Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.8.4 on Fri Sep 4 12:08:32 2020
- *nat
- :PREROUTING ACCEPT [2:124]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [25:2120]
- :POSTROUTING ACCEPT [25:2120]
- :DOCKER - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_ZONES - [0:0]
- :POSTROUTING_direct - [0:0]
- :POST_FedoraWorkstation - [0:0]
- :POST_FedoraWorkstation_allow - [0:0]
- :POST_FedoraWorkstation_deny - [0:0]
- :POST_FedoraWorkstation_log - [0:0]
- :POST_FedoraWorkstation_post - [0:0]
- :POST_FedoraWorkstation_pre - [0:0]
- :POST_docker - [0:0]
- :POST_docker_allow - [0:0]
- :POST_docker_deny - [0:0]
- :POST_docker_log - [0:0]
- :POST_docker_post - [0:0]
- :POST_docker_pre - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraWorkstation - [0:0]
- :PRE_FedoraWorkstation_allow - [0:0]
- :PRE_FedoraWorkstation_deny - [0:0]
- :PRE_FedoraWorkstation_log - [0:0]
- :PRE_FedoraWorkstation_post - [0:0]
- :PRE_FedoraWorkstation_pre - [0:0]
- :PRE_docker - [0:0]
- :PRE_docker_allow - [0:0]
- :PRE_docker_deny - [0:0]
- :PRE_docker_log - [0:0]
- :PRE_docker_post - [0:0]
- :PRE_docker_pre - [0:0]
- [2:124] -A PREROUTING -j PREROUTING_direct
- [2:124] -A PREROUTING -j PREROUTING_ZONES
- [0:0] -A PREROUTING -m addrtype --dst-type LOCAL -j DOCKER
- [25:2120] -A OUTPUT -j OUTPUT_direct
- [0:0] -A OUTPUT ! -d 127.0.0.0/8 -m addrtype --dst-type LOCAL -j DOCKER
- [1:92] -A POSTROUTING -s 172.17.0.0/16 ! -o docker0 -j MASQUERADE
- [25:2120] -A POSTROUTING -j POSTROUTING_direct
- [25:2120] -A POSTROUTING -j POSTROUTING_ZONES
- [0:0] -A DOCKER -i docker0 -j RETURN
- [8:608] -A POSTROUTING_ZONES -o wlp4s0 -g POST_FedoraWorkstation
- [0:0] -A POSTROUTING_ZONES -o docker0 -g POST_docker
- [17:1512] -A POSTROUTING_ZONES -g POST_FedoraWorkstation
- [25:2120] -A POST_FedoraWorkstation -j POST_FedoraWorkstation_pre
- [25:2120] -A POST_FedoraWorkstation -j POST_FedoraWorkstation_log
- [25:2120] -A POST_FedoraWorkstation -j POST_FedoraWorkstation_deny
- [25:2120] -A POST_FedoraWorkstation -j POST_FedoraWorkstation_allow
- [25:2120] -A POST_FedoraWorkstation -j POST_FedoraWorkstation_post
- [0:0] -A POST_docker -j POST_docker_pre
- [0:0] -A POST_docker -j POST_docker_log
- [0:0] -A POST_docker -j POST_docker_deny
- [0:0] -A POST_docker -j POST_docker_allow
- [0:0] -A POST_docker -j POST_docker_post
- [1:32] -A PREROUTING_ZONES -i wlp4s0 -g PRE_FedoraWorkstation
- [1:92] -A PREROUTING_ZONES -i docker0 -g PRE_docker
- [0:0] -A PREROUTING_ZONES -g PRE_FedoraWorkstation
- [1:32] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_pre
- [1:32] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_log
- [1:32] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_deny
- [1:32] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_allow
- [1:32] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_post
- [1:92] -A PRE_docker -j PRE_docker_pre
- [1:92] -A PRE_docker -j PRE_docker_log
- [1:92] -A PRE_docker -j PRE_docker_deny
- [1:92] -A PRE_docker -j PRE_docker_allow
- [1:92] -A PRE_docker -j PRE_docker_post
- COMMIT
- # Completed on Fri Sep 4 12:08:32 2020
- # Generated by iptables-save v1.8.4 on Fri Sep 4 12:08:32 2020
- *mangle
- :PREROUTING ACCEPT [187:55457]
- :INPUT ACCEPT [184:55181]
- :FORWARD ACCEPT [3:276]
- :OUTPUT ACCEPT [171:26825]
- :POSTROUTING ACCEPT [174:27101]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- :POSTROUTING_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraWorkstation - [0:0]
- :PRE_FedoraWorkstation_allow - [0:0]
- :PRE_FedoraWorkstation_deny - [0:0]
- :PRE_FedoraWorkstation_log - [0:0]
- :PRE_FedoraWorkstation_post - [0:0]
- :PRE_FedoraWorkstation_pre - [0:0]
- :PRE_docker - [0:0]
- :PRE_docker_allow - [0:0]
- :PRE_docker_deny - [0:0]
- :PRE_docker_log - [0:0]
- :PRE_docker_post - [0:0]
- :PRE_docker_pre - [0:0]
- [187:55457] -A PREROUTING -j PREROUTING_direct
- [187:55457] -A PREROUTING -j PREROUTING_ZONES
- [184:55181] -A INPUT -j INPUT_direct
- [3:276] -A FORWARD -j FORWARD_direct
- [171:26825] -A OUTPUT -j OUTPUT_direct
- [174:27101] -A POSTROUTING -j POSTROUTING_direct
- [131:32234] -A PREROUTING_ZONES -i wlp4s0 -g PRE_FedoraWorkstation
- [3:276] -A PREROUTING_ZONES -i docker0 -g PRE_docker
- [53:22947] -A PREROUTING_ZONES -g PRE_FedoraWorkstation
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_pre
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_log
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_deny
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_allow
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_post
- [3:276] -A PRE_docker -j PRE_docker_pre
- [3:276] -A PRE_docker -j PRE_docker_log
- [3:276] -A PRE_docker -j PRE_docker_deny
- [3:276] -A PRE_docker -j PRE_docker_allow
- [3:276] -A PRE_docker -j PRE_docker_post
- COMMIT
- # Completed on Fri Sep 4 12:08:32 2020
- # Generated by iptables-save v1.8.4 on Fri Sep 4 12:08:32 2020
- *raw
- :PREROUTING ACCEPT [187:55457]
- :OUTPUT ACCEPT [171:26825]
- :OUTPUT_direct - [0:0]
- :PREROUTING_ZONES - [0:0]
- :PREROUTING_direct - [0:0]
- :PRE_FedoraWorkstation - [0:0]
- :PRE_FedoraWorkstation_allow - [0:0]
- :PRE_FedoraWorkstation_deny - [0:0]
- :PRE_FedoraWorkstation_log - [0:0]
- :PRE_FedoraWorkstation_post - [0:0]
- :PRE_FedoraWorkstation_pre - [0:0]
- :PRE_docker - [0:0]
- :PRE_docker_allow - [0:0]
- :PRE_docker_deny - [0:0]
- :PRE_docker_log - [0:0]
- :PRE_docker_post - [0:0]
- :PRE_docker_pre - [0:0]
- [187:55457] -A PREROUTING -j PREROUTING_direct
- [187:55457] -A PREROUTING -j PREROUTING_ZONES
- [171:26825] -A OUTPUT -j OUTPUT_direct
- [131:32234] -A PREROUTING_ZONES -i wlp4s0 -g PRE_FedoraWorkstation
- [3:276] -A PREROUTING_ZONES -i docker0 -g PRE_docker
- [53:22947] -A PREROUTING_ZONES -g PRE_FedoraWorkstation
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_pre
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_log
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_deny
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_allow
- [184:55181] -A PRE_FedoraWorkstation -j PRE_FedoraWorkstation_post
- [0:0] -A PRE_FedoraWorkstation_allow -p udp -m udp --dport 137 -j CT --helper netbios-ns
- [3:276] -A PRE_docker -j PRE_docker_pre
- [3:276] -A PRE_docker -j PRE_docker_log
- [3:276] -A PRE_docker -j PRE_docker_deny
- [3:276] -A PRE_docker -j PRE_docker_allow
- [3:276] -A PRE_docker -j PRE_docker_post
- COMMIT
- # Completed on Fri Sep 4 12:08:32 2020
- # Generated by iptables-save v1.8.4 on Fri Sep 4 12:08:32 2020
- *security
- :INPUT ACCEPT [183:55149]
- :FORWARD ACCEPT [3:276]
- :OUTPUT ACCEPT [171:26825]
- :FORWARD_direct - [0:0]
- :INPUT_direct - [0:0]
- :OUTPUT_direct - [0:0]
- [183:55149] -A INPUT -j INPUT_direct
- [3:276] -A FORWARD -j FORWARD_direct
- [171:26825] -A OUTPUT -j OUTPUT_direct
- COMMIT
- # Completed on Fri Sep 4 12:08:32 2020
- # Generated by iptables-save v1.8.4 on Fri Sep 4 12:08:32 2020
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [171:26825]
- :DOCKER - [0:0]
- :DOCKER-ISOLATION-STAGE-1 - [0:0]
- :DOCKER-ISOLATION-STAGE-2 - [0:0]
- :DOCKER-USER - [0:0]
- :FORWARD_IN_ZONES - [0:0]
- :FORWARD_OUT_ZONES - [0:0]
- :FORWARD_direct - [0:0]
- :FWDI_FedoraWorkstation - [0:0]
- :FWDI_FedoraWorkstation_allow - [0:0]
- :FWDI_FedoraWorkstation_deny - [0:0]
- :FWDI_FedoraWorkstation_log - [0:0]
- :FWDI_FedoraWorkstation_post - [0:0]
- :FWDI_FedoraWorkstation_pre - [0:0]
- :FWDI_docker - [0:0]
- :FWDI_docker_allow - [0:0]
- :FWDI_docker_deny - [0:0]
- :FWDI_docker_log - [0:0]
- :FWDI_docker_post - [0:0]
- :FWDI_docker_pre - [0:0]
- :FWDO_FedoraWorkstation - [0:0]
- :FWDO_FedoraWorkstation_allow - [0:0]
- :FWDO_FedoraWorkstation_deny - [0:0]
- :FWDO_FedoraWorkstation_log - [0:0]
- :FWDO_FedoraWorkstation_post - [0:0]
- :FWDO_FedoraWorkstation_pre - [0:0]
- :FWDO_docker - [0:0]
- :FWDO_docker_allow - [0:0]
- :FWDO_docker_deny - [0:0]
- :FWDO_docker_log - [0:0]
- :FWDO_docker_post - [0:0]
- :FWDO_docker_pre - [0:0]
- :INPUT_ZONES - [0:0]
- :INPUT_direct - [0:0]
- :IN_FedoraWorkstation - [0:0]
- :IN_FedoraWorkstation_allow - [0:0]
- :IN_FedoraWorkstation_deny - [0:0]
- :IN_FedoraWorkstation_log - [0:0]
- :IN_FedoraWorkstation_post - [0:0]
- :IN_FedoraWorkstation_pre - [0:0]
- :IN_docker - [0:0]
- :IN_docker_allow - [0:0]
- :IN_docker_deny - [0:0]
- :IN_docker_log - [0:0]
- :IN_docker_post - [0:0]
- :IN_docker_pre - [0:0]
- :OUTPUT_direct - [0:0]
- [183:55149] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
- [0:0] -A INPUT -i lo -j ACCEPT
- [1:32] -A INPUT -j INPUT_direct
- [1:32] -A INPUT -j INPUT_ZONES
- [0:0] -A INPUT -m conntrack --ctstate INVALID -j LOG --log-prefix "STATE_INVALID_DROP: "
- [0:0] -A INPUT -m conntrack --ctstate INVALID -j DROP
- [1:32] -A INPUT -j LOG --log-prefix "FINAL_REJECT: "
- [1:32] -A INPUT -j REJECT --reject-with icmp-host-prohibited
- [3:276] -A FORWARD -j DOCKER-USER
- [3:276] -A FORWARD -j DOCKER-ISOLATION-STAGE-1
- [0:0] -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -o docker0 -j DOCKER
- [3:276] -A FORWARD -i docker0 ! -o docker0 -j ACCEPT
- [0:0] -A FORWARD -i docker0 -o docker0 -j ACCEPT
- [0:0] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
- [0:0] -A FORWARD -i lo -j ACCEPT
- [0:0] -A FORWARD -j FORWARD_direct
- [0:0] -A FORWARD -j FORWARD_IN_ZONES
- [0:0] -A FORWARD -j FORWARD_OUT_ZONES
- [0:0] -A FORWARD -m conntrack --ctstate INVALID -j LOG --log-prefix "STATE_INVALID_DROP: "
- [0:0] -A FORWARD -m conntrack --ctstate INVALID -j DROP
- [0:0] -A FORWARD -j LOG --log-prefix "FINAL_REJECT: "
- [0:0] -A FORWARD -j REJECT --reject-with icmp-host-prohibited
- [0:0] -A OUTPUT -o lo -j ACCEPT
- [171:26825] -A OUTPUT -j OUTPUT_direct
- [3:276] -A DOCKER-ISOLATION-STAGE-1 -j RETURN
- [0:0] -A DOCKER-ISOLATION-STAGE-2 -j RETURN
- [3:276] -A DOCKER-USER -j RETURN
- [0:0] -A FORWARD_IN_ZONES -i wlp4s0 -g FWDI_FedoraWorkstation
- [0:0] -A FORWARD_IN_ZONES -i docker0 -g FWDI_docker
- [0:0] -A FORWARD_IN_ZONES -g FWDI_FedoraWorkstation
- [0:0] -A FORWARD_OUT_ZONES -o wlp4s0 -g FWDO_FedoraWorkstation
- [0:0] -A FORWARD_OUT_ZONES -o docker0 -g FWDO_docker
- [0:0] -A FORWARD_OUT_ZONES -g FWDO_FedoraWorkstation
- [0:0] -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_pre
- [0:0] -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_log
- [0:0] -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_deny
- [0:0] -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_allow
- [0:0] -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_post
- [0:0] -A FWDI_FedoraWorkstation -p icmp -j ACCEPT
- [0:0] -A FWDI_docker -j FWDI_docker_pre
- [0:0] -A FWDI_docker -j FWDI_docker_log
- [0:0] -A FWDI_docker -j FWDI_docker_deny
- [0:0] -A FWDI_docker -j FWDI_docker_allow
- [0:0] -A FWDI_docker -j FWDI_docker_post
- [0:0] -A FWDI_docker -j ACCEPT
- [0:0] -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_pre
- [0:0] -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_log
- [0:0] -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_deny
- [0:0] -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_allow
- [0:0] -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_post
- [0:0] -A FWDO_docker -j FWDO_docker_pre
- [0:0] -A FWDO_docker -j FWDO_docker_log
- [0:0] -A FWDO_docker -j FWDO_docker_deny
- [0:0] -A FWDO_docker -j FWDO_docker_allow
- [0:0] -A FWDO_docker -j FWDO_docker_post
- [0:0] -A FWDO_docker -j ACCEPT
- [1:32] -A INPUT_ZONES -i wlp4s0 -g IN_FedoraWorkstation
- [0:0] -A INPUT_ZONES -i docker0 -g IN_docker
- [0:0] -A INPUT_ZONES -g IN_FedoraWorkstation
- [1:32] -A IN_FedoraWorkstation -j IN_FedoraWorkstation_pre
- [1:32] -A IN_FedoraWorkstation -j IN_FedoraWorkstation_log
- [1:32] -A IN_FedoraWorkstation -j IN_FedoraWorkstation_deny
- [1:32] -A IN_FedoraWorkstation -j IN_FedoraWorkstation_allow
- [1:32] -A IN_FedoraWorkstation -j IN_FedoraWorkstation_post
- [0:0] -A IN_FedoraWorkstation -p icmp -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -p udp -m udp --dport 1025:65535 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 1025:65535 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
- [0:0] -A IN_docker -j IN_docker_pre
- [0:0] -A IN_docker -j IN_docker_log
- [0:0] -A IN_docker -j IN_docker_deny
- [0:0] -A IN_docker -j IN_docker_allow
- [0:0] -A IN_docker -j IN_docker_post
- [0:0] -A IN_docker -j ACCEPT
- COMMIT
- # Completed on Fri Sep 4 12:08:32 2020
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement