Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Wed Mar 30 19:06:19 2022
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [4:301]
- :OUTPUT ACCEPT [111:28606]
- -A INPUT -p tcp -m tcp --sport 443 --tcp-flags RST RST -j DROP
- -A INPUT -i wlan0 -j ACCEPT
- -A INPUT -i eth1 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 139 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 445 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -i eth0 -p udp -m udp --dport 443 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -s 172.29.3.0/24 -j ACCEPT
- -A INPUT -d 172.29.3.0/24 -j ACCEPT
- -A INPUT -p udp -m udp --dport 16881 -j ACCEPT
- -A INPUT -p udp -m udp --sport 6881 -j ACCEPT
- -A INPUT -p udp -m udp --sport 6882 -j ACCEPT
- -A INPUT -p udp -m udp --sport 6883 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6962 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6982 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6899 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 23880 -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -i eth1 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 5/hour -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 110 -j ACCEPT
- -A INPUT -p tcp -m tcp --sport 110 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 143 -j ACCEPT
- -A INPUT -d 192.168.1.64/32 -p icmp -m icmp --icmp-type 8 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6667 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6668 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 6669 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 8443 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 2010:2020 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 2010:2020 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 23122 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 23122 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 23123 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 23123 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 25 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 25 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 6883 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 6883 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 6882 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 6882 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 23125 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 23125 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 7881 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 7881 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 8881 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 8881 -j ACCEPT
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -p udp -m udp --dport 500 -j ACCEPT
- -A INPUT -p udp -m udp --dport 4500 -j ACCEPT
- -A INPUT -p esp -j ACCEPT
- -A INPUT -p ah -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 500 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 500 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 4500 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 4500 -j ACCEPT
- -A INPUT -p tcp -m multiport --dports 1701 -j ACCEPT
- -A INPUT -p udp -m multiport --dports 1701 -j ACCEPT
- -A INPUT -p tcp -m tcp --dport 56055 -j ACCEPT
- -A INPUT -p udp -m udp --dport 56055 -j ACCEPT
- -A INPUT -p udp -m udp --dport 6882 -j ACCEPT
- -A INPUT -p udp -m udp --dport 6885 -j ACCEPT
- -A INPUT -m mark --mark 0x10000/0x10000 -j ACCEPT
- -A INPUT -s 172.29.2.0/24 -i eth1 -j ACCEPT
- -A INPUT -s 172.29.3.0/24 -i eth1 -j ACCEPT
- -A INPUT -s 10.0.2.0/24 -i eth1 -j ACCEPT
- -A INPUT -i ppp+ -m state --state NEW -j DROP
- -A INPUT -i eth0 -m state --state NEW -j DROP
- -A FORWARD -s 194.67.1.14/32 -j DROP
- -A FORWARD -d 194.67.1.14/32 -j DROP
- -A FORWARD -s 91.192.150.4/32 -j DROP
- -A FORWARD -s 91.192.149.113/32 -j DROP
- -A FORWARD -s 91.192.148.113/32 -j DROP
- -A FORWARD -s 91.192.149.4/32 -j DROP
- -A FORWARD -s 91.192.150.113/32 -j DROP
- -A FORWARD -s 91.192.148.4/32 -j DROP
- -A FORWARD -d 91.192.148.4/32 -j DROP
- -A FORWARD -d 91.192.150.113/32 -j DROP
- -A FORWARD -d 91.192.150.4/32 -j DROP
- -A FORWARD -d 91.192.149.113/32 -j DROP
- -A FORWARD -d 91.192.149.4/32 -j DROP
- -A FORWARD -d 91.192.148.113/32 -j DROP
- -A FORWARD -s 195.85.23.141/32 -j DROP
- -A FORWARD -d 172.29.2.5/32 -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -d 172.29.2.14/32 -p udp -m udp --dport 500 -j ACCEPT
- -A FORWARD -d 172.29.2.14/32 -p udp -m udp --dport 4500 -j ACCEPT
- -A OUTPUT -s 172.29.3.0/24 -j ACCEPT
- -A OUTPUT -d 172.29.3.0/24 -j ACCEPT
- -A OUTPUT -p udp -m udp --dport 16881 -j ACCEPT
- -A OUTPUT -p udp -m udp --sport 6881 -j ACCEPT
- -A OUTPUT -p udp -m udp --sport 6882 -j ACCEPT
- -A OUTPUT -p udp -m udp --sport 6883 -j ACCEPT
- -A OUTPUT -p tcp -m tcp --sport 443 -j ACCEPT
- -A OUTPUT -s 192.168.1.64/32 -p icmp -m icmp --icmp-type 0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT -p udp -m udp --sport 6882 -j ACCEPT
- COMMIT
- # Completed on Wed Mar 30 19:06:19 2022
- # Generated by iptables-save v1.6.0 on Wed Mar 30 19:06:19 2022
- *nat
- :PREROUTING ACCEPT [18:1563]
- :INPUT ACCEPT [13:747]
- :OUTPUT ACCEPT [1:73]
- :POSTROUTING ACCEPT [1:73]
- -A PREROUTING -p tcp -m multiport --dports 2010:2020 -j DNAT --to-destination 172.29.2.5
- -A PREROUTING -p udp -m multiport --dports 2010:2020 -j DNAT --to-destination 172.29.2.5
- -A PREROUTING -p tcp -m multiport --dports 23122 -j DNAT --to-destination 172.29.2.2:22
- -A PREROUTING -p udp -m multiport --dports 23122 -j DNAT --to-destination 172.29.2.2:22
- -A PREROUTING -p tcp -m multiport --dports 23123 -j DNAT --to-destination 172.29.2.3:22
- -A PREROUTING -p udp -m multiport --dports 23123 -j DNAT --to-destination 172.29.2.3:22
- -A PREROUTING -p tcp -m multiport --dports 25 -j DNAT --to-destination 172.29.2.3:25
- -A PREROUTING -p udp -m multiport --dports 25 -j DNAT --to-destination 172.29.2.3:25
- -A PREROUTING -p tcp -m multiport --dports 6883 -j DNAT --to-destination 172.29.2.3:6883
- -A PREROUTING -p udp -m multiport --dports 6883 -j DNAT --to-destination 172.29.2.3:6883
- -A PREROUTING -p tcp -m multiport --dports 6882 -j DNAT --to-destination 172.29.2.3:6882
- -A PREROUTING -p udp -m multiport --dports 6882 -j DNAT --to-destination 172.29.2.3:6882
- -A PREROUTING -p tcp -m multiport --dports 23125 -j DNAT --to-destination 172.29.2.5:22
- -A PREROUTING -p udp -m multiport --dports 23125 -j DNAT --to-destination 172.29.2.5:22
- -A PREROUTING -p tcp -m multiport --dports 7881 -j DNAT --to-destination 172.29.2.2:7881
- -A PREROUTING -p udp -m multiport --dports 7881 -j DNAT --to-destination 172.29.2.2:7881
- -A PREROUTING -p tcp -m multiport --dports 8881 -j DNAT --to-destination 172.29.2.2:8881
- -A PREROUTING -p udp -m multiport --dports 8881 -j DNAT --to-destination 172.29.2.2:8881
- -A PREROUTING -p tcp -m multiport --dports 500 -j DNAT --to-destination 172.29.2.14:500
- -A PREROUTING -p udp -m multiport --dports 500 -j DNAT --to-destination 172.29.2.14:500
- -A PREROUTING -p tcp -m multiport --dports 4500 -j DNAT --to-destination 172.29.2.14:4500
- -A PREROUTING -p udp -m multiport --dports 4500 -j DNAT --to-destination 172.29.2.14:4500
- -A PREROUTING -p tcp -m multiport --dports 1701 -j DNAT --to-destination 172.29.2.14:1701
- -A PREROUTING -p udp -m multiport --dports 1701 -j DNAT --to-destination 172.29.2.14:1701
- -A PREROUTING -d <host>/32 -i eth1 -p udp -m udp --dport 500 -j DNAT --to-destination 172.29.2.14
- -A PREROUTING -d <host>/32 -i eth1 -p udp -m udp --dport 4500 -j DNAT --to-destination 172.29.2.14
- -A PREROUTING -p tcp -m mark --mark 0x12225 -j REDIRECT --to-ports 22
- -A POSTROUTING -s 172.29.2.0/24 -o eth0 -m policy --dir out --pol ipsec -j ACCEPT
- -A POSTROUTING -m policy --dir out --pol ipsec -j ACCEPT
- -A POSTROUTING -s 172.29.2.14/32 -p udp -m udp --sport 500 -j SNAT --to-source <host>
- -A POSTROUTING -s 172.29.2.14/32 -p udp -m udp --sport 4500 -j SNAT --to-source <host>
- -A POSTROUTING -s 172.29.2.0/24 -o eth0 -j SNAT --to-source 192.168.1.64
- -A POSTROUTING -s 172.29.3.0/24 -o eth0 -j SNAT --to-source 192.168.1.64
- -A POSTROUTING -s 10.0.2.0/24 -o eth0 -j SNAT --to-source 192.168.1.64
- -A POSTROUTING -s 172.29.2.0/24 -o wlan+ -j MASQUERADE
- -A POSTROUTING -s 172.29.3.0/24 -o wlan+ -j MASQUERADE
- -A POSTROUTING -s 10.0.2.0/24 -o wlan+ -j MASQUERADE
- -A POSTROUTING -d 10.0.2.0/24 -j ACCEPT
- -A POSTROUTING -s 10.0.2.0/24 -j ACCEPT
- -A POSTROUTING -s 172.29.2.0/24 -d 172.29.3.0/24 -j ACCEPT
- -A POSTROUTING -d 172.29.2.0/24 -j ACCEPT
- -A POSTROUTING -d 172.29.3.0/24 -j ACCEPT
- -A POSTROUTING -s 172.29.3.0/24 -j ACCEPT
- -A POSTROUTING -s 172.29.2.0/24 -o eth0 -j SNAT --to-source 192.168.1.64
- -A POSTROUTING -s 172.29.3.0/24 -o eth0 -j SNAT --to-source 192.168.1.64
- COMMIT
- # Completed on Wed Mar 30 19:06:19 2022
- # Generated by iptables-save v1.6.0 on Wed Mar 30 19:06:19 2022
- *mangle
- :PREROUTING ACCEPT [572:113873]
- :INPUT ACCEPT [278:48273]
- :FORWARD ACCEPT [290:64800]
- :OUTPUT ACCEPT [111:28606]
- :POSTROUTING ACCEPT [446:103228]
- -A PREROUTING -d 192.168.1.64/32 -p tcp -m multiport --dports 23123 -j MARK --set-xmark 0x12225/0x12225
- -A PREROUTING -d 192.168.1.64/32 -p tcp -m multiport --dports 23123 -j MARK --set-xmark 0x12225/0x12225
- -A PREROUTING -d 192.168.1.64/32 -p tcp -m multiport --dports 23125 -j MARK --set-xmark 0x12225/0x12225
- -A PREROUTING -d 192.168.1.64/32 -p tcp -m multiport --dports 4422 -j MARK --set-xmark 0x12225/0x12225
- -A FORWARD -s 172.29.2.0/24 -o ppp+ -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- -A FORWARD -s 172.29.3.0/24 -o ppp+ -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- COMMIT
- # Completed on Wed Mar 30 19:06:19 2022
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement