Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@mon02:~# pve-firewall compile
- ipset cmdlist:
- exists PVEFW-0-management-v4 (IhYp62jU7XtKvLTE7SZci/oDVPk)
- create PVEFW-0-management-v4 hash:net family inet hashsize 64 maxelem 64 bucketsize 12
- add PVEFW-0-management-v4 192.168.10.0/24
- add PVEFW-0-management-v4 192.168.10.13
- add PVEFW-0-management-v4 192.168.10.14
- add PVEFW-0-management-v4 192.168.10.15
- add PVEFW-0-management-v4 192.168.10.8
- exists PVEFW-0-management-v6 (6g+lzHFoCegXcweHRfBY4vRsbOc)
- create PVEFW-0-management-v6 hash:net family inet6 hashsize 64 maxelem 64 bucketsize 12
- iptables cmdlist:
- exists PVEFW-Drop (83WlR/a4wLbmURFqMQT3uJSgIG8)
- -A PVEFW-Drop -j PVEFW-DropBroadcast
- -A PVEFW-Drop -p icmp -m icmp --icmp-type fragmentation-needed -j ACCEPT
- -A PVEFW-Drop -p icmp -m icmp --icmp-type time-exceeded -j ACCEPT
- -A PVEFW-Drop -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Drop -p udp --match multiport --dports 135,445 -j DROP
- -A PVEFW-Drop -p udp --dport 137:139 -j DROP
- -A PVEFW-Drop -p udp --sport 137 --dport 1024:65535 -j DROP
- -A PVEFW-Drop -p tcp --match multiport --dports 135,139,445 -j DROP
- -A PVEFW-Drop -p udp --dport 1900 -j DROP
- -A PVEFW-Drop -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Drop -p udp --sport 53 -j DROP
- exists PVEFW-DropBroadcast (NyjHNAtFbkH7WGLamPpdVnxHy4w)
- -A PVEFW-DropBroadcast -m addrtype --dst-type BROADCAST -j DROP
- -A PVEFW-DropBroadcast -m addrtype --dst-type MULTICAST -j DROP
- -A PVEFW-DropBroadcast -m addrtype --dst-type ANYCAST -j DROP
- -A PVEFW-DropBroadcast -d 224.0.0.0/4 -j DROP
- exists PVEFW-FORWARD (qnNexOcGa+y+jebd4dAUqFSp5nw)
- -A PVEFW-FORWARD -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-FORWARD -m physdev --physdev-is-bridged --physdev-in fwln+ -j PVEFW-FWBR-IN
- -A PVEFW-FORWARD -m physdev --physdev-is-bridged --physdev-out fwln+ -j PVEFW-FWBR-OUT
- exists PVEFW-FWBR-IN (Ijl7/xz0DD7LF91MlLCz0ybZBE0)
- -A PVEFW-FWBR-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
- exists PVEFW-FWBR-OUT (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- exists PVEFW-HOST-IN (ezgtFmiN1hX8rDNGlqtbBtqScxM)
- -A PVEFW-HOST-IN -i lo -j ACCEPT
- -A PVEFW-HOST-IN -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-IN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
- -A PVEFW-HOST-IN -p igmp -j RETURN
- -A PVEFW-HOST-IN -i vmbr10 -s 192.168.10.0/24 -d 192.168.10.0/24 -p tcp --dport 3551 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.70.0/24 -d 192.168.70.0/24 -p tcp --dport 6800:7300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.128/25 -p udp --dport 5405:5406 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.0/25 -p udp --dport 5405:5406 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp --dport 6789 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp --dport 3300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp --dport 6800:7300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.70.0/24 -p tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -d 192.168.80.128/25 -p tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -d 192.168.80.0/25 -p tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v4 src -p tcp --dport 8006 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v4 src -p tcp --dport 5900:5999 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v4 src -p tcp --dport 3128 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v4 src -p tcp --dport 22 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v4 src -p tcp --dport 60000:60050 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.112 -s 192.168.80.111 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.212 -s 192.168.80.211 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.112 -s 192.168.80.113 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.212 -s 192.168.80.213 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.112 -s 192.168.80.101 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.212 -s 192.168.80.201 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.112 -s 192.168.80.102 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.212 -s 192.168.80.202 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.112 -s 192.168.80.103 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.212 -s 192.168.80.203 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -j PVEFW-Drop
- -A PVEFW-HOST-IN -j DROP
- exists PVEFW-HOST-OUT (YAYn8j1iTEcJy69ORHbJBP454RY)
- -A PVEFW-HOST-OUT -o lo -j ACCEPT
- -A PVEFW-HOST-OUT -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-OUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-OUT -p igmp -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp --dport 8006 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp --dport 22 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp --dport 5900:5999 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp --dport 3128 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112 -d 192.168.80.111 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212 -d 192.168.80.211 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112 -d 192.168.80.113 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212 -d 192.168.80.213 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112 -d 192.168.80.101 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212 -d 192.168.80.201 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112 -d 192.168.80.102 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212 -d 192.168.80.202 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112 -d 192.168.80.103 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212 -d 192.168.80.203 -p udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -j RETURN
- exists PVEFW-INPUT (+5iMmLaxKXynOB/+5xibfx7WhFk)
- -A PVEFW-INPUT -j PVEFW-HOST-IN
- exists PVEFW-OUTPUT (LjHoZeSSiWAG3+2ZAyL/xuEehd0)
- -A PVEFW-OUTPUT -j PVEFW-HOST-OUT
- exists PVEFW-Reject (h3DyALVslgH5hutETfixGP08w7c)
- -A PVEFW-Reject -j PVEFW-DropBroadcast
- -A PVEFW-Reject -p icmp -m icmp --icmp-type fragmentation-needed -j ACCEPT
- -A PVEFW-Reject -p icmp -m icmp --icmp-type time-exceeded -j ACCEPT
- -A PVEFW-Reject -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Reject -p udp --match multiport --dports 135,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp --dport 137:139 -j PVEFW-reject
- -A PVEFW-Reject -p udp --sport 137 --dport 1024:65535 -j PVEFW-reject
- -A PVEFW-Reject -p tcp --match multiport --dports 135,139,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp --dport 1900 -j DROP
- -A PVEFW-Reject -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Reject -p udp --sport 53 -j DROP
- exists PVEFW-SET-ACCEPT-MARK (Hg/OIgIwJChBUcWU8Xnjhdd2jUY)
- -A PVEFW-SET-ACCEPT-MARK -j MARK --set-mark 0x80000000/0x80000000
- exists PVEFW-logflags (MN4PH1oPZeABMuWr64RrygPfW7A)
- -A PVEFW-logflags -j DROP
- exists PVEFW-reject (Jlkrtle1mDdtxDeI9QaDSL++Npc)
- -A PVEFW-reject -m addrtype --dst-type BROADCAST -j DROP
- -A PVEFW-reject -s 224.0.0.0/4 -j DROP
- -A PVEFW-reject -p icmp -j DROP
- -A PVEFW-reject -p tcp -j REJECT --reject-with tcp-reset
- -A PVEFW-reject -p udp -j REJECT --reject-with icmp-port-unreachable
- -A PVEFW-reject -p icmp -j REJECT --reject-with icmp-host-unreachable
- -A PVEFW-reject -j REJECT --reject-with icmp-host-prohibited
- exists PVEFW-smurflog (2gfT1VMkfr0JL6OccRXTGXo+1qk)
- -A PVEFW-smurflog -j DROP
- exists PVEFW-smurfs (HssVe5QCBXd5mc9kC88749+7fag)
- -A PVEFW-smurfs -s 0.0.0.0/32 -j RETURN
- -A PVEFW-smurfs -m addrtype --src-type BROADCAST -g PVEFW-smurflog
- -A PVEFW-smurfs -s 224.0.0.0/4 -g PVEFW-smurflog
- exists PVEFW-tcpflags (CMFojwNPqllyqD67NeI5m+bP5mo)
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g PVEFW-logflags
- ip6tables cmdlist:
- exists PVEFW-Drop (Jb79Uw7z1vZglIcV7QXA5uY/nbk)
- -A PVEFW-Drop -p tcp --dport 43 -j PVEFW-reject
- -A PVEFW-Drop -j PVEFW-DropBroadcast
- -A PVEFW-Drop -p icmpv6 -m icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
- -A PVEFW-Drop -p icmpv6 -m icmpv6 --icmpv6-type time-exceeded -j ACCEPT
- -A PVEFW-Drop -p icmpv6 -m icmpv6 --icmpv6-type packet-too-big -j ACCEPT
- -A PVEFW-Drop -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Drop -p udp --match multiport --dports 135,445 -j DROP
- -A PVEFW-Drop -p udp --dport 137:139 -j DROP
- -A PVEFW-Drop -p udp --sport 137 --dport 1024:65535 -j DROP
- -A PVEFW-Drop -p tcp --match multiport --dports 135,139,445 -j DROP
- -A PVEFW-Drop -p udp --dport 1900 -j DROP
- -A PVEFW-Drop -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Drop -p udp --sport 53 -j DROP
- exists PVEFW-DropBroadcast (8Krk5Nh8pDZOOc7BQAbM6PlyFSU)
- -A PVEFW-DropBroadcast -d ff00::/8 -j DROP
- exists PVEFW-FORWARD (qnNexOcGa+y+jebd4dAUqFSp5nw)
- -A PVEFW-FORWARD -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-FORWARD -m physdev --physdev-is-bridged --physdev-in fwln+ -j PVEFW-FWBR-IN
- -A PVEFW-FORWARD -m physdev --physdev-is-bridged --physdev-out fwln+ -j PVEFW-FWBR-OUT
- exists PVEFW-FWBR-IN (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- exists PVEFW-FWBR-OUT (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- exists PVEFW-HOST-IN (t+/LTT8OHyoSgF5i9Hox+PZEud4)
- -A PVEFW-HOST-IN -i lo -j ACCEPT
- -A PVEFW-HOST-IN -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-IN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-IN -p icmpv6 --icmpv6-type router-solicitation -j RETURN
- -A PVEFW-HOST-IN -p icmpv6 --icmpv6-type router-advertisement -j RETURN
- -A PVEFW-HOST-IN -p icmpv6 --icmpv6-type neighbor-solicitation -j RETURN
- -A PVEFW-HOST-IN -p icmpv6 --icmpv6-type neighbor-advertisement -j RETURN
- -A PVEFW-HOST-IN -p igmp -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v6 src -p tcp --dport 8006 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v6 src -p tcp --dport 5900:5999 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v6 src -p tcp --dport 3128 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v6 src -p tcp --dport 22 -j RETURN
- -A PVEFW-HOST-IN -m set --match-set PVEFW-0-management-v6 src -p tcp --dport 60000:60050 -j RETURN
- -A PVEFW-HOST-IN -j PVEFW-Drop
- -A PVEFW-HOST-IN -j DROP
- exists PVEFW-HOST-OUT (br2bPbA9ZjuHOMNhV8tfLRw1mAs)
- -A PVEFW-HOST-OUT -o lo -j ACCEPT
- -A PVEFW-HOST-OUT -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-OUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-OUT -p icmpv6 --icmpv6-type router-solicitation -j RETURN
- -A PVEFW-HOST-OUT -p icmpv6 --icmpv6-type neighbor-solicitation -j RETURN
- -A PVEFW-HOST-OUT -p icmpv6 --icmpv6-type neighbor-advertisement -j RETURN
- -A PVEFW-HOST-OUT -p igmp -j RETURN
- -A PVEFW-HOST-OUT -j RETURN
- exists PVEFW-INPUT (+5iMmLaxKXynOB/+5xibfx7WhFk)
- -A PVEFW-INPUT -j PVEFW-HOST-IN
- exists PVEFW-OUTPUT (LjHoZeSSiWAG3+2ZAyL/xuEehd0)
- -A PVEFW-OUTPUT -j PVEFW-HOST-OUT
- exists PVEFW-Reject (aL1nrxJk/u3XmTb3Am2eaM/3yCM)
- -A PVEFW-Reject -p tcp --dport 43 -j PVEFW-reject
- -A PVEFW-Reject -j PVEFW-DropBroadcast
- -A PVEFW-Reject -p icmpv6 -m icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
- -A PVEFW-Reject -p icmpv6 -m icmpv6 --icmpv6-type time-exceeded -j ACCEPT
- -A PVEFW-Reject -p icmpv6 -m icmpv6 --icmpv6-type packet-too-big -j ACCEPT
- -A PVEFW-Reject -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Reject -p udp --match multiport --dports 135,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp --dport 137:139 -j PVEFW-reject
- -A PVEFW-Reject -p udp --sport 137 --dport 1024:65535 -j PVEFW-reject
- -A PVEFW-Reject -p tcp --match multiport --dports 135,139,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp --dport 1900 -j DROP
- -A PVEFW-Reject -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Reject -p udp --sport 53 -j DROP
- exists PVEFW-SET-ACCEPT-MARK (Hg/OIgIwJChBUcWU8Xnjhdd2jUY)
- -A PVEFW-SET-ACCEPT-MARK -j MARK --set-mark 0x80000000/0x80000000
- exists PVEFW-logflags (MN4PH1oPZeABMuWr64RrygPfW7A)
- -A PVEFW-logflags -j DROP
- exists PVEFW-reject (etEECUYcgUdzuuO+LDP83pu0S8Y)
- -A PVEFW-reject -p icmpv6 -j DROP
- -A PVEFW-reject -p tcp -j REJECT --reject-with tcp-reset
- -A PVEFW-reject -p udp -j REJECT --reject-with icmp6-port-unreachable
- -A PVEFW-reject -j REJECT --reject-with icmp6-adm-prohibited
- exists PVEFW-tcpflags (CMFojwNPqllyqD67NeI5m+bP5mo)
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g PVEFW-logflags
- ebtables cmdlist:
- exists PVEFW-FORWARD (ULtZ6lqjrD/jAKLY+OZo3BbXs9k)
- -A PVEFW-FORWARD -p IPv4 -j ACCEPT
- -A PVEFW-FORWARD -p IPv6 -j ACCEPT
- -A PVEFW-FORWARD -o fwln+ -j PVEFW-FWBR-OUT
- exists PVEFW-FWBR-OUT (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- ignore FORWARD (zuQi5YOvmMWiM9zohnQw/qWemOA)
- ignore INPUT (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- ignore OUTPUT (2jmj7l5rSw0yVb/vlWAYkK/YBwk)
- iptables table raw cmdlist:
- ip6tables table raw cmdlist:
- no changes
- root@mon02:~#
- root@mon02:~#
- root@mon02:~# iptables-save
- # Generated by iptables-save v1.8.7 on Thu Dec 30 06:51:09 2021
- *raw
- :PREROUTING ACCEPT [133755091:64546199927]
- :OUTPUT ACCEPT [130661975:69754270776]
- COMMIT
- # Completed on Thu Dec 30 06:51:09 2021
- # Generated by iptables-save v1.8.7 on Thu Dec 30 06:51:09 2021
- *filter
- :INPUT ACCEPT [1585054:94997148]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [776103:46568441]
- :PVEFW-Drop - [0:0]
- :PVEFW-DropBroadcast - [0:0]
- :PVEFW-FORWARD - [0:0]
- :PVEFW-FWBR-IN - [0:0]
- :PVEFW-FWBR-OUT - [0:0]
- :PVEFW-HOST-IN - [0:0]
- :PVEFW-HOST-OUT - [0:0]
- :PVEFW-INPUT - [0:0]
- :PVEFW-OUTPUT - [0:0]
- :PVEFW-Reject - [0:0]
- :PVEFW-SET-ACCEPT-MARK - [0:0]
- :PVEFW-logflags - [0:0]
- :PVEFW-reject - [0:0]
- :PVEFW-smurflog - [0:0]
- :PVEFW-smurfs - [0:0]
- :PVEFW-tcpflags - [0:0]
- -A INPUT -j PVEFW-INPUT
- -A FORWARD -j PVEFW-FORWARD
- -A OUTPUT -j PVEFW-OUTPUT
- -A PVEFW-Drop -j PVEFW-DropBroadcast
- -A PVEFW-Drop -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
- -A PVEFW-Drop -p icmp -m icmp --icmp-type 11 -j ACCEPT
- -A PVEFW-Drop -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Drop -p udp -m multiport --dports 135,445 -j DROP
- -A PVEFW-Drop -p udp -m udp --dport 137:139 -j DROP
- -A PVEFW-Drop -p udp -m udp --sport 137 --dport 1024:65535 -j DROP
- -A PVEFW-Drop -p tcp -m multiport --dports 135,139,445 -j DROP
- -A PVEFW-Drop -p udp -m udp --dport 1900 -j DROP
- -A PVEFW-Drop -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Drop -p udp -m udp --sport 53 -j DROP
- -A PVEFW-Drop -m comment --comment "PVESIG:83WlR/a4wLbmURFqMQT3uJSgIG8"
- -A PVEFW-DropBroadcast -m addrtype --dst-type BROADCAST -j DROP
- -A PVEFW-DropBroadcast -m addrtype --dst-type MULTICAST -j DROP
- -A PVEFW-DropBroadcast -m addrtype --dst-type ANYCAST -j DROP
- -A PVEFW-DropBroadcast -d 224.0.0.0/4 -j DROP
- -A PVEFW-DropBroadcast -m comment --comment "PVESIG:NyjHNAtFbkH7WGLamPpdVnxHy4w"
- -A PVEFW-FORWARD -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-FORWARD -m physdev --physdev-in fwln+ --physdev-is-bridged -j PVEFW-FWBR-IN
- -A PVEFW-FORWARD -m physdev --physdev-out fwln+ --physdev-is-bridged -j PVEFW-FWBR-OUT
- -A PVEFW-FORWARD -m comment --comment "PVESIG:qnNexOcGa+y+jebd4dAUqFSp5nw"
- -A PVEFW-FWBR-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
- -A PVEFW-FWBR-IN -m comment --comment "PVESIG:Ijl7/xz0DD7LF91MlLCz0ybZBE0"
- -A PVEFW-FWBR-OUT -m comment --comment "PVESIG:2jmj7l5rSw0yVb/vlWAYkK/YBwk"
- -A PVEFW-HOST-IN -i lo -j ACCEPT
- -A PVEFW-HOST-IN -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-IN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
- -A PVEFW-HOST-IN -p igmp -j RETURN
- -A PVEFW-HOST-IN -s 192.168.10.0/24 -d 192.168.10.0/24 -i vmbr10 -p tcp -m tcp --dport 3551 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.70.0/24 -d 192.168.70.0/24 -p tcp -m tcp --dport 6800:7300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.128/25 -p udp -m udp --dport 5405:5406 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.80.0/25 -p udp -m udp --dport 5405:5406 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp -m tcp --dport 6789 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp -m tcp --dport 3300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.10.0/24 -p tcp -m tcp --dport 6800:7300 -j RETURN
- -A PVEFW-HOST-IN -d 192.168.70.0/24 -p tcp -m tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -d 192.168.80.128/25 -p tcp -m tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -d 192.168.80.0/25 -p tcp -m tcp --dport 8006 -j PVEFW-reject
- -A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 8006 -j RETURN
- -A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 5900:5999 -j RETURN
- -A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 3128 -j RETURN
- -A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 22 -j RETURN
- -A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 60000:60050 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.111/32 -d 192.168.80.112/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.211/32 -d 192.168.80.212/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.113/32 -d 192.168.80.112/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.213/32 -d 192.168.80.212/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.101/32 -d 192.168.80.112/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.201/32 -d 192.168.80.212/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.102/32 -d 192.168.80.112/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.202/32 -d 192.168.80.212/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.103/32 -d 192.168.80.112/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -s 192.168.80.203/32 -d 192.168.80.212/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-IN -j PVEFW-Drop
- -A PVEFW-HOST-IN -j DROP
- -A PVEFW-HOST-IN -m comment --comment "PVESIG:ezgtFmiN1hX8rDNGlqtbBtqScxM"
- -A PVEFW-HOST-OUT -o lo -j ACCEPT
- -A PVEFW-HOST-OUT -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-HOST-OUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A PVEFW-HOST-OUT -p igmp -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp -m tcp --dport 8006 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp -m tcp --dport 22 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp -m tcp --dport 5900:5999 -j RETURN
- -A PVEFW-HOST-OUT -d 192.168.10.0/24 -p tcp -m tcp --dport 3128 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112/32 -d 192.168.80.111/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212/32 -d 192.168.80.211/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112/32 -d 192.168.80.113/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212/32 -d 192.168.80.213/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112/32 -d 192.168.80.101/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212/32 -d 192.168.80.201/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112/32 -d 192.168.80.102/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212/32 -d 192.168.80.202/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.112/32 -d 192.168.80.103/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -s 192.168.80.212/32 -d 192.168.80.203/32 -p udp -m udp --dport 5404:5405 -j RETURN
- -A PVEFW-HOST-OUT -j RETURN
- -A PVEFW-HOST-OUT -m comment --comment "PVESIG:YAYn8j1iTEcJy69ORHbJBP454RY"
- -A PVEFW-INPUT -j PVEFW-HOST-IN
- -A PVEFW-INPUT -m comment --comment "PVESIG:+5iMmLaxKXynOB/+5xibfx7WhFk"
- -A PVEFW-OUTPUT -j PVEFW-HOST-OUT
- -A PVEFW-OUTPUT -m comment --comment "PVESIG:LjHoZeSSiWAG3+2ZAyL/xuEehd0"
- -A PVEFW-Reject -j PVEFW-DropBroadcast
- -A PVEFW-Reject -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
- -A PVEFW-Reject -p icmp -m icmp --icmp-type 11 -j ACCEPT
- -A PVEFW-Reject -m conntrack --ctstate INVALID -j DROP
- -A PVEFW-Reject -p udp -m multiport --dports 135,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp -m udp --dport 137:139 -j PVEFW-reject
- -A PVEFW-Reject -p udp -m udp --sport 137 --dport 1024:65535 -j PVEFW-reject
- -A PVEFW-Reject -p tcp -m multiport --dports 135,139,445 -j PVEFW-reject
- -A PVEFW-Reject -p udp -m udp --dport 1900 -j DROP
- -A PVEFW-Reject -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- -A PVEFW-Reject -p udp -m udp --sport 53 -j DROP
- -A PVEFW-Reject -m comment --comment "PVESIG:h3DyALVslgH5hutETfixGP08w7c"
- -A PVEFW-SET-ACCEPT-MARK -j MARK --set-xmark 0x80000000/0x80000000
- -A PVEFW-SET-ACCEPT-MARK -m comment --comment "PVESIG:Hg/OIgIwJChBUcWU8Xnjhdd2jUY"
- -A PVEFW-logflags -j DROP
- -A PVEFW-logflags -m comment --comment "PVESIG:MN4PH1oPZeABMuWr64RrygPfW7A"
- -A PVEFW-reject -m addrtype --dst-type BROADCAST -j DROP
- -A PVEFW-reject -s 224.0.0.0/4 -j DROP
- -A PVEFW-reject -p icmp -j DROP
- -A PVEFW-reject -p tcp -j REJECT --reject-with tcp-reset
- -A PVEFW-reject -p udp -j REJECT --reject-with icmp-port-unreachable
- -A PVEFW-reject -p icmp -j REJECT --reject-with icmp-host-unreachable
- -A PVEFW-reject -j REJECT --reject-with icmp-host-prohibited
- -A PVEFW-reject -m comment --comment "PVESIG:Jlkrtle1mDdtxDeI9QaDSL++Npc"
- -A PVEFW-smurflog -j DROP
- -A PVEFW-smurflog -m comment --comment "PVESIG:2gfT1VMkfr0JL6OccRXTGXo+1qk"
- -A PVEFW-smurfs -s 0.0.0.0/32 -j RETURN
- -A PVEFW-smurfs -m addrtype --src-type BROADCAST -g PVEFW-smurflog
- -A PVEFW-smurfs -s 224.0.0.0/4 -g PVEFW-smurflog
- -A PVEFW-smurfs -m comment --comment "PVESIG:HssVe5QCBXd5mc9kC88749+7fag"
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g PVEFW-logflags
- -A PVEFW-tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g PVEFW-logflags
- -A PVEFW-tcpflags -m comment --comment "PVESIG:CMFojwNPqllyqD67NeI5m+bP5mo"
- COMMIT
- # Completed on Thu Dec 30 06:51:09 2021
- root@mon02:~#
- root@mon02:~#
- root@mon02:~# pve-firewall localnet
- local hostname: mon02
- local IP address: 192.168.10.202
- network auto detect: 192.168.10.0/24
- using detected local_network: 192.168.10.0/24
- accepting corosync traffic from/to:
- - mon01: 192.168.80.111 (link: 0)
- - mon01: 192.168.80.211 (link: 1)
- - mon03: 192.168.80.113 (link: 0)
- - mon03: 192.168.80.213 (link: 1)
- - pve01: 192.168.80.101 (link: 0)
- - pve01: 192.168.80.201 (link: 1)
- - pve02: 192.168.80.102 (link: 0)
- - pve02: 192.168.80.202 (link: 1)
- - pve03: 192.168.80.103 (link: 0)
- - pve03: 192.168.80.203 (link: 1)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement