Les régles iptables en place
iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
INETIN all – anywhere anywhere
ACCEPT all – localnet/24 anywhere
ACCEPT all – anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
INETIN all -- anywhere anywhere
INETOUT all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
INETOUT all -- anywhere anywhere
Chain DMZIN (0 references)
target prot opt source destination
Chain DMZOUT (0 references)
target prot opt source destination
Chain INETIN (2 references)
target prot opt source destination
LTREJECT all -- anywhere anywhere state INVALID
LTREJECT icmp -- anywhere anywhere icmp redirect
LTREJECT icmp -- anywhere anywhere icmp router-advertisement
LTREJECT icmp -- anywhere anywhere icmp router-solicitation
LTREJECT icmp -- anywhere anywhere icmptype 15
LTREJECT icmp -- anywhere anywhere icmptype 16
LTREJECT icmp -- anywhere anywhere icmp address-mask-request
LTREJECT icmp -- anywhere anywhere icmp address-mask-reply
ACCEPT icmp -- anywhere anywhere icmp echo-request limit: avg 50/sec burst 5
LTREJECT icmp -- anywhere anywhere icmp echo-request
TCPACCEPT tcp -- anywhere anywhere tcp dpt:ssh
TCPACCEPT tcp -- anywhere anywhere tcp dpt:http
TCPACCEPT tcp -- anywhere anywhere tcp dpt:https
UDPACCEPT udp -- anywhere anywhere udp dpt:domain
ACCEPT all -- anywhere anywhere state ESTABLISHED
TCPACCEPT tcp -- anywhere anywhere tcp dpts:1024:65535 state RELATED
UDPACCEPT udp -- anywhere anywhere udp dpts:1024:65535 state RELATED
LTREJECT all -- anywhere anywhere
Chain INETOUT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain LDROP (0 references)
target prot opt source destination
LOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "TCP Dropped "
LOG udp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "UDP Dropped "
LOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "ICMP Dropped "
LOG all -f anywhere anywhere limit: avg 2/sec burst 5 LOG level warning prefix "FRAGMENT Dropped "
DROP all -- anywhere anywhere
Chain LREJECT (0 references)
target prot opt source destination
LOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "TCP Rejected "
LOG udp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "UDP Rejected "
LOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "ICMP Rejected "
LOG all -f anywhere anywhere limit: avg 2/sec burst 5 LOG level warning prefix "FRAGMENT Rejected "
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain LTREJECT (13 references)
target prot opt source destination
LOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "TCP Rejected "
LOG udp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "UDP Rejected "
LOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 LOG level info prefix "ICMP Rejected "
LOG all -f anywhere anywhere limit: avg 2/sec burst 5 LOG level warning prefix "FRAGMENT Rejected "
TREJECT all -- anywhere anywhere
Chain TCPACCEPT (4 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN limit: avg 500/sec burst 5
LOG tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN limit: avg 2/sec burst 5 LOG level warning prefix "Possible SynFlood "
LTREJECT tcp -- anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcpflags:! FIN,SYN,RST,ACK/SYN
LOG all -- anywhere anywhere limit: avg 2/sec burst 5 LOG level warning prefix "Mismatch in TCPACCEPT "
LTREJECT all -- anywhere anywhere
Chain TREJECT (1 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
DROP icmp -- anywhere anywhere
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain UDPACCEPT (2 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere
LOG all -- anywhere anywhere limit: avg 2/sec burst 5 LOG level warning prefix "Mismatch on UDPACCEPT "
LTREJECT all -- anywhere anywhere
Chain ULDROP (0 references)
target prot opt source destination
ULOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LDROP_TCP" queue_threshold 1
ULOG udp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LDROP_UDP" queue_threshold 1
ULOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LDROP_ICMP" queue_threshold 1
ULOG all -f anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LDROP_FRAG" queue_threshold 1
DROP all -- anywhere anywhere
Chain ULREJECT (0 references)
target prot opt source destination
ULOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LREJECT_TCP" queue_threshold 1
ULOG udp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LREJECT_UDP" queue_threshold 1
ULOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LREJECT_UDP" queue_threshold 1
ULOG all -f anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LREJECT_FRAG" queue_threshold 1
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain ULTREJECT (0 references)
target prot opt source destination
ULOG tcp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LTREJECT_TCP" queue_threshold 1
ULOG udp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LTREJECT_UDP" queue_threshold 1
ULOG icmp -- anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LTREJECT_ICMP" queue_threshold 1
ULOG all -f anywhere anywhere limit: avg 2/sec burst 5 ULOG copy_range 0 nlgroup 1 prefix "LTREJECT_FRAG" queue_threshold 1
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
DROP icmp -- anywhere anywhere
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Le contenu du fichier resolv
#search psf-fr.net
nameserver 192.168.6.98
nameserver 8.8.8.8