Created
October 14, 2016 20:06
-
-
Save anonymous/18c5c7895128ca0a246c2a3210930118 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
$ sudo iptables-save | |
# Generated by iptables-save v1.6.0 on Fri Oct 14 22:05:28 2016 | |
*raw | |
:PREROUTING ACCEPT [9628:19945100] | |
:OUTPUT ACCEPT [8089:382590] | |
-A PREROUTING -i lo -j CT --notrack | |
-A OUTPUT -o lo -j CT --notrack | |
COMMIT | |
# Completed on Fri Oct 14 22:05:28 2016 | |
# Generated by iptables-save v1.6.0 on Fri Oct 14 22:05:28 2016 | |
*filter | |
:INPUT DROP [0:0] | |
:FORWARD DROP [0:0] | |
:OUTPUT ACCEPT [6075:281742] | |
:forward_ext - [0:0] | |
:input_ext - [0:0] | |
:reject_func - [0:0] | |
-A INPUT -i lo -j ACCEPT | |
-A INPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT | |
-A INPUT -p icmp -m conntrack --ctstate RELATED -j ACCEPT | |
-A INPUT -j input_ext | |
-A INPUT -m limit --limit 3/min -j LOG --log-prefix "SFW2-IN-ILL-TARGET " --log-tcp-options --log-ip-options | |
-A INPUT -j DROP | |
-A FORWARD -m limit --limit 3/min -j LOG --log-prefix "SFW2-FWD-ILL-ROUTING " --log-tcp-options --log-ip-options | |
-A OUTPUT -o lo -j ACCEPT | |
-A input_ext -m pkttype --pkt-type broadcast -j DROP | |
-A input_ext -p icmp -m icmp --icmp-type 4 -j ACCEPT | |
-A input_ext -p icmp -m icmp --icmp-type 8 -j ACCEPT | |
-A input_ext -m pkttype --pkt-type multicast -j DROP | |
-A input_ext -m pkttype --pkt-type broadcast -j DROP | |
-A input_ext -p tcp -m limit --limit 3/min -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options | |
-A input_ext -p icmp -m limit --limit 3/min -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options | |
-A input_ext -p udp -m limit --limit 3/min -m conntrack --ctstate NEW -j LOG --log-prefix "SFW2-INext-DROP-DEFLT " --log-tcp-options --log-ip-options | |
-A input_ext -j DROP | |
-A reject_func -p tcp -j REJECT --reject-with tcp-reset | |
-A reject_func -p udp -j REJECT --reject-with icmp-port-unreachable | |
-A reject_func -j REJECT --reject-with icmp-proto-unreachable | |
COMMIT | |
# Completed on Fri Oct 14 22:05:28 2016 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment