Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- iptables -F
- iptables -Z
- iptables -P INPUT DROP
- iptables -P OUTPUT DROP
- iptables -P FORWARD ACCEPT
- iptables -N BRUTEFORCE
- iptables -A INPUT -i lo -j ACCEPT
- iptables -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --set
- iptables -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 --name DEFAULT --mask 255.255.255.255 --rsource -j BRUTEFORCE
- iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- iptables -A OUTPUT -o lo -j ACCEPT
- iptables -A OUTPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT
- iptables -A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- iptables -A BRUTEFORCE -p tcp -m tcp --dport 22 -j LOG --log-prefix "BRUTE FORCE OR DDOS SSH"
- iptables -A BRUTEFORCE -j DROP
- iptables -L
- ip6tables -F
- ip6tables -Z
- ip6tables -P INPUT DROP
- ip6tables -P OUTPUT DROP
- ip6tables -P FORWARD ACCEPT
- ip6tables -N BRUTEFORCE
- ip6tables -A INPUT -i lo -j ACCEPT
- ip6tables -A INPUT -p icmpv6 -j ACCEPT
- ip6tables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --set
- ip6tables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -j BRUTEFORCE
- ip6tables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- ip6tables -A OUTPUT -o lo -j ACCEPT
- ip6tables -A OUTPUT -p icmpv6 -j ACCEPT
- ip6tables -A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
- ip6tables -A BRUTEFORCE -p tcp -m tcp --dport 22 -j LOG --log-prefix "BRUTE FORCE OR DDOS SSH"
- ip6tables -A BRUTEFORCE -j DROP
- ip6tables -L
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement