Changes between Version 9 and Version 10 of HowTo/SakuraVpsSetup3
- Timestamp:
- Apr 29, 2017, 10:31:59 PM (7 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
HowTo/SakuraVpsSetup3
v9 v10 135 135 /sbin/iptables -A INPUT -i lo -j ACCEPT 136 136 137 /sbin/iptables -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,53,587,993,80,443 -j ACCEPT 137 /sbin/iptables -A INPUT -m tcp -p tcp -m state --state NEW --dport 53 -j ACCEPT 138 /sbin/iptables -A INPUT -m udp -p udp -m state --state NEW --dport 53 -j ACCEPT 139 /sbin/iptables -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,587,993,80,443 -j ACCEPT 138 140 /sbin/iptables -A INPUT -j REJECT --reject-with icmp-port-unreachable 139 141 /sbin/iptables -A FORWARD -j REJECT --reject-with icmp-port-unreachable … … 164 166 /sbin/ip6tables -A INPUT -i lo -j ACCEPT 165 167 166 /sbin/ip6tables -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,53,587,993,80,443 -j ACCEPT 168 /sbin/ip6tables -A INPUT -m tcp -p tcp -m state --state NEW --dport 53 -j ACCEPT 169 /sbin/ip6tables -A INPUT -m udp -p udp -m state --state NEW --dport 53 -j ACCEPT 170 /sbin/ip6tables -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,587,993,80,443 -j ACCEPT 167 171 /sbin/ip6tables -A INPUT -j REJECT --reject-with icmp6-port-unreachable 168 172 /sbin/ip6tables -A FORWARD -j REJECT --reject-with icmp6-port-unreachable … … 183 187 ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0 184 188 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 185 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports 22,25,53,587,993,80,443 189 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 state NEW 190 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53 state NEW 191 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW multiport dports 22,25,587,993,80,443 186 192 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable 187 193 … … 199 205 ACCEPT icmp ::/0 ::/0 200 206 ACCEPT all ::/0 ::/0 201 ACCEPT tcp ::/0 ::/0 state NEW multiport dports 22,25,53,587,993,80,443 207 ACCEPT tcp ::/0 ::/0 tcp dpt:53 state NEW 208 ACCEPT udp ::/0 ::/0 udp dpt:53 state NEW 209 ACCEPT tcp ::/0 ::/0 state NEW multiport dports 22,25,587,993,80,443 202 210 REJECT all ::/0 ::/0 reject-with icmp6-port-unreachable 203 211 … … 219 227 {{{ 220 228 # cat /etc/iptables/rules.v4 221 # Generated by iptables-save v1.6.0 on Sat Apr 29 06:40:352017229 # Generated by iptables-save v1.6.0 on Sat Apr 29 22:29:46 2017 222 230 *filter 223 231 :INPUT ACCEPT [0:0] 224 232 :FORWARD ACCEPT [0:0] 225 :OUTPUT ACCEPT [ 283:43644]233 :OUTPUT ACCEPT [36:3368] 226 234 -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 227 235 -A INPUT -p icmp -j ACCEPT 228 236 -A INPUT -i lo -j ACCEPT 229 -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,53,587,993,80,443 -j ACCEPT 237 -A INPUT -p tcp -m tcp --dport 53 -m state --state NEW -j ACCEPT 238 -A INPUT -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT 239 -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,587,993,80,443 -j ACCEPT 230 240 -A INPUT -j REJECT --reject-with icmp-port-unreachable 231 241 -A FORWARD -j REJECT --reject-with icmp-port-unreachable 232 242 -A OUTPUT -p udp -m udp -m multiport --dports 161,162 -j REJECT --reject-with icmp-port-unreachable 233 243 COMMIT 234 # Completed on Sat Apr 29 06:40:352017244 # Completed on Sat Apr 29 22:29:46 2017 235 245 # cat /etc/iptables/rules.v6 236 # Generated by ip6tables-save v1.6.0 on Sat Apr 29 06:40:352017246 # Generated by ip6tables-save v1.6.0 on Sat Apr 29 22:29:46 2017 237 247 *filter 238 248 :INPUT ACCEPT [0:0] … … 242 252 -A INPUT -p icmp -j ACCEPT 243 253 -A INPUT -i lo -j ACCEPT 244 -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,53,587,993,80,443 -j ACCEPT 254 -A INPUT -p tcp -m tcp --dport 53 -m state --state NEW -j ACCEPT 255 -A INPUT -p udp -m udp --dport 53 -m state --state NEW -j ACCEPT 256 -A INPUT -p tcp -m state --state NEW -m multiport --dports 22,25,587,993,80,443 -j ACCEPT 245 257 -A INPUT -j REJECT --reject-with icmp6-port-unreachable 246 258 -A FORWARD -j REJECT --reject-with icmp6-port-unreachable 247 259 -A OUTPUT -p udp -m udp -m multiport --dports 161,162 -j REJECT --reject-with icmp6-port-unreachable 248 260 COMMIT 249 # Completed on Sat Apr 29 06:40:352017261 # Completed on Sat Apr 29 22:29:46 2017 250 262 # 251 263 }}}