From Anorexic Cockroach, 10 Years ago, written in Plain Text.
Embed
  1. user@debo8:~$ sudo iptables-save
  2. # Generated by iptables-save v1.4.21 on Wed Apr  8 10:54:11 2015
  3. *nat
  4. :PREROUTING ACCEPT [186:23737]
  5. :INPUT ACCEPT [0:0]
  6. :OUTPUT ACCEPT [0:0]
  7. :POSTROUTING ACCEPT [0:0]
  8. -A POSTROUTING -j MASQUERADE
  9. COMMIT
  10. # Completed on Wed Apr  8 10:54:11 2015
  11. # Generated by iptables-save v1.4.21 on Wed Apr  8 10:54:11 2015
  12. *mangle
  13. :PREROUTING ACCEPT [56161:17340662]
  14. :INPUT ACCEPT [54512:17086123]
  15. :FORWARD ACCEPT [1648:253074]
  16. :OUTPUT ACCEPT [54746:16444902]
  17. :POSTROUTING ACCEPT [56394:16697976]
  18. -A PREROUTING ! -d 213.245.127.195/32 -i p10p1 -j DROP
  19. -A PREROUTING ! -s 192.168.0.0/16 ! -d 192.168.2.3/32 -i p9p1 -j DROP
  20. -A PREROUTING ! -d 10.241.0.8/32 -i tun0 -j DROP
  21. -A OUTPUT -s 213.245.127.195/32 -j MARK --set-xmark 0x1/0xffffffff
  22. -A OUTPUT -s 64.15.65.114/32 -j MARK --set-xmark 0x3/0xffffffff
  23. -A OUTPUT -s 192.168.2.3/32 -j MARK --set-xmark 0x4/0xffffffff
  24. -A OUTPUT -d 64.15.65.123/32 -p udp -m udp --sport 23446 --dport 10000 -j MARK --set-xmark 0x2/0xffffffff
  25. -A OUTPUT -d 130.211.92.240/32 -p udp -m udp --sport 23446 --dport 27652 -j MARK --set-xmark 0x1/0xffffffff
  26. -A POSTROUTING -o tun0 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
  27. COMMIT
  28. # Completed on Wed Apr  8 10:54:11 2015
  29. # Generated by iptables-save v1.4.21 on Wed Apr  8 10:54:11 2015
  30. *filter
  31. :INPUT DROP [129:17592]
  32. :FORWARD DROP [0:0]
  33. :OUTPUT DROP [0:0]
  34. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  35. -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
  36. -A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 10/sec -j ACCEPT
  37. -A INPUT -i lo -j ACCEPT
  38. -A INPUT -p udp -m udp --dport 23446 -j ACCEPT
  39. -A INPUT -i tun0 -p tcp -m tcp --dport 443 -j ACCEPT
  40. -A INPUT -i p10p1 -j DROP
  41. -A INPUT -p tcp -m tcp --dport 6697 -j ACCEPT
  42. -A INPUT -i tun0 -j DROP
  43. -A INPUT -p udp -m udp --dport 53 -j ACCEPT
  44. -A FORWARD -i p10p1 -j DROP
  45. -A FORWARD -o p10p1 -j DROP
  46. -A FORWARD -d 192.168.0.0/16 -o p10p1 -j DROP
  47. -A FORWARD -d 192.168.0.0/24 -o p9p1 -j DROP
  48. -A FORWARD -s 192.168.2.0/24 -d 192.168.0.0/24 -i p9p1 -j ACCEPT
  49. -A FORWARD -s 192.168.0.0/24 -d 192.168.2.0/24 -j ACCEPT
  50. -A FORWARD -s 192.168.0.0/16 -i tun0 -j DROP
  51. -A FORWARD -d 192.168.0.0/16 -o tun0 -j DROP
  52. -A FORWARD -s 192.168.0.0/16 -o tun0 -j ACCEPT
  53. -A FORWARD -d 192.168.0.0/16 -j ACCEPT
  54. -A OUTPUT -j ACCEPT
  55. COMMIT
  56. # Completed on Wed Apr  8 10:54:11 2015
  57. user@debo8:~$
  58.