Skip to content

Instantly share code, notes, and snippets.

@Stevemoretz
Last active September 29, 2022 13:57
Show Gist options
  • Save Stevemoretz/be556e4b5f4c19981436034419bc7835 to your computer and use it in GitHub Desktop.
Save Stevemoretz/be556e4b5f4c19981436034419bc7835 to your computer and use it in GitHub Desktop.
My routes
ip route
default via 6.8.198.225 dev ens192
6.8.198.224/27 dev ens192 proto kernel scope link src 6.8.198.252
10.8.0.0/24 dev tun0 proto kernel scope link src 10.8.0.1
10.66.66.0/24 dev wg0 proto kernel scope link src 10.66.66.1
169.254.0.0/16 dev ens192 scope link metric 1002
192.168.122.0/24 dev virbr0 proto kernel scope link src 192.168.122.1
ip rule
0: from all lookup local
32766: from all lookup main
32767: from all lookup default
iptables-save
# Generated by iptables-save v1.4.21 on Thu Sep 29 07:00:21 2022
*nat
:PREROUTING ACCEPT [338:24309]
:INPUT ACCEPT [289:18442]
:OUTPUT ACCEPT [85:5698]
:POSTROUTING ACCEPT [8:480]
-A OUTPUT -p tcp -m multiport --dports 80,443 -m set --match-set csp dst -j DNAT --to-destination 46.4.23.46
-A POSTROUTING -o ens192 -j MASQUERADE
COMMIT
# Completed on Thu Sep 29 07:00:21 2022
# Generated by iptables-save v1.4.21 on Thu Sep 29 07:00:21 2022
*mangle
:PREROUTING ACCEPT [7073:5748118]
:INPUT ACCEPT [4350:4421403]
:FORWARD ACCEPT [2723:1326715]
:OUTPUT ACCEPT [4549:3145503]
:POSTROUTING ACCEPT [7262:4470985]
COMMIT
# Completed on Thu Sep 29 07:00:21 2022
# Generated by iptables-save v1.4.21 on Thu Sep 29 07:00:21 2022
*raw
:PREROUTING ACCEPT [7074:5748494]
:OUTPUT ACCEPT [4552:3146295]
COMMIT
# Completed on Thu Sep 29 07:00:21 2022
# Generated by iptables-save v1.4.21 on Thu Sep 29 07:00:21 2022
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:ALLOWIN - [0:0]
:ALLOWOUT - [0:0]
:DENYIN - [0:0]
:DENYOUT - [0:0]
:INVALID - [0:0]
:INVDROP - [0:0]
:LOCALINPUT - [0:0]
:LOCALOUTPUT - [0:0]
:LOGDROPIN - [0:0]
:LOGDROPOUT - [0:0]
-A INPUT -s 213.133.99.99/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -s 213.133.99.99/32 ! -i lo -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -s 213.133.99.99/32 ! -i lo -p tcp -m tcp --sport 53 -j ACCEPT
-A INPUT -s 213.133.99.99/32 ! -i lo -p udp -m udp --sport 53 -j ACCEPT
-A INPUT -s 213.133.98.98/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -s 213.133.98.98/32 ! -i lo -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -s 213.133.98.98/32 ! -i lo -p tcp -m tcp --sport 53 -j ACCEPT
-A INPUT -s 213.133.98.98/32 ! -i lo -p udp -m udp --sport 53 -j ACCEPT
-A INPUT ! -i lo -j LOCALINPUT
-A INPUT -i lo -j ACCEPT
-A INPUT ! -i lo -p tcp -j INVALID
-A INPUT ! -i lo -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A INPUT ! -i lo -p icmp -m icmp --icmp-type 8 -j LOGDROPIN
-A INPUT ! -i lo -p icmp -j ACCEPT
-A INPUT ! -i lo -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 20 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 21 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 22 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 25 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 53 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 80 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 110 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 143 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 443 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 465 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 587 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 993 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 995 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2077 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2078 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2079 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2080 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2082 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2083 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2086 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2087 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2095 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2096 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 8443 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 51820 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 64731 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 5903 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 70 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 8090 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 8091 -j ACCEPT
-A INPUT ! -i lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 1196 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 20 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 21 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 53 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 80 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 443 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 51820 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 64731 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 5903 -j ACCEPT
-A INPUT ! -i lo -p udp -m conntrack --ctstate NEW -m udp --dport 70 -j ACCEPT
-A INPUT ! -i lo -j LOGDROPIN
-A INPUT -i wg0 -j ACCEPT
-A INPUT -i tun+ -j ACCEPT
-A FORWARD -i wg0 -j ACCEPT
-A FORWARD -o wg0 -j ACCEPT
-A FORWARD -i wg0 -o ens192 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ens192 -o wg0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i tun+ -j ACCEPT
-A FORWARD -o tun0 -j ACCEPT
-A FORWARD -i tun+ -o ens192 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ens192 -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -d 213.133.99.99/32 ! -o lo -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -d 213.133.99.99/32 ! -o lo -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -d 213.133.99.99/32 ! -o lo -p tcp -m tcp --sport 53 -j ACCEPT
-A OUTPUT -d 213.133.99.99/32 ! -o lo -p udp -m udp --sport 53 -j ACCEPT
-A OUTPUT -d 213.133.98.98/32 ! -o lo -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -d 213.133.98.98/32 ! -o lo -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -d 213.133.98.98/32 ! -o lo -p tcp -m tcp --sport 53 -j ACCEPT
-A OUTPUT -d 213.133.98.98/32 ! -o lo -p udp -m udp --sport 53 -j ACCEPT
-A OUTPUT ! -o lo -j LOCALOUTPUT
-A OUTPUT ! -o lo -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m tcp --sport 53 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m udp --sport 53 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT ! -o lo -p tcp -j INVALID
-A OUTPUT ! -o lo -p icmp -j ACCEPT
-A OUTPUT ! -o lo -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 20 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 21 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 22 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 25 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 37 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 43 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 80 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 110 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 113 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 443 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 587 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 873 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 993 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 995 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2086 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2087 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2089 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 2703 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 51820 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 64731 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 5903 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 70 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 8090 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 8091 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m conntrack --ctstate NEW -m tcp --dport 1196 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 20 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 21 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 113 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 123 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 873 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 6277 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 24441 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 51820 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 64731 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 5903 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m conntrack --ctstate NEW -m udp --dport 70 -j ACCEPT
-A OUTPUT ! -o lo -j LOGDROPOUT
-A ALLOWIN -s 34.254.37.129/32 ! -i lo -p tcp -m tcp --dport 8443 -j ACCEPT
-A ALLOWIN -s 34.254.37.129/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 34.254.37.129/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 52.213.169.7/32 ! -i lo -p tcp -m tcp --dport 8443 -j ACCEPT
-A ALLOWIN -s 52.213.169.7/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 52.213.169.7/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 52.51.23.204/32 ! -i lo -p tcp -m tcp --dport 8443 -j ACCEPT
-A ALLOWIN -s 52.51.23.204/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 52.51.23.204/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.121.86/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.121.85/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.121.83/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.121.82/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.123.3/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 1022 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 1021 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 1020 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 40 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 16 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 14 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 10 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 8 -j ACCEPT
-A ALLOWIN -s 208.74.123.2/32 ! -i lo -p tcp -m tcp --dport 4 -j ACCEPT
-A ALLOWIN -s 199.66.201.132/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 199.66.201.132/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 199.66.201.132/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 91.199.212.132/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 91.199.212.132/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 91.199.212.132/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 91.199.212.52/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 91.199.212.52/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 91.199.212.52/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 178.255.81.13/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 178.255.81.13/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 178.255.81.13/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 178.255.81.12/32 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 178.255.81.12/32 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 178.255.81.12/32 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 162.19.81.159/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 135.125.189.195/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 194.59.170.215/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 199.66.201.132/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 91.199.212.132/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 178.255.81.13/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 178.255.81.12/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 46.4.23.46/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 51.91.215.129/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 162.55.214.253/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 5.9.42.47/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 159.69.47.78/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 5.144.132.18/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 5.144.132.16/32 ! -i lo -j ACCEPT
-A ALLOWIN -s 5.238.66.50/32 ! -i lo -j ACCEPT
-A ALLOWOUT -d 162.19.81.159/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 135.125.189.195/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 194.59.170.215/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 199.66.201.132/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 91.199.212.132/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 178.255.81.13/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 178.255.81.12/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 46.4.23.46/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 51.91.215.129/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 162.55.214.253/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 5.9.42.47/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 159.69.47.78/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 5.144.132.18/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 5.144.132.16/32 ! -o lo -j ACCEPT
-A ALLOWOUT -d 5.238.66.50/32 ! -o lo -j ACCEPT
-A DENYIN -s 61.177.173.42/32 ! -i lo -j DROP
-A DENYIN -s 184.168.126.75/32 ! -i lo -j DROP
-A DENYIN -s 187.234.78.142/32 ! -i lo -j DROP
-A DENYIN -s 51.79.65.33/32 ! -i lo -j DROP
-A DENYIN -s 68.183.132.72/32 ! -i lo -j DROP
-A DENYIN -s 178.128.220.159/32 ! -i lo -j DROP
-A DENYIN -s 157.230.113.181/32 ! -i lo -j DROP
-A DENYIN -s 43.159.39.129/32 ! -i lo -j DROP
-A DENYIN -s 159.223.107.133/32 ! -i lo -j DROP
-A DENYIN -s 20.228.209.161/32 ! -i lo -j DROP
-A DENYIN -s 165.232.132.79/32 ! -i lo -j DROP
-A DENYIN -s 107.204.170.133/32 ! -i lo -j DROP
-A DENYIN -s 5.34.207.157/32 ! -i lo -j DROP
-A DENYIN -s 51.124.239.107/32 ! -i lo -j DROP
-A DENYIN -s 88.147.254.66/32 ! -i lo -j DROP
-A DENYIN -s 190.156.238.155/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.35/32 ! -i lo -j DROP
-A DENYIN -s 110.138.90.57/32 ! -i lo -j DROP
-A DENYIN -s 50.192.223.205/32 ! -i lo -j DROP
-A DENYIN -s 103.96.75.55/32 ! -i lo -j DROP
-A DENYIN -s 165.227.198.19/32 ! -i lo -j DROP
-A DENYIN -s 62.84.124.148/32 ! -i lo -j DROP
-A DENYIN -s 138.197.142.81/32 ! -i lo -j DROP
-A DENYIN -s 106.240.49.115/32 ! -i lo -j DROP
-A DENYIN -s 181.176.145.114/32 ! -i lo -j DROP
-A DENYIN -s 119.127.10.111/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.43/32 ! -i lo -j DROP
-A DENYIN -s 54.38.186.60/32 ! -i lo -j DROP
-A DENYIN -s 167.172.90.213/32 ! -i lo -j DROP
-A DENYIN -s 103.79.169.34/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.87/32 ! -i lo -j DROP
-A DENYIN -s 115.94.79.59/32 ! -i lo -j DROP
-A DENYIN -s 51.12.93.163/32 ! -i lo -j DROP
-A DENYIN -s 123.30.212.86/32 ! -i lo -j DROP
-A DENYIN -s 51.38.49.17/32 ! -i lo -j DROP
-A DENYIN -s 186.154.4.20/32 ! -i lo -j DROP
-A DENYIN -s 64.227.134.154/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.56/32 ! -i lo -j DROP
-A DENYIN -s 134.209.109.149/32 ! -i lo -j DROP
-A DENYIN -s 128.199.163.55/32 ! -i lo -j DROP
-A DENYIN -s 212.24.51.234/32 ! -i lo -j DROP
-A DENYIN -s 159.65.129.227/32 ! -i lo -j DROP
-A DENYIN -s 170.210.203.212/32 ! -i lo -j DROP
-A DENYIN -s 103.147.4.25/32 ! -i lo -j DROP
-A DENYIN -s 71.67.66.226/32 ! -i lo -j DROP
-A DENYIN -s 64.227.167.192/32 ! -i lo -j DROP
-A DENYIN -s 201.163.162.179/32 ! -i lo -j DROP
-A DENYIN -s 135.125.107.159/32 ! -i lo -j DROP
-A DENYIN -s 85.247.0.210/32 ! -i lo -j DROP
-A DENYIN -s 218.248.16.73/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.50/32 ! -i lo -j DROP
-A DENYIN -s 43.154.123.203/32 ! -i lo -j DROP
-A DENYIN -s 188.170.13.225/32 ! -i lo -j DROP
-A DENYIN -s 167.71.253.237/32 ! -i lo -j DROP
-A DENYIN -s 187.75.209.161/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.5/32 ! -i lo -j DROP
-A DENYIN -s 103.98.119.63/32 ! -i lo -j DROP
-A DENYIN -s 94.70.249.157/32 ! -i lo -j DROP
-A DENYIN -s 89.40.72.31/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.55/32 ! -i lo -j DROP
-A DENYIN -s 107.172.219.107/32 ! -i lo -j DROP
-A DENYIN -s 128.199.82.76/32 ! -i lo -j DROP
-A DENYIN -s 188.173.136.132/32 ! -i lo -j DROP
-A DENYIN -s 103.42.57.139/32 ! -i lo -j DROP
-A DENYIN -s 159.223.132.184/32 ! -i lo -j DROP
-A DENYIN -s 104.128.89.207/32 ! -i lo -j DROP
-A DENYIN -s 125.99.46.49/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.41/32 ! -i lo -j DROP
-A DENYIN -s 61.216.131.31/32 ! -i lo -j DROP
-A DENYIN -s 46.101.225.227/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.53/32 ! -i lo -j DROP
-A DENYIN -s 209.97.183.120/32 ! -i lo -j DROP
-A DENYIN -s 129.146.242.59/32 ! -i lo -j DROP
-A DENYIN -s 206.189.49.176/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.51/32 ! -i lo -j DROP
-A DENYIN -s 77.74.224.161/32 ! -i lo -j DROP
-A DENYIN -s 103.146.30.113/32 ! -i lo -j DROP
-A DENYIN -s 202.165.24.237/32 ! -i lo -j DROP
-A DENYIN -s 128.199.138.145/32 ! -i lo -j DROP
-A DENYIN -s 139.59.169.162/32 ! -i lo -j DROP
-A DENYIN -s 50.99.197.42/32 ! -i lo -j DROP
-A DENYIN -s 125.129.82.220/32 ! -i lo -j DROP
-A DENYIN -s 103.126.162.102/32 ! -i lo -j DROP
-A DENYIN -s 209.141.34.233/32 ! -i lo -j DROP
-A DENYIN -s 77.170.129.154/32 ! -i lo -j DROP
-A DENYIN -s 190.64.135.122/32 ! -i lo -j DROP
-A DENYIN -s 118.70.180.189/32 ! -i lo -j DROP
-A DENYIN -s 118.70.180.188/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.48/32 ! -i lo -j DROP
-A DENYIN -s 210.245.92.136/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.61/32 ! -i lo -j DROP
-A DENYIN -s 104.236.17.54/32 ! -i lo -j DROP
-A DENYIN -s 162.215.1.198/32 ! -i lo -j DROP
-A DENYIN -s 192.227.174.167/32 ! -i lo -j DROP
-A DENYIN -s 152.228.164.249/32 ! -i lo -j DROP
-A DENYIN -s 190.202.124.93/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.54/32 ! -i lo -j DROP
-A DENYIN -s 52.184.91.79/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.40/32 ! -i lo -j DROP
-A DENYIN -s 190.103.202.7/32 ! -i lo -j DROP
-A DENYIN -s 109.80.164.62/32 ! -i lo -j DROP
-A DENYIN -s 43.155.86.244/32 ! -i lo -j DROP
-A DENYIN -s 178.62.34.139/32 ! -i lo -j DROP
-A DENYIN -s 103.172.151.239/32 ! -i lo -j DROP
-A DENYIN -s 156.232.9.101/32 ! -i lo -j DROP
-A DENYIN -s 103.172.151.237/32 ! -i lo -j DROP
-A DENYIN -s 165.232.35.74/32 ! -i lo -j DROP
-A DENYIN -s 124.194.74.203/32 ! -i lo -j DROP
-A DENYIN -s 201.32.178.190/32 ! -i lo -j DROP
-A DENYIN -s 85.18.236.229/32 ! -i lo -j DROP
-A DENYIN -s 4.7.94.244/32 ! -i lo -j DROP
-A DENYIN -s 179.43.156.130/32 ! -i lo -j DROP
-A DENYIN -s 174.87.234.153/32 ! -i lo -j DROP
-A DENYIN -s 210.217.159.60/32 ! -i lo -j DROP
-A DENYIN -s 61.194.35.119/32 ! -i lo -j DROP
-A DENYIN -s 114.206.23.151/32 ! -i lo -j DROP
-A DENYIN -s 40.87.17.163/32 ! -i lo -j DROP
-A DENYIN -s 134.122.8.241/32 ! -i lo -j DROP
-A DENYIN -s 122.165.132.5/32 ! -i lo -j DROP
-A DENYIN -s 35.210.132.198/32 ! -i lo -j DROP
-A DENYIN -s 65.182.3.163/32 ! -i lo -j DROP
-A DENYIN -s 88.215.1.25/32 ! -i lo -j DROP
-A DENYIN -s 190.124.32.18/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.76/32 ! -i lo -j DROP
-A DENYIN -s 81.45.44.185/32 ! -i lo -j DROP
-A DENYIN -s 5.58.8.4/32 ! -i lo -j DROP
-A DENYIN -s 128.199.89.26/32 ! -i lo -j DROP
-A DENYIN -s 178.62.233.181/32 ! -i lo -j DROP
-A DENYIN -s 2.228.139.162/32 ! -i lo -j DROP
-A DENYIN -s 20.163.60.255/32 ! -i lo -j DROP
-A DENYIN -s 92.255.85.113/32 ! -i lo -j DROP
-A DENYIN -s 167.172.159.73/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.36/32 ! -i lo -j DROP
-A DENYIN -s 54.37.106.214/32 ! -i lo -j DROP
-A DENYIN -s 164.92.151.187/32 ! -i lo -j DROP
-A DENYIN -s 172.96.227.178/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.124/32 ! -i lo -j DROP
-A DENYIN -s 34.151.215.28/32 ! -i lo -j DROP
-A DENYIN -s 82.196.7.111/32 ! -i lo -j DROP
-A DENYIN -s 148.153.110.76/32 ! -i lo -j DROP
-A DENYIN -s 188.166.53.188/32 ! -i lo -j DROP
-A DENYIN -s 20.214.160.160/32 ! -i lo -j DROP
-A DENYIN -s 218.92.0.221/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.104/32 ! -i lo -j DROP
-A DENYIN -s 37.44.236.164/32 ! -i lo -j DROP
-A DENYIN -s 20.212.109.250/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.52/32 ! -i lo -j DROP
-A DENYIN -s 94.180.247.20/32 ! -i lo -j DROP
-A DENYIN -s 67.205.189.194/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.49/32 ! -i lo -j DROP
-A DENYIN -s 149.202.45.57/32 ! -i lo -j DROP
-A DENYIN -s 109.134.162.71/32 ! -i lo -j DROP
-A DENYIN -s 14.143.137.18/32 ! -i lo -j DROP
-A DENYIN -s 159.65.132.116/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.39/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.46/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.19/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.90/32 ! -i lo -j DROP
-A DENYIN -s 104.248.91.215/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.114/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.47/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.98/32 ! -i lo -j DROP
-A DENYIN -s 105.27.208.1/32 ! -i lo -j DROP
-A DENYIN -s 144.22.255.183/32 ! -i lo -j DROP
-A DENYIN -s 103.146.122.225/32 ! -i lo -j DROP
-A DENYIN -s 139.255.66.218/32 ! -i lo -j DROP
-A DENYIN -s 103.135.215.66/32 ! -i lo -j DROP
-A DENYIN -s 5.34.207.194/32 ! -i lo -j DROP
-A DENYIN -s 61.177.172.108/32 ! -i lo -j DROP
-A DENYIN -s 206.189.114.103/32 ! -i lo -j DROP
-A DENYIN -s 134.209.175.24/32 ! -i lo -j DROP
-A DENYIN -s 200.90.50.102/32 ! -i lo -j DROP
-A DENYIN -s 61.177.173.37/32 ! -i lo -j DROP
-A DENYIN -s 193.151.13.207/32 ! -i lo -j DROP
-A DENYIN -s 114.33.94.230/32 ! -i lo -j DROP
-A DENYIN -s 123.30.240.31/32 ! -i lo -j DROP
-A DENYIN -s 14.241.100.188/32 ! -i lo -j DROP
-A DENYIN -s 210.211.116.80/32 ! -i lo -j DROP
-A DENYIN -s 173.15.106.189/32 ! -i lo -j DROP
-A DENYIN -s 49.206.244.232/32 ! -i lo -j DROP
-A DENYIN -s 67.164.27.145/32 ! -i lo -j DROP
-A DENYIN -s 83.150.212.101/32 ! -i lo -j DROP
-A DENYIN -s 20.226.35.13/32 ! -i lo -j DROP
-A DENYIN -s 46.101.254.194/32 ! -i lo -j DROP
-A DENYIN -s 222.255.115.237/32 ! -i lo -j DROP
-A DENYIN -s 24.63.51.246/32 ! -i lo -j DROP
-A DENYIN -s 43.154.90.251/32 ! -i lo -j DROP
-A DENYIN -s 178.62.53.174/32 ! -i lo -j DROP
-A DENYIN -s 157.245.193.50/32 ! -i lo -j DROP
-A DENYIN -s 159.223.107.102/32 ! -i lo -j DROP
-A DENYIN -s 217.182.253.249/32 ! -i lo -j DROP
-A DENYIN -s 192.99.59.56/32 ! -i lo -j DROP
-A DENYIN -s 152.32.209.140/32 ! -i lo -j DROP
-A DENYIN -s 142.93.116.249/32 ! -i lo -j DROP
-A DENYIN -s 76.215.177.94/32 ! -i lo -j DROP
-A DENYIN -s 128.199.10.70/32 ! -i lo -j DROP
-A DENYIN -s 134.209.102.211/32 ! -i lo -j DROP
-A DENYIN -s 54.212.217.238/32 ! -i lo -j DROP
-A DENYIN -s 190.128.171.250/32 ! -i lo -j DROP
-A DENYIN -s 115.178.76.24/32 ! -i lo -j DROP
-A DENYOUT -d 61.177.173.42/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 184.168.126.75/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 187.234.78.142/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 51.79.65.33/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 68.183.132.72/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 178.128.220.159/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 157.230.113.181/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 43.159.39.129/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 159.223.107.133/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 20.228.209.161/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 165.232.132.79/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 107.204.170.133/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 5.34.207.157/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 51.124.239.107/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 88.147.254.66/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.156.238.155/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.35/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 110.138.90.57/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 50.192.223.205/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.96.75.55/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 165.227.198.19/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 62.84.124.148/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 138.197.142.81/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 106.240.49.115/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 181.176.145.114/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 119.127.10.111/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.43/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 54.38.186.60/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 167.172.90.213/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.79.169.34/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.87/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 115.94.79.59/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 51.12.93.163/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 123.30.212.86/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 51.38.49.17/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 186.154.4.20/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 64.227.134.154/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.56/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 134.209.109.149/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 128.199.163.55/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 212.24.51.234/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 159.65.129.227/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 170.210.203.212/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.147.4.25/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 71.67.66.226/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 64.227.167.192/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 201.163.162.179/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 135.125.107.159/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 85.247.0.210/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 218.248.16.73/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.50/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 43.154.123.203/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 188.170.13.225/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 167.71.253.237/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 187.75.209.161/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.5/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.98.119.63/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 94.70.249.157/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 89.40.72.31/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.55/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 107.172.219.107/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 128.199.82.76/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 188.173.136.132/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.42.57.139/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 159.223.132.184/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 104.128.89.207/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 125.99.46.49/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.41/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.216.131.31/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 46.101.225.227/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.53/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 209.97.183.120/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 129.146.242.59/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 206.189.49.176/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.51/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 77.74.224.161/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.146.30.113/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 202.165.24.237/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 128.199.138.145/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 139.59.169.162/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 50.99.197.42/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 125.129.82.220/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.126.162.102/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 209.141.34.233/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 77.170.129.154/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.64.135.122/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 118.70.180.189/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 118.70.180.188/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.48/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 210.245.92.136/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.61/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 104.236.17.54/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 162.215.1.198/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 192.227.174.167/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 152.228.164.249/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.202.124.93/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.54/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 52.184.91.79/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.40/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.103.202.7/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 109.80.164.62/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 43.155.86.244/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 178.62.34.139/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.172.151.239/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 156.232.9.101/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.172.151.237/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 165.232.35.74/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 124.194.74.203/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 201.32.178.190/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 85.18.236.229/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 4.7.94.244/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 179.43.156.130/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 174.87.234.153/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 210.217.159.60/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.194.35.119/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 114.206.23.151/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 40.87.17.163/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 134.122.8.241/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 122.165.132.5/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 35.210.132.198/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 65.182.3.163/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 88.215.1.25/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.124.32.18/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.76/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 81.45.44.185/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 5.58.8.4/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 128.199.89.26/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 178.62.233.181/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 2.228.139.162/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 20.163.60.255/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 92.255.85.113/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 167.172.159.73/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.36/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 54.37.106.214/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 164.92.151.187/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 172.96.227.178/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.124/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 34.151.215.28/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 82.196.7.111/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 148.153.110.76/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 188.166.53.188/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 20.214.160.160/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 218.92.0.221/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.104/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 37.44.236.164/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 20.212.109.250/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.52/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 94.180.247.20/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 67.205.189.194/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.49/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 149.202.45.57/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 109.134.162.71/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 14.143.137.18/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 159.65.132.116/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.39/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.46/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.19/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.90/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 104.248.91.215/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.114/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.47/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.98/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 105.27.208.1/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 144.22.255.183/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.146.122.225/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 139.255.66.218/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 103.135.215.66/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 5.34.207.194/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.172.108/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 206.189.114.103/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 134.209.175.24/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 200.90.50.102/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 61.177.173.37/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 193.151.13.207/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 114.33.94.230/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 123.30.240.31/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 14.241.100.188/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 210.211.116.80/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 173.15.106.189/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 49.206.244.232/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 67.164.27.145/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 83.150.212.101/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 20.226.35.13/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 46.101.254.194/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 222.255.115.237/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 24.63.51.246/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 43.154.90.251/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 178.62.53.174/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 157.245.193.50/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 159.223.107.102/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 217.182.253.249/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 192.99.59.56/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 152.32.209.140/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 142.93.116.249/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 76.215.177.94/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 128.199.10.70/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 134.209.102.211/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 54.212.217.238/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 190.128.171.250/32 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 115.178.76.24/32 ! -o lo -j LOGDROPOUT
-A INVALID -m conntrack --ctstate INVALID -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,ACK FIN -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags PSH,ACK PSH -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags ACK,URG URG -j INVDROP
-A INVALID -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m conntrack --ctstate NEW -j INVDROP
-A INVDROP -j DROP
-A LOCALINPUT ! -i lo -j ALLOWIN
-A LOCALINPUT ! -i lo -j DENYIN
-A LOCALOUTPUT ! -o lo -j ALLOWOUT
-A LOCALOUTPUT ! -o lo -j DENYOUT
-A LOGDROPIN -p tcp -m tcp --dport 23 -j DROP
-A LOGDROPIN -p udp -m udp --dport 23 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 67 -j DROP
-A LOGDROPIN -p udp -m udp --dport 67 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 68 -j DROP
-A LOGDROPIN -p udp -m udp --dport 68 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 111 -j DROP
-A LOGDROPIN -p udp -m udp --dport 111 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 113 -j DROP
-A LOGDROPIN -p udp -m udp --dport 113 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 135:139 -j DROP
-A LOGDROPIN -p udp -m udp --dport 135:139 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 445 -j DROP
-A LOGDROPIN -p udp -m udp --dport 445 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 500 -j DROP
-A LOGDROPIN -p udp -m udp --dport 500 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 513 -j DROP
-A LOGDROPIN -p udp -m udp --dport 513 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 520 -j DROP
-A LOGDROPIN -p udp -m udp --dport 520 -j DROP
-A LOGDROPIN -p tcp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP_IN Blocked* "
-A LOGDROPIN -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP_IN Blocked* "
-A LOGDROPIN -p icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP_IN Blocked* "
-A LOGDROPIN -j DROP
-A LOGDROPOUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP_OUT Blocked* " --log-uid
-A LOGDROPOUT -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP_OUT Blocked* " --log-uid
-A LOGDROPOUT -p icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP_OUT Blocked* " --log-uid
-A LOGDROPOUT -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Thu Sep 29 07:00:21 2022
netstat -4npl
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:2080 0.0.0.0:* LISTEN 3116/cpdavd - accep
tcp 0 0 0.0.0.0:993 0.0.0.0:* LISTEN 1914/dovecot
tcp 0 0 0.0.0.0:2082 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 127.0.0.1:579 0.0.0.0:* LISTEN 3113/cPhulkd - proc
tcp 0 0 0.0.0.0:2083 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 0.0.0.0:995 0.0.0.0:* LISTEN 1914/dovecot
tcp 0 0 0.0.0.0:2086 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 0.0.0.0:2087 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 0.0.0.0:2091 0.0.0.0:* LISTEN 3116/cpdavd - accep
tcp 0 0 127.0.0.1:6379 0.0.0.0:* LISTEN 1928/redis-server 1
tcp 0 0 0.0.0.0:587 0.0.0.0:* LISTEN 924/exim
tcp 0 0 0.0.0.0:1196 0.0.0.0:* LISTEN 17974/openvpn
tcp 0 0 0.0.0.0:32844 0.0.0.0:* LISTEN 1913/checkstatus
tcp 0 0 0.0.0.0:110 0.0.0.0:* LISTEN 1914/dovecot
tcp 0 0 0.0.0.0:2095 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 127.0.0.1:783 0.0.0.0:* LISTEN 2270/perl
tcp 0 0 0.0.0.0:143 0.0.0.0:* LISTEN 1914/dovecot
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 781/rpcbind
tcp 0 0 0.0.0.0:2096 0.0.0.0:* LISTEN 1944/cpsrvd
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 2755/httpd
tcp 0 0 0.0.0.0:465 0.0.0.0:* LISTEN 924/exim
tcp 0 0 0.0.0.0:53 0.0.0.0:* LISTEN 1933/pdns_server
tcp 0 0 0.0.0.0:21 0.0.0.0:* LISTEN 1925/pure-ftpd (SER
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1916/sshd
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 1921/cupsd
tcp 0 0 127.0.0.1:953 0.0.0.0:* LISTEN 1933/pdns_server
tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 924/exim
tcp 0 0 0.0.0.0:8090 0.0.0.0:* LISTEN 1999/php
tcp 0 0 0.0.0.0:8091 0.0.0.0:* LISTEN 2212/php
tcp 0 0 0.0.0.0:443 0.0.0.0:* LISTEN 2755/httpd
tcp 0 0 0.0.0.0:2077 0.0.0.0:* LISTEN 3116/cpdavd - accep
tcp 0 0 0.0.0.0:2078 0.0.0.0:* LISTEN 3116/cpdavd - accep
tcp 0 0 0.0.0.0:2079 0.0.0.0:* LISTEN 3116/cpdavd - accep
udp 0 0 0.0.0.0:53 0.0.0.0:* 1933/pdns_server
udp 0 0 0.0.0.0:67 0.0.0.0:* 2766/dnsmasq
udp 0 0 0.0.0.0:68 0.0.0.0:* 1682/dhclient
udp 0 0 0.0.0.0:111 0.0.0.0:* 781/rpcbind
udp 0 0 0.0.0.0:58483 0.0.0.0:* 773/avahi-daemon: r
udp 0 0 0.0.0.0:64731 0.0.0.0:* -
udp 0 0 0.0.0.0:5353 0.0.0.0:* 773/avahi-daemon: r
udp 0 0 127.0.0.1:323 0.0.0.0:* 790/chronyd
udp 0 0 0.0.0.0:946 0.0.0.0:* 781/rpcbind
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment