NAT rules



  • Hey.

    want to ask if these rules can work.
    i used them on my Debian some years ago want to ask so i can change it before i lock my self out :p

    iptables -A INPUT -p tcp -m tcp –dport 2222 -j ACCEPT
    iptables -A INPUT -p tcp -m tcp --dport 8000 -j ACCEPT
    iptables -A INPUT -p tcp -m tcp --dport 8001 -j ACCEPT
    iptables -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
    iptables -A INPUT -p tcp -m tcp --dport 88 -j ACCEPT
    iptables -A INPUT -p tcp -m tcp --dport 8080 -j ACCEPT

    iptables -A INPUT -i lo -j ACCEPT
    iptables -A INPUT ! -i lo -d 127.0.0.0/8 -j REJECT
    iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
    iptables -A OUTPUT -j ACCEPT
    iptables -A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level 7
    iptables -A INPUT -j REJECT
    iptables -A FORWARD -j REJECT

    iptables -A INPUT -j DROP

    2222 - 80 - 8080 on pfsense
    and the other once on NAS



  • As written the rules won't work as there is no iptables in pfsense. But the rules will work if translated to of style rule in the GUI. There is already anti lock out rules in place.



  • i just copy/paste from old file.

    but thanks now i know a bit more


Locked