# Generated by iptables-save v1.2.10 on Wed Jan 16 10:16:53 2089
*nat
:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
COMMIT
# Completed on Wed Jan 16 10:16:53 2089
# Generated by iptables-save v1.2.10 on Wed Jan 16 10:16:53 2089
*mangle
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [269038:79359673]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1:60]
:POSTROUTING ACCEPT [304715:182924818]
COMMIT
# Completed on Wed Jan 16 10:16:53 2089
# Generated by iptables-save v1.2.10 on Wed Jan 16 10:16:53 2089
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [1:60]
:fragment - [0:0]
:net-bios - [0:0]
:ping-death - [0:0]
[0:0] -A INPUT -i lo -j ACCEPT
[0:0] -A INPUT -s 192.168.0.0/255.255.255.0 -j ACCEPT
[0:0] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A INPUT -f -j fragment
[0:0] -A INPUT -s ! 192.168.0.0/255.255.255.0 -p tcp -m multiport --dports 135,137,138,139,445 -j net-bios
[0:0] -A INPUT -s ! 192.168.0.0/255.255.255.0 -p udp -m multiport --dports 135,137,138,139,445 -j net-bios
[0:0] -A INPUT -p icmp -m icmp --icmp-type 8 -j ping-death
[0:0] -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
[0:0] -A INPUT -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 22 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 25 -j ACCEPT
[0:0] -A INPUT -p tcp -m tcp --dport 110 -j ACCEPT
[0:0] -A INPUT -s 192.168.0.0/255.255.255.0 -p tcp -m tcp --dport 10000 -j ACCEPT
[0:0] -A INPUT -j LOG --log-prefix "[iptables INPUT DROP] "
[0:0] -A INPUT -j DROP
[0:0] -A FORWARD -j LOG --log-prefix "[iptables FORWARD DROP] "
[0:0] -A FORWARD -j DROP
[0:0] -A OUTPUT -d ! 192.168.0.0/255.255.255.0 -p tcp -m multiport --sports 135,137,138,139,445 -j net-bios
[0:0] -A OUTPUT -d ! 192.168.0.0/255.255.255.0 -p udp -m multiport --sports 135,137,138,139,445 -j net-bios
[0:0] -A fragment -j LOG --log-prefix "[iptables FRAGMENT] "
[0:0] -A fragment -j DROP
[0:0] -A net-bios -j LOG --log-prefix "[iptables NETBIOS] "
[0:0] -A net-bios -j DROP
[0:0] -A ping-death -m limit --limit 1/sec --limit-burst 4 -j ACCEPT
[0:0] -A ping-death -j LOG --log-prefix "[iptables PING DEATH] "
[0:0] -A ping-death -j DROP
COMMIT
# Completed on Wed Jan 16 10:16:53 2089