<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Sdogi's Script - Revision history</title>
		<link>https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.40.0</generator>
		<lastBuildDate>Wed, 08 Apr 2026 16:08:02 GMT</lastBuildDate>
		<item>
			<title>Erik: Copy from old</title>
			<link>https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;diff=177&amp;oldid=prev</link>
			<guid isPermaLink="false">https://www.slackwiki.com/index.php?title=Sdogi%27s_Script&amp;diff=177&amp;oldid=prev</guid>
			<description>&lt;p&gt;Copy from old&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Security]]&lt;br /&gt;
&amp;lt;pre&amp;gt;# Internet + sharing&lt;br /&gt;
adsl-start&lt;br /&gt;
iptables -F&lt;br /&gt;
iptables -X&lt;br /&gt;
iptables -t nat -F&lt;br /&gt;
iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o &amp;quot;ppp0&amp;quot; -j MASQUERADE&lt;br /&gt;
&lt;br /&gt;
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
iptables -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
# BANNED FROM LOGS&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 445 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 135 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 139 -j DROP&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 113 -j REJECT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2449 -j DROP&lt;br /&gt;
&lt;br /&gt;
# Forwarded or accepted&lt;br /&gt;
iptables -t nat -PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6002 -j DNAT --to 192.168.0.3&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1988 -j DNAT --to 192.168.0.2&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p udp --dport 1988 -j DNAT --to 192.168.0.2&lt;br /&gt;
iptables -t nat -A PREROUTING -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6666 -j DNAT --to 192.168.0.1:8000&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1984 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 13931 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8080 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8001 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 8000 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -s 192.168.0.4 -p tcp --dport 6000 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -s 192.168.0.4 -p udp --dport 177 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2086 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 31731 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2000:2500 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 6881:6889 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 9176 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 2234 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 5534 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 80 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 21 -j ACCEPT&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 22 -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# Log everything else to messages and drop them(logging is not really good idea because&lt;br /&gt;
# /var/log/messages can get full pretty fast. Look above for making them not show up in logs)&lt;br /&gt;
&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1:65535 -j LOG&lt;br /&gt;
iptables -A INPUT -i &amp;quot;ppp0&amp;quot; -p tcp --dport 1:65535 -j DROP&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</description>
			<pubDate>Sat, 06 Jun 2009 23:20:26 GMT</pubDate>
			<dc:creator>Erik</dc:creator>
			<comments>https://www.slackwiki.com/Talk:Sdogi%27s_Script</comments>
		</item>
</channel></rss>