<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.slackwiki.com/index.php?action=history&amp;feed=atom&amp;title=Sdogi%27s_Script</id>
	<title>Sdogi's Script - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.slackwiki.com/index.php?action=history&amp;feed=atom&amp;title=Sdogi%27s_Script"/>
	<link rel="alternate" type="text/html" href="https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;action=history"/>
	<updated>2026-04-08T16:07:03Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.40.0</generator>
	<entry>
		<id>https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;diff=177&amp;oldid=prev</id>
		<title>Erik: Copy from old</title>
		<link rel="alternate" type="text/html" href="https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;diff=177&amp;oldid=prev"/>
		<updated>2009-06-06T23:20:26Z</updated>

		<summary type="html">&lt;p&gt;Copy from old&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Security]]&lt;br /&gt;
&amp;lt;pre&amp;gt;# Internet + sharing&lt;br /&gt;
adsl-start&lt;br /&gt;
iptables -F&lt;br /&gt;
iptables -X&lt;br /&gt;
iptables -t nat -F&lt;br /&gt;
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o &amp;quot;ppp0&amp;quot; -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
iptables -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
# BANNED FROM LOGS&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 445 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 135 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 139 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 113 -j REJECT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2449 -j DROP&lt;br /&gt;
&lt;br /&gt;
# Forwarded or accepted&lt;br /&gt;
iptables -t nat -PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6002 -j DNAT --to 192.168.0.3&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1988 -j DNAT --to 192.168.0.2&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p udp --dport 1988 -j DNAT --to 192.168.0.2&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6666 -j DNAT --to 192.168.0.1:8000&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1984 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 13931 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8080 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8001 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8000 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -s 192.168.0.4 -p tcp --dport 6000 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -s 192.168.0.4 -p udp --dport 177 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2086 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 31731 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2000:2500 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6881:6889 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 9176 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2234 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 5534 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 80 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 21 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 22 -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# Log everything else to messages and drop them(logging is not really good idea because&lt;br /&gt;
# /var/log/messages can get full pretty fast. Look above for making them not show up in logs)&lt;br /&gt;
&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1:65535 -j LOG&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1:65535 -j DROP&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Erik</name></author>
	</entry>
</feed>