木曜日, 4月 08, 2010

デスクトップLinux PCのおすすめiptablesルール

3年間位ローカルデスクトップのiptablesが順調で動いてます。下記はdump結果です、おすすめかな?
ーーーーーここからーーーーーーー
# iptables -v -L
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
663K 905M ACCEPT all -- any any anywhere anywhere state RELATED,ESTABLISHED
105 6300 ACCEPT all -- lo any anywhere anywhere
0 0 ACCEPT icmp -- any any anywhere anywhere icmp destination-unreachable
0 0 ACCEPT icmp -- any any anywhere anywhere icmp time-exceeded
0 0 ACCEPT icmp -- any any anywhere anywhere icmp source-quench
0 0 ACCEPT icmp -- any any anywhere anywhere icmp parameter-problem
0 0 DROP tcp -- any any anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN state NEW

Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
ーーーーーここ迄ーーーーーーーー

unixfreaxjp

0 件のコメント:

コメントを投稿