- # Generated by ip6tables-save v1.6.0 on Fri Feb 22 23:40:52 2019
- *mangle
- :PREROUTING ACCEPT [696415:82503926]
- :INPUT ACCEPT [696415:82503926]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [637909:81459016]
- :POSTROUTING ACCEPT [637909:81459016]
- COMMIT
- # Completed on Fri Feb 22 23:40:52 2019
- # Generated by ip6tables-save v1.6.0 on Fri Feb 22 23:40:52 2019
- *raw
- :PREROUTING ACCEPT [696416:82503998]
- :OUTPUT ACCEPT [637910:81459180]
- COMMIT
- # Completed on Fri Feb 22 23:40:52 2019
- # Generated by ip6tables-save v1.6.0 on Fri Feb 22 23:40:52 2019
- *nat
- :PREROUTING ACCEPT [822:101891]
- :INPUT ACCEPT [760:59676]
- :OUTPUT ACCEPT [491:39328]
- :POSTROUTING ACCEPT [491:39328]
- COMMIT
- # Completed on Fri Feb 22 23:40:52 2019
- # Generated by ip6tables-save v1.6.0 on Fri Feb 22 23:40:52 2019
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :ALLOWIN - [0:0]
- :ALLOWOUT - [0:0]
- :DENYIN - [0:0]
- :DENYOUT - [0:0]
- :INVALID - [0:0]
- :INVDROP - [0:0]
- :LOCALINPUT - [0:0]
- :LOCALOUTPUT - [0:0]
- :LOGDROPIN - [0:0]
- :LOGDROPOUT - [0:0]
- -A INPUT ! -i lo -j LOCALINPUT
- -A INPUT -i lo -j ACCEPT
- -A INPUT ! -i lo -p tcp -j INVALID
- -A INPUT ! -i lo -p ipv6-icmp -j ACCEPT
- -A INPUT ! -i lo -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 113 -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 6660:6669 -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 7000 -j ACCEPT
- -A INPUT ! -i lo -p tcp -m state --state NEW -m tcp --dport 6697 -j ACCEPT
- -A INPUT ! -i lo -j LOGDROPIN
- -A OUTPUT ! -o lo -j LOCALOUTPUT
- -A OUTPUT ! -o lo -p tcp -m tcp --dport 53 -j ACCEPT
- -A OUTPUT ! -o lo -p udp -m udp --dport 53 -j ACCEPT
- -A OUTPUT ! -o lo -p tcp -m tcp --sport 53 -j ACCEPT
- -A OUTPUT ! -o lo -p udp -m udp --sport 53 -j ACCEPT
- -A OUTPUT -o lo -j ACCEPT
- -A OUTPUT ! -o lo -p tcp -j INVALID
- -A OUTPUT ! -o lo -p ipv6-icmp -j ACCEPT
- -A OUTPUT ! -o lo -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A OUTPUT ! -o lo -p tcp -m state --state NEW -m tcp -j ACCEPT
- -A OUTPUT ! -o lo -p udp -m state --state NEW -m udp -j ACCEPT
- -A OUTPUT ! -o lo -j REJECT --reject-with icmp6-port-unreachable
- -A ALLOWIN -s 2001:123/128 ! -i lo -j ACCEPT
- -A ALLOWIN -s 2a05:123/128 ! -i lo -j ACCEPT
- -A ALLOWOUT -d 2001:123/128 ! -o lo -j ACCEPT
- -A ALLOWOUT -d 2a05:123/128 ! -o lo -j ACCEPT
- -A INVALID -m state --state INVALID -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags FIN,ACK FIN -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags PSH,ACK PSH -j INVDROP
- -A INVALID -p tcp -m tcp --tcp-flags ACK,URG URG -j INVDROP
- -A INVALID -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j INVDROP
- -A INVDROP -j DROP
- -A LOCALINPUT ! -i lo -j ALLOWIN
- -A LOCALINPUT ! -i lo -j DENYIN
- -A LOCALOUTPUT ! -o lo -j ALLOWOUT
- -A LOCALOUTPUT ! -o lo -j DENYOUT
- -A LOGDROPIN -p tcp -m tcp --dport 67 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 67 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 68 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 68 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 111 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 111 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 113 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 113 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 135:139 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 135:139 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 445 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 445 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 500 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 500 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 513 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 513 -j DROP
- -A LOGDROPIN -p tcp -m tcp --dport 520 -j DROP
- -A LOGDROPIN -p udp -m udp --dport 520 -j DROP
- -A LOGDROPIN -p tcp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP6IN Blocked* "
- -A LOGDROPIN -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP6IN Blocked* "
- -A LOGDROPIN -p ipv6-icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP6IN Blocked* "
- -A LOGDROPIN -j DROP
- -A LOGDROPOUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP6OUT Blocked* " --log-uid
- -A LOGDROPOUT -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP6OUT Blocked* " --log-uid
- -A LOGDROPOUT -p ipv6-icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP6OUT Blocked* " --log-uid
- -A LOGDROPOUT -j REJECT --reject-with icmp6-port-unreachable
- COMMIT
- # Completed on Fri Feb 22 23:40:52 2019