- $PATH_IPT -P OUTPUT DROP
- $PATH_IPT6 -P INPUT DROP
- $PATH_IPT6 -P FORWARD DROP
- $PATH_IPT6 -P OUTPUT DROP
- $PATH_IPT -F
- $PATH_IPT -X
- $PATH_IPT6 -F
- $PATH_IPT6 -X
- #enable admin ssh
- $PATH_IPT -A INPUT -s $ipADM -d $ipSRV -p TCP --dport ssh -j ACCEPT
- $PATH_IPT -A OUTPUT -s $ipSRV -d $ipADM -p TCP --sport ssh -j ACCEPT
- # enable http, https, 8081 and DNS
- $PATH_IPT -A INPUT -p TCP --dport 8081 -j ACCEPT
- #$PATH_IPT -A INPUT -p TCP --sport 8081 -j ACCEPT
- $PATH_IPT -A OUTPUT -p TCP --sport 8081 -j ACCEPT
- #$PATH_IPT -A OUTPUT -p TCP --dport 8081 -j ACCEPT
- $PATH_IPT -A INPUT -p TCP --dport 80 -j ACCEPT
- $PATH_IPT -A OUTPUT -p TCP --sport 80 -j ACCEPT
- $PATH_IPT -A OUTPUT -p UDP --sport 53 -j ACCEPT
- $PATH_IPT -A OUTPUT -p UDP --sport 8081 -j ACCEPT
- $PATH_IPT -A INPUT -p UDP --dport 8081 -j ACCEPT
- #$PATH_IPT -A OUTPUT -p UDP --sport 22 -j ACCEPT
- #$PATH_IPT -A INPUT -p UDP --dport 22 -j ACCEPT
- $PATH_IPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement