Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- iptables -A INPUT -m conntrack --ctstate INVALID -j LOG --log-prefix "DROP INVALID: " --log-tcp-options --log-ip-options
- iptables -A INPUT -m conntrack --ctstate INVALID -j DROP
- iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- iptables -A INPUT -d 172.17.52.22/32 -i eth0 -p tcp -m conntrack --ctstate NEW -m tcp --dport 51496 -j LOG --log-prefix "Service_CONNECT: "
- iptables -A INPUT -d 172.17.52.22/32 -i eth0 -p tcp -m conntrack --ctstate NEW -m tcp --dport 51496 -j ACCEPT
- iptables -A INPUT -d 172.17.52.22/32 -i eth0 -p tcp -m conntrack --ctstate NEW -m tcp --dport 22222 -j ACCEPT
- iptables -A INPUT -d 172.17.52.22/32 -i eth0 -p tcp -m conntrack --ctstate NEW -m tcp --dport 22223 -j ACCEPT
- iptables -A INPUT -m conntrack --ctstate NEW -s 10.0.0.0/24 -i eth0 -p tcp -m tcp --dport 3128 -j ACCEPT
- iptables -A INPUT --j LOG --log-prefix "DROP: " --log-tcp-options --log-ip-options
- iptables -A INPUT -i lo -j ACCEPT
- iptables -P INPUT DROP
- iptables -P FORWARD DROP
- iptables -P OUTPUT ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement