Ja nevim. ICMP prochazi, TCP ne. Nedokazu urcit pricinu. Mate tam packet fitering a nevite o tom. Placam nesmysly. Jen tak zesrandy: # iptables -L vypise co ?
Vypise to toto ale neni to cele /v terminali sa mi zobrazi len isty pocet riadkov a som lama a neviem to obist../
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:domain state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:domain state ESTABLISHED
Chain in_external_icmp_c3 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state ESTABLISHED
Chain in_external_icq_c6 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:aol dpts:32768:61000 state ESTABLISHED
Chain in_external_jabber_c7 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:xmpp-client dpts:32768:61000 state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:5223 dpts:32768:61000 state ESTABLISHED
Chain in_external_ping_c4 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state ESTABLISHED icmp echo-reply
Chain in_external_ssh_s1 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ssh state NEW,ESTABLISHED
Chain in_external_telnet_c5 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:telnet dpts:32768:61000 state ESTABLISHED
Chain in_external_webcache_c8 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:webcache dpts:32768:61000 state ESTABLISHED
Chain in_internal (1 references)
target prot opt source destination
DROP all -- anywhere anywhere state INVALID
pr_internal_fragments all -f anywhere anywhere
pr_internal_nosyn tcp -- anywhere anywhere state NEW tcp flags:!FIN,SYN,RST,ACK/SYN
pr_internal_icmpflood icmp -- anywhere anywhere icmp echo-request
pr_internal_synflood tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN
pr_internal_malxmas tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,PSH,ACK,URG
pr_internal_malnull tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE
pr_internal_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN
pr_internal_malbad tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST
pr_internal_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,ACK,URG
pr_internal_malbad tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,PSH,URG
in_internal_dns_s1 all -- anywhere anywhere
in_internal_netbios_ns_s2 all -- anywhere anywhere
in_internal_netbios_dgm_s3 all -- anywhere anywhere
in_internal_netbios_ssn_s4 all -- anywhere anywhere
in_internal_samba_s5 all -- anywhere anywhere
in_internal_squid_s6 all -- anywhere anywhere
in_internal_icmp_s7 all -- anywhere anywhere
in_internal_ping_s8 all -- anywhere anywhere
in_internal_all_c9 all -- anywhere anywhere
in_internal_irc_c10 all -- anywhere anywhere
in_internal_ftp_c11 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `''IN-internal':''
DROP all -- anywhere anywhere
Chain in_internal2external (1 references)
target prot opt source destination
in_internal2external_all_s1 all -- anywhere anywhere
in_internal2external_irc_s2 all -- anywhere anywhere
in_internal2external_ftp_s3 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED
Chain in_internal2external_all_s1 (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere state NEW,ESTABLISHED
Chain in_internal2external_ftp_s3 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ftp state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ftp-data state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:1024:65535 state RELATED,ESTABLISHED
Chain in_internal2external_irc_s2 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ircd state NEW,ESTABLISHED
Chain in_internal_all_c9 (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere state ESTABLISHED
Chain in_internal_dns_s1 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:domain state NEW,ESTABLISHED
Chain in_internal_ftp_c11 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:ftp dpts:32768:61000 state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:ftp-data dpts:32768:61000 state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:32768:61000 state ESTABLISHED
Chain in_internal_icmp_s7 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state NEW,ESTABLISHED
Chain in_internal_irc_c10 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:ircd dpts:32768:61000 state ESTABLISHED
Chain in_internal_netbios_dgm_s3 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpt:netbios-dgm state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpt:netbios-dgm state NEW,ESTABLISHED
Chain in_internal_netbios_ns_s2 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpt:netbios-ns state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpt:netbios-ns state NEW,ESTABLISHED
Chain in_internal_netbios_ssn_s4 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:netbios-ssn state NEW,ESTABLISHED
Chain in_internal_ping_s8 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state NEW,ESTABLISHED icmp echo-request
Chain in_internal_samba_s5 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpt:netbios-ns state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpt:netbios-ns state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpt:netbios-dgm state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spts:1024:65535 dpt:netbios-dgm state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:netbios-ssn state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:microsoft-ds state NEW,ESTABLISHED
Chain in_internal_squid_s6 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:3128 state NEW,ESTABLISHED
Chain out_external (1 references)
target prot opt source destination
out_external_ssh_s1 all -- anywhere anywhere
out_external_dns_c2 all -- anywhere anywhere
out_external_icmp_c3 all -- anywhere anywhere
out_external_ping_c4 all -- anywhere anywhere
out_external_telnet_c5 all -- anywhere anywhere
out_external_icq_c6 all -- anywhere anywhere
out_external_jabber_c7 all -- anywhere anywhere
out_external_webcache_c8 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `''OUT-external':''
DROP all -- anywhere anywhere
Chain out_external_dns_c2 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp dpt:domain state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:domain state NEW,ESTABLISHED
Chain out_external_icmp_c3 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state NEW,ESTABLISHED
Chain out_external_icq_c6 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:aol state NEW,ESTABLISHED
Chain out_external_jabber_c7 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:xmpp-client state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:5223 state NEW,ESTABLISHED
Chain out_external_ping_c4 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state NEW,ESTABLISHED icmp echo-request
Chain out_external_ssh_s1 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:ssh dpts:1024:65535 state ESTABLISHED
Chain out_external_telnet_c5 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:telnet state NEW,ESTABLISHED
Chain out_external_webcache_c8 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:webcache state NEW,ESTABLISHED
Chain out_internal (1 references)
target prot opt source destination
out_internal_dns_s1 all -- anywhere anywhere
out_internal_netbios_ns_s2 all -- anywhere anywhere
out_internal_netbios_dgm_s3 all -- anywhere anywhere
out_internal_netbios_ssn_s4 all -- anywhere anywhere
out_internal_samba_s5 all -- anywhere anywhere
out_internal_squid_s6 all -- anywhere anywhere
out_internal_icmp_s7 all -- anywhere anywhere
out_internal_ping_s8 all -- anywhere anywhere
out_internal_all_c9 all -- anywhere anywhere
out_internal_irc_c10 all -- anywhere anywhere
out_internal_ftp_c11 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `''OUT-internal':''
DROP all -- anywhere anywhere
Chain out_internal2external (1 references)
target prot opt source destination
out_internal2external_all_s1 all -- anywhere anywhere
out_internal2external_irc_s2 all -- anywhere anywhere
out_internal2external_ftp_s3 all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED
Chain out_internal2external_all_s1 (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere state ESTABLISHED
Chain out_internal2external_ftp_s3 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:ftp dpts:1024:65535 state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:ftp-data dpts:1024:65535 state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpts:1024:65535 state ESTABLISHED
Chain out_internal2external_irc_s2 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:ircd dpts:1024:65535 state ESTABLISHED
Chain out_internal_all_c9 (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere state NEW,ESTABLISHED
Chain out_internal_dns_s1 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:domain state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:domain state ESTABLISHED
Chain out_internal_ftp_c11 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ftp state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ftp-data state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpts:1024:65535 state RELATED,ESTABLISHED
Chain out_internal_icmp_s7 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state ESTABLISHED
Chain out_internal_irc_c10 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spts:32768:61000 dpt:ircd state NEW,ESTABLISHED
Chain out_internal_netbios_dgm_s3 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpts:1024:65535 state ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpt:netbios-dgm state ESTABLISHED
Chain out_internal_netbios_ns_s2 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpts:1024:65535 state ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpt:netbios-ns state ESTABLISHED
Chain out_internal_netbios_ssn_s4 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:netbios-ssn dpts:1024:65535 state ESTABLISHED
Chain out_internal_ping_s8 (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state ESTABLISHED icmp echo-reply
Chain out_internal_samba_s5 (1 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpt:netbios-ns state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-ns dpts:1024:65535 state NEW,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpt:netbios-dgm state ESTABLISHED
ACCEPT udp -- anywhere anywhere udp spt:netbios-dgm dpts:1024:65535 state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:netbios-ssn dpts:1024:65535 state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:microsoft-ds dpts:1024:65535 state ESTABLISHED
Chain out_internal_squid_s6 (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:3128 dpts:1024:65535 state ESTABLISHED
Chain pr_external_fragments (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'PACKET FRAGMENTS:''
DROP all -- anywhere anywhere
Chain pr_external_icmpflood (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'ICMP FLOOD:''
DROP all -- anywhere anywhere
Chain pr_external_malbad (4 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED BAD:''
DROP all -- anywhere anywhere
Chain pr_external_malnull (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED NULL:''
DROP all -- anywhere anywhere
Chain pr_external_malxmas (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED XMAS:''
DROP all -- anywhere anywhere
Chain pr_external_nosyn (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'NEW TCP w/o SYN:''
DROP all -- anywhere anywhere
Chain pr_external_synflood (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'SYN FLOOD:''
DROP all -- anywhere anywhere
Chain pr_internal_fragments (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'PACKET FRAGMENTS:''
DROP all -- anywhere anywhere
Chain pr_internal_icmpflood (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'ICMP FLOOD:''
DROP all -- anywhere anywhere
Chain pr_internal_malbad (4 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED BAD:''
DROP all -- anywhere anywhere
Chain pr_internal_malnull (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED NULL:''
DROP all -- anywhere anywhere
Chain pr_internal_malxmas (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'MALFORMED XMAS:''
DROP all -- anywhere anywhere
Chain pr_internal_nosyn (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'NEW TCP w/o SYN:''
DROP all -- anywhere anywhere
Chain pr_internal_synflood (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere limit: avg 10/sec burst 10
LOG all -- anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `'SYN FLOOD:''
DROP all -- anywhere anywhere