Advertisement
Guest User

Untitled

a guest
Sep 23rd, 2018
69
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.45 KB | None | 0 0
  1. iptables-save
  2. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:56:03 2018
  3. *security
  4. :INPUT ACCEPT [326566:104515603]
  5. :FORWARD ACCEPT [0:0]
  6. :OUTPUT ACCEPT [341384:197219549]
  7. COMMIT
  8. # Completed on Sun Sep 23 23:56:03 2018
  9. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:56:03 2018
  10. *raw
  11. :PREROUTING ACCEPT [344731:105476093]
  12. :OUTPUT ACCEPT [341385:197219717]
  13. COMMIT
  14. # Completed on Sun Sep 23 23:56:03 2018
  15. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:56:03 2018
  16. *nat
  17. :PREROUTING ACCEPT [26157:1403594]
  18. :INPUT ACCEPT [8161:453356]
  19. :OUTPUT ACCEPT [20698:1441595]
  20. :POSTROUTING ACCEPT [20698:1441595]
  21. COMMIT
  22. # Completed on Sun Sep 23 23:56:03 2018
  23. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:56:03 2018
  24. *mangle
  25. :PREROUTING ACCEPT [344731:105476093]
  26. :INPUT ACCEPT [344731:105476093]
  27. :FORWARD ACCEPT [0:0]
  28. :OUTPUT ACCEPT [341385:197219717]
  29. :POSTROUTING ACCEPT [341385:197219717]
  30. COMMIT
  31. # Completed on Sun Sep 23 23:56:03 2018
  32. # Generated by iptables-save v1.4.21 on Sun Sep 23 23:56:03 2018
  33. *filter
  34. :INPUT ACCEPT [0:0]
  35. :FORWARD ACCEPT [0:0]
  36. :OUTPUT ACCEPT [51:12904]
  37. :INBOUND - [0:0]
  38. -A INPUT -m state --state NEW -j LOG --log-prefix "New Connection: "
  39. -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
  40. -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
  41. -A INPUT -i lo -j ACCEPT
  42. -A INPUT -s 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable
  43. -A INPUT -p icmp -m state --state NEW -m icmp --icmp-type 8 -j ACCEPT
  44. -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
  45. -A INPUT -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
  46. -A INPUT -p tcp -m tcp --dport 443 -m state --state NEW -j ACCEPT
  47. -A INPUT -p tcp -m tcp --dport 3306 -m state --state NEW -j ACCEPT
  48. -A INPUT -p tcp -m tcp --dport 21 -m state --state NEW -j ACCEPT
  49. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  50. -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables_INPUT_denied: " --log-level 7
  51. -A INPUT -p tcp -m tcp --dport 993 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  52. -A INPUT -p tcp -m tcp --dport 110 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  53. -A INPUT -p tcp -m tcp --dport 995 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  54. -A INPUT -p tcp -m tcp --dport 143 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
  55. -A INPUT -j LOG
  56. -A INPUT -j LOG --log-prefix "BAD_INPUT: "
  57. -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
  58. -A INPUT -j LOG --log-prefix "BAD_INPUT: " --log-level 7
  59. -A INPUT -j LOG --log-prefix "BAD_INPUT: "
  60. -A INPUT -p tcp -j LOG --log-prefix " INPUT TCP "
  61. -A INPUT -i eth0 -p tcp -m state --state RELATED,ESTABLISHED -j INBOUND
  62. -A INPUT -j REJECT --reject-with icmp-port-unreachable
  63. -A FORWARD -m limit --limit 5/min -j LOG --log-prefix "iptables_FORWARD_denied: " --log-level 7
  64. -A FORWARD -j REJECT --reject-with icmp-port-unreachable
  65. -A FORWARD -j LOG --log-prefix "BAD_FORWARD: "
  66. -A FORWARD -j LOG --log-prefix "BAD_FORWARD: " --log-level 7
  67. -A OUTPUT -p tcp -m tcp --sport 993 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  68. -A OUTPUT -p tcp -m tcp --sport 110 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  69. -A OUTPUT -p tcp -m tcp --sport 995 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  70. -A OUTPUT -p tcp -m tcp --sport 143 -m conntrack --ctstate ESTABLISHED -j ACCEPT
  71. -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: "
  72. -A OUTPUT -j LOG --log-prefix "BAD_OUTPUT: " --log-level 7
  73. -A INBOUND -p tcp -j LOG --log-prefix " INBOUND TCP "
  74. -A INBOUND -p tcp -j ACCEPT
  75. COMMIT
  76. # Completed on Sun Sep 23 23:56:03 2018
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement