*filter
:INPUT DROP [207:118466]
:FORWARD DROP [4:200]
:OUTPUT ACCEPT [731:375626]
:allowed - [0:0]
:allowed_udp - [0:0]
:bad_tcp_packets - [0:0]
:fail2ban-proftpd - [0:0]
:fail2ban-ssh - [0:0]
:icmp_packets - [0:0]
:tcp_packets - [0:0]
:udpincoming_packets - [0:0]
-A INPUT -p tcp -j bad_tcp_packets
-A INPUT -i ppp0 -p icmp -j icmp_packets
-A INPUT -i ppp0 -p tcp -j tcp_packets
-A INPUT -i ppp0 -p udp -j udpincoming_packets
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/24 -j ACCEPT
-A INPUT -i ppp0 -j ACCEPT
-A INPUT -i ppp0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i tap0 -p tcp -j ACCEPT
-A INPUT -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT INPUT packet died:" --log-level 7
-A INPUT -p tcp -m tcp --dport 22 -j TARPIT
-A FORWARD -p tcp -j bad_tcp_packets
-A FORWARD -i bridge1 -o bridge1 -p udp -m udp --dport 5060 -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A FORWARD -i ppp0 -j ACCEPT
-A FORWARD -i bridge1 -o bridge1 -p udp -j LOG --log-prefix "IP_Phone:"
-A FORWARD -p tcp -j tcp_packets
-A FORWARD -p icmp -j icmp_packets
-A FORWARD -p udp -j allowed_udp
-A FORWARD -p tcp -m multiport --dports 20,21 -m state --state NEW -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT FORWARD packet died:" --log-level 7
-A OUTPUT -p tcp -j bad_tcp_packets
-A allowed -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A allowed -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A allowed -p tcp -j DROP
-A allowed_udp -p udp -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A allowed_udp -p udp -j DROP
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A icmp_packets -p icmp -j ACCEPT
-A tcp_packets -p tcp -m multiport --dports 22,25,443,53,110,143,995,1194,22222,9080,4899,48999 -j allowed
-A tcp_packets -p tcp -m multiport --dports 465,1780,4121,5222,5666,10153,11520,60180 -j allowed
-A tcp_packets -i ppp0 -p tcp -m multiport --dports 137:139,445 -j DROP
-A udpincoming_packets -p udp -m multiport --dports 53,9001,5060 -j allowed_udp
COMMIT