Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Thu Sep 6 14:21:01 2018
- *nat
- :PREROUTING ACCEPT [4274:302933]
- :INPUT ACCEPT [3163:236004]
- :OUTPUT ACCEPT [1509:103763]
- :POSTROUTING ACCEPT [1641:110664]
- :DOCKER - [0:0]
- -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.0/16 ! -o pterodactyl0 -j MASQUERADE
- -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.3/32 -d 172.18.0.3/32 -p tcp -m tcp --dport 22011 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.3/32 -d 172.18.0.3/32 -p udp -m udp --dport 22011 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.3/32 -d 172.18.0.3/32 -p tcp -m tcp --dport 22007 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.3/32 -d 172.18.0.3/32 -p udp -m udp --dport 22007 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.5/32 -d 172.18.0.5/32 -p tcp -m tcp --dport 22006 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.5/32 -d 172.18.0.5/32 -p udp -m udp --dport 22006 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.5/32 -d 172.18.0.5/32 -p tcp -m tcp --dport 22005 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.5/32 -d 172.18.0.5/32 -p udp -m udp --dport 22005 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.6/32 -d 172.18.0.6/32 -p tcp -m tcp --dport 25560 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.6/32 -d 172.18.0.6/32 -p udp -m udp --dport 25560 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.6/32 -d 172.18.0.6/32 -p tcp -m tcp --dport 22010 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.6/32 -d 172.18.0.6/32 -p udp -m udp --dport 22010 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p tcp -m tcp --dport 22002 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p udp -m udp --dport 22002 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p tcp -m tcp --dport 22001 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.7/32 -d 172.18.0.7/32 -p udp -m udp --dport 22001 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.4/32 -d 172.18.0.4/32 -p tcp -m tcp --dport 22004 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.4/32 -d 172.18.0.4/32 -p udp -m udp --dport 22004 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.4/32 -d 172.18.0.4/32 -p tcp -m tcp --dport 22003 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.4/32 -d 172.18.0.4/32 -p udp -m udp --dport 22003 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.2/32 -d 172.18.0.2/32 -p tcp -m tcp --dport 22020 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.2/32 -d 172.18.0.2/32 -p udp -m udp --dport 22020 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.2/32 -d 172.18.0.2/32 -p tcp -m tcp --dport 22019 -j MASQUERADE
- -A POSTROUTING -s 172.18.0.2/32 -d 172.18.0.2/32 -p udp -m udp --dport 22019 -j MASQUERADE
- -A DOCKER -i docker0 -j RETURN
- -A DOCKER -i pterodactyl0 -j RETURN
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22011 -j DNAT --to-destination 172.18.0.3:22011
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22011 -j DNAT --to-destination 172.18.0.3:22011
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22007 -j DNAT --to-destination 172.18.0.3:22007
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22007 -j DNAT --to-destination 172.18.0.3:22007
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22006 -j DNAT --to-destination 172.18.0.5:22006
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22006 -j DNAT --to-destination 172.18.0.5:22006
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22005 -j DNAT --to-destination 172.18.0.5:22005
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22005 -j DNAT --to-destination 172.18.0.5:22005
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 25560 -j DNAT --to-destination 172.18.0.6:25560
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 25560 -j DNAT --to-destination 172.18.0.6:25560
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22010 -j DNAT --to-destination 172.18.0.6:22010
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22010 -j DNAT --to-destination 172.18.0.6:22010
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22002 -j DNAT --to-destination 172.18.0.7:22002
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22002 -j DNAT --to-destination 172.18.0.7:22002
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22001 -j DNAT --to-destination 172.18.0.7:22001
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22001 -j DNAT --to-destination 172.18.0.7:22001
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22004 -j DNAT --to-destination 172.18.0.4:22004
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22004 -j DNAT --to-destination 172.18.0.4:22004
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22003 -j DNAT --to-destination 172.18.0.4:22003
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22003 -j DNAT --to-destination 172.18.0.4:22003
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22020 -j DNAT --to-destination 172.18.0.2:22020
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22020 -j DNAT --to-destination 172.18.0.2:22020
- -A DOCKER ! -i pterodactyl0 -p tcp -m tcp --dport 22019 -j DNAT --to-destination 172.18.0.2:22019
- -A DOCKER ! -i pterodactyl0 -p udp -m udp --dport 22019 -j DNAT --to-destination 172.18.0.2:22019
- COMMIT
- # Completed on Thu Sep 6 14:21:01 2018
- # Generated by iptables-save v1.6.0 on Thu Sep 6 14:21:01 2018
- *filter
- :INPUT ACCEPT [1693:238161]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [1657:363908]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :f2b-sshd - [0:0]
- -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
- -A FORWARD -j DOCKER-USER
- -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -o pterodactyl0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o pterodactyl0 -j DOCKER
- -A FORWARD -i pterodactyl0 ! -o pterodactyl0 -j ACCEPT
- -A FORWARD -i pterodactyl0 -o pterodactyl0 -j ACCEPT
- -A FORWARD -i tun0 -j ACCEPT
- -A FORWARD -i tun0 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i eth0 -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A DOCKER -d 172.18.0.3/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22011 -j ACCEPT
- -A DOCKER -d 172.18.0.3/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22011 -j ACCEPT
- -A DOCKER -d 172.18.0.3/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22007 -j ACCEPT
- -A DOCKER -d 172.18.0.3/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22007 -j ACCEPT
- -A DOCKER -d 172.18.0.5/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22006 -j ACCEPT
- -A DOCKER -d 172.18.0.5/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22006 -j ACCEPT
- -A DOCKER -d 172.18.0.5/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22005 -j ACCEPT
- -A DOCKER -d 172.18.0.5/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22005 -j ACCEPT
- -A DOCKER -d 172.18.0.6/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 25560 -j ACCEPT
- -A DOCKER -d 172.18.0.6/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 25560 -j ACCEPT
- -A DOCKER -d 172.18.0.6/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22010 -j ACCEPT
- -A DOCKER -d 172.18.0.6/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22010 -j ACCEPT
- -A DOCKER -d 172.18.0.7/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22002 -j ACCEPT
- -A DOCKER -d 172.18.0.7/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22002 -j ACCEPT
- -A DOCKER -d 172.18.0.7/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22001 -j ACCEPT
- -A DOCKER -d 172.18.0.7/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22001 -j ACCEPT
- -A DOCKER -d 172.18.0.4/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22004 -j ACCEPT
- -A DOCKER -d 172.18.0.4/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22004 -j ACCEPT
- -A DOCKER -d 172.18.0.4/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22003 -j ACCEPT
- -A DOCKER -d 172.18.0.4/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22003 -j ACCEPT
- -A DOCKER -d 172.18.0.2/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22020 -j ACCEPT
- -A DOCKER -d 172.18.0.2/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22020 -j ACCEPT
- -A DOCKER -d 172.18.0.2/32 ! -i pterodactyl0 -o pterodactyl0 -p tcp -m tcp --dport 22019 -j ACCEPT
- -A DOCKER -d 172.18.0.2/32 ! -i pterodactyl0 -o pterodactyl0 -p udp -m udp --dport 22019 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i pterodactyl0 ! -o pterodactyl0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o pterodactyl0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- -A DOCKER-USER -j RETURN
- -A f2b-sshd -s 5.188.10.176/32 -j REJECT --reject-with icmp-port-unreachable
- -A f2b-sshd -j RETURN
- COMMIT
- # Completed on Thu Sep 6 14:21:01 2018
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement