Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -P INPUT ACCEPT
- -P FORWARD DROP
- -P OUTPUT ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT ! -i br0 -p udp -m udp --dport 67 -j REJECT --reject-with icmp-port-unreachable
- -A INPUT ! -i br0 -p udp -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --set --name SSH --rsource
- -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 8 --rttl --name SSH --rsource -j DROP
- -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -p udp -m udp --dport 123 -j ACCEPT
- -A INPUT -i br0 -p tcp -m tcp --dport 137:139 -j ACCEPT
- -A INPUT -i br0 -p udp -m udp --dport 137:139 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 143 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 587 -j ACCEPT
- -A INPUT ! -i br0 -p tcp -m tcp --dport 0:1023 -j DROP
- -A INPUT ! -i br0 -p udp -m udp --dport 0:1023 -j DROP
- -A INPUT ! -d 192.168.0.1/32 -i br0 -j ACCEPT
- -A INPUT ! -i br0 -m state --state NEW -j REJECT --reject-with icmp-host-prohibited
Add Comment
Please, Sign In to add comment