Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/sh
- # My system IP/set ip address of server
- SERVER_IP="xxxxxxxx"
- # Flushing all rules
- iptables -F
- iptables -X
- # Setting default filter policy
- iptables -P INPUT DROP
- iptables -P OUTPUT DROP
- iptables -P FORWARD DROP
- # Allow unlimited traffic on loopback
- iptables -A INPUT -i lo -j ACCEPT
- iptables -A OUTPUT -o lo -j ACCEPT
- # Allow incoming ssh only
- for port in 22 80 443
- do
- iptables -A INPUT -p tcp -s 0/0 -d $SERVER_IP --sport 513:65535 --dport $port -m state --state NEW,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -p tcp -s $SERVER_IP -d 0/0 --sport $port --dport 513:65535 -m state --state ESTABLISHED -j ACCEPT
- done
- # make sure nothing comes or goes out of this boxi
- iptables -A INPUT -j DROP
- #iptables -A OUTPUT -j DROP
Add Comment
Please, Sign In to add comment