mirror of
https://github.com/nchevsky/systemrescue-zfs.git
synced 2026-01-06 00:29:58 +01:00
Update iptables config to log dropped packets
This commit is contained in:
parent
67a0f88d39
commit
eb0d1b98bb
|
|
@ -2,7 +2,11 @@
|
|||
:INPUT DROP [0:0]
|
||||
:FORWARD DROP [0:0]
|
||||
:OUTPUT ACCEPT [0:0]
|
||||
-N LOGDROP
|
||||
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A INPUT -i lo -j ACCEPT
|
||||
-A INPUT -p ipv6-icmp -m icmp6 --icmpv6-type 128 -m conntrack --ctstate NEW -j ACCEPT
|
||||
-A INPUT -j LOGDROP
|
||||
-A LOGDROP -m limit --limit 10/sec -j LOG --log-prefix "iptables-dropped: "
|
||||
-A LOGDROP -j DROP
|
||||
COMMIT
|
||||
|
|
|
|||
|
|
@ -2,7 +2,11 @@
|
|||
:INPUT DROP [0:0]
|
||||
:FORWARD DROP [0:0]
|
||||
:OUTPUT ACCEPT [0:0]
|
||||
-N LOGDROP
|
||||
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A INPUT -i lo -j ACCEPT
|
||||
-A INPUT -p icmp -m icmp --icmp-type 8 -m conntrack --ctstate NEW -j ACCEPT
|
||||
-A INPUT -j LOGDROP
|
||||
-A LOGDROP -m limit --limit 10/sec -j LOG --log-prefix "iptables-dropped: "
|
||||
-A LOGDROP -j DROP
|
||||
COMMIT
|
||||
|
|
|
|||
Loading…
Reference in a new issue