Advertisement
Guest User

Untitled

a guest
Nov 12th, 2019
140
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.55 KB | None | 0 0
  1. -P INPUT ACCEPT
  2. -P FORWARD ACCEPT
  3. -P OUTPUT ACCEPT
  4. -N LIBVIRT_FWI
  5. -N LIBVIRT_FWO
  6. -N LIBVIRT_FWX
  7. -N LIBVIRT_INP
  8. -N LIBVIRT_OUT
  9. -N nixos-fw
  10. -N nixos-fw-accept
  11. -N nixos-fw-log-refuse
  12. -N nixos-fw-refuse
  13. -A INPUT -j LIBVIRT_INP
  14. -A INPUT -j nixos-fw
  15. -A FORWARD -j LIBVIRT_FWX
  16. -A FORWARD -j LIBVIRT_FWI
  17. -A FORWARD -j LIBVIRT_FWO
  18. -A OUTPUT -j LIBVIRT_OUT
  19. -A LIBVIRT_FWI -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  20. -A LIBVIRT_FWI -o virbr0 -j REJECT --reject-with icmp-port-unreachable
  21. -A LIBVIRT_FWO -s 192.168.122.0/24 -i virbr0 -j ACCEPT
  22. -A LIBVIRT_FWO -i virbr0 -j REJECT --reject-with icmp-port-unreachable
  23. -A LIBVIRT_FWX -i virbr0 -o virbr0 -j ACCEPT
  24. -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
  25. -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
  26. -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
  27. -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
  28. -A LIBVIRT_OUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
  29. -A nixos-fw -i lo -j nixos-fw-accept
  30. -A nixos-fw -m conntrack --ctstate RELATED,ESTABLISHED -j nixos-fw-accept
  31. -A nixos-fw -p tcp -m tcp --dport 22 -j nixos-fw-accept
  32. -A nixos-fw -p icmp -m icmp --icmp-type 8 -j nixos-fw-accept
  33. -A nixos-fw -j nixos-fw-log-refuse
  34. -A nixos-fw-accept -j ACCEPT
  35. -A nixos-fw-log-refuse -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j LOG --log-prefix "refused connection: " --log-level 6
  36. -A nixos-fw-log-refuse -m pkttype ! --pkt-type unicast -j nixos-fw-refuse
  37. -A nixos-fw-log-refuse -j nixos-fw-refuse
  38. -A nixos-fw-refuse -j DROP
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement