1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
| #!/bin/bash /usr/sbin/iptables -F /usr/sbin/ip6tables -F /usr/sbin/iptables -I INPUT -s 140.205.201.0/28 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.201.16/29 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.201.32/28 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.192/29 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.200/30 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.184/29 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.183/32 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.206/32 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.205/32 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.195/32 -j DROP /usr/sbin/iptables -I INPUT -s 140.205.225.204/32 -j DROP /usr/sbin/iptables -A INPUT -i lo -j ACCEPT /usr/sbin/iptables -A OUTPUT -o lo -j ACCEPT /usr/sbin/ip6tables -A INPUT -i lo -j ACCEPT /usr/sbin/ip6tables -A OUTPUT -o lo -j ACCEPT /usr/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT /usr/sbin/iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT /usr/sbin/ip6tables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT /usr/sbin/ip6tables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT /usr/sbin/iptables -A INPUT -p tcp ! --dport 22 -j DROP /usr/sbin/ip6tables -A INPUT -p tcp ! --dport 22 -j DROP /usr/sbin/iptables -I INPUT -s 172.16.0.0/12 -j ACCEPT /usr/sbin/iptables -I OUTPUT -s 172.16.0.0/12 -j ACCEPT /usr/sbin/iptables -I INPUT -p tcp -m multiport --dports 80,443,8024 -j ACCEPT /usr/sbin/iptables -I INPUT -p udp --dport 6000:6002 -j ACCEPT /usr/sbin/iptables -I INPUT -p tcp --dport 21000:22000 -j ACCEPT
|