Advertisement
Logos01

Untitled

Oct 15th, 2013
301
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.42 KB | None | 0 0
  1. *filter
  2. :INPUT DROP [0:0]
  3. :FORWARD DROP [0:0]
  4. :OUTPUT DROP [0:0]
  5. :FIREWALL DROP [0:0]
  6. :LO ACCEPT [0:0]
  7. :TCP DROP [0:0]
  8. :UDP DROP [0:0]
  9. :LOGNDROP DROP [0:0]
  10. -A INPUT -j FIREWALL
  11. -A FORWARD -j FIREWALL
  12.  
  13. -A FIREWALL -m state --state INVALID -j DROP
  14. -A FIREWALL -m state --state RELATED,ESTABLISHED -j ACCEPT
  15. -A FIREWALL -m state --state NEW -p icmp --icmp-type echo-request -j ACCEPT
  16. -A FIREWALL -m state --state NEW -i lo -j LO
  17. -A FIREWALL -m state --state NEW -m tcp -p tcp -j TCP
  18. -A FIREWALL -m state --state NEW -m udp -p udp -j UDP
  19. -A FIREWALL -m state --state NEW -j LOGNDROP
  20.  
  21. -A LO -m tcp -p tcp --dport 22 -j ACCEPT
  22. -A LO -m tcp -p tcp --dport 25 -j ACCEPT
  23. -A LO -m udp -p udp --dport 161 -j ACCEPT
  24.  
  25. -A TCP -m tcp -p tcp --dport 22 -j ACCEPT
  26. -A TCP -m tcp -p tcp --dport 25 -j ACCEPT
  27. -A TCP -m tcp -p tcp --dport 5432 -j ACCEPT
  28. -A TCP -m tcp -p tcp -j LOGNDROP
  29.  
  30. -A UDP -m udp -p udp --dport 161 -j ACCEPT
  31. -A UDP -m udp -p udp -j LOGNDROP
  32.  
  33. -A LOGNDROP -m limit --limit 2/min -j LOG --log-prefix "IPTables Packet Dropped: " --log-level 7
  34. -A LOGNDROP -j REJECT --reject-with icmp-host-prohibited
  35.  
  36. -A OUTPUT -m state --state INVALID -j DROP
  37. -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  38. -A OUTPUT -o lo -j ACCEPT
  39. -A OUTPUT -o eth0 -p icmp -m state --state NEW -j ACCEPT
  40. -A OUTPUT -o eth0 -p tcp -m state --state NEW -j ACCEPT
  41. -A OUTPUT -d 192.168.0.0/16 -o eth0 -m state --state NEW -j ACCEPT
  42. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement