Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # iptables -L
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- REJECT all -- 127.0.0.0/8 anywhere reject-with icmp-port-unreachable
- ACCEPT icmp -- anywhere anywhere state NEW icmp echo-request
- ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spt:ftp state ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spt:ftp-data state RELATED,ESTABLISHED
- ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:1024:65535 state ESTABLISHED
- ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:ssh
- ACCEPT udp -- anywhere anywhere state NEW,ESTABLISHED udp dpt:openvpn
- ACCEPT udp -- anywhere anywhere state ESTABLISHED udp spt:domain
- ACCEPT tcp -- anywhere anywhere state ESTABLISHED tcp spt:domain
- ACCEPT tcp -- anywhere anywhere state ESTABLISHED tcp spt:http
- ACCEPT tcp -- anywhere anywhere state ESTABLISHED tcp spt:https
- ACCEPT all -- anywhere anywhere
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning prefix "iptables_INPUT_denied: "
- REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT all -- 10.89.0.0/24 anywhere
- ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning prefix "iptables_FORWARD_denied: "
- REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- ACCEPT all -- anywhere anywhere
- ACCEPT icmp -- anywhere anywhere
- ACCEPT tcp -- anywhere anywhere state ESTABLISHED tcp spt:ssh
- ACCEPT udp -- anywhere anywhere state ESTABLISHED udp spt:openvpn
- ACCEPT udp -- anywhere anywhere state NEW,ESTABLISHED udp dpt:domain
- ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:domain
- ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:http
- ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:https
- ACCEPT all -- anywhere anywhere
- LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning prefix "iptables_OUTPUT_denied: "
- REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement