Advertisement
Guest User

Untitled

a guest
Sep 25th, 2017
90
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.43 KB | None | 0 0
  1. # Generated by iptables-save v1.3.6 on Sun Jul 24 22:26:05 2011
  2. *mangle
  3. :PREROUTING ACCEPT [524022091:258131213068]
  4. :INPUT ACCEPT [246743216:78638830887]
  5. :FORWARD ACCEPT [277262267:179491444738]
  6. :OUTPUT ACCEPT [224716191:223343817740]
  7. :POSTROUTING ACCEPT [135705450:103595191361]
  8. :high - [0:0]
  9. :normal - [0:0]
  10. :unknown - [0:0]
  11. -A PREROUTING -m layer7 --l7proto ssh -j MARK --set-mark 0xa
  12. -A POSTROUTING -j CONNMARK --restore-mark
  13. -A POSTROUTING -m mark ! --mark 0x0 -m mark ! --mark 0x5 -j ACCEPT
  14. -A POSTROUTING -m layer7 --l7proto ssh -j MARK --set-mark 0xa
  15. -A POSTROUTING -m layer7 --l7proto sip -j MARK --set-mark 0xa
  16. -A POSTROUTING -m layer7 --l7proto dns -j MARK --set-mark 0xa
  17. -A POSTROUTING -p icmp -j MARK --set-mark 0xa
  18. -A POSTROUTING -m layer7 --l7proto jabber -j MARK --set-mark 0x14
  19. -A POSTROUTING -m layer7 --l7proto msnmessenger -j MARK --set-mark 0x14
  20. -A POSTROUTING -m layer7 --l7proto yahoo -j MARK --set-mark 0x14
  21. -A POSTROUTING -m layer7 --l7proto aim -j MARK --set-mark 0x14
  22. -A POSTROUTING -m layer7 --l7proto http -j MARK --set-mark 0x14
  23. -A POSTROUTING -m layer7 --l7proto ssl -j MARK --set-mark 0x14
  24. -A POSTROUTING -m layer7 --l7proto smtp -j MARK --set-mark 0x14
  25. -A POSTROUTING -m layer7 --l7proto imap -j MARK --set-mark 0x14
  26. -A POSTROUTING -m layer7 --l7proto pop3 -j MARK --set-mark 0x14
  27. -A POSTROUTING -m layer7 --l7proto nntp -j MARK --set-mark 0x1e
  28. -A POSTROUTING -m layer7 --l7proto ftp -j MARK --set-mark 0x1e
  29. -A POSTROUTING -m layer7 --l7proto unset -j MARK --set-mark 0x5
  30. -A POSTROUTING -m layer7 --l7proto unknown -j MARK --set-mark 0xf
  31. -A POSTROUTING -m mark --mark 0xf -j unknown
  32. -A POSTROUTING -m mark --mark 0xa -j high
  33. -A POSTROUTING -m mark --mark 0x14 -j normal
  34. -A POSTROUTING -j CONNMARK --save-mark
  35. COMMIT
  36. # Completed on Sun Jul 24 22:26:05 2011
  37. # Generated by iptables-save v1.3.6 on Sun Jul 24 22:26:05 2011
  38. *nat
  39. :PREROUTING ACCEPT [31045697:3851644635]
  40. :POSTROUTING ACCEPT [304408:19004438]
  41. :OUTPUT ACCEPT [5200956:533603656]
  42. -A PREROUTING -i eth0 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 192.168.1.10:8081
  43. -A PREROUTING -i eth0 -p tcp -m tcp --dport 5545 -j DNAT --to-destination 192.168.1.10:5545
  44. -A PREROUTING -i eth0 -p udp -m udp --dport 5545 -j DNAT --to-destination 192.168.1.10:5545
  45. -A PREROUTING -i eth0 -p tcp -m tcp --dport 1185 -j DNAT --to-destination 192.168.1.10:1185
  46. -A PREROUTING -i eth0 -p udp -m udp --dport 1185 -j DNAT --to-destination 192.168.1.10:1185
  47. -A PREROUTING -i eth0 -p tcp -m tcp --dport 4912 -j DNAT --to-destination 192.168.1.10:4912
  48. -A PREROUTING -i eth0 -p udp -m udp --dport 4912 -j DNAT --to-destination 192.168.1.10:4912
  49. -A POSTROUTING -o eth0 -j MASQUERADE
  50. COMMIT
  51. # Completed on Sun Jul 24 22:26:05 2011
  52. # Generated by iptables-save v1.3.6 on Sun Jul 24 22:26:05 2011
  53. *filter
  54. :INPUT DROP [13967359:1970857069]
  55. :FORWARD ACCEPT [277262268:179491446204]
  56. :OUTPUT ACCEPT [224716242:223343824912]
  57. :fail2ban-ssh - [0:0]
  58. -A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh
  59. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  60. -A INPUT -i ! eth0 -j ACCEPT
  61. -A INPUT -p icmp -j ACCEPT
  62. -A INPUT -p tcp -m tcp --dport 20849 -j ACCEPT
  63. -A INPUT -p tcp -m tcp --dport 8080 -j ACCEPT
  64. -A INPUT -p tcp -m tcp --dport 5901 -j ACCEPT
  65. -A INPUT -p tcp -m multiport --dports 20:21,50000:50005 -j ACCEPT
  66. -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
  67. -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
  68. -A fail2ban-ssh -j RETURN
  69. COMMIT
  70. # Completed on Sun Jul 24 22:26:05 2011
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement