iptables.save
# Generated by iptables-save v1.4.4 on Tue Aug 2 21:08:19 2011
*mangle
:PREROUTING ACCEPT [12086:10787642]
:INPUT ACCEPT [12002:10776560]
:FORWARD ACCEPT [72:10462]
:OUTPUT ACCEPT [12962:11096913]
:POSTROUTING ACCEPT [13030:11108358]
COMMIT
# Completed on Tue Aug 2 21:08:19 2011
# Generated by iptables-save v1.4.4 on Tue Aug 2 21:08:19 2011
*nat
:PREROUTING ACCEPT [53:3559]
:POSTROUTING ACCEPT [6:1150]
:OUTPUT ACCEPT [156:11050]
[142:9440] -A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Tue Aug 2 21:08:19 2011
# Generated by iptables-save v1.4.4 on Tue Aug 2 21:08:19 2011
*filter
:INPUT ACCEPT [1598:139806]
:FORWARD ACCEPT [11:560]
:OUTPUT ACCEPT [1329:452002]
[4077:276351] -A INPUT -i eth1 -j ACCEPT
[0:0] -A INPUT -d 192.168.0.1/32 -j ACCEPT
[4:200] -A INPUT -i lo -j ACCEPT
[7912:10499111] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
[2:116] -A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
[2:522] -A INPUT -p udp -m udp --dport 138 -j DROP
[0:0] -A INPUT -p udp -m udp --dport 113 -j REJECT --reject-with icmp-port-unreachable
[0:0] -A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
[0:0] -A INPUT -p udp -j RETURN
[0:0] -A INPUT -p icmp -f -j DROP
[0:0] -A INPUT -m state --state INVALID -j DROP
[0:0] -A INPUT -i eth0 -p icmp -m icmp --icmp-type 4 -j ACCEPT
[0:0] -A INPUT -i eth0 -p icmp -m icmp --icmp-type 0 -j ACCEPT
[0:0] -A INPUT -i eth0 -p icmp -m icmp --icmp-type 12 -j ACCEPT
[0:0] -A INPUT -i eth0 -p icmp -m icmp --icmp-type 4 -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 113 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --dport 113 -j DROP
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 21 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 22 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 25 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 80 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 443 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 587 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 993 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 873 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 67 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 68 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 3128 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 110 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 10000 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 20 --dport 1024:65535 -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 23 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 79 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 43 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 70 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 210 --dport 1024:65535 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 21 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 10000 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 137 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 138 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 139 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 445 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 25 -j ACCEPT
[0:0] -A INPUT -d 192.168.1.4/32 -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 110 -j ACCEPT
[33:2394] -A FORWARD -i eth1 -o eth0 -m state --state NEW,ESTABLISHED -j ACCEPT
[39:8068] -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A FORWARD -m state --state INVALID -j DROP
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 21 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 587 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 993 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 873 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 67 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 68 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 3128 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 110 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 10000 -j ACCEPT
[7661:10655334] -A OUTPUT -o eth1 -j ACCEPT
[0:0] -A OUTPUT -d 192.168.0.1/32 -j ACCEPT
[4:200] -A OUTPUT -o lo -j ACCEPT
[10:560] -A OUTPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
[93:6754] -A OUTPUT -p udp -j ACCEPT
[0:0] -A OUTPUT -p icmp -f -j DROP
[0:0] -A OUTPUT -o eth0 -p icmp -m icmp --icmp-type 4 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p icmp -m icmp --icmp-type 12 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 113 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 21 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 22 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 25 -j ACCEPT
[5021:381240] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 80 -j ACCEPT
[12:2053] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 443 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 587 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 993 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 873 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 67 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 68 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 3128 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 110 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 10000 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 20 ! --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 23 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 79 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 43 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 70 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 210 -j ACCEPT
[0:0] -A OUTPUT -o eth0 -p udp -m udp --sport 32769:65535 --dport 33434:33523 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 21 --dport 1024:65535 -j ACCEPT
[100:37608] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 22 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 80 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 10000 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 137 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 138 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 139 --dport 1024:65535 -j ACCEPT
[2:112] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 445 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 25 --dport 1024:65535 -j ACCEPT
[0:0] -A OUTPUT -s 192.168.1.4/32 -o eth0 -p tcp -m tcp --sport 110 --dport 1024:65535 -j ACCEPT
COMMIT
# Completed on Tue Aug 2 21:08:19 2011