Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- localhost dem # iptables --list
- Chain INPUT (policy DROP)
- target prot opt source destination
- dynamic all -- anywhere anywhere ctstate INVALID,NEW
- net2fw all -- anywhere anywhere
- loc2fw all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:INPUT:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain FORWARD (policy DROP)
- target prot opt source destination
- dynamic all -- anywhere anywhere ctstate INVALID,NEW
- net2loc all -- anywhere anywhere
- loc2net all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:FORWARD:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain OUTPUT (policy DROP)
- target prot opt source destination
- fw2net all -- anywhere anywhere
- fw2loc all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:OUTPUT:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain Drop (0 references)
- target prot opt source destination
- all -- anywhere anywhere
- reject tcp -- anywhere anywhere tcp dpt:auth
- dropBcast all -- anywhere anywhere
- ACCEPT icmp -- anywhere anywhere icmp fragmentation-needed
- ACCEPT icmp -- anywhere anywhere icmp time-exceeded
- dropInvalid all -- anywhere anywhere
- DROP udp -- anywhere anywhere multiport dports epmap,microsoft-ds
- DROP udp -- anywhere anywhere udp dpts:netbios-ns:netbios-ssn
- DROP udp -- anywhere anywhere udp spt:netbios-ns dpts:1024:65535
- DROP tcp -- anywhere anywhere multiport dports epmap,netbios-ssn,microsoft-ds
- DROP udp -- anywhere anywhere udp dpt:1900
- dropNotSyn tcp -- anywhere anywhere
- DROP udp -- anywhere anywhere udp spt:domain
- Chain Reject (6 references)
- target prot opt source destination
- all -- anywhere anywhere
- reject tcp -- anywhere anywhere tcp dpt:auth
- dropBcast all -- anywhere anywhere
- ACCEPT icmp -- anywhere anywhere icmp fragmentation-needed
- ACCEPT icmp -- anywhere anywhere icmp time-exceeded
- dropInvalid all -- anywhere anywhere
- reject udp -- anywhere anywhere multiport dports epmap,microsoft-ds
- reject udp -- anywhere anywhere udp dpts:netbios-ns:netbios-ssn
- reject udp -- anywhere anywhere udp spt:netbios-ns dpts:1024:65535
- reject tcp -- anywhere anywhere multiport dports epmap,netbios-ssn,microsoft-ds
- DROP udp -- anywhere anywhere udp dpt:1900
- dropNotSyn tcp -- anywhere anywhere
- DROP udp -- anywhere anywhere udp spt:domain
- Chain dropBcast (2 references)
- target prot opt source destination
- DROP all -- anywhere 172.16.255.255
- DROP all -- anywhere 192.168.1.255
- DROP all -- anywhere 255.255.255.255
- DROP all -- anywhere base-address.mcast.net/4
- Chain dropInvalid (2 references)
- target prot opt source destination
- DROP all -- anywhere anywhere ctstate INVALID
- Chain dropNotSyn (2 references)
- target prot opt source destination
- DROP tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN
- Chain dynamic (2 references)
- target prot opt source destination
- Chain fw2loc (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere
- Chain fw2net (1 references)
- target prot opt source destination
- ACCEPT udp -- anywhere anywhere udp dpts:bootps:bootpc
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere
- Chain loc2fw (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:loc2fw:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain loc2net (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- ACCEPT all -- anywhere anywhere
- Chain logdrop (0 references)
- target prot opt source destination
- DROP all -- anywhere anywhere
- Chain logreject (0 references)
- target prot opt source destination
- reject all -- anywhere anywhere
- Chain net2fw (1 references)
- target prot opt source destination
- ACCEPT udp -- anywhere anywhere udp dpts:bootps:bootpc
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:net2fw:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain net2loc (1 references)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED
- Reject all -- anywhere anywhere
- LOG all -- anywhere anywhere LOG level info prefix `Shorewall:net2loc:REJECT:'
- reject all -- anywhere anywhere [goto]
- Chain reject (13 references)
- target prot opt source destination
- DROP all -- anywhere 172.16.255.255
- DROP all -- anywhere 192.168.1.255
- DROP all -- anywhere 255.255.255.255
- DROP all -- base-address.mcast.net/4 anywhere
- DROP igmp -- anywhere anywhere
- REJECT tcp -- anywhere anywhere reject-with tcp-reset
- REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
- REJECT icmp -- anywhere anywhere reject-with icmp-host-unreachable
- REJECT all -- anywhere anywhere reject-with icmp-host-prohibited
- Chain shorewall (0 references)
- target prot opt source destination
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement