1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
|
iptables -L -n
Chain INPUT (policy DROP)
target prot opt source destination
bad_packages all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT icmp -- 63.208.196.0/24 0.0.0.0/0 icmp type 8 state NEW,RELATED,ESTABLISHED
ACCEPT icmp -- 63.208.196.0/24 0.0.0.0/0 icmp type 0 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9102 state NEW,RELATED,ESTABLISHED
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
REJECT all -- 192.168.178.1 224.0.0.1 reject-with icmp-port-unreachable
LOG all -- 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 0 level 4 prefix `INPUT-Chain'
Chain FORWARD (policy DROP)
target prot opt source destination
bad_packages all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT udp -- 192.168.123.47 0.0.0.0/0 udp dpt:123 state NEW,RELATED,ESTABLISHED
ACCEPT udp -- 192.168.123.47 145.253.2.11 udp dpt:53 state NEW
ACCEPT tcp -- 192.168.123.47 145.253.2.11 tcp dpt:53 state NEW
ACCEPT udp -- 192.168.123.47 145.253.2.75 udp dpt:53 state NEW
ACCEPT tcp -- 192.168.123.47 145.253.2.75 tcp dpt:53 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:22 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:21 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:443 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:8080 state NEW
ACCEPT tcp -- 192.168.123.0/24 62.149.9.12 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 62.197.40.130 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 78.46.221.126 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 80.68.87.200 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 81.91.83.16 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 81.91.243.120 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 81.223.20.162 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 83.164.192.205 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 88.156.78.16 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 88.198.224.205 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 89.206.169.171 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 91.121.180.229 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 92.240.244.16 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 129.143.116.10 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 130.230.54.100 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 137.226.34.228 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 193.1.193.64 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 193.219.32.205 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 194.97.4.250 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 194.146.132.15 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.0/24 217.19.16.188 tcp dpt:873 state NEW
ACCEPT tcp -- 192.168.123.47 64.12.0.0/16 tcp dpt:5190 state NEW
ACCEPT tcp -- 192.168.123.47 205.188.0.0/16 tcp dpt:5190 state NEW
ACCEPT tcp -- 192.168.123.47 64.4.0.0/16 tcp dpt:1863 state NEW
ACCEPT tcp -- 192.168.123.47 65.54.0.0/16 tcp dpt:1863 state NEW
ACCEPT tcp -- 192.168.123.47 205.188.0.0/16 tcp dpt:1863 state NEW
ACCEPT tcp -- 192.168.123.47 207.46.0.0/16 tcp dpt:1863 state NEW
ACCEPT tcp -- 192.168.123.47 69.28.151.0/24 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 65.113.241.34 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 69.28.140.0/24 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 79.141.0.0/16 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 69.28.151.178 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 207.173.177.11 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 207.173.177.12 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 87.248.196.194 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 72.165.61.0/24 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 69.28.153.82 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 68.142.72.250 tcp spts:1000:1460 state NEW
ACCEPT tcp -- 192.168.123.47 83.141.0.0/16 tcp spts:1000:1500 state NEW
ACCEPT udp -- 192.168.123.47 83.141.0.0/16 udp spts:1000:1500 state NEW
ACCEPT tcp -- 192.168.123.47 79.110.0.0/16 tcp spts:1000:1500 state NEW
ACCEPT udp -- 192.168.123.47 79.110.0.0/16 udp spts:1000:1500 state NEW
ACCEPT tcp -- 192.168.123.47 83.141.0.0/16 tcp spts:1000:1500 state NEW
ACCEPT udp -- 192.168.123.47 83.141.0.0/16 udp spts:1000:1500 state NEW
ACCEPT tcp -- 192.168.123.47 213.165.64.22 tcp dpt:110 state NEW
ACCEPT tcp -- 192.168.123.47 87.106.133.50 tcp dpt:8993 state NEW
ACCEPT tcp -- 192.168.123.47 87.106.222.137 tcp dpt:8993 state NEW
ACCEPT tcp -- 192.168.123.47 212.227.67.1 tcp dpt:993 state NEW
ACCEPT tcp -- 192.168.123.47 213.165.64.20 tcp dpt:25 state NEW
ACCEPT tcp -- 192.168.123.47 213.165.64.21 tcp dpt:25 state NEW
ACCEPT tcp -- 192.168.123.47 87.106.133.50 tcp dpt:25 state NEW
ACCEPT tcp -- 192.168.123.47 87.106.222.137 tcp dpt:25 state NEW
ACCEPT tcp -- 192.168.123.47 212.227.67.1 tcp dpt:25 state NEW
ACCEPT tcp -- 192.168.123.47 192.168.178.1 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.178.1 0.0.0.0/0 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 72.21.0.0/16 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 203.58.241.0/24 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 147.243.3.83 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 217.26.52.29 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 87.230.62.237 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 203.58.241.10 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 74.125.43.0/24 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 74.125.54.205 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 209.85.129.0/24 tcp dpt:80 state NEW
ACCEPT tcp -- 192.168.123.47 63.245.209.0/24 tcp dpt:443 state NEW
ACCEPT tcp -- 192.168.123.47 63.245.213.0/24 tcp dpt:443 state NEW
ACCEPT tcp -- 192.168.123.47 0.0.0.0/0 tcp dpt:43 state NEW
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
REJECT all -- 192.168.178.1 224.0.0.1 reject-with icmp-port-unreachable
LOG all -- 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 0 level 4 prefix `FORWARD-Chain'
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT icmp -- 0.0.0.0/0 63.208.196.0/24 icmp type 0 state NEW,RELATED,ESTABLISHED
ACCEPT icmp -- 0.0.0.0/0 63.208.196.0/24 icmp type 8 state NEW,RELATED,ESTABLISHED
ACCEPT udp -- 0.0.0.0/0 145.253.2.11 udp dpt:53 state NEW,RELATED,ESTABLISHED
ACCEPT udp -- 0.0.0.0/0 145.253.2.75 udp dpt:53 state NEW,RELATED,ESTABLISHED
ACCEPT udp -- 0.0.0.0/0 192.168.123.47 udp dpt:53 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 62.149.9.12 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 62.197.40.130 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 78.46.221.126 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 80.68.87.200 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 81.91.83.16 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 81.91.243.120 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 81.223.20.162 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 83.164.192.205 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 88.156.78.16 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 88.198.224.205 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 89.206.169.171 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 91.121.180.229 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 92.240.244.16 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 129.143.116.10 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 130.230.54.100 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 137.226.34.228 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 193.1.193.64 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 193.219.32.205 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 194.97.4.250 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 194.146.132.15 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 217.19.16.188 tcp dpt:873 state NEW,RELATED,ESTABLISHED
ACCEPT udp -- 0.0.0.0/0 10.0.23.46 udp dpt:514 state NEW
ACCEPT tcp -- 0.0.0.0/0 192.168.123.77 tcp dpt:25 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:9103 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 204.13.248.0/24 tcp dpt:80 state NEW,RELATED,ESTABLISHED
ACCEPT tcp -- 0.0.0.0/0 63.208.196.0/24 tcp dpt:80 state NEW,RELATED,ESTABLISHED
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT udp -- 192.168.123.47 0.0.0.0/0 udp dpt:53
LOG all -- 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 0 level 4 prefix `OUTPUT-Chain'
Chain bad_packages (2 references)
target prot opt source destination
DROP all -- 0.0.0.0/0 0.0.0.0/0 state INVALID
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:!0x17/0x02 state NEW
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 1/sec burst 5
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00 limit: avg 1/hour burst 5
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x3F limit: avg 1/hour burst 5
RETURN all -- 0.0.0.0/0 0.0.0.0/0
|