From 628a36ab7772d5302d9fbf841abc4666cfeea6e5 Mon Sep 17 00:00:00 2001 From: caskd Date: Sun, 2 Feb 2020 17:25:11 +0100 Subject: [PATCH] Initial commit --- ip6tables.rules | 27 +++++++++++++++++++++++++++ iptables.rules | 30 ++++++++++++++++++++++++++++++ 2 files changed, 57 insertions(+) create mode 100644 ip6tables.rules create mode 100644 iptables.rules diff --git a/ip6tables.rules b/ip6tables.rules new file mode 100644 index 0000000..fc26e76 --- /dev/null +++ b/ip6tables.rules @@ -0,0 +1,27 @@ +# Generated by ip6tables-save v1.8.4 on Thu Jan 30 09:05:19 2020 +*filter +:INPUT DROP [17:2112] +:FORWARD DROP [0:0] +:OUTPUT ACCEPT [31:3265] +-A INPUT -m conntrack --ctstate INVALID -j DROP +-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP +-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP +-A INPUT -i lo -j ACCEPT +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +COMMIT +# Completed on Thu Jan 30 09:05:19 2020 +# Generated by ip6tables-save v1.8.4 on Thu Jan 30 09:05:19 2020 +*mangle +:PREROUTING ACCEPT [18:2161] +:INPUT ACCEPT [18:2161] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [31:3265] +:POSTROUTING ACCEPT [48:5377] +COMMIT +# Completed on Thu Jan 30 09:05:19 2020 +# Generated by ip6tables-save v1.8.4 on Thu Jan 30 09:05:19 2020 +*raw +:PREROUTING ACCEPT [18:2161] +:OUTPUT ACCEPT [31:3265] +COMMIT +# Completed on Thu Jan 30 09:05:19 2020 diff --git a/iptables.rules b/iptables.rules new file mode 100644 index 0000000..b15ca6a --- /dev/null +++ b/iptables.rules @@ -0,0 +1,30 @@ +# Generated by iptables-save v1.8.4 on Thu Jan 30 10:59:37 2020 +*filter +:INPUT DROP [0:0] +:FORWARD DROP [0:0] +:OUTPUT ACCEPT [6:359] +-A INPUT -m conntrack --ctstate INVALID -j DROP +-A INPUT -i lo -j ACCEPT +-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP +-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -p icmp -m icmp --icmp-type 8 -m conntrack --ctstate NEW -j ACCEPT +-A INPUT -p tcp -j REJECT --reject-with tcp-reset +-A INPUT -p udp -j REJECT --reject-with icmp-port-unreachable +COMMIT +# Completed on Thu Jan 30 10:59:37 2020 +# Generated by iptables-save v1.8.4 on Thu Jan 30 10:59:37 2020 +*mangle +:PREROUTING ACCEPT [8948:5925361] +:INPUT ACCEPT [8943:5924001] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [10902:1431630] +:POSTROUTING ACCEPT [10965:1438415] +COMMIT +# Completed on Thu Jan 30 10:59:37 2020 +# Generated by iptables-save v1.8.4 on Thu Jan 30 10:59:37 2020 +*raw +:PREROUTING ACCEPT [8948:5925361] +:OUTPUT ACCEPT [10902:1431630] +COMMIT +# Completed on Thu Jan 30 10:59:37 2020