Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ip firewall filter print
- Flags: X - disabled, I - invalid; D - dynamic
- 0 D ;;; special dummy rule to show fasttrack counters
- chain=forward action=passthrough
- 1 ;;; DHCP-client
- chain=input action=accept protocol=udp dst-port=68 log=no log-prefix=""
- 2 ;;; Established,related,untracked
- chain=input action=accept connection-state=established,related,untracked log=no log-prefix=""
- 3 X ;;; Local loopback (for CAPsMAN)
- chain=input action=accept dst-address=127.0.0.1 log=no log-prefix=""
- 4 X ;;; IPSec policy (input)
- chain=forward action=accept log=no log-prefix="" ipsec-policy=in,ipsec
- 5 X ;;; IPSec policy (output)
- chain=forward action=accept log=no log-prefix="" ipsec-policy=out,ipsec
- 6 ;;; FASTTRACK
- chain=forward action=fasttrack-connection hw-offload=yes connection-state=established,related log=no log-prefix=""
- 7 ;;; Established,related, untracked
- chain=forward action=accept connection-state=established,related,untracked log=no log-prefix=""
- 8 ;;; Invalid
- chain=input action=drop connection-state=invalid log=no log-prefix=""
- 9 ;;; Invalid
- chain=forward action=drop connection-state=invalid log=no log-prefix=""
- 10 ;;; XMAS scan (tcp)
- chain=input action=drop tcp-flags=!,fin,syn,rst,psh,ack,urg connection-state=new connection-nat-state=!dstnat protocol=tcp
- in-interface-list=WAN log=no log-prefix=""
- 11 ;;; NULL packets
- chain=input action=drop tcp-flags=!,fin,syn,rst,ack connection-state=new protocol=tcp in-interface-list=WAN log=no log-prefix=""
- 12 ;;; XMAS scan (udp)
- chain=input action=drop connection-state=new connection-nat-state=!dstnat protocol=udp in-interface-list=WAN log=no log-prefix=""
- 13 ;;; Unusual TCP options
- chain=forward action=drop protocol=tcp in-interface-list=WAN tcp-mss=!300-2000 log=no log-prefix=""
- 14 ;;; WAN access
- chain=input action=drop protocol=tcp in-interface-list=WAN dst-port=422,8443,9291 log=no log-prefix=""
- 15 ;;; Honeypot (tcp)
- chain=input action=add-src-to-address-list protocol=tcp address-list=Honeypot address-list-timeout=4w2d in-interface-list=WAN
- dst-port=21-25,53,80,135-139,161,443-445,1433,1723,2375,3306,3389,5000 log=no log-prefix=""
- 16 ;;; Honeypot (tcp)
- chain=input action=add-src-to-address-list protocol=tcp address-list=Honeypot
- address-list-timeout=4w2d in-interface-list=WAN
- dst-port=5432,5900,5985,6379,8000,8080,8443,9000,9200,27017,11211,50000,47808,49152 log=no
- log-prefix=""
- 17 ;;; Honeypot (udp)
- chain=input action=add-src-to-address-list protocol=udp address-list=Honeypot
- address-list-timeout=4w2d in-interface-list=WAN
- dst-port=21-25,53,80,135-139,161,443-445,1433,1723,2375,3306,3389,5000 log=no log-prefix=""
- 18 ;;; Honeypot (udp)
- chain=input action=add-src-to-address-list protocol=udp address-list=Honeypot
- address-list-timeout=4w2d in-interface-list=WAN
- dst-port=5432,5900,5985,6379,8000,8080,8443,9000,9200,27017,11211,50000,47808,49152 log=no
- log-prefix=""
- 19 ;;; Path MTU Discovery
- chain=forward action=accept protocol=icmp in-interface-list=WAN icmp-options=3:4 log=no
- log-prefix=""
- 20 ;;; ICMP
- chain=input action=drop protocol=icmp in-interface-list=WAN log=no log-prefix=""
- 21 ;;; Broadcast
- chain=forward action=drop protocol=tcp out-interface-list=WAN
- dst-port=135-139,445,1900,2000,2001,5353,5355,5678,5679,5675,8728,8729 log=no log-prefix=""
- 22 ;;; Broadcast
- chain=forward action=drop protocol=udp out-interface-list=WAN
- dst-port=135-139,445,1900,2000,2001,5353,5355,5678,5679,5675,8728,8729 log=no log-prefix=""
- 23 ;;; Broadcast
- chain=output action=drop protocol=tcp out-interface-list=WAN
- dst-port=135-139,445,1900,2000,2001,5353,5355,5678,5679,5675,8728,8729 log=no log-prefix=""
- 24 ;;; Broadcast
- chain=output action=drop protocol=udp out-interface-list=WAN
- dst-port=135-139,445,1900,2000,2001,5353,5355,5678,5679,5675,8728,8729 log=no log-prefix=""
- 25 ;;; All incoming from WAN
- chain=input action=drop in-interface-list=WAN log=no log-prefix=""
- 26 ;;; All from WAN not DSTNATed
- chain=forward action=drop connection-state=new connection-nat-state=!dstnat
- in-interface-list=WAN log=no log-prefix=""
Advertisement
Add Comment
Please, Sign In to add comment