Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.3.5 on Fri Mar 24 11:39:13 2017
- *filter
- :INPUT DROP [61:10913]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [82894:17022322]
- :LOGGING - [0:0]
- :ssh - [0:0]
- [2297:425231] -A INPUT -i lo -j ACCEPT
- [80126:16336900] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [1:40] -A INPUT -m conntrack --ctstate INVALID -j DROP
- [0:0] -A INPUT -p tcp -m tcp --dport 19 -j ssh
- [4322:864503] -A INPUT -j LOGGING
- [2:1950] -A INPUT -s 64.136.173.31 -i eth0 -p udp -m udp -m multiport --dports 5060,5061 -j ACCEPT
- [0:0] -A INPUT -s 64.136.174.30 -i eth0 -p udp -m udp -m multiport --dports 5060,5061 -j ACCEPT
- [0:0] -A INPUT -s 209.166.154.70 -i eth0 -p udp -m udp -m multiport --dports 5060,5061 -j ACCEPT
- [4215:843000] -A INPUT -s 104.192.64.0/255.255.248.0 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 68.169.169.0/255.255.255.0 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,5063,5065,5066,5067,5068,5069,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 108.174.105.177 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [10:2000] -A INPUT -s 173.247.19.21 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [4:800] -A INPUT -s 173.166.244.106 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 74.221.189.40 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 68.42.4.138 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 75.130.71.66 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 24.107.250.225 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 24.107.250.2 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 96.4.234.152 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 104.128.160.214 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 64.18.111.254 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -s 68.59.133.69 -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j ACCEPT
- [0:0] -A INPUT -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -m iprange --src-range 96.4.234.129-96.4.234.159 -j ACCEPT
- [29:5800] -A INPUT -i eth0 -p udp -m udp -m multiport --dports 69,5060,5061,10000:20000 -j DROP
- [0:0] -A INPUT -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -m iprange --src-range 104.192.66.239-104.192.66.244 -j ACCEPT
- [0:0] -A INPUT -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -m iprange --src-range 96.4.234.129-96.4.234.159 -j ACCEPT
- [0:0] -A INPUT -s 68.42.4.138 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
- [0:0] -A INPUT -s 172.78.87.85 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
- [0:0] -A INPUT -s 165.138.70.222 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
- [1:40] -A INPUT -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW -j DROP
- [0:0] -A INPUT -p icmp -m icmp --icmp-type 8 -m state --state NEW -j DROP
- [0:0] -A LOGGING -s 64.18.111.245 -m conntrack --ctstate NEW -j LOG --log-prefix "Traffic from 64.18.111.245: "
- [0:0] -A LOGGING -s 64.18.111.245 -j ACCEPT
- [0:0] -A ssh -p tcp -m tcp --dport 19 -m conntrack --ctstate NEW -m recent --set --name SSH --rsource
- [0:0] -A ssh -p tcp -m tcp --dport 19 -m conntrack --ctstate NEW -m recent --update --seconds 30 --hitcount 6 --rttl --name SSH --rsource -j LOG --log-prefix "SSH break in attempt "
- [0:0] -A ssh -p tcp -m tcp --dport 19 -m conntrack --ctstate NEW -m recent --update --seconds 30 --hitcount 6 --rttl --name SSH --rsource -j DROP
- [0:0] -A ssh -p tcp -m tcp --dport 19 -j ACCEPT
- COMMIT
- # Completed on Fri Mar 24 11:39:13 2017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement