Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -P INPUT DROP -c 16 1442
- -P FORWARD DROP -c 0 0
- -P OUTPUT ACCEPT -c 0 0
- -N DOCKER
- -N DOCKER-ISOLATION-STAGE-1
- -N DOCKER-ISOLATION-STAGE-2
- -N DOCKER-USER
- -N ufw-after-forward
- -N ufw-after-input
- -N ufw-after-logging-forward
- -N ufw-after-logging-input
- -N ufw-after-logging-output
- -N ufw-after-output
- -N ufw-before-forward
- -N ufw-before-input
- -N ufw-before-logging-forward
- -N ufw-before-logging-input
- -N ufw-before-logging-output
- -N ufw-before-output
- -N ufw-logging-allow
- -N ufw-logging-deny
- -N ufw-not-local
- -N ufw-reject-forward
- -N ufw-reject-input
- -N ufw-reject-output
- -N ufw-skip-to-policy-forward
- -N ufw-skip-to-policy-input
- -N ufw-skip-to-policy-output
- -N ufw-track-forward
- -N ufw-track-input
- -N ufw-track-output
- -N ufw-user-forward
- -N ufw-user-input
- -N ufw-user-limit
- -N ufw-user-limit-accept
- -N ufw-user-logging-forward
- -N ufw-user-logging-input
- -N ufw-user-logging-output
- -N ufw-user-output
- -A INPUT -c 476280 1664885264 -j ufw-before-logging-input
- -A INPUT -c 476280 1664885264 -j ufw-before-input
- -A INPUT -c 104744 20269506 -j ufw-after-input
- -A INPUT -c 58681 3081683 -j ufw-after-logging-input
- -A INPUT -c 58681 3081683 -j ufw-reject-input
- -A INPUT -c 58681 3081683 -j ufw-track-input
- -A INPUT -i tun0 -c 0 0 -j ACCEPT
- -A INPUT -i ens18 -p udp -m udp --dport 1194 -c 21 1032 -j ACCEPT
- -A FORWARD -c 374909 309140570 -j DOCKER-USER
- -A FORWARD -c 374909 309140570 -j DOCKER-ISOLATION-STAGE-1
- -A FORWARD -o br-7119b3a28dd1 -m conntrack --ctstate RELATED,ESTABLISHED -c 11 1792 -j ACCEPT
- -A FORWARD -o br-7119b3a28dd1 -c 2 120 -j DOCKER
- -A FORWARD -i br-7119b3a28dd1 ! -o br-7119b3a28dd1 -c 8 1992 -j ACCEPT
- -A FORWARD -i br-7119b3a28dd1 -o br-7119b3a28dd1 -c 0 0 -j ACCEPT
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -c 68035 10398947 -j ACCEPT
- -A FORWARD -o docker0 -c 8079 460132 -j DOCKER
- -A FORWARD -i docker0 ! -o docker0 -c 61911 51234298 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -c 0 0 -j ACCEPT
- -A FORWARD -o br-1d68cb679fa0 -m conntrack --ctstate RELATED,ESTABLISHED -c 0 0 -j ACCEPT
- -A FORWARD -o br-1d68cb679fa0 -c 0 0 -j DOCKER
- -A FORWARD -i br-1d68cb679fa0 ! -o br-1d68cb679fa0 -c 0 0 -j ACCEPT
- -A FORWARD -i br-1d68cb679fa0 -o br-1d68cb679fa0 -c 0 0 -j ACCEPT
- -A FORWARD -c 238577 247774262 -j ufw-before-logging-forward
- -A FORWARD -c 238577 247774262 -j ufw-before-forward
- -A FORWARD -c 2813 397830 -j ufw-after-forward
- -A FORWARD -c 2813 397830 -j ufw-after-logging-forward
- -A FORWARD -c 2813 397830 -j ufw-reject-forward
- -A FORWARD -c 2813 397830 -j ufw-track-forward
- -A FORWARD -i ens18 -o tun0 -c 0 0 -j ACCEPT
- -A FORWARD -i tun0 -o ens18 -c 2813 397830 -j ACCEPT
- -A OUTPUT -c 329766 260918734 -j ufw-before-logging-output
- -A OUTPUT -c 329766 260918734 -j ufw-before-output
- -A OUTPUT -c 2046 142472 -j ufw-after-output
- -A OUTPUT -c 2046 142472 -j ufw-after-logging-output
- -A OUTPUT -c 2046 142472 -j ufw-reject-output
- -A OUTPUT -c 2046 142472 -j ufw-track-output
- -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -c 5879 341324 -j ACCEPT
- -A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 15643 -c 26 1532 -j ACCEPT
- -A DOCKER-ISOLATION-STAGE-1 -i br-7119b3a28dd1 ! -o br-7119b3a28dd1 -c 8 1992 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -c 61911 51234298 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -i br-1d68cb679fa0 ! -o br-1d68cb679fa0 -c 0 0 -j DOCKER-ISOLATION-STAGE-2
- -A DOCKER-ISOLATION-STAGE-1 -c 443104 841261168 -j RETURN
- -A DOCKER-ISOLATION-STAGE-2 -o br-7119b3a28dd1 -c 0 0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o docker0 -c 0 0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -o br-1d68cb679fa0 -c 0 0 -j DROP
- -A DOCKER-ISOLATION-STAGE-2 -c 87694 52739299 -j RETURN
- -A DOCKER-USER -c 443104 841261168 -j RETURN
- -A ufw-after-input -p udp -m udp --dport 137 -c 622 49164 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 138 -c 717 172526 -j ufw-skip-to-policy-input
- -A ufw-after-input -p tcp -m tcp --dport 139 -c 139 6336 -j ufw-skip-to-policy-input
- -A ufw-after-input -p tcp -m tcp --dport 445 -c 4863 213576 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 67 -c 39715 16745869 -j ufw-skip-to-policy-input
- -A ufw-after-input -p udp -m udp --dport 68 -c 1 28 -j ufw-skip-to-policy-input
- -A ufw-after-input -m addrtype --dst-type BROADCAST -c 6 324 -j ufw-skip-to-policy-input
- -A ufw-after-logging-forward -m limit --limit 3/min --limit-burst 10 -c 0 0 -j LOG --log-prefix "[UFW BLOCK] "
- -A ufw-after-logging-input -m limit --limit 3/min --limit-burst 10 -c 21 1659 -j LOG --log-prefix "[UFW BLOCK] "
- -A ufw-before-forward -m conntrack --ctstate RELATED,ESTABLISHED -c 235764 247376432 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 3 -c 0 0 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 11 -c 0 0 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 12 -c 0 0 -j ACCEPT
- -A ufw-before-forward -p icmp -m icmp --icmp-type 8 -c 0 0 -j ACCEPT
- -A ufw-before-forward -c 2813 397830 -j ufw-user-forward
- -A ufw-before-input -i lo -c 5933 502716 -j ACCEPT
- -A ufw-before-input -m conntrack --ctstate RELATED,ESTABLISHED -c 359745 1643798326 -j ACCEPT
- -A ufw-before-input -m conntrack --ctstate INVALID -c 1091 55240 -j ufw-logging-deny
- -A ufw-before-input -m conntrack --ctstate INVALID -c 1091 55240 -j DROP
- -A ufw-before-input -p icmp -m icmp --icmp-type 3 -c 0 0 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 11 -c 0 0 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 12 -c 0 0 -j ACCEPT
- -A ufw-before-input -p icmp -m icmp --icmp-type 8 -c 2572 123732 -j ACCEPT
- -A ufw-before-input -p udp -m udp --sport 67 --dport 68 -c 0 0 -j ACCEPT
- -A ufw-before-input -c 106939 20405250 -j ufw-not-local
- -A ufw-before-input -d 224.0.0.251/32 -p udp -m udp --dport 5353 -c 0 0 -j ACCEPT
- -A ufw-before-input -d 239.255.255.250/32 -p udp -m udp --dport 1900 -c 0 0 -j ACCEPT
- -A ufw-before-input -c 106939 20405250 -j ufw-user-input
- -A ufw-before-output -o lo -c 5933 502716 -j ACCEPT
- -A ufw-before-output -m conntrack --ctstate RELATED,ESTABLISHED -c 321787 260273546 -j ACCEPT
- -A ufw-before-output -c 2046 142472 -j ufw-user-output
- -A ufw-logging-allow -m limit --limit 3/min --limit-burst 10 -c 0 0 -j LOG --log-prefix "[UFW ALLOW] "
- -A ufw-logging-deny -m conntrack --ctstate INVALID -m limit --limit 3/min --limit-burst 10 -c 0 0 -j RETURN
- -A ufw-logging-deny -m limit --limit 3/min --limit-burst 10 -c 0 0 -j LOG --log-prefix "[UFW BLOCK] "
- -A ufw-not-local -m addrtype --dst-type LOCAL -c 65957 3443351 -j RETURN
- -A ufw-not-local -m addrtype --dst-type MULTICAST -c 0 0 -j RETURN
- -A ufw-not-local -m addrtype --dst-type BROADCAST -c 40982 16961899 -j RETURN
- -A ufw-not-local -m limit --limit 3/min --limit-burst 10 -c 0 0 -j ufw-logging-deny
- -A ufw-not-local -c 0 0 -j DROP
- -A ufw-skip-to-policy-forward -c 0 0 -j DROP
- -A ufw-skip-to-policy-input -c 46063 17187823 -j DROP
- -A ufw-skip-to-policy-output -c 0 0 -j ACCEPT
- -A ufw-track-output -p tcp -m conntrack --ctstate NEW -c 881 52860 -j ACCEPT
- -A ufw-track-output -p udp -m conntrack --ctstate NEW -c 1161 87800 -j ACCEPT
- -A ufw-user-input -p tcp -m tcp --dport 8022 -c 0 0 -j ACCEPT
- -A ufw-user-input -p udp -m udp --dport 8022 -c 0 0 -j ACCEPT
- -A ufw-user-input -p tcp -m tcp --dport 15643 -c 0 0 -j ACCEPT
- -A ufw-user-input -p udp -m udp --dport 15643 -c 0 0 -j ACCEPT
- -A ufw-user-input -p tcp -m tcp --dport 8080 -c 0 0 -j ACCEPT
- -A ufw-user-input -p udp -m udp --dport 8080 -c 0 0 -j ACCEPT
- -A ufw-user-input -p tcp -m tcp --dport 25 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 25 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 465 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 465 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 587 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 587 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 143 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 143 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 993 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 993 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 110 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 110 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 995 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 995 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 4190 -c 0 0 -j DROP
- -A ufw-user-input -p udp -m udp --dport 4190 -c 0 0 -j DROP
- -A ufw-user-input -p tcp -m tcp --dport 80 -m comment --comment "\'dapp_Nginx%20HTTP\'" -c 9 540 -j ACCEPT
- -A ufw-user-limit -m limit --limit 3/min -c 0 0 -j LOG --log-prefix "[UFW LIMIT BLOCK] "
- -A ufw-user-limit -c 0 0 -j REJECT --reject-with icmp-port-unreachable
- -A ufw-user-limit-accept -c 0 0 -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement