Advertisement
Guest User

Untitled

a guest
Nov 9th, 2018
453
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.96 KB | None | 0 0
  1. *nat
  2. :PREROUTING ACCEPT [0:0]
  3. :INPUT ACCEPT [0:0]
  4. :OUTPUT ACCEPT [1:76]
  5. #:POSTROUTING ACCEPT [1:76]
  6. :PREROUTING ACCEPT [0:0]
  7.  
  8. -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
  9. COMMIT
  10. #
  11. # Run that command to get above, 'iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE'
  12. #
  13. *filter
  14. :INPUT DROP [0:0]
  15. :FORWARD DROP [0:0]
  16. :OUTPUT ACCEPT [0:0]
  17.  
  18. -A INPUT -i lo -j ACCEPT
  19. #-A OUTPUT -o lo -j ACCEPT
  20.  
  21. -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
  22.  
  23. -A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
  24. -A INPUT -p udp -m state --state NEW -m udp --dport 1194 -j ACCEPT
  25.  
  26. -A INPUT -i tun0 -j ACCEPT
  27. -A FORWARD -i tun0 -j ACCEPT
  28. -A FORWARD -i tun0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
  29. -A FORWARD -i eth0 -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT
  30.  
  31. -A INPUT -p icmp -j ACCEPT
  32. -A INPUT -j REJECT --reject-with icmp-host-prohibited
  33. -A FORWARD -j REJECT --reject-with icmp-host-prohibited
  34. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement