Advertisement
synthnassizer

quarx_iptables

Sep 28th, 2014
857
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.94 KB | None | 0 0
  1. root@vms:~# iptables-save
  2. # Generated by iptables-save v1.4.14 on Sun Sep 28 22:58:15 2014
  3. *filter
  4. :INPUT DROP [0:0]
  5. :FORWARD DROP [6:1824]
  6. :OUTPUT ACCEPT [348:143331]
  7. :IP_ICMP - [0:0]
  8. :IP_TCP - [0:0]
  9. :IP_UDP - [0:0]
  10. -A INPUT -i lo -j ACCEPT
  11. -A INPUT -m state --state ESTABLISHED -j ACCEPT
  12. -A INPUT -m state --state RELATED -j ACCEPT
  13. -A INPUT -p tcp -m tcp --tcp-flags ACK ACK -j ACCEPT
  14. -A INPUT -s 127.0.0.1/32 -i eth0 -j DROP
  15. -A INPUT -i eth0 -p icmp -j IP_ICMP
  16. -A INPUT -i eth0 -p udp -m udp -j IP_UDP
  17. -A INPUT -i eth0 -p tcp -m tcp -j IP_TCP
  18. -A INPUT -m limit --limit 3/sec --limit-burst 3 -j ULOG --ulog-prefix "FW_INPUT: "
  19. -A INPUT -i virbr0 -j ACCEPT
  20. -A IP_ICMP -p icmp -m icmp --icmp-type 0 -j ACCEPT
  21. -A IP_ICMP -p icmp -m icmp --icmp-type 3 -j ACCEPT
  22. -A IP_ICMP -p icmp -m icmp --icmp-type 4 -j ACCEPT
  23. -A IP_ICMP -p icmp -m icmp --icmp-type 11 -j ACCEPT
  24. -A IP_ICMP -p icmp -m icmp --icmp-type 12 -j ACCEPT
  25. -A IP_ICMP -p icmp -m icmp --icmp-type 8 -j ACCEPT
  26. -A IP_ICMP -p icmp -j RETURN
  27. -A IP_TCP -p tcp -m tcp --dport 2049:2050 -j DROP
  28. -A IP_TCP -p tcp -m tcp --dport 6000:6063 -j DROP
  29. -A IP_TCP -p tcp -m tcp --dport 7000:7010 -j DROP
  30. -A IP_TCP -p tcp -m tcp --dport 19001 -j ACCEPT
  31. -A IP_TCP -p tcp -m tcp --dport 12321 -j ACCEPT
  32. -A IP_TCP -p tcp -m tcp --dport 80 -j ACCEPT
  33. -A IP_TCP -p tcp -m tcp --dport 443 -j ACCEPT
  34. -A IP_TCP -p tcp -m tcp -j RETURN
  35. -A IP_UDP -p udp -m udp -j RETURN
  36. COMMIT
  37. # Completed on Sun Sep 28 22:58:15 2014
  38. # Generated by iptables-save v1.4.14 on Sun Sep 28 22:58:15 2014
  39. *mangle
  40. :PREROUTING ACCEPT [357:82809]
  41. :INPUT ACCEPT [342:80283]
  42. :FORWARD ACCEPT [6:1824]
  43. :OUTPUT ACCEPT [357:144615]
  44. :POSTROUTING ACCEPT [357:144615]
  45. COMMIT
  46. # Completed on Sun Sep 28 22:58:15 2014
  47. # Generated by iptables-save v1.4.14 on Sun Sep 28 22:58:15 2014
  48. *nat
  49. :PREROUTING ACCEPT [9:702]
  50. :INPUT ACCEPT [0:0]
  51. :OUTPUT ACCEPT [0:0]
  52. :POSTROUTING ACCEPT [0:0]
  53. COMMIT
  54. # Completed on Sun Sep 28 22:58:15 2014
  55. root@vms:~#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement