Skip to content

Instantly share code, notes, and snippets.

@sbose78
Created February 11, 2018 12:59
Show Gist options
  • Save sbose78/0d2950082b6f691f68a21f6e0d08cb0b to your computer and use it in GitHub Desktop.
Save sbose78/0d2950082b6f691f68a21f6e0d08cb0b to your computer and use it in GitHub Desktop.
iptables
# Generated by iptables-save v1.4.21 on Sun Feb 11 07:53:09 2018
*filter
:INPUT ACCEPT [1244:91569]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [63565:78684068]
-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -p icmp -j ACCEPT
-A INPUT -i eth0 -j DROP
-A FORWARD -s 192.168.56.0/24 -d 143.215.130.30/32 -j ACCEPT
-A FORWARD -s 192.168.56.0/24 -d 54.202.185.61/32 -j ACCEPT
-A FORWARD -s 192.168.56.0/24 -d 130.207.0.0/16 -j DROP
-A FORWARD -s 192.168.56.0/24 -d 143.215.0.0/16 -j DROP
-A FORWARD -s 192.168.56.0/24 -d 128.61.0.0/16 -j DROP
-A FORWARD -p udp -m udp --dport 135:139 -j DROP
-A FORWARD -p tcp -m tcp --dport 135:139 -j DROP
-A FORWARD -p udp -m udp --dport 445 -j DROP
-A FORWARD -p tcp -m tcp --dport 445 -j DROP
-A FORWARD -s 192.168.56.0/24 -i vboxnet0 -o eth0 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
COMMIT
# Completed on Sun Feb 11 07:53:09 2018
# Generated by iptables-save v1.4.21 on Sun Feb 11 07:53:09 2018
*mangle
:PREROUTING ACCEPT [60503:104678731]
:INPUT ACCEPT [60386:104670816]
:FORWARD ACCEPT [115:6763]
:OUTPUT ACCEPT [63565:78684068]
:POSTROUTING ACCEPT [63754:78700026]
-A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
COMMIT
# Completed on Sun Feb 11 07:53:09 2018
# Generated by iptables-save v1.4.21 on Sun Feb 11 07:53:09 2018
*nat
:PREROUTING ACCEPT [130:10047]
:INPUT ACCEPT [104:7797]
:OUTPUT ACCEPT [5010:324296]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -p tcp -m tcp --dport 25 -j DNAT --to-destination 143.215.130.30:25
-A POSTROUTING -j MASQUERADE
COMMIT
# Completed on Sun Feb 11 07:53:09 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment