- ### HOST
- └─$ sudo iptables -v -L
- Chain INPUT (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT udp -- virbr0 any anywhere anywhere udp dpt:domain
- 0 0 ACCEPT tcp -- virbr0 any anywhere anywhere tcp dpt:domain
- 6 1968 ACCEPT udp -- virbr0 any anywhere anywhere udp dpt:bootps
- 0 0 ACCEPT tcp -- virbr0 any anywhere anywhere tcp dpt:bootps
- 556K 1051M ufw-before-logging-input all -- any any anywhere anywhere
- 556K 1051M ufw-before-input all -- any any anywhere anywhere
- 3721 522K ufw-after-input all -- any any anywhere anywhere
- 3531 485K ufw-after-logging-input all -- any any anywhere anywhere
- 3531 485K ufw-reject-input all -- any any anywhere anywhere
- 3531 485K ufw-track-input all -- any any anywhere anywhere
- Chain FORWARD (policy DROP 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 17 1292 ACCEPT all -- any virbr0 anywhere 192.168.122.0/24 ctstate RELATED,ESTABLISHED
- 18 1396 ACCEPT all -- virbr0 any 192.168.122.0/24 anywhere
- 0 0 ACCEPT all -- virbr0 virbr0 anywhere anywhere
- 0 0 REJECT all -- any virbr0 anywhere anywhere reject-with icmp-port-unreachable
- 0 0 REJECT all -- virbr0 any anywhere anywhere reject-with icmp-port-unreachable
- 0 0 ufw-before-logging-forward all -- any any anywhere anywhere
- 0 0 ufw-before-forward all -- any any anywhere anywhere
- 0 0 ufw-after-forward all -- any any anywhere anywhere
- 0 0 ufw-after-logging-forward all -- any any anywhere anywhere
- 0 0 ufw-reject-forward all -- any any anywhere anywhere
- 0 0 ufw-track-forward all -- any any anywhere anywhere
- Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 6 1974 ACCEPT udp -- any virbr0 anywhere anywhere udp dpt:bootpc
- 540K 692M ufw-before-logging-output all -- any any anywhere anywhere
- 540K 692M ufw-before-output all -- any any anywhere anywhere
- 7776 659K ufw-after-output all -- any any anywhere anywhere
- 7776 659K ufw-after-logging-output all -- any any anywhere anywhere
- 7776 659K ufw-reject-output all -- any any anywhere anywhere
- 7776 659K ufw-track-output all -- any any anywhere anywhere
- Chain ufw-after-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-after-input (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ufw-skip-to-policy-input udp -- any any anywhere anywhere udp dpt:netbios-ns
- 38 9367 ufw-skip-to-policy-input udp -- any any anywhere anywhere udp dpt:netbios-dgm
- 0 0 ufw-skip-to-policy-input tcp -- any any anywhere anywhere tcp dpt:netbios-ssn
- 0 0 ufw-skip-to-policy-input tcp -- any any anywhere anywhere tcp dpt:microsoft-ds
- 0 0 ufw-skip-to-policy-input udp -- any any anywhere anywhere udp dpt:bootps
- 0 0 ufw-skip-to-policy-input udp -- any any anywhere anywhere udp dpt:bootpc
- 0 0 ufw-skip-to-policy-input all -- any any anywhere anywhere ADDRTYPE match dst-type BROADCAST
- Chain ufw-after-logging-forward (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- any any anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] "
- Chain ufw-after-logging-input (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- any any anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] "
- Chain ufw-after-logging-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-after-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-forward (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp destination-unreachable
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp source-quench
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp time-exceeded
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp parameter-problem
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp echo-request
- 0 0 ufw-user-forward all -- any any anywhere anywhere
- Chain ufw-before-input (1 references)
- pkts bytes target prot opt in out source destination
- 6720 817K ACCEPT all -- lo any anywhere anywhere
- 161K 61M ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
- 7 280 ufw-logging-deny all -- any any anywhere anywhere ctstate INVALID
- 7 280 DROP all -- any any anywhere anywhere ctstate INVALID
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp destination-unreachable
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp source-quench
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp time-exceeded
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp parameter-problem
- 0 0 ACCEPT icmp -- any any anywhere anywhere icmp echo-request
- 0 0 ACCEPT udp -- any any anywhere anywhere udp spt:bootps dpt:bootpc
- 42 9659 ufw-not-local all -- any any anywhere anywhere
- 4 292 ACCEPT udp -- any any anywhere 224.0.0.251 udp dpt:mdns
- 0 0 ACCEPT udp -- any any anywhere 239.255.255.250 udp dpt:1900
- 38 9367 ufw-user-input all -- any any anywhere anywhere
- Chain ufw-before-logging-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-logging-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-logging-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-before-output (1 references)
- pkts bytes target prot opt in out source destination
- 6720 817K ACCEPT all -- any lo anywhere anywhere
- 168K 16M ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
- 1412 102K ufw-user-output all -- any any anywhere anywhere
- Chain ufw-logging-allow (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- any any anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW ALLOW] "
- Chain ufw-logging-deny (2 references)
- pkts bytes target prot opt in out source destination
- 7 280 RETURN all -- any any anywhere anywhere ctstate INVALID limit: avg 3/min burst 10
- 0 0 LOG all -- any any anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] "
- Chain ufw-not-local (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN all -- any any anywhere anywhere ADDRTYPE match dst-type LOCAL
- 4 292 RETURN all -- any any anywhere anywhere ADDRTYPE match dst-type MULTICAST
- 38 9367 RETURN all -- any any anywhere anywhere ADDRTYPE match dst-type BROADCAST
- 0 0 ufw-logging-deny all -- any any anywhere anywhere limit: avg 3/min burst 10
- 0 0 DROP all -- any any anywhere anywhere
- Chain ufw-reject-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-reject-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-reject-output (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-skip-to-policy-forward (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- any any anywhere anywhere
- Chain ufw-skip-to-policy-input (7 references)
- pkts bytes target prot opt in out source destination
- 38 9367 DROP all -- any any anywhere anywhere
- Chain ufw-skip-to-policy-output (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- any any anywhere anywhere
- Chain ufw-track-forward (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-track-input (1 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-track-output (1 references)
- pkts bytes target prot opt in out source destination
- 461 27660 ACCEPT tcp -- any any anywhere anywhere ctstate NEW
- 947 74057 ACCEPT udp -- any any anywhere anywhere ctstate NEW
- Chain ufw-user-forward (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- virbr0 virbr0 anywhere anywhere
- Chain ufw-user-input (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:8000
- 0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:8000
- Chain ufw-user-limit (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- any any anywhere anywhere limit: avg 3/min burst 5 LOG level warning prefix "[UFW LIMIT BLOCK] "
- 0 0 REJECT all -- any any anywhere anywhere reject-with icmp-port-unreachable
- Chain ufw-user-limit-accept (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- any any anywhere anywhere
- Chain ufw-user-logging-forward (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-logging-input (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-logging-output (0 references)
- pkts bytes target prot opt in out source destination
- Chain ufw-user-output (1 references)
- pkts bytes target prot opt in out source destination
- ### GUEST
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 14057 5756K ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
- 15 1048 ACCEPT all -- lo any anywhere anywhere
- 12 492 INPUT_direct all -- any any anywhere anywhere
- 12 492 INPUT_ZONES_SOURCE all -- any any anywhere anywhere
- 12 492 INPUT_ZONES all -- any any anywhere anywhere
- 0 0 ACCEPT icmp -- any any anywhere anywhere
- 9 360 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
- 0 0 ACCEPT all -- lo any anywhere anywhere
- 0 0 FORWARD_direct all -- any any anywhere anywhere
- 0 0 FORWARD_IN_ZONES_SOURCE all -- any any anywhere anywhere
- 0 0 FORWARD_IN_ZONES all -- any any anywhere anywhere
- 0 0 FORWARD_OUT_ZONES_SOURCE all -- any any anywhere anywhere
- 0 0 FORWARD_OUT_ZONES all -- any any anywhere anywhere
- 0 0 ACCEPT icmp -- any any anywhere anywhere
- 0 0 REJECT all -- any any anywhere anywhere reject-with icmp-host-prohibited
- Chain OUTPUT (policy ACCEPT 297 packets, 89402 bytes)
- pkts bytes target prot opt in out source destination
- 9516 4180K OUTPUT_direct all -- any any anywhere anywhere
- Chain FORWARD_IN_ZONES (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 FWDI_public all -- enp0s3 any anywhere anywhere [goto]
- 0 0 FWDI_public all -- + any anywhere anywhere [goto]
- Chain FORWARD_IN_ZONES_SOURCE (1 references)
- pkts bytes target prot opt in out source destination
- Chain FORWARD_OUT_ZONES (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 FWDO_public all -- any enp0s3 anywhere anywhere [goto]
- 0 0 FWDO_public all -- any + anywhere anywhere [goto]
- Chain FORWARD_OUT_ZONES_SOURCE (1 references)
- pkts bytes target prot opt in out source destination
- Chain FORWARD_direct (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDI_public (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 FWDI_public_log all -- any any anywhere anywhere
- 0 0 FWDI_public_deny all -- any any anywhere anywhere
- 0 0 FWDI_public_allow all -- any any anywhere anywhere
- Chain FWDI_public_allow (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDI_public_deny (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDI_public_log (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDO_public (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 FWDO_public_log all -- any any anywhere anywhere
- 0 0 FWDO_public_deny all -- any any anywhere anywhere
- 0 0 FWDO_public_allow all -- any any anywhere anywhere
- Chain FWDO_public_allow (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDO_public_deny (1 references)
- pkts bytes target prot opt in out source destination
- Chain FWDO_public_log (1 references)
- pkts bytes target prot opt in out source destination
- Chain INPUT_ZONES (1 references)
- pkts bytes target prot opt in out source destination
- 1 44 IN_public all -- enp0s3 any anywhere anywhere [goto]
- 0 0 IN_public all -- + any anywhere anywhere [goto]
- Chain INPUT_ZONES_SOURCE (1 references)
- pkts bytes target prot opt in out source destination
- Chain INPUT_direct (1 references)
- pkts bytes target prot opt in out source destination
- Chain IN_public (2 references)
- pkts bytes target prot opt in out source destination
- 12 492 IN_public_log all -- any any anywhere anywhere
- 12 492 IN_public_deny all -- any any anywhere anywhere
- 12 492 IN_public_allow all -- any any anywhere anywhere
- Chain IN_public_allow (1 references)
- pkts bytes target prot opt in out source destination
- 3 132 ACCEPT tcp -- any any anywhere anywhere tcp dpt:ssh ctstate NEW
- Chain IN_public_deny (1 references)
- pkts bytes target prot opt in out source destination
- Chain IN_public_log (1 references)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT_direct (1 references)
- pkts bytes target prot opt in out source destination
Untitled
Posted by Anonymous on Mon 4th Apr 2016 18:59
raw | new post
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.