引用:
# Generated by iptables-save v1.2.11 on Thu Jan 24 12:11:08 2008
*nat
REROUTING ACCEPT [655:38556]
OSTROUTING ACCEPT [9:560]
:OUTPUT ACCEPT [9:560]
COMMIT
# Completed on Thu Jan 24 12:11:08 2008
# Generated by iptables-save v1.2.11 on Thu Jan 24 12:11:08 2008
*mangle
REROUTING ACCEPT [2194:568790]
:INPUT ACCEPT [2194:568790]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2252:1242137]
OSTROUTING ACCEPT [2252:1242137]
COMMIT
# Completed on Thu Jan 24 12:11:08 2008
# Generated by iptables-save v1.2.11 on Thu Jan 24 12:11:08 2008
*filter
:FORWARD ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 10000 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1024:65535 --sport 80 ! --tcp-flags SYN,ACK,RST SYN -j ACCEPT
-A INPUT -p udp -m udp --sport 53 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 53 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1024:65535 --sport 21 ! --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1024:65535 --sport 20 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1024:65535 --sport 1024:65535 ! --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A INPUT -p tcp -m state -m tcp --dport 21 --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state -m tcp --dport 20 --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state -m tcp --dport 25 --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 3128 -j ACCEPT
-A FORWARD -m state -i eth0 -o eth1 --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eh0 -j ACCEPT
-A FORWARD -p tcp -m tcp -m state ! --tcp-flags SYN,RST,ACK SYN --state NEW -j DROP
-A FORWARD -m limit -f --limit 100/sec --limit-burst 100 -j ACCEPT
-A FORWARD -p icmp -m limit --limit 1/sec --limit-burst 10 -j ACCEPT
-A FORWARD -j DROP
-A OUTPUT -p tcp -m tcp --sport 22 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 10000 -j ACCEPT
-A OUTPUT -p icmp -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 80 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 80 --sport 1024:65535 -j ACCEPT
-A OUTPUT -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 21 --sport 1024:65535 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 20 --sport 1024:65535 ! --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 1024:65535 --sport 1024:65535 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 110 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 3128 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -j DROP
-A OUTPUT -p tcp -m tcp --sport 110 -j ACCEPT
COMMIT
# Completed on Thu Jan 24 12:11:08 2008