Create a gist now

Instantly share code, notes, and snippets.

What would you like to do?
iptables rules example
# Generated by iptables-save v1.6.0 on Thu Dec 7 20:15:26 2017
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [7:532]
:LOGGING - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -i ens7 -p icmp -j DROP
-A INPUT -i ens3 -p icmp -j DROP
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -m conntrack --ctstate INVALID -j DROP
-A INPUT -s 10.4.1.3/32 -p tcp -m tcp --dport 223 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
-A INPUT -s 10.4.1.3/32 -p tcp -m tcp --dport 5901 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
-A INPUT -i ens3 -j LOG --log-prefix "IPtables dropped packets:"
-A INPUT -i ens7 -j LOG --log-prefix "IPtables dropped packets:"
-A INPUT -j LOGGING
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 223 -m conntrack --ctstate ESTABLISHED -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 5901 -m conntrack --ctstate ESTABLISHED -j ACCEPT
-A LOGGING -m limit --limit 2/min -j LOG --log-prefix "IPTables Packet Dropped: " --log-level 7
-A LOGGING -j DROP
COMMIT
# Completed on Thu Dec 7 20:15:26 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment