mirror of
https://github.com/nchevsky/systemrescue-zfs.git
synced 2026-01-02 14:50:14 +01:00
13 lines
319 B
Plaintext
13 lines
319 B
Plaintext
*filter
|
|
:INPUT DROP [0:0]
|
|
:FORWARD DROP [0:0]
|
|
:OUTPUT ACCEPT [0:0]
|
|
-N LOGDROP
|
|
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
|
-A INPUT -i lo -j ACCEPT
|
|
-A INPUT -p ipv6-icmp -j ACCEPT
|
|
-A INPUT -j LOGDROP
|
|
-A LOGDROP -m limit --limit 10/sec -j LOG --log-prefix "iptables-dropped: "
|
|
-A LOGDROP -j DROP
|
|
COMMIT
|