Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- table ip Filter {
- chain Input {
- type filter hook input priority 0; policy accept;
- ct state established accept
- ct state related accept
- iif "lo" accept
- tcp dport ssh counter packets 0 bytes 0 accept
- counter packets 3106 bytes 192457 log drop
- }
- chain Output {
- type filter hook output priority 0; policy accept;
- ct state established accept
- ct state related accept
- oif "lo" accept
- ct state new counter packets 21446 bytes 1442088 accept
- }
- }
- table ip6 Filter {
- chain Input {
- type filter hook input priority 0; policy accept;
- ct state established accept
- ct state related accept
- iif "lo" accept
- tcp dport ssh counter packets 0 bytes 0 accept
- icmpv6 type { nd-neighbor-solicit, echo-request, nd-router-advert, nd-neighbor-advert} accept
- counter packets 51 bytes 7529 log drop
- }
- chain Output {
- type filter hook output priority 0; policy accept;
- ct state established accept
- ct state related accept
- oif "lo" accept
- ct state new counter packets 1140 bytes 104444 accept
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement