Advertisement
Guest User

ubuntu2

a guest
Apr 18th, 2022
55
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.44 KB | None | 0 0
  1. root@box-688896:~# iptables-save
  2. # Generated by iptables-save v1.8.4 on Tue Apr 19 01:16:59 2022
  3. *filter
  4. :INPUT ACCEPT [17:3423]
  5. :FORWARD ACCEPT [0:0]
  6. :OUTPUT ACCEPT [42:5425]
  7. :f2b-sshd - [0:0]
  8. :ufw-after-forward - [0:0]
  9. :ufw-after-input - [0:0]
  10. :ufw-after-logging-forward - [0:0]
  11. :ufw-after-logging-input - [0:0]
  12. :ufw-after-logging-output - [0:0]
  13. :ufw-after-output - [0:0]
  14. :ufw-before-forward - [0:0]
  15. :ufw-before-input - [0:0]
  16. :ufw-before-logging-forward - [0:0]
  17. :ufw-before-logging-input - [0:0]
  18. :ufw-before-logging-output - [0:0]
  19. :ufw-before-output - [0:0]
  20. :ufw-reject-forward - [0:0]
  21. :ufw-reject-input - [0:0]
  22. :ufw-reject-output - [0:0]
  23. :ufw-track-forward - [0:0]
  24. :ufw-track-input - [0:0]
  25. :ufw-track-output - [0:0]
  26. -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
  27. -A INPUT -p udp -m udp --dport 1194 -j ACCEPT
  28. -A INPUT -p udp -m udp --dport 1701 -m policy --dir in --pol none -j DROP
  29. -A INPUT -m conntrack --ctstate INVALID -j DROP
  30. -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  31. -A INPUT -p udp -m multiport --dports 500,4500 -j ACCEPT
  32. -A INPUT -p udp -m udp --dport 1701 -m policy --dir in --pol ipsec -j ACCEPT
  33. -A INPUT -p udp -m udp --dport 1701 -j DROP
  34. -A INPUT -j ufw-before-logging-input
  35. -A INPUT -j ufw-before-input
  36. -A INPUT -j ufw-after-input
  37. -A INPUT -j ufw-after-logging-input
  38. -A INPUT -j ufw-reject-input
  39. -A INPUT -j ufw-track-input
  40. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  41. -A FORWARD -s 10.8.0.0/24 -j ACCEPT
  42. -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
  43. -A FORWARD -m conntrack --ctstate INVALID -j DROP
  44. -A FORWARD -i ens3 -o ppp+ -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  45. -A FORWARD -i ppp+ -o ens3 -j ACCEPT
  46. -A FORWARD -i ppp+ -o ppp+ -j ACCEPT
  47. -A FORWARD -d 192.168.43.0/24 -i ens3 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  48. -A FORWARD -s 192.168.43.0/24 -o ens3 -j ACCEPT
  49. -A FORWARD -s 192.168.43.0/24 -o ppp+ -j ACCEPT
  50. -A FORWARD -j ufw-before-logging-forward
  51. -A FORWARD -j ufw-before-forward
  52. -A FORWARD -j ufw-after-forward
  53. -A FORWARD -j ufw-after-logging-forward
  54. -A FORWARD -j ufw-reject-forward
  55. -A FORWARD -j ufw-track-forward
  56. -A FORWARD -j DROP
  57. -A FORWARD -i tun0 -j ACCEPT
  58. -A FORWARD -i ens3 -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT
  59. -A FORWARD -i ens3 -p tcp -m tcp --dport 8080 -j ACCEPT
  60. -A OUTPUT -j ufw-before-logging-output
  61. -A OUTPUT -j ufw-before-output
  62. -A OUTPUT -j ufw-after-output
  63. -A OUTPUT -j ufw-after-logging-output
  64. -A OUTPUT -j ufw-reject-output
  65. -A OUTPUT -j ufw-track-output
  66. -A f2b-sshd -s 185.98.225.148/32 -j REJECT --reject-with icmp-port-unreachable
  67. -A f2b-sshd -s 66.96.237.197/32 -j REJECT --reject-with icmp-port-unreachable
  68. -A f2b-sshd -s 43.155.109.48/32 -j REJECT --reject-with icmp-port-unreachable
  69. -A f2b-sshd -s 73.13.104.201/32 -j REJECT --reject-with icmp-port-unreachable
  70. -A f2b-sshd -s 109.167.197.20/32 -j REJECT --reject-with icmp-port-unreachable
  71. -A f2b-sshd -j RETURN
  72. COMMIT
  73. # Completed on Tue Apr 19 01:16:59 2022
  74. # Generated by iptables-save v1.8.4 on Tue Apr 19 01:16:59 2022
  75. *nat
  76. :PREROUTING ACCEPT [284:30034]
  77. :INPUT ACCEPT [66:6533]
  78. :OUTPUT ACCEPT [0:0]
  79. :POSTROUTING ACCEPT [2:96]
  80. -A PREROUTING -p tcp -m tcp --dport 8080 -j DNAT --to-destination 10.8.0.2
  81. -A POSTROUTING -s 192.168.42.0/24 -o ens3 -j MASQUERADE
  82. -A POSTROUTING -s 192.168.43.0/24 -o ens3 -m policy --dir out --pol none -j MASQUERADE
  83. -A POSTROUTING -s 10.8.0.0/24 -o ens3 -j MASQUERADE
  84. -A POSTROUTING -o ens3 -j MASQUERADE
  85. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement