Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- sudo iptables -xvnL
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 7022 384496 LOG_AND_DROP all -- * * 0.0.0.0/0 0.0.0.0/0 match-set countries src
- 31431 10369511 f2b-postfix-sasl tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 25
- 149619 11405575 f2b-dovecot tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 110,995,143,993
- 947249 113664839 ufw-before-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
- 947249 113664839 ufw-before-input all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-after-input all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-after-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-reject-input all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-track-input all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ufw-before-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-before-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-after-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-after-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-reject-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ufw-track-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 9 packets, 1136 bytes)
- pkts bytes target prot opt in out source destination
- 955410 207335217 ufw-before-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
- 955410 207335217 ufw-before-output all -- * * 0.0.0.0/0 0.0.0.0/0
- 32052 2677411 ufw-after-output all -- * * 0.0.0.0/0 0.0.0.0/0
- 32052 2677411 ufw-after-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
- 32052 2677411 ufw-reject-output all -- * * 0.0.0.0/0 0.0.0.0/0
- 32052 2677411 ufw-track-output all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain LOG_AND_DROP (1 references)
- pkts bytes target prot opt in out source destination
- 7022 384496 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4 prefix "Source host denied "
- 7022 384496 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain f2b-dovecot (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 REJECT all -- * * 79.124.49.234 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.53.212 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.41.150.141 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.140.50 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 220.167.202.215 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 79.124.49.234 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.55.5 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.54.20 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.54.172 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.53.44 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.53.212 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.53.150 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.52.76 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.140.97 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 49.86.140.146 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 36.100.33.103 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 36.100.244.88 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 223.221.76.254 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 223.221.76.158 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 223.221.209.156 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 223.221.206.245 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 218.91.29.141 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 180.119.94.66 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 180.119.94.171 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 180.119.94.109 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.41.150.141 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 125.72.178.146 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 118.213.38.52 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 110.166.210.182 0.0.0.0/0 reject-with icmp-port-unreachable
- 150013 11440857 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain f2b-postfix-sasl (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 REJECT all -- * * 45.94.31.137 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 87.120.93.10 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 91.202.233.22 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 79.124.49.234 0.0.0.0/0 reject-with icmp-port-unreachable
- 12 608 REJECT all -- * * 196.251.92.119 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.191 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.177 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.128/26 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 103.237.86.47 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 91.202.233.22 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 87.120.120.49 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 79.124.49.234 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.126.43 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.126.239 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.125.51 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.125.161 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.121.0/25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 58.53.120.70 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 196.251.92.119 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 185.208.159.90 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.86.82 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.86.107 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.86.0/24 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.85.87 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.85.0/25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.84.182 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.84.164 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 171.81.84.160/27 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 165.154.209.175 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.131.0/25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.130.35 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.129.47 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.129.32/27 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.129.0/25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.128.0/26 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.128.0/25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.102.128.0/24 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.55.17 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.52.25 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.35.124 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.35.0/24 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.111.204 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.110.97 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.110.150 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.109.216 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.107.130 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 119.101.104.199 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 116.209.103.42 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 116.209.101.166 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 116.209.101.158 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 116.209.101.128/26 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.191 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.177 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 115.231.8.128/26 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- * * 103.237.86.47 0.0.0.0/0 reject-with icmp-port-unreachable
- 31459 10371469 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-after-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-after-input (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:137
- 0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:138
- 0 0 ufw-skip-to-policy-input tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:139
- 0 0 ufw-skip-to-policy-input tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:445
- 0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
- 0 0 ufw-skip-to-policy-input udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68
- 0 0 ufw-skip-to-policy-input all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
- Chain ufw-after-logging-forward (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
- Chain ufw-after-logging-input (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
- Chain ufw-after-logging-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-after-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-forward (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 3
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 11
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 12
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 0 0 ufw-user-forward all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-before-input (1 references)
- pkts bytes target prot opt in out source destination
- 478238 51390988 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
- 447370 61100727 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 1733 70132 ufw-logging-deny all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
- 1733 70132 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 3
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 11
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 12
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:67 dpt:68
- 19908 1102992 ufw-not-local all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 224.0.0.251 udp dpt:5353
- 0 0 ACCEPT udp -- * * 0.0.0.0/0 239.255.255.250 udp dpt:1900
- 19908 1102992 ufw-user-input all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-before-logging-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-logging-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-logging-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-output (1 references)
- pkts bytes target prot opt in out source destination
- 478238 51390988 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
- 445120 153266818 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- 32052 2677411 ufw-user-output all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-logging-allow (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW ALLOW] "
- Chain ufw-logging-deny (2 references)
- pkts bytes target prot opt in out source destination
- 1665 67412 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID limit: avg 3/min burst 10
- 68 2720 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10 LOG flags 0 level 4 prefix "[UFW BLOCK] "
- Chain ufw-not-local (1 references)
- pkts bytes target prot opt in out source destination
- 19908 1102992 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type LOCAL
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
- 0 0 ufw-logging-deny all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 10
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-reject-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-reject-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-reject-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-skip-to-policy-forward (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-skip-to-policy-input (7 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-skip-to-policy-output (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-track-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-track-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-track-output (1 references)
- pkts bytes target prot opt in out source destination
- 657 39684 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate NEW
- 31259 2624659 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 ctstate NEW
- Chain ufw-user-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-input (1 references)
- pkts bytes target prot opt in out source destination
- 1894 108984 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443 /* 'dapp_Apache%20Full' */
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
- 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:11000
- 1268 75048 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:25
- 10286 535128 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:587
- 339 19952 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:995
- 58 3140 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:143
- 1772 104120 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:993
- 43 2272 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- 4244 254108 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:465
- 4 240 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6969
- Chain ufw-user-limit (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 3/min burst 5 LOG flags 0 level 4 prefix "[UFW LIMIT BLOCK] "
- 0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- Chain ufw-user-limit-accept (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ufw-user-logging-forward (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-logging-input (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-logging-output (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-output (1 references)
- pkts bytes target prot opt in out source destination
- gordon@server1:~$
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement