Removed random iptables
This commit is contained in:
67
rules.v4
67
rules.v4
@@ -3,17 +3,6 @@
|
||||
:INPUT ACCEPT [49625:4770941]
|
||||
:FORWARD ACCEPT [0:0]
|
||||
:OUTPUT ACCEPT [50317:5079310]
|
||||
:DOCKER - [0:0]
|
||||
:DOCKER-ISOLATION-STAGE-1 - [0:0]
|
||||
:DOCKER-ISOLATION-STAGE-2 - [0:0]
|
||||
:DOCKER-USER - [0:0]
|
||||
-A INPUT -p tcp -m tcp --dport 2223 -m comment --comment "AMP:ADS01:FileManagerPlugin.SFTP.SFTPPortNumber" -j ACCEPT
|
||||
-A INPUT -p udp -m udp --dport 12820 -m comment --comment "AMP:ADS01:ADSModule.Network.MetricsServerPort" -j ACCEPT
|
||||
-A INPUT -p tcp -m tcp --dport 2224 -m comment --comment "AMP:Minecraft01:FileManagerPlugin.SFTP.SFTPPortNumber" -j ACCEPT
|
||||
-A INPUT -p tcp -m tcp --dport 8080 -m comment --comment "AMP:ADS01:Core.Webserver.Port" -j ACCEPT
|
||||
-A INPUT -p tcp -m tcp --dport 25565 -m comment --comment "AMP:Minecraft01:MinecraftModule.Minecraft.PortNumber" -j ACCEPT
|
||||
-A INPUT -p udp -m udp --dport 25565 -m comment --comment "AMP:Minecraft01:MinecraftModule.Minecraft.PortNumber" -j ACCEPT
|
||||
-A INPUT -i tun0 -j ACCEPT
|
||||
-A INPUT -s 101.36.108.0/24 -j DROP
|
||||
-A INPUT -s 103.101.176.0/24 -j DROP
|
||||
-A INPUT -s 103.130.212.0/24 -j DROP
|
||||
@@ -2129,61 +2118,5 @@
|
||||
-A INPUT -s 45.232.225.0/24 -j DROP
|
||||
-A INPUT -s 45.4.224.0/24 -j DROP
|
||||
-A INPUT -s 45.4.225.0/24 -j DROP
|
||||
-A FORWARD -j DOCKER-USER
|
||||
-A FORWARD -j DOCKER-ISOLATION-STAGE-1
|
||||
-A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A FORWARD -o docker0 -j DOCKER
|
||||
-A FORWARD -i docker0 ! -o docker0 -j ACCEPT
|
||||
-A FORWARD -i docker0 -o docker0 -j ACCEPT
|
||||
-A FORWARD -o br-1558eabebce2 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A FORWARD -o br-1558eabebce2 -j DOCKER
|
||||
-A FORWARD -i br-1558eabebce2 ! -o br-1558eabebce2 -j ACCEPT
|
||||
-A FORWARD -i br-1558eabebce2 -o br-1558eabebce2 -j ACCEPT
|
||||
-A FORWARD -i tun0 -j ACCEPT
|
||||
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
|
||||
-A FORWARD -d 10.8.0.0/24 -i tun0 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 3128 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 443 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 943 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p udp -m udp --dport 1194 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 1688 -j ACCEPT
|
||||
-A DOCKER-ISOLATION-STAGE-1 -i docker0 ! -o docker0 -j DOCKER-ISOLATION-STAGE-2
|
||||
-A DOCKER-ISOLATION-STAGE-1 -i br-1558eabebce2 ! -o br-1558eabebce2 -j DOCKER-ISOLATION-STAGE-2
|
||||
-A DOCKER-ISOLATION-STAGE-1 -j RETURN
|
||||
-A DOCKER-ISOLATION-STAGE-2 -o docker0 -j DROP
|
||||
-A DOCKER-ISOLATION-STAGE-2 -o br-1558eabebce2 -j DROP
|
||||
-A DOCKER-ISOLATION-STAGE-2 -j RETURN
|
||||
-A DOCKER-USER -j RETURN
|
||||
COMMIT
|
||||
# Completed on Tue Sep 9 22:15:34 2025
|
||||
# Generated by iptables-save v1.8.10 (nf_tables) on Tue Sep 9 22:15:34 2025
|
||||
*nat
|
||||
:PREROUTING ACCEPT [58666:4169004]
|
||||
:INPUT ACCEPT [40320:2867543]
|
||||
:OUTPUT ACCEPT [778:46680]
|
||||
:POSTROUTING ACCEPT [778:46680]
|
||||
:DOCKER - [0:0]
|
||||
-A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
|
||||
-A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
|
||||
-A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.18.0.0/16 ! -o br-1558eabebce2 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 443 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 1688 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 943 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p udp -m udp --dport 1194 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 3128 -j MASQUERADE
|
||||
-A POSTROUTING -s 10.8.0.0/24 -o enp4s0 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.2/32 -d 172.17.0.2/32 -p tcp -m tcp --dport 3128 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 443 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p tcp -m tcp --dport 943 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.3/32 -d 172.17.0.3/32 -p udp -m udp --dport 1194 -j MASQUERADE
|
||||
-A POSTROUTING -s 172.17.0.4/32 -d 172.17.0.4/32 -p tcp -m tcp --dport 1688 -j MASQUERADE
|
||||
-A DOCKER -i docker0 -j RETURN
|
||||
-A DOCKER -i br-1558eabebce2 -j RETURN
|
||||
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 9093 -j DNAT --to-destination 172.17.0.2:3128
|
||||
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 8443 -j DNAT --to-destination 172.17.0.3:443
|
||||
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 943 -j DNAT --to-destination 172.17.0.3:943
|
||||
-A DOCKER ! -i docker0 -p udp -m udp --dport 1194 -j DNAT --to-destination 172.17.0.3:1194
|
||||
-A DOCKER ! -i docker0 -p tcp -m tcp --dport 1688 -j DNAT --to-destination 172.17.0.4:1688
|
||||
COMMIT
|
||||
# Completed on Tue Sep 9 22:15:34 2025
|
||||
|
||||
Reference in New Issue
Block a user