Skip to content

Instantly share code, notes, and snippets.

@m-wynn
Created January 5, 2017 22:35
Show Gist options
  • Save m-wynn/002a8ab798ec5027db467a58dd18dad8 to your computer and use it in GitHub Desktop.
Save m-wynn/002a8ab798ec5027db467a58dd18dad8 to your computer and use it in GitHub Desktop.
Firewall Configuration
# Generated by ip6tables-save v1.6.0 on Wed Dec 21 01:48:26 2016
*raw
:PREROUTING ACCEPT [374:283173]
:OUTPUT ACCEPT [249:23548]
COMMIT
# Completed on Wed Dec 21 01:48:26 2016
# Generated by ip6tables-save v1.6.0 on Wed Dec 21 01:48:26 2016
*mangle
:PREROUTING ACCEPT [5:449]
:INPUT ACCEPT [5:449]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [4:322]
:POSTROUTING ACCEPT [4:322]
COMMIT
# Completed on Wed Dec 21 01:48:26 2016
# Generated by ip6tables-save v1.6.0 on Wed Dec 21 01:48:26 2016
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [4:322]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p ipv6-icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
# Completed on Wed Dec 21 01:48:26 2016
# Generated by iptables-save v1.6.0 on Wed Dec 21 01:40:53 2016
*nat
:PREROUTING ACCEPT [140:75914]
:INPUT ACCEPT [1:328]
:OUTPUT ACCEPT [274:16674]
:POSTROUTING ACCEPT [274:16674]
COMMIT
# Completed on Wed Dec 21 01:40:53 2016
# Generated by iptables-save v1.6.0 on Wed Dec 21 01:40:53 2016
*raw
:PREROUTING ACCEPT [14676:2226170]
:OUTPUT ACCEPT [14254:906539]
COMMIT
# Completed on Wed Dec 21 01:40:53 2016
# Generated by iptables-save v1.6.0 on Wed Dec 21 01:40:53 2016
*mangle
:PREROUTING ACCEPT [14676:2226170]
:INPUT ACCEPT [14545:2151893]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [14254:906539]
:POSTROUTING ACCEPT [14254:906539]
COMMIT
# Completed on Wed Dec 21 01:40:53 2016
# Generated by iptables-save v1.6.0 on Wed Dec 21 01:40:53 2016
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [776:45961]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -d 127.0.0.0/8 ! -i lo -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Wed Dec 21 01:40:53 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment