Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- From router
- ip6tables -F INPUT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type echo-request -m recent --set
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type echo-request -m recent --update --seconds 10 --hitcount 5 -j DROP
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type echo-request -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type echo-reply -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type router-advertisement -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type router-solicitation -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type neighbour-advertisement -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type neighbour-solicitation -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type packet-too-big -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type time-exceeded -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type parameter-problem -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type unknown-header-type -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 --icmpv6-type redirect -j ACCEPT
- ip6tables -A INPUT -i brwan -p icmpv6 -j DROP
- ip6tables -A INPUT -i brwan -p tcp ! --syn -m state --state NEW -j DROP
- ip6tables -A INPUT -i brwan -m rt --rt-type 0 -j DROP
- ip6tables -A INPUT -i brwan -p tcp --tcp-flags ALL ALL -j DROP
- ip6tables -A INPUT -i brwan -p tcp --tcp-flags ALL NONE -j DROP
- ip6tables -A INPUT -i brwan -m pkttype --pkt-type multicast -j DROP
- ip6tables -A INPUT -i brwan -m pkttype --pkt-type broadcast -j DROP
- ip6tables -A INPUT -i brwan -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- #ip6tables -A INPUT -i brwan -p tcp -m tcp --dport 22 -j ACCEPT
- ip6tables -A INPUT -i brwan -p udp -m udp --dport 546 -j ACCEPT
- ip6tables -A INPUT -i brwan -j DROP
- # From home network
- ip6tables -F FORWARD
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type echo-request -m recent --set
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type echo-request -m recent --update --seconds 10 --hitcount 5 -j DROP
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type echo-request -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type echo-reply -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type router-advertisement -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type router-solicitation -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type neighbour-advertisement -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type neighbour-solicitation -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type destination-unreachable -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type packet-too-big -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type time-exceeded -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type parameter-problem -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type unknown-header-type -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 --icmpv6-type redirect -j ACCEPT
- ip6tables -A FORWARD -i brwan -p icmpv6 -j DROP
- ip6tables -A FORWARD -i brwan -p tcp ! --syn -m state --state NEW -j DROP
- ip6tables -A FORWARD -i brwan -m rt --rt-type 0 -j DROP
- ip6tables -A FORWARD -i brwan -p tcp --tcp-flags ALL ALL -j DROP
- ip6tables -A FORWARD -i brwan -p tcp --tcp-flags ALL NONE -j DROP
- ip6tables -A FORWARD -i brwan -m pkttype --pkt-type multicast -j ACCEPT
- ip6tables -A FORWARD -i brwan -m pkttype --pkt-type broadcast -j ACCEPT
- ip6tables -A FORWARD -i brwan -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- ip6tables -A FORWARD -i brwan -p tcp -m multiport --dports 2222,7200 -j ACCEPT
- ip6tables -A FORWARD -i brwan -p udp -m udp --dport 7200 -j ACCEPT
- ip6tables -A FORWARD -i brwan -p udp -m udp --dport 546 -j ACCEPT
- ip6tables -A FORWARD -i brwan -j DROP
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement