Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- utm:/var/mdw/etc/iptables # cat iptable.filter
- # Generated by iptables-save v1.4.4 on Mon Feb 1 14:24:48 2010
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :GEOIP_REJECT - [0:0]
- :GEOIP_OUT - [0:0]
- :AUTO_FORWARD - [0:0]
- :AUTO_INPUT - [0:0]
- :AUTO_OUTPUT - [0:0]
- :HA_IN - [0:0]
- :HA_OUT - [0:0]
- :LOCKOUT - [0:0]
- :INVALID_PKT - [0:0]
- :LOCAL_RESTAPI - [0:0]
- :LOGACCEPT - [0:0]
- :LOGDROP - [0:0]
- :LOGREJECT - [0:0]
- :PSD_ACTION - [0:0]
- :PSD_MATCH - [0:0]
- :RELATED_FWD - [0:0]
- :SANITY_CHECKS - [0:0]
- :STRICT_TCP_DROP - [0:0]
- :STRICT_TCP_STATE - [0:0]
- :MULTIPATH_DROP - [0:0]
- :USR_FORWARD - [0:0]
- :USR_INPUT - [0:0]
- :USR_OUTPUT - [0:0]
- #slow http attack prevention [NUTM-9287]
- -A INPUT -p tcp --dport webadmin -m connlimit --connlimit-above 10 -j REJECT --reject-with tcp-reset
- -A INPUT -i lo -j ACCEPT
- -A INPUT -m confirmed ! -d 224.0.0.0/4 -j ACCEPT
- -A INPUT -m conntrack --ctstate RELATED -j CONFIRMED
- -A INPUT -j HA_IN
- -A INPUT -j LOCKOUT
- -A INPUT -j PSD_MATCH
- -A INPUT -j SANITY_CHECKS
- -A INPUT -j AUTO_INPUT
- -A INPUT -j USR_INPUT
- -A INPUT -m logmark --logmark 60001 -j LOGDROP
- -A FORWARD -m confirmed ! -d 224.0.0.0/4 -j ACCEPT
- -A FORWARD -m conntrack --ctstate RELATED -j RELATED_FWD
- -A FORWARD -j PSD_MATCH
- -A FORWARD -j AUTO_FORWARD
- -A FORWARD -j USR_FORWARD
- -A FORWARD -m logmark --logmark 60002 -j LOGDROP
- -A OUTPUT -p tcp -d 127.0.0.1 --dport 4472 -m owner --uid-owner 100 -j LOGDROP
- -A OUTPUT -o lo -p tcp --dport 3002 -j LOCAL_RESTAPI
- -A OUTPUT -o lo -p tcp --dport 3498 -j LOCAL_RESTAPI
- -A OUTPUT -o lo -j ACCEPT
- -A OUTPUT -m confirmed ! -d 224.0.0.0/4 -j ACCEPT
- -A OUTPUT -m conntrack --ctstate RELATED -j CONFIRMED
- # allow root to temporarily override output rules
- -A OUTPUT -m condition --condition "OUTPUT_ACCEPT_ALL" -m owner --uid-owner root --gid-owner root -j CONFIRMED
- # NUTM-10626: The dehydrated output rules are unconditional because Middleware would try to connect outbound before creating the rules
- -A OUTPUT -p tcp -m tcp --sport 1:65535 --dport 443 -m owner --uid-owner dehydrated --gid-owner dehydrated -j CONFIRMED
- -A OUTPUT -j HA_OUT
- -A OUTPUT -j SANITY_CHECKS
- -A OUTPUT -j AUTO_OUTPUT
- -A OUTPUT -j USR_OUTPUT
- -A OUTPUT ! -o eth2 -p tcp --tcp-flags SYN,ACK,FIN ACK,FIN -j DROP
- -A OUTPUT ! -o eth2 -p tcp --tcp-flags SYN,RST RST -j DROP
- -A OUTPUT -m logmark --logmark 60003 -j LOGDROP
- -A INVALID_PKT -m logmark --logmark 60007 -j NFLOG --nflog-prefix "INVALID_PKT: "
- -A INVALID_PKT -j DROP
- -A STRICT_TCP_DROP -j DROP
- -A LOGACCEPT -j NFLOG --nflog-prefix "ACCEPT: "
- -A LOGACCEPT -j CONFIRMED
- -A LOGDROP -j NFLOG --nflog-prefix "DROP: "
- -A LOGDROP -j DROP
- -A LOGREJECT -j NFLOG --nflog-prefix "REJECT: "
- -A LOGREJECT -j REJECT --reject-with icmp-port-unreachable
- -A GEOIP_REJECT -p tcp -j REJECT --reject-with tcp-reset
- -A GEOIP_REJECT -j REJECT --reject-with icmp-port-unreachable
- -A RELATED_FWD -j CONFIRMED
- -A LOCAL_RESTAPI -m owner --uid-owner root -j ACCEPT
- -A LOCAL_RESTAPI -m owner --uid-owner loginuser -j ACCEPT
- -A LOCAL_RESTAPI -j DROP
- COMMIT
- # Completed on Mon Feb 1 14:24:48 2010
Advertisement
Add Comment
Please, Sign In to add comment