Advertisement
Guest User

Untitled

a guest
Sep 23rd, 2017
93
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.25 KB | None | 0 0
  1. *nat
  2. :PREROUTING ACCEPT [6:2126]
  3. :INPUT ACCEPT [0:0]
  4. :OUTPUT ACCEPT [17:6239]
  5. :POSTROUTING ACCEPT [6:408]
  6.  
  7. -A PREROUTING ! -i lo -p udp -m udp --dport 53 -j REDIRECT --to-ports 5353
  8. -A PREROUTING ! -i lo -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REDIRECT --to-ports 9040
  9. -A OUTPUT -o lo -j RETURN
  10. --ipv4 -A OUTPUT -d 192.168.0.0/16 -j RETURN
  11. -A OUTPUT -m owner --uid-owner "tor" -j RETURN
  12. -A OUTPUT -p udp -m udp --dport 53 -j REDIRECT --to-ports 5353
  13. -A OUTPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REDIRECT --to-ports 9040
  14. COMMIT
  15.  
  16. *filter
  17. :INPUT DROP [0:0]
  18. :FORWARD DROP [0:0]
  19. :OUTPUT DROP [0:0]
  20.  
  21. -A INPUT -i lo -j ACCEPT
  22. -A INPUT -p icmp -j ACCEPT
  23. -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  24. --ipv4 -A INPUT -p tcp -j REJECT --reject-with tcp-reset
  25. --ipv4 -A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable
  26. --ipv4 -A INPUT -j REJECT --reject-with icmp-proto-unreachable
  27. --ipv6 -A INPUT -j REJECT
  28. --ipv4 -A OUTPUT -d 127.0.0.0/8 -j ACCEPT
  29. --ipv4 -A OUTPUT -d 192.168.0.0/16 -j ACCEPT
  30. --ipv6 -A OUTPUT -d ::1/8 -j ACCEPT
  31. -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  32. -A OUTPUT -m owner --uid-owner "tor" -j ACCEPT
  33. --ipv4 -A OUTPUT -j REJECT --reject-with icmp-port-unreachable
  34. --ipv6 -A OUTPUT -j REJECT
  35. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement