| Line 1... |
Line 1... |
| 1 |
*filter
|
1 |
*filter
|
| 2 |
:LOG_ICMP - [0:0]
|
- |
|
| 3 |
:FORWARD ACCEPT [0:0]
|
- |
|
| 4 |
:LOG_REJECT - [0:0]
|
- |
|
| 5 |
:INPUT ACCEPT [0:0]
|
- |
|
| 6 |
:OUTPUT ACCEPT [0:0]
|
- |
|
| 7 |
:LOG_ACCEPT - [0:0]
|
- |
|
| 8 |
:LOG_IPSEC - [0:0]
|
- |
|
| 9 |
-A LOG_REJECT -j LOG --log-tcp-options --log-ip-options --log-prefix "[IPTABLES REJECT] : "
|
- |
|
| 10 |
-A LOG_REJECT -j REJECT
|
- |
|
| 11 |
-A LOG_ACCEPT -j LOG --log-tcp-options --log-ip-options --log-prefix "[IPTABLES ACCEPT] : "
|
- |
|
| 12 |
-A LOG_ACCEPT -j ACCEPT
|
- |
|
| 13 |
-A LOG_ICMP -j LOG --log-tcp-options --log-ip-options --log-prefix "[IPTABLES ICMP] : "
|
- |
|
| 14 |
-A LOG_ICMP -j ACCEPT
|
- |
|
| 15 |
-A LOG_IPSEC -j LOG --log-tcp-options --log-ip-options --log-prefix "[IPTABLES IPSEC] : "
|
- |
|
| 16 |
-A LOG_IPSEC -j ACCEPT
|
- |
|
| 17 |
-A INPUT -p esp -m esp -i eth1 -j ACCEPT
|
2 |
-A INPUT -p esp -m esp -i eth1 -j ACCEPT
|
| 18 |
-A INPUT -p ah -m ah -i eth1 -j ACCEPT
|
3 |
-A INPUT -p ah -m ah -i eth1 -j ACCEPT
|
| 19 |
-A INPUT -p udp -m udp -i eth1 --dport 500 -j ACCEPT
|
4 |
-A INPUT -p udp -m udp -i eth1 --dport 500 -j ACCEPT
|
| 20 |
-A INPUT -p tcp -m tcp -i eth1 --dport 443 -j LOG_ACCEPT
|
5 |
-A INPUT -p tcp -m tcp -i eth1 --dport 443 -j ACCEPT
|
| 21 |
-A INPUT -p udp -m udp -i eth1 --dport 1194 -j ACCEPT
|
6 |
-A INPUT -p udp -m udp -i eth1 --dport 1194 -j ACCEPT
|
| 22 |
# Closed by Cox
|
7 |
# Closed by Cox
|
| 23 |
-A INPUT -p tcp -m tcp -i eth1 --dport 80 -j LOG_REJECT
|
8 |
-A INPUT -p tcp -m tcp -i eth1 --dport 80 -j REJECT
|
| 24 |
-A INPUT -p tcp -m tcp -i eth1 --dport 8000 -j LOG_REJECT
|
9 |
-A INPUT -p tcp -m tcp -i eth1 --dport 8000 -j REJECT
|
| 25 |
-A INPUT -p tcp -m tcp -i eth1 --dport 8080 -j LOG_REJECT
|
10 |
-A INPUT -p tcp -m tcp -i eth1 --dport 8080 -j REJECT
|
| 26 |
# Closed by Cox
|
11 |
# Closed by Cox
|
| 27 |
-A INPUT -p tcp -m tcp -i eth1 --dport 25 -j LOG_REJECT
|
12 |
-A INPUT -p tcp -m tcp -i eth1 --dport 25 -j REJECT
|
| 28 |
-A INPUT -p tcp -m tcp -i eth1 --dport 22 -j LOG_REJECT
|
13 |
-A INPUT -p tcp -m tcp -i eth1 --dport 22 -j REJECT
|
| 29 |
-A INPUT -p tcp -m tcp -i eth1 --dport 53 -j LOG_REJECT
|
14 |
-A INPUT -p tcp -m tcp -i eth1 --dport 53 -j REJECT
|
| 30 |
-A INPUT -p tcp -m tcp -i eth1 --dport 111 -j LOG_REJECT
|
15 |
-A INPUT -p tcp -m tcp -i eth1 --dport 111 -j REJECT
|
| 31 |
-A INPUT -p tcp -m tcp -i eth1 --dport 135 -j LOG_REJECT
|
16 |
-A INPUT -p tcp -m tcp -i eth1 --dport 135 -j REJECT
|
| 32 |
-A INPUT -p tcp -m tcp -i eth1 --dport 136 -j LOG_REJECT
|
17 |
-A INPUT -p tcp -m tcp -i eth1 --dport 136 -j REJECT
|
| 33 |
-A INPUT -p tcp -m tcp -i eth1 --dport 137 -j LOG_REJECT
|
18 |
-A INPUT -p tcp -m tcp -i eth1 --dport 137 -j REJECT
|
| 34 |
-A INPUT -p tcp -m tcp -i eth1 --dport 138 -j LOG_REJECT
|
19 |
-A INPUT -p tcp -m tcp -i eth1 --dport 138 -j REJECT
|
| 35 |
-A INPUT -p tcp -m tcp -i eth1 --dport 139 -j LOG_REJECT
|
20 |
-A INPUT -p tcp -m tcp -i eth1 --dport 139 -j REJECT
|
| 36 |
-A INPUT -p tcp -m tcp -i eth1 --dport 177 -j LOG_REJECT
|
21 |
-A INPUT -p tcp -m tcp -i eth1 --dport 177 -j REJECT
|
| 37 |
-A INPUT -p tcp -m tcp -i eth1 --dport 445 -j LOG_REJECT
|
22 |
-A INPUT -p tcp -m tcp -i eth1 --dport 445 -j REJECT
|
| 38 |
-A INPUT -p tcp -m tcp -i eth1 --dport 631 -j LOG_REJECT
|
23 |
-A INPUT -p tcp -m tcp -i eth1 --dport 631 -j REJECT
|
| 39 |
-A INPUT -p tcp -m tcp -i eth1 --dport 783 -j LOG_REJECT
|
24 |
-A INPUT -p tcp -m tcp -i eth1 --dport 783 -j REJECT
|
| 40 |
-A INPUT -p tcp -m tcp -i eth1 --dport 953 -j LOG_REJECT
|
25 |
-A INPUT -p tcp -m tcp -i eth1 --dport 953 -j REJECT
|
| 41 |
-A INPUT -p tcp -m tcp -i eth1 --dport 1433 -j LOG_REJECT
|
26 |
-A INPUT -p tcp -m tcp -i eth1 --dport 1433 -j REJECT
|
| 42 |
-A INPUT -p tcp -m tcp -i eth1 --dport 10000 -j LOG_REJECT
|
27 |
-A INPUT -p tcp -m tcp -i eth1 --dport 10000 -j REJECT
|
| 43 |
-A INPUT -p tcp -m tcp -i eth1 --dport 27374 -j LOG_REJECT
|
28 |
-A INPUT -p tcp -m tcp -i eth1 --dport 27374 -j REJECT
|
| 44 |
-A INPUT -p tcp -m tcp -i eth1 --dport 32770 -j LOG_REJECT
|
29 |
-A INPUT -p tcp -m tcp -i eth1 --dport 32770 -j REJECT
|
| 45 |
-A INPUT -p tcp -m tcp -i eth1 --dport 32771 -j LOG_REJECT
|
30 |
-A INPUT -p tcp -m tcp -i eth1 --dport 32771 -j REJECT
|
| 46 |
-A INPUT -p udp -m udp -i eth1 --dport 53 -j LOG_REJECT
|
31 |
-A INPUT -p udp -m udp -i eth1 --dport 53 -j REJECT
|
| 47 |
-A INPUT -p udp -m udp -i eth1 --dport 68 -j LOG_REJECT
|
32 |
-A INPUT -p udp -m udp -i eth1 --dport 68 -j REJECT
|
| 48 |
-A INPUT -p udp -m udp -i eth1 --dport 111 -j LOG_REJECT
|
33 |
-A INPUT -p udp -m udp -i eth1 --dport 111 -j REJECT
|
| 49 |
-A INPUT -p udp -m udp -i eth1 --dport 135 -j LOG_REJECT
|
34 |
-A INPUT -p udp -m udp -i eth1 --dport 135 -j REJECT
|
| 50 |
-A INPUT -p udp -m udp -i eth1 --dport 136 -j LOG_REJECT
|
35 |
-A INPUT -p udp -m udp -i eth1 --dport 136 -j REJECT
|
| 51 |
-A INPUT -p udp -m udp -i eth1 --dport 137 -j LOG_REJECT
|
36 |
-A INPUT -p udp -m udp -i eth1 --dport 137 -j REJECT
|
| 52 |
-A INPUT -p udp -m udp -i eth1 --dport 138 -j LOG_REJECT
|
37 |
-A INPUT -p udp -m udp -i eth1 --dport 138 -j REJECT
|
| 53 |
-A INPUT -p udp -m udp -i eth1 --dport 139 -j LOG_REJECT
|
38 |
-A INPUT -p udp -m udp -i eth1 --dport 139 -j REJECT
|
| 54 |
# Allow NTP client traffic
|
39 |
# Allow NTP client traffic
|
| 55 |
-A INPUT -p udp -m udp --dport 123 -j LOG_ACCEPT
|
40 |
-A INPUT -p udp -m udp --dport 123 -j ACCEPT
|
| 56 |
-A INPUT -p udp -m udp --sport 123 -j LOG_ACCEPT
|
41 |
-A INPUT -p udp -m udp --sport 123 -j ACCEPT
|
| 57 |
-A INPUT -p udp -m udp -i eth1 --dport 177 -j LOG_REJECT
|
42 |
-A INPUT -p udp -m udp -i eth1 --dport 177 -j REJECT
|
| 58 |
-A INPUT -p udp -m udp -i eth1 --dport 445 -j LOG_REJECT
|
43 |
-A INPUT -p udp -m udp -i eth1 --dport 445 -j REJECT
|
| 59 |
-A INPUT -p udp -m udp -i eth1 --dport 922 -j LOG_REJECT
|
44 |
-A INPUT -p udp -m udp -i eth1 --dport 922 -j REJECT
|
| 60 |
-A INPUT -p udp -m udp -i eth1 --dport 1433 -j LOG_REJECT
|
45 |
-A INPUT -p udp -m udp -i eth1 --dport 1433 -j REJECT
|
| 61 |
-A INPUT -p udp -m udp -i eth1 --dport 3130 -j LOG_REJECT
|
46 |
-A INPUT -p udp -m udp -i eth1 --dport 3130 -j REJECT
|
| 62 |
-A INPUT -p udp -m udp -i eth1 --dport 10000 -j LOG_REJECT
|
47 |
-A INPUT -p udp -m udp -i eth1 --dport 10000 -j REJECT
|
| 63 |
-A INPUT -p udp -m udp -i eth1 --dport 27374 -j LOG_REJECT
|
48 |
-A INPUT -p udp -m udp -i eth1 --dport 27374 -j REJECT
|
| 64 |
-A INPUT -p udp -m udp -i eth1 --dport 32768 -j LOG_REJECT
|
49 |
-A INPUT -p udp -m udp -i eth1 --dport 32768 -j REJECT
|
| 65 |
# Allow openvpn traffic
|
50 |
# Allow openvpn traffic
|
| 66 |
-A INPUT -p udp -m udp --dport 1194 -j LOG_ACCEPT
|
51 |
-A INPUT -p udp -m udp --dport 1194 -j ACCEPT
|
| 67 |
-A INPUT -p udp -m udp --sport 1194 -j LOG_ACCEPT
|
52 |
-A INPUT -p udp -m udp --sport 1194 -j ACCEPT
|
| 68 |
-A INPUT -p icmp -m icmp -i eth1 -j LOG_ICMP
|
53 |
-A INPUT -p icmp -m icmp -i eth1 -j ACCEPT
|
| 69 |
COMMIT
|
54 |
COMMIT
|
| 70 |
|
55 |
|
| 71 |
*nat
|
56 |
*nat
|
| 72 |
:PREROUTING ACCEPT [9:1101]
|
57 |
:PREROUTING ACCEPT [9:1101]
|
| 73 |
:POSTROUTING ACCEPT [14:962]
|
58 |
:POSTROUTING ACCEPT [14:962]
|
| 74 |
:OUTPUT ACCEPT [14:962]
|
59 |
:OUTPUT ACCEPT [14:962]
|
| 75 |
|
60 |
|
| 76 |
# Webserver
|
61 |
# Webserver
|
| 77 |
# http (Closed by Cox)
|
- |
|
| 78 |
#-A PREROUTING -i eth1 -p tcp --dport 80 -j DNAT --to-destination 10.192.25.240:80
|
- |
|
| 79 |
#-A PREROUTING -i eth0 -d 72.219.238.135 -p tcp --dport 80 -j DNAT --to-destination 10.192.25.240:80
|
- |
|
| 80 |
# https
|
- |
|
| 81 |
-A PREROUTING -i eth1 -p tcp --dport 443 -j DNAT --to-destination 10.192.25.240:443
|
62 |
-A PREROUTING -i eth1 -p tcp --dport 443 -j DNAT --to-destination 10.192.25.240:443
|
| 82 |
-A PREROUTING -i eth0 -d 72.192.249.173 -p tcp --dport 443 -j DNAT --to-destination 10.192.25.240:443
|
63 |
-A PREROUTING -i eth0 -d 72.192.249.173 -p tcp --dport 443 -j DNAT --to-destination 10.192.25.240:443
|
| 83 |
|
- |
|
| 84 |
# Squid
|
- |
|
| 85 |
#-A PREROUTING -i eth0 -s 10.192.25.231/32 -p tcp --dport 80 -j DNAT --to 10.192.25.240:3128
|
- |
|
| 86 |
#-A POSTROUTING -o eth1 -s 10.192.25.231/32 -d 10.192.25.240 -j SNAT --to 10.192.25.254
|
- |
|
| 87 |
#-A PREROUTING -i eth0 -s 10.192.25.232/32 -p tcp --dport 80 -j DNAT --to 10.192.25.240:3128
|
- |
|
| 88 |
#-A POSTROUTING -o eth1 -s 10.192.25.232/32 -d 10.192.25.240 -j SNAT --to 10.192.25.254
|
- |
|
| 89 |
#-A PREROUTING -i eth0 -s 10.192.25.203/32 -p tcp --dport 80 -j DNAT --to 10.192.25.240:3128
|
- |
|
| 90 |
#-A POSTROUTING -o eth1 -s 10.192.25.203/32 -d 10.192.25.240 -j SNAT --to 10.192.25.254
|
- |
|
| 91 |
#-A PREROUTING -i eth0 -s 10.192.25.205/32 -p tcp --dport 80 -j DNAT --to 10.192.25.240:3128
|
- |
|
| 92 |
#-A POSTROUTING -o eth1 -s 10.192.25.205/32 -d 10.192.25.240 -j SNAT --to 10.192.25.254
|
- |
|
| 93 |
#-A PREROUTING -i eth0 -s 10.192.25.206/32 -p tcp --dport 80 -j DNAT --to 10.192.25.240:3128
|
- |
|
| 94 |
#-A POSTROUTING -o eth1 -s 10.192.25.206/32 -d 10.192.25.240 -j SNAT --to 10.192.25.254
|
- |
|
| 95 |
|
64 |
|
| 96 |
# openvpn
|
65 |
# openvpn
|
| 97 |
-A POSTROUTING -s 192.168.200.0/24 -d 10.192.25.0/24 -j ACCEPT
|
66 |
-A POSTROUTING -s 192.168.200.0/24 -d 10.192.25.0/24 -j ACCEPT
|
| 98 |
-A POSTROUTING -d 192.168.200.0/24 -s 10.192.25.0/24 -j ACCEPT
|
67 |
-A POSTROUTING -d 192.168.200.0/24 -s 10.192.25.0/24 -j ACCEPT
|
| 99 |
|
68 |
|