ASUSWRT-Merlin RT-AC3200 380.68-2 Mon Sep 11 21:45:15 UTC 2017
rhodess@Asus-Merlin:/tmp/home/root# iptables-save -t filter
# Generated by iptables-save v1.4.14 on Mon Nov 11 04:48:08 2019
*filter
:INPUT ACCEPT [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [760:150278]
:ACCESS_RESTRICTION - [0:0]
:FUPNP - [0:0]
:INPUT_ICMP - [0:0]
:NSFW - [0:0]
:PControls - [0:0]
:PTCSRVLAN - [0:0]
:PTCSRVWAN - [0:0]
:SECURITY - [0:0]
:SSHBFP - [0:0]
:dropkids - [0:0]
:iptfromlan - [0:0]
:ipttolan - [0:0]
:logaccept - [0:0]
:logdrop - [0:0]
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 8 -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -m state --state INVALID -j DROP
-A INPUT ! -i br0 -j PTCSRVWAN
-A INPUT -i br0 -j PTCSRVLAN
-A INPUT -i br0 -m state --state NEW -j ACCEPT
-A INPUT -i lo -m state --state NEW -j ACCEPT
-A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A INPUT -d 10.0.1.1/32 -p tcp -m conntrack --ctstate DNAT -m tcp --dport 8443 -j ACCEPT
-A INPUT -d 10.0.1.1/32 -p tcp -m conntrack --ctstate DNAT -m tcp --dport 80 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 2222 -m state --state NEW -j SSHBFP
-A INPUT -p tcp -m tcp --dport 8082 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 7443 -j ACCEPT
-A INPUT -p icmp -j INPUT_ICMP
-A INPUT -j DROP
-A FORWARD -m time --timestart 00:00:00 --timestop 08:59:00 --weekdays Fri,Sat --kerneltz -j dropkids
-A FORWARD -m time --timestart 02:00:00 --timestop 23:59:59 --weekdays Fri,Sat --kerneltz -j dropkids
-A FORWARD -m time --timestart 00:00:00 --timestop 07:15:00 --weekdays Mon,Tue,Wed,Thu,Sun --kerneltz -j dropkids
-A FORWARD -m time --timestart 23:30:00 --timestop 23:59:59 --weekdays Mon,Tue,Wed,Thu,Sun --kerneltz -j dropkids
-A FORWARD -o br0 -j ipttolan
-A FORWARD -i br0 -j iptfromlan
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD ! -i br0 -o eth0 -j DROP
-A FORWARD -i eth0 -m state --state INVALID -j DROP
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD -j NSFW
-A FORWARD -m conntrack --ctstate DNAT -j ACCEPT
-A FORWARD -i br0 -j ACCEPT
-A INPUT_ICMP -p icmp -m icmp --icmp-type 8 -j RETURN
-A INPUT_ICMP -p icmp -m icmp --icmp-type 13 -j RETURN
-A INPUT_ICMP -p icmp -j ACCEPT
-A PControls -j ACCEPT
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -j DROP
-A SECURITY -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j RETURN
-A SECURITY -p icmp -m icmp --icmp-type 8 -j DROP
-A SECURITY -j RETURN
-A SSHBFP -m recent --set --name SSH --rsource
-A SSHBFP -m recent --update --seconds 60 --hitcount 4 --name SSH --rsource -j DROP
-A SSHBFP -j ACCEPT
-A dropkids -d 10.0.1.111/32 -j DROP
-A dropkids -s 10.0.1.111/32 -j DROP
-A dropkids -d 10.0.1.234/32 -j DROP
-A dropkids -s 10.0.1.234/32 -j DROP
-A dropkids -d 10.0.1.118/32 -j DROP
-A dropkids -s 10.0.1.118/32 -j DROP
-A dropkids -d 10.0.1.151/32 -j DROP
-A dropkids -s 10.0.1.151/32 -j DROP
-A dropkids -d 10.0.1.190/32 -j DROP
-A dropkids -s 10.0.1.190/32 -j DROP
-A dropkids -m mac --mac-source 14:10:9F:D9:25:1D -j DROP
-A dropkids -m mac --mac-source B8:53:AC:9D:F7:B6 -j DROP
-A dropkids -m mac --mac-source 6C:AD:F8:86:41:B9 -j DROP
-A dropkids -m mac --mac-source 14:CC:20:1E:59:33 -j DROP
-A dropkids -m mac --mac-source 94:9A:A9:95:5F:A4 -j DROP
-A iptfromlan -o eth0 -m account--aaddr 10.0.1.0/255.255.255.0 --aname lan -j RETURN
-A ipttolan -i eth0 -m account--aaddr 10.0.1.0/255.255.255.0 --aname lan -j RETURN
-A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logaccept -j ACCEPT
-A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logdrop -j DROP
COMMIT
# Completed on Mon Nov 11 04:48:09 2019
rhodess@Asus-Merlin:/tmp/home/root#