Advertisement
Guest User

Untitled

a guest
Sep 15th, 2017
127
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.83 KB | None | 0 0
  1. $ sudo iptables -S
  2. -P INPUT ACCEPT
  3. -P FORWARD ACCEPT
  4. -P OUTPUT ACCEPT
  5. -N DOCKER
  6. -N DOCKER-ISOLATION
  7. -N f2b-ReqLimit
  8. -N f2b-sshd
  9. -N sshguard
  10. -A INPUT -p tcp -m multiport --dports 80,443 -j f2b-ReqLimit
  11. -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
  12. -A INPUT -j sshguard
  13. -A FORWARD -j DOCKER-ISOLATION
  14. -A FORWARD -o docker0 -j DOCKER
  15. -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
  16. -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
  17. -A FORWARD -i docker0 -o docker0 -j ACCEPT
  18. -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 443 -j ACCEPT
  19. -A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -j ACCEPT
  20. -A DOCKER-ISOLATION -j RETURN
  21. -A f2b-ReqLimit -s 97.100.10.105/32 -j REJECT --reject-with icmp-port-unreachable
  22. -A f2b-ReqLimit -j RETURN
  23. -A f2b-sshd -j RETURN
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement