Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- -P INPUT ACCEPT
- -P FORWARD ACCEPT
- -P OUTPUT ACCEPT
- -N DOCKER
- -N DOCKER-ISOLATION
- -N FORWARD_IN_ZONES
- -N FORWARD_IN_ZONES_SOURCE
- -N FORWARD_OUT_ZONES
- -N FORWARD_OUT_ZONES_SOURCE
- -N FORWARD_direct
- -N FWDI_cameras
- -N FWDI_cameras_allow
- -N FWDI_cameras_deny
- -N FWDI_cameras_log
- -N FWDI_internal
- -N FWDI_internal_allow
- -N FWDI_internal_deny
- -N FWDI_internal_log
- -N FWDO_cameras
- -N FWDO_cameras_allow
- -N FWDO_cameras_deny
- -N FWDO_cameras_log
- -N FWDO_internal
- -N FWDO_internal_allow
- -N FWDO_internal_deny
- -N FWDO_internal_log
- -N INPUT_ZONES
- -N INPUT_ZONES_SOURCE
- -N INPUT_direct
- -N IN_cameras
- -N IN_cameras_allow
- -N IN_cameras_deny
- -N IN_cameras_log
- -N IN_internal
- -N IN_internal_allow
- -N IN_internal_deny
- -N IN_internal_log
- -N OUTPUT_direct
- -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -j INPUT_direct
- -A INPUT -j INPUT_ZONES_SOURCE
- -A INPUT -j INPUT_ZONES
- -A INPUT -m conntrack --ctstate INVALID -j DROP
- -A INPUT -j REJECT --reject-with icmp-host-prohibited
- -A FORWARD -j DOCKER-ISOLATION
- -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -o docker0 -j DOCKER
- -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
- -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- -A FORWARD -i docker0 -o docker0 -j ACCEPT
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -i lo -j ACCEPT
- -A FORWARD -j FORWARD_direct
- -A FORWARD -j FORWARD_IN_ZONES_SOURCE
- -A FORWARD -j FORWARD_IN_ZONES
- -A FORWARD -j FORWARD_OUT_ZONES_SOURCE
- -A FORWARD -j FORWARD_OUT_ZONES
- -A FORWARD -m conntrack --ctstate INVALID -j DROP
- -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
- -A OUTPUT -j OUTPUT_direct
- -A DOCKER-ISOLATION -j RETURN
- -A FORWARD_IN_ZONES -i bridge0 -g FWDI_internal
- -A FORWARD_IN_ZONES -i bridge1 -g FWDI_cameras
- -A FORWARD_IN_ZONES -g FWDI_internal
- -A FORWARD_IN_ZONES_SOURCE -s 192.168.1.4/32 -g FWDI_cameras
- -A FORWARD_OUT_ZONES -o bridge0 -g FWDO_internal
- -A FORWARD_OUT_ZONES -o bridge1 -g FWDO_cameras
- -A FORWARD_OUT_ZONES -g FWDO_internal
- -A FORWARD_OUT_ZONES_SOURCE -d 192.168.1.4/32 -g FWDO_cameras
- -A FWDI_cameras -j FWDI_cameras_log
- -A FWDI_cameras -j FWDI_cameras_deny
- -A FWDI_cameras -j FWDI_cameras_allow
- -A FWDI_cameras -p icmp -j ACCEPT
- -A FWDI_internal -j FWDI_internal_log
- -A FWDI_internal -j FWDI_internal_deny
- -A FWDI_internal -j FWDI_internal_allow
- -A FWDI_internal -p icmp -j ACCEPT
- -A FWDO_cameras -j FWDO_cameras_log
- -A FWDO_cameras -j FWDO_cameras_deny
- -A FWDO_cameras -j FWDO_cameras_allow
- -A FWDO_internal -j FWDO_internal_log
- -A FWDO_internal -j FWDO_internal_deny
- -A FWDO_internal -j FWDO_internal_allow
- -A INPUT_ZONES -i bridge0 -g IN_internal
- -A INPUT_ZONES -i bridge1 -g IN_cameras
- -A INPUT_ZONES -g IN_internal
- -A INPUT_ZONES_SOURCE -s 192.168.1.4/32 -g IN_cameras
- -A IN_cameras -j IN_cameras_log
- -A IN_cameras -j IN_cameras_deny
- -A IN_cameras -j IN_cameras_allow
- -A IN_cameras -p icmp -j ACCEPT
- -A IN_cameras_allow -p udp -m udp --dport 123 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal -j IN_internal_log
- -A IN_internal -j IN_internal_deny
- -A IN_internal -j IN_internal_allow
- -A IN_internal -p icmp -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 139 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 445 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 20048 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 20048 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 111 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 111 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 2049 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 123 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p tcp -m tcp --dport 53 -m conntrack --ctstate NEW -j ACCEPT
- -A IN_internal_allow -p udp -m udp --dport 53 -m conntrack --ctstate NEW -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment