Chain INPUT (policy ACCEPT)target prot opt source destination
ACCEPT all -- anywhere anywhere
DROP all -- 100.64.0.0/10 anywhere
DROP all -- 127.0.0.0/8 anywhere
DROP all -- 169.254.0.0/16 anywhere
DROP all -- 192.0.0.0/24 anywhere
DROP all -- 192.0.2.0/24 anywhere
DROP all -- 198.18.0.0/15 anywhere
DROP all -- 198.51.100.0/24 anywhere
DROP all -- 203.0.113.0/24 anywhere
DROP all -- base-address.mcast.net/4 anywhere
DROP all -- 240.0.0.0/4 anywhere
TMP_DROP all -- anywhere anywhere
TALLOW all -- anywhere anywhere
TDENY all -- anywhere anywhere
TGALLOW all -- anywhere anywhere
TGDENY all -- anywhere anywhere
DROP tcp -- anywhere anywhere tcp dpts:epmap:netbios-ssn
DROP udp -- anywhere anywhere udp dpts:epmap:netbios-ssn
DROP tcp -- anywhere anywhere tcp dpt:sunrpc
DROP udp -- anywhere anywhere udp dpt:sunrpc
DROP tcp -- anywhere anywhere tcp dpt:login
DROP udp -- anywhere anywhere udp dpt:who
DROP tcp -- anywhere anywhere tcp dpt:efs
DROP udp -- anywhere anywhere udp dpt:router
DROP tcp -- anywhere anywhere tcp dpt:microsoft-ds
DROP udp -- anywhere anywhere udp dpt:microsoft-ds
DROP tcp -- anywhere anywhere tcp dpt:ms-sql-s
DROP udp -- anywhere anywhere udp dpt:ms-sql-s
DROP tcp -- anywhere anywhere tcp dpt:ms-sql-m
DROP udp -- anywhere anywhere udp dpt:ms-sql-m
DROP tcp -- anywhere anywhere tcp dpt:search-agent
DROP udp -- anywhere anywhere udp dpt:search-agent
DROP tcp -- anywhere anywhere tcp dpt:ingreslock
DROP udp -- anywhere anywhere udp dpt:ingreslock
DROP tcp -- anywhere anywhere tcp dpt:ctx-bridge
DROP udp -- anywhere anywhere udp dpt:ctx-bridge
IN_SANITY all -- anywhere anywhere
FRAG_UDP all -- anywhere anywhere
PZERO all -- anywhere anywhere
P2P all -- anywhere anywhere
ACCEPT tcp -- anywhere pr.in.th tcp dpt:ftp
ACCEPT tcp -- anywhere pr.in.th tcp dpt:ssh
ACCEPT tcp -- anywhere pr.in.th tcp dpt:smtp
ACCEPT tcp -- anywhere pr.in.th tcp dpt:domain
ACCEPT tcp -- anywhere pr.in.th tcp dpt:http
ACCEPT tcp -- anywhere pr.in.th tcp dpt:pop3
ACCEPT tcp -- anywhere pr.in.th tcp dpt:sunrpc
ACCEPT tcp -- anywhere pr.in.th tcp dpt:imap
ACCEPT tcp -- anywhere pr.in.th tcp dpt:https
ACCEPT tcp -- anywhere pr.in.th tcp dpt:rockwell-csp2
ACCEPT tcp -- anywhere pr.in.th tcp dpt:filenet-rpc
ACCEPT udp -- anywhere pr.in.th udp dpt:domain
ACCEPT udp -- anywhere pr.in.th udp dpt:sunrpc
ACCEPT udp -- anywhere pr.in.th udp dpt:ipp
ACCEPT udp -- anywhere pr.in.th udp dpt:724
ACCEPT udp -- anywhere pr.in.th udp dpt:mdns
ACCEPT udp -- anywhere pr.in.th udp dpt:filenet-tms
ACCEPT udp -- anywhere pr.in.th udp dpt:32809
ACCEPT icmp -- anywhere pr.in.th icmp destination-unreachable limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere pr.in.th icmp redirect limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere pr.in.th icmp time-exceeded limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere pr.in.th icmp echo-reply limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere pr.in.th icmp type 30 limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere pr.in.th icmp echo-request limit: avg 30/sec burst 5
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:ftp
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:ssh
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:smtp
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:domain
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:http
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:pop3
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:sunrpc
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:imap
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:https
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:rockwell-csp2
ACCEPT tcp -- anywhere localhost.localdomain tcp dpt:filenet-rpc
ACCEPT udp -- anywhere localhost.localdomain udp dpt:domain
ACCEPT udp -- anywhere localhost.localdomain udp dpt:sunrpc
ACCEPT udp -- anywhere localhost.localdomain udp dpt:ipp
ACCEPT udp -- anywhere localhost.localdomain udp dpt:724
ACCEPT udp -- anywhere localhost.localdomain udp dpt:mdns
ACCEPT udp -- anywhere localhost.localdomain udp dpt:filenet-tms
ACCEPT udp -- anywhere localhost.localdomain udp dpt:32809
ACCEPT icmp -- anywhere localhost.localdomain icmp destination-unreachable limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere localhost.localdomain icmp redirect limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere localhost.localdomain icmp time-exceeded limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere localhost.localdomain icmp echo-reply limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere localhost.localdomain icmp type 30 limit: avg 30/sec burst 5
ACCEPT icmp -- anywhere localhost.localdomain icmp echo-request limit: avg 30/sec burst 5
DROP tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN state NEW
ACCEPT tcp -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT udp -- 103.22.180.14 anywhere udp spt:domain dpts:1023:65535
ACCEPT tcp -- 103.22.180.14 anywhere tcp spt:domain dpts:1023:65535
DROP tcp -- anywhere anywhere tcp spt:domain dpts:1023:65535
DROP udp -- anywhere anywhere udp spt:domain dpts:1023:65535
ACCEPT udp -- 103.22.183.40 anywhere udp spt:domain dpts:1023:65535
ACCEPT tcp -- 103.22.183.40 anywhere tcp spt:domain dpts:1023:65535
DROP tcp -- anywhere anywhere tcp spt:domain dpts:1023:65535
DROP udp -- anywhere anywhere udp spt:domain dpts:1023:65535
ACCEPT tcp -- anywhere anywhere tcp spts:1023:65535 dpt:ftp state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere multiport dports ftp,ftp-data state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere multiport dports ftp,ftp-data state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:ssh dpts:login:65535 state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spts:1024:65535 dpt:ssh flags:FIN,SYN,RST,ACK/SYN state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp dpt:ssh state ESTABLISHED
ACCEPT udp -- anywhere anywhere state NEW udp dpts:traceroute:33534
DROP tcp -- anywhere anywhere
DROP udp -- anywhere anywhere
DROP all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
DROP all -- anywhere 100.64.0.0/10
DROP all -- anywhere 127.0.0.0/8
DROP all -- anywhere 169.254.0.0/16
DROP all -- anywhere 192.0.0.0/24
DROP all -- anywhere 192.0.2.0/24
DROP all -- anywhere 198.18.0.0/15
DROP all -- anywhere 198.51.100.0/24
DROP all -- anywhere 203.0.113.0/24
DROP all -- anywhere base-address.mcast.net/4
DROP all -- anywhere 240.0.0.0/4
TMP_DROP all -- anywhere anywhere
TALLOW all -- anywhere anywhere
TDENY all -- anywhere anywhere
TGALLOW all -- anywhere anywhere
TGDENY all -- anywhere anywhere
DROP tcp -- anywhere anywhere tcp dpts:epmap:netbios-ssn
DROP udp -- anywhere anywhere udp dpts:epmap:netbios-ssn
DROP tcp -- anywhere anywhere tcp dpt:sunrpc
DROP udp -- anywhere anywhere udp dpt:sunrpc
DROP tcp -- anywhere anywhere tcp dpt:login
DROP udp -- anywhere anywhere udp dpt:who
DROP tcp -- anywhere anywhere tcp dpt:efs
DROP udp -- anywhere anywhere udp dpt:router
DROP tcp -- anywhere anywhere tcp dpt:microsoft-ds
DROP udp -- anywhere anywhere udp dpt:microsoft-ds
DROP tcp -- anywhere anywhere tcp dpt:ms-sql-s
DROP udp -- anywhere anywhere udp dpt:ms-sql-s
DROP tcp -- anywhere anywhere tcp dpt:ms-sql-m
DROP udp -- anywhere anywhere udp dpt:ms-sql-m
DROP tcp -- anywhere anywhere tcp dpt:search-agent
DROP udp -- anywhere anywhere udp dpt:search-agent
DROP tcp -- anywhere anywhere tcp dpt:ingreslock
DROP udp -- anywhere anywhere udp dpt:ingreslock
DROP tcp -- anywhere anywhere tcp dpt:ctx-bridge
DROP udp -- anywhere anywhere udp dpt:ctx-bridge
OUT_SANITY all -- anywhere anywhere
FRAG_UDP all -- anywhere anywhere
PZERO all -- anywhere anywhere
P2P all -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpts:1024:65535 state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere udp dpts:1024:65535 state RELATED,ESTABLISHED
ACCEPT udp -- anywhere 103.22.180.14 udp spts:1023:65535 dpt:domain
ACCEPT tcp -- anywhere 103.22.180.14 tcp spts:1023:65535 dpt:domain
ACCEPT udp -- anywhere 103.22.180.14 udp spts:1023:65535 dpt:domain
ACCEPT tcp -- anywhere 103.22.180.14 tcp spts:1023:65535 dpt:domain
ACCEPT udp -- anywhere 103.22.183.40 udp spts:1023:65535 dpt:domain
ACCEPT tcp -- anywhere 103.22.183.40 tcp spts:1023:65535 dpt:domain
ACCEPT udp -- anywhere 103.22.183.40 udp spts:1023:65535 dpt:domain
ACCEPT tcp -- anywhere 103.22.183.40 tcp spts:1023:65535 dpt:domain
ACCEPT tcp -- anywhere anywhere tcp spt:ftp dpts:1023:65535 state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere multiport dports ftp,ftp-data state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere multiport dports ftp,ftp-data state RELATED,ESTABLISHED
ACCEPT udp -- anywhere anywhere state NEW udp dpts:traceroute:33534
ACCEPT all -- anywhere anywhere
Chain FRAG_UDP (2 references)
target prot opt source destination
DROP udp -f anywhere anywhere
Chain IN_SANITY (1 references)
target prot opt source destination
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN
DROP tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST
DROP tcp -- anywhere anywhere tcp flags:FIN,RST/FIN,RST
DROP tcp -- anywhere anywhere tcp flags:FIN,ACK/FIN
DROP tcp -- anywhere anywhere tcp flags:ACK,URG/URG
DROP tcp -- anywhere anywhere tcp flags:PSH,ACK/PSH
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,PSH,URG
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,ACK,URG
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,SYN,RST,PSH,ACK,URG
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN
Chain OUT_SANITY (1 references)
target prot opt source destination
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE
DROP tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN
DROP tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST
DROP tcp -- anywhere anywhere tcp flags:FIN,RST/FIN,RST
DROP tcp -- anywhere anywhere tcp flags:FIN,ACK/FIN
DROP tcp -- anywhere anywhere tcp flags:PSH,ACK/PSH
DROP tcp -- anywhere anywhere tcp flags:ACK,URG/URG
Chain P2P (2 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere tcp dpt:kazaa reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:kazaa dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:kazaa reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:kazaa dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:3d-nfsd reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:3d-nfsd dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:3d-nfsd reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:3d-nfsd dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spts:1024:65534 dpts:smaclmgr:traversal reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spts:smaclmgr:traversal dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpts:smaclmgr:traversal reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:smaclmgr:traversal dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:6257 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:6257 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:6257 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:6257 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:6699 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:6699 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:6699 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:6699 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:gnutella-svc reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:gnutella-svc dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:gnutella-svc reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:gnutella-svc dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:gnutella-rtr reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:gnutella-rtr dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:gnutella-rtr reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:gnutella-rtr dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spts:1024:65534 dpts:6881:6889 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spts:6881:6889 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpts:6881:6889 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:6881:6889 dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:gnutella-svc reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:gnutella-svc dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:gnutella-svc reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:gnutella-svc dpts:1024:65534 reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp dpt:interwise reject-with icmp-port-unreachable
REJECT tcp -- anywhere anywhere tcp spt:interwise dpts:1024:65534 reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spts:1024:65534 dpt:interwise reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp spt:interwise dpts:1024:65534 reject-with icmp-port-unreachable
Chain PROHIBIT (0 references)
target prot opt source destination
REJECT all -- anywhere anywhere reject-with icmp-host-prohibited
Chain PZERO (2 references)
target prot opt source destination
DROP tcp -- anywhere anywhere tcp dpt:0
DROP udp -- anywhere anywhere udp dpt:0
DROP tcp -- anywhere anywhere tcp spt:0
DROP udp -- anywhere anywhere udp spt:0
Chain RESET (0 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere reject-with tcp-reset
Chain TALLOW (2 references)
target prot opt source destination
Chain TDENY (2 references)
target prot opt source destination
DROP all -- static-84-242-82-157.net.upcbroadband.cz anywhere
DROP all -- anywhere static-84-242-82-157.net.upcbroadband.cz
DROP all -- 220.172.191.31 anywhere
DROP all -- anywhere 220.172.191.31
DROP all -- 67-23-32-241.static.cloud-ips.com anywhere
DROP all -- anywhere 67-23-32-241.static.cloud-ips.com
DROP all -- 82.138.60.174 anywhere
DROP all -- anywhere 82.138.60.174
DROP all -- bomba.intrex.hu anywhere
DROP all -- anywhere bomba.intrex.hu
DROP all -- 60.12.251.5 anywhere
DROP all -- anywhere 60.12.251.5
DROP all -- 221.133.231.118 anywhere
DROP all -- anywhere 221.133.231.118
DROP all -- 218.78.187.14 anywhere
DROP all -- anywhere 218.78.187.14
DROP all -- 78.186.156.7.static.ttnet.com.tr anywhere
DROP all -- anywhere 78.186.156.7.static.ttnet.com.tr
DROP all -- 61.164.147.2 anywhere
DROP all -- anywhere 61.164.147.2
DROP all -- 222.80.184.46 anywhere
DROP all -- anywhere 222.80.184.46
DROP all -- 65.119.103.46 anywhere
DROP all -- anywhere 65.119.103.46
DROP all -- 101.44.1.135 anywhere
DROP all -- anywhere 101.44.1.135
DROP all -- 121.14.204.41 anywhere
DROP all -- anywhere 121.14.204.41
Chain TGALLOW (2 references)
target prot opt source destination
Chain TGDENY (2 references)
target prot opt source destination
Chain TMP_DROP (2 references)
target prot opt source destination
rule เยอะจนงง