1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56
| # iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT icmp -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere tcp dpt:49152
ACCEPT tcp -- anywhere anywhere tcp dpt:49153
ACCEPT tcp -- anywhere anywhere tcp dpt:23456
ACCEPT tcp -- anywhere anywhere tcp dpt:smtp
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT tcp -- anywhere anywhere tcp dpt:www
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3
ACCEPT udp -- anywhere anywhere udp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:imap2
ACCEPT tcp -- anywhere anywhere tcp dpt:sftp
ACCEPT udp -- anywhere anywhere udp dpt:ntp
ACCEPT tcp -- 192.168.2.128/26 anywhere tcp dpt:http-alt
ACCEPT tcp -- 192.168.2.64/26 anywhere tcp dpt:http-alt
ACCEPT tcp -- 192.168.2.192/26 anywhere tcp dpt:http-alt
ACCEPT udp -- anywhere anywhere udp dpt:http-alt
ACCEPT tcp -- anywhere anywhere multiport dports sunrpc,nfs,4000:4003
ACCEPT udp -- anywhere anywhere multiport dports sunrpc,nfs,4000:4003
ACCEPT tcp -- anywhere anywhere tcp dpt:nut
ACCEPT tcp -- anywhere anywhere multiport dports 6969,6881:6889
ACCEPT udp -- anywhere anywhere udp dpt:6881
ACCEPT udp -- anywhere anywhere udp dpt:3826
ACCEPT tcp -- anywhere anywhere tcp dpt:3826
ACCEPT udp -- anywhere anywhere udp dpt:31416
ACCEPT tcp -- anywhere anywhere tcp dpt:31416
ULOG all -- anywhere anywhere ULOG copy_range 0 nlgroup 1 queue_threshold 1
DROP all -- anywhere anywhere
REJECT tcp -- !192.168.2.0/26 anywhere tcp dpt:3128 reject-with icmp-port-unreachable
REJECT tcp -- !192.168.2.0/26 anywhere tcp dpt:3128 reject-with icmp-port-unreachable
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:465
ACCEPT tcp -- anywhere anywhere tcp dpt:ssmtp
ACCEPT udp -- anywhere anywhere udp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3
ACCEPT tcp -- anywhere anywhere tcp dpt:pop3s
REJECT all -- !192.168.2.0/28 anywhere reject-with icmp-port-unreachable
ACCEPT all -- 192.168.2.0/26 anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:ntp
REJECT tcp -- !192.168.2.0/26 anywhere tcp dpt:msnp reject-with icmp-port-unreachable
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain spamlist (0 references)
target prot opt source destination |