Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
input_int all -- anywhere anywhere
input_int all -- anywhere anywhere
input_int all -- anywhere anywhere
input_int all -- anywhere anywhere
input_int all -- anywhere anywhere
LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-IN-ILL-TARGET '
DROP all -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
ACCEPT all -- anywhere anywhere
forward_int all -- anywhere anywhere
forward_int all -- anywhere anywhere
forward_int all -- anywhere anywhere
forward_int all -- anywhere anywhere
LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWD-ILL-ROUTING '
DROP all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state NEW,RELATED,ESTABLISHED
LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-OUT-ERROR '
Chain forward_int (4 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp echo-reply
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp time-exceeded
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp parameter-problem
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp timestamp-reply
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp address-mask-reply
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp protocol-unreachable
ACCEPT icmp -- anywhere anywhere state RELATED,ESTABLISHED icmp redirect
LOG all -- anywhere anywhere limit: avg 3/min burst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
DROP all -- anywhere anywhere PKTTYPE = multicast
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT '
LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-FWDint-DROP-DEFLT-INV '
reject_func all -- anywhere anywhere
Chain input_int (5 references)
target prot opt source destination
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:177
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:631
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:123
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:427
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:137
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:138
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:67
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:5353
ACCEPT udp -- anywhere anywhere PKTTYPE = broadcast udp dpt:67
DROP all -- anywhere anywhere PKTTYPE = broadcast
ACCEPT icmp -- anywhere anywhere icmp source-quench
ACCEPT icmp -- anywhere anywhere icmp echo-request
ACCEPT esp -- anywhere anywhere
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:5801 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:5801
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:5901 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:5901
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:53 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:53
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:80 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:80
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:443 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:443
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:143 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:143
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:993 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:993
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:631 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:631
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:3260 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:3260
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:389 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:389
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:636 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:636
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:445 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:445
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:3306 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:3306
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:139 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:139
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:15001 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:15001
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:15002 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:15002
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:15003 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:15003
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:15004 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:15004
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:110 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:110
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:995 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:995
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:873 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:873
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:25 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:25
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:22 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:22
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:427 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:427
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:177 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:177
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:53 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:53
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:631 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:631
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:143 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:143
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:993 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:993
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:110 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:110
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:995 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:995
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:2000 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:2000
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:3306 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:3306
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:389 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:389
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:636 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:636
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:22 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:22
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:3690 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:3690
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpts:5800:5899 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpts:5800:5899
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpts:5900:5999 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpts:5900:5999
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:21 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:21
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:20 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:20
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:5801 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:5801
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp dpt:5901 flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-TCP '
ACCEPT tcp -- anywhere anywhere tcp dpt:5901
ACCEPT udp -- anywhere anywhere udp dpt:68
ACCEPT udp -- anywhere anywhere udp dpt:67
ACCEPT udp -- anywhere anywhere udp dpt:53
ACCEPT udp -- anywhere anywhere udp dpt:631
ACCEPT udp -- anywhere anywhere udp dpt:4500
ACCEPT udp -- anywhere anywhere udp dpt:500
ACCEPT udp -- anywhere anywhere udp dpt:138
ACCEPT udp -- anywhere anywhere udp dpt:137
ACCEPT udp -- anywhere anywhere udp dpt:123
ACCEPT udp -- anywhere anywhere udp dpt:15003
ACCEPT udp -- anywhere anywhere udp dpt:427
ACCEPT udp -- anywhere anywhere udp dpt:69
ACCEPT udp -- anywhere anywhere udp dpt:177
ACCEPT udp -- anywhere anywhere udp dpt:5353
ACCEPT udp -- anywhere anywhere udp dpt:53
ACCEPT udp -- anywhere anywhere udp dpt:631
ACCEPT udp -- anywhere anywhere udp dpt:67
ACCEPT udp -- anywhere anywhere udp dpt:389
ACCEPT udp -- anywhere anywhere udp dpt:20
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 state NEW udp dpt:111 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT udp -- anywhere anywhere udp dpt:111
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:111 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:111
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 state NEW udp dpt:32773 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT udp -- anywhere anywhere udp dpt:32773
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:54769 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:54769
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 state NEW udp dpt:2049 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT udp -- anywhere anywhere udp dpt:2049
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:2049 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:2049
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 state NEW udp dpt:32772 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT udp -- anywhere anywhere udp dpt:32772
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:60807 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:60807
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 state NEW udp dpt:32771 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT udp -- anywhere anywhere udp dpt:32771
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:60118 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:60118
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 state NEW tcp dpt:27116 LOG level warning tcp-options ip-options prefix `SFW2-INint-ACC-RPC '
ACCEPT tcp -- anywhere anywhere tcp dpt:27116
LOG all -- anywhere anywhere limit: avg 3/min burst 5 PKTTYPE = multicast LOG level warning tcp-options ip-options prefix `SFW2-INint-DROP-DEFLT '
DROP all -- anywhere anywhere PKTTYPE = multicast
LOG tcp -- anywhere anywhere limit: avg 3/min burst 5 tcp flags:FIN,SYN,RST,ACK/SYN LOG level warning tcp-options ip-options prefix `SFW2-INint-DROP-DEFLT '
LOG icmp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INint-DROP-DEFLT '
LOG udp -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning tcp-options ip-options prefix `SFW2-INint-DROP-DEFLT '
LOG all -- anywhere anywhere limit: avg 3/min burst 5 state INVALID LOG level warning tcp-options ip-options prefix `SFW2-INint-DROP-DEFLT-INV '
reject_func all -- anywhere anywhere
Chain reject_func (2 references)
target prot opt source destination
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable