# Generated by iptables-save v1.4.8 on Thu Apr 12 21:40:27 2012
*nat
REROUTING ACCEPT [61:3005]
OSTROUTING ACCEPT [6:240]
:OUTPUT ACCEPT [0:0]
-A PREROUTING -i eth1 -p tcp -m tcp --dport 25565 -j DNAT --to-destination 82.211.56.216
COMMIT
# Completed on Thu Apr 12 21:40:27 2012
# Generated by iptables-save v1.4.8 on Thu Apr 12 21:40:27 2012
*mangle
REROUTING ACCEPT [27016:36636338]
:INPUT ACCEPT [27016:36636338]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [14411:912957]
OSTROUTING ACCEPT [14411:912957]
COMMIT
# Completed on Thu Apr 12 21:40:27 2012
# Generated by iptables-save v1.4.8 on Thu Apr 12 21:40:27 2012
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:MY_DROP - [0:0]
:MY_REJECT - [0:0]
-A INPUT -p tcp -m tcp --dport 25565 -j ACCEPT
-A INPUT -m state --state INVALID -m limit --limit 2/sec -j LOG --log-prefix "INPUT INVALID "
-A INPUT -m state --state INVALID -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,ACK FIN -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags PSH,ACK PSH -j MY_DROP
-A INPUT -p tcp -m tcp --tcp-flags ACK,URG URG -j MY_DROP
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 3 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 4 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 12 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 465 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 995 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 993 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 119 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
-A INPUT -i venet0 -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 21 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
-A INPUT -i venet0 -p udp -m state --state NEW -m udp --dport 123 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 6060 -j ACCEPT
-A INPUT -i venet0 -p tcp -m state --state NEW -m tcp --dport 6667 -j ACCEPT
-A INPUT -j MY_REJECT
-A INPUT -p tcp -m tcp --dport 25565 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -p tcp -m state --state NEW -m tcp --dport 25565 -j ACCEPT
-A FORWARD -o eth0 -p tcp -m tcp --dport 25565 -j ACCEPT
-A FORWARD -i eth0 -p tcp -m tcp --sport 25565 -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 25565 -j ACCEPT
-A OUTPUT -m state --state INVALID -m limit --limit 2/sec -j LOG --log-prefix "OUTPUT INVALID "
-A OUTPUT -m state --state INVALID -j DROP
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT
-A OUTPUT -p icmp -m icmp --icmp-type 3 -j ACCEPT
-A OUTPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A OUTPUT -j MY_REJECT
-A OUTPUT -p tcp -m tcp --dport 25565 -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A MY_DROP -m limit --limit 2/sec -j LOG --log-prefix "PORTSCAN DROP "
-A MY_DROP -j DROP
-A MY_REJECT -p tcp -m limit --limit 2/sec -j LOG --log-prefix "REJECT TCP "
-A MY_REJECT -p tcp -j REJECT --reject-with tcp-reset
-A MY_REJECT -p udp -m limit --limit 2/sec -j LOG --log-prefix "REJECT UDP "
-A MY_REJECT -p udp -j REJECT --reject-with icmp-port-unreachable
-A MY_REJECT -p icmp -m limit --limit 2/sec -j LOG --log-prefix "DROP ICMP "
-A MY_REJECT -p icmp -j DROP
-A MY_REJECT -m limit --limit 2/sec -j LOG --log-prefix "REJECT OTHER "
-A MY_REJECT -j REJECT --reject-with icmp-proto-unreachable
COMMIT
# Completed on Thu Apr 12 21:40:27 2012