# Generated by iptables-save v1.4.12 on Sun Nov 3 09:32:35 2013
*nat
:PREROUTING ACCEPT [21648:2439409]
:INPUT ACCEPT [24362:2511031]
:OUTPUT ACCEPT [14779:907316]
:POSTROUTING ACCEPT [14804:908644]
-A PREROUTING -s 10.0.0.0/24 -i ppp+ -p tcp -m multiport --dports 80 -j REDIRECT --to-ports 3128
-A POSTROUTING -s 10.0.0.0/24 -o eth0 -j SNAT --to-source 82.x.x.x
COMMIT
# Completed on Sun Nov 3 09:32:35 2013
# Generated by iptables-save v1.4.12 on Sun Nov 3 09:32:35 2013
*mangle
:PREROUTING ACCEPT [2078771:1436763921]
:INPUT ACCEPT [2068010:1433728471]
:FORWARD ACCEPT [9151:2586623]
:OUTPUT ACCEPT [2429225:2034753280]
:POSTROUTING ACCEPT [2438360:2037339263]
COMMIT
# Completed on Sun Nov 3 09:32:35 2013
# Generated by iptables-save v1.4.12 on Sun Nov 3 09:32:35 2013
*filter
:INPUT DROP [33:4069]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:bad_packets - [0:0]
:bad_tcp_packets - [0:0]
:icmp_packets - [0:0]
:tcp_packets_ext - [0:0]
:tcp_packets_int - [0:0]
:udp_packets_ext - [0:0]
:udp_packets_int - [0:0]
-A INPUT -j bad_packets
-A INPUT -d 224.0.0.0/8 -j DROP
-A INPUT -s 10.175.8.0/21 -i eth2 -j ACCEPT
-A INPUT -s 127.0.0.1/32 -i lo -j ACCEPT
-A INPUT -s 10.0.0.0/24 -d 10.0.0.1/32 -j ACCEPT
-A INPUT -d 82.x.x.x/32 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -p tcp -j tcp_packets_ext
-A INPUT -i eth0 -p udp -j udp_packets_ext
-A INPUT -i eth0 -p icmp -j icmp_packets
-A INPUT -m pkttype --pkt-type broadcast -j DROP
-A INPUT -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT INPUT packet died: "
-A FORWARD -j bad_packets
-A FORWARD -p tcp -j tcp_packets_int
-A FORWARD -p udp -j udp_packets_int
-A FORWARD -p icmp -j icmp_packets
-A FORWARD -i eth0 -p tcp -m multiport --dports 25,80,110,3389,4899 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT FORWARD packet died: "
-A OUTPUT -p icmp -m state --state INVALID -j DROP
-A OUTPUT -s 127.0.0.1/32 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -s 10.175.8.3/32 -j ACCEPT
-A OUTPUT -o eth1 -j ACCEPT
-A OUTPUT -o eth0 -j ACCEPT
-A OUTPUT -s 10.0.0.0/24 -j ACCEPT
-A OUTPUT -o ppp+ -j ACCEPT
-A OUTPUT -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT OUTPUT packet died: "
-A bad_packets -s 10.0.0.0/24 -i eth0 -j LOG --log-prefix "Illegal source: "
-A bad_packets -s 10.0.0.0/24 -i eth0 -j DROP
-A bad_packets -m state --state INVALID -j LOG --log-prefix "Invalid packet: "
-A bad_packets -m state --state INVALID -j DROP
-A bad_packets -p tcp -j bad_tcp_packets
-A bad_packets -j RETURN
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j LOG --log-prefix "New not syn:"
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j LOG --log-prefix "Stealth scan: "
-A bad_tcp_packets -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
-A bad_tcp_packets -p tcp -j RETURN
-A icmp_packets -p icmp -m icmp --icmp-type 3 -j ACCEPT
-A icmp_packets -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A icmp_packets -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A icmp_packets -p icmp -j RETURN
-A tcp_packets_ext -p tcp -m tcp --dport 21 -j ACCEPT
-A tcp_packets_ext -p tcp -m tcp --dport 22 -j ACCEPT
-A tcp_packets_ext -p tcp -m tcp --dport 80 -j ACCEPT
-A tcp_packets_ext -p tcp -m tcp --dport 1723 -j ACCEPT
-A tcp_packets_ext -p gre -j ACCEPT
-A tcp_packets_ext -p tcp -j DROP
-A tcp_packets_int -s 10.0.0.7/32 -p tcp -m multiport --dports 1:65535 -j ACCEPT
-A udp_packets_ext -p udp -m udp --dport 53 -j ACCEPT
-A udp_packets_ext -p udp -m udp --dport 33434 -j ACCEPT
-A udp_packets_ext -p udp -m udp --dport 123 -j ACCEPT
-A udp_packets_ext -p udp -j DROP
-A udp_packets_int -s 10.0.0.7/32 -p udp -m multiport --dports 1:65535 -j ACCEPT
COMMIT
# Completed on Sun Nov 3 09:32:35 2013