blob: 58b3e3e4400ae95ede4f07816f32cb9bf2b83984 [file] [log] [blame]
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +02001iptables:
2 schema:
3 epoch: 1
4 service:
5 v4:
6 enabled: true
7 modules:
8 - nf_conntrack_ftp
9 - nf_conntrack_pptp
10 v6:
11 enabled: false
12 modules:
13 - nf_conntrack_ipv6
14 defaults:
15 v4:
16 metadata_rules: false
17 policy: ACCEPT
18 ruleset:
19 action: ACCEPT
20 params: ""
21 rule: ""
22 v6:
23 metadata_rules: false
Dzmitry Stremkouskia5871a62018-11-07 23:04:36 +010024 policy: ACCEPT
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020025 ruleset:
26 action: ACCEPT
27 params: ""
28 rule: ""
29 tables:
30 v4:
31 filter:
32 chains:
Dzmitry Stremkouskia5871a62018-11-07 23:04:36 +010033 FORWARD:
34 policy: DROP
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020035 INPUT:
36 ruleset:
37 5:
38 action: log_drop
39 10:
40 rule: -s 192.168.0.0/24 -p tcp
41 log_drop:
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020042 ruleset:
43 10:
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020044 action: LOG
45 nat:
46 chains:
Dzmitry Stremkouski1ca901c2018-11-05 13:20:52 +010047 OUTPUT: {}
48 PREROUTING: {}
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020049 POSTROUTING:
50 policy: ACCEPT
51 ruleset:
52 10:
53 rule: -s 192.168.0.0/24 -p tcp -o lo
54 action: SNAT
55 params: --to-source=127.0.0.1
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020056 v6:
57 filter:
58 chains:
59 INPUT:
60 ruleset:
61 5:
62 action: log_drop
63 10:
64 rule: -s 200A:0:200C::1/64 -p tcp
65 log_drop:
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020066 ruleset:
67 10:
Dzmitry Stremkouskie353ce32018-08-30 17:22:32 +020068 action: LOG