Posted by ixpict on Thu 7 May 20:14
report abuse | download | new post
- # Generated by iptables-save v1.4.0 on Thu Jan 15 12:28:13 2009
- *filter
- :INPUT ACCEPT [102584:73931546]
- :FORWARD ACCEPT [17077894:9975279461]
- :OUTPUT ACCEPT [432526:247117410]
- -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -s 192.168.1.3 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -s 192.168.1.4 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -s 192.168.1.7 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -s 192.168.1.8 -j DROP
- -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -m state --state NEW -j DROP
- -A INPUT -i eth1 -p tcp -m tcp --dport 3128 -j QUEUE
- -A INPUT -i lo -j ACCEPT
- -A INPUT -i eth1 -j ACCEPT
- -A INPUT -i ! eth1 -p udp -m udp --dport 67 -j REJECT --reject-with icmp-port-unreachable
- -A INPUT -i ! eth1 -p udp -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable
- #-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 9000 -j ACCEPT
- -A INPUT -i eth0 -p tcp -m tcp --dport 5001 -j ACCEPT
- #-A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
- #-A OUTPUT -d 192.168.1.3 -j DROP
- #-A OUTPUT -d 192.168.1.8 -j DROP
- #-A OUTPUT -d 192.168.1.7 -j DROP
- #-A OUTPUT -d 192.168.1.4 -j DROP
- -A INPUT -i ! eth1 -p tcp -m tcp --dport 0:1023 -j DROP
- -A INPUT -i ! eth1 -p udp -m udp --dport 0:1023 -j DROP
- -A FORWARD -s 10.77.0.0/16 -j ACCEPT
- -A FORWARD -d 10.77.0.0/16 -j ACCEPT
- -A FORWARD -j QUEUE
- -A FORWARD -d 192.168.1.0/24 -i eth1 -j ACCEPT
- -A FORWARD -s 192.168.1.0/24 -i eth1 -j ACCEPT
- -A FORWARD -d 192.168.1.0/24 -i eth0 -j ACCEPT
- -A OUTPUT -o eth1 -p tcp -m tcp --sport 3128 -j QUEUE
- COMMIT
- # Completed on Thu Jan 15 12:28:13 2009
- # Generated by iptables-save v1.4.0 on Thu Jan 15 12:28:13 2009
- *mangle
- :PREROUTING ACCEPT [23599235:11582305562]
- :INPUT ACCEPT [6208460:1568216903]
- :FORWARD ACCEPT [17388381:10013850058]
- :OUTPUT ACCEPT [6435727:2617960240]
- :POSTROUTING ACCEPT [23822209:12631867337]
- COMMIT
- # Completed on Thu Jan 15 12:28:13 2009
- # Generated by iptables-save v1.4.0 on Thu Jan 15 12:28:13 2009
- *nat
- :PREROUTING ACCEPT [728181:46586206]
- :POSTROUTING ACCEPT [57404:4247740]
- :OUTPUT ACCEPT [256334:17111711]
- -A PREROUTING -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
- -A POSTROUTING -o eth0 -j MASQUERADE
- COMMIT
- # Completed on Thu Jan 15 12:28:13 2009
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.