1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
| -
!
-
|
|
!
-
|
|
|
!
-
!
-
!
-
!
-
|
|
|
!
-
!
-
|
|
|
!
-
|
|
|
!
-
|
|
|
!
-
!
-
!
-
!
-
!
-
|
|
!
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
!
-
!
-
!
-
|
|
|
!
-
!
-
!
|
LOCAL_NW="<ネットワークアドレス(e.g. 192.168.5.0/24)>"
modprobe ipt_state
modprobe ipt_LOG
modprobe ipt_REJECT
modprobe ipt_limit
iptables -F
iptables -t nat -F
iptables -X
iptables -Z
iptables -P FORWARD DROP
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -N drop_invalid_packet
iptables -A drop_invalid_packet -j LOG --log-prefix "Droped invalid packet: " -m limit --limit 1/m --limit-burst 3
iptables -A drop_invalid_packet -j DROP
iptables -N _drop_badflag_packet
iptables -A _drop_badflag_packet -j LOG --log-prefix "Droped bad flag packet: " -m limit --limit 1/m --limit-burst 3
iptables -A _drop_badflag_packet -j DROP
iptables -N drop_badflag_packet
iptables -A drop_badflag_packet -p tcp --tcp-flags ALL FIN,PSH,URG -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags ALL ALL -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags ALL NONE -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags ACK,FIN FIN -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags FIN,RST FIN,RST -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags SYN,FIN SYN,FIN -j _drop_badflag_packet iptables -A drop_badflag_packet -p tcp --tcp-flags SYN,RST SYN,RST -j _drop_badflag_packet
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p icmp -s $LOCAL_NW -j ACCEPT
iptables -A INPUT -p tcp -m state --state INVALID -j drop_invalid_packet
iptables -A INPUT -p tcp -j drop_badflag_packet
iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j ACCEPT
iptables -A INPUT -m pkttype --pkt-type MULTICAST -j DROP
iptables -A INPUT -m pkttype --pkt-type BROADCAST -j DROP
iptables -A INPUT -j LOG --log-prefix "Unexpected input: " -m limit --limit 1/m --limit-burst 3
iptables -A OUTPUT -o lo -j ACCEPT
iptables -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -j LOG --log-prefix "Unexpected output: " -m limit --limit 1/m --limit-burst 3
|