LinuxHippy
2004-10-23, 06:01 PM CDT
I get a strange reading now from my iptables since I installed firestarter. Can I restore my iptables somehow? When I type (as root) /sbin/iptables-restore my pc just sits there until I interrupt it with CTRL-C.
This is what /sbin/iptables -L -v gives:
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- any any dslrouter anywhere tcp flags:!SYN,RST,ACK/SYN
706 93004 ACCEPT udp -- any any dslrouter anywhere
0 0 ACCEPT tcp -- any any dslrouter anywhere tcp flags:!SYN,RST,ACK/SYN
0 0 ACCEPT udp -- any any dslrouter anywhere
0 0 ACCEPT all -- any any clock2.redhat.com anywhere
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:33270
0 0 DROP udp -- any any anywhere anywhere udp dpt:33270
70 3826 ACCEPT all -- lo any anywhere anywhere
0 0 ACCEPT icmp -- any any anywhere 192.168.1.0/24 limit: avg 10/sec burst 5
348 181K NR all -- eth0 any !192.168.1.0/24 anywhere
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:31337 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:31337 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:33270 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:33270 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:1234 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:6711 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:16660 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:60001 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:135 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:135 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:ingreslock limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:27665 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:27444 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:31335 limit: avg 2/min burst 5
0 0 LD all -- any any BASE-ADDRESS.MCAST.NET/8 anywhere
0 0 LD all -- any any anywhere BASE-ADDRESS.MCAST.NET/8
0 0 LD all -- any any 255.255.255.255 anywhere
0 0 LD all -- any any anywhere 0.0.0.0
0 0 DROP all -- any any anywhere anywhere state INVALID
0 0 LD all -f any any anywhere anywhere limit: avg 10/min burst 5
0 0 ACCEPT tcp -- eth0 any anywhere anywhere tcp dpts:bootps:bootpc
0 0 ACCEPT udp -- eth0 any anywhere anywhere udp dpts:bootps:bootpc
0 0 LD tcp -- any any anywhere anywhere tcp flags:!SYN,RST,ACK/SYN state NEW
348 181K STATE tcp -- any any anywhere 192.168.1.0/24 tcp dpts:1024:65535
0 0 ACCEPT udp -- any any anywhere 192.168.1.0/24 udp dpts:1023:65535
0 0 LD all -- any any anywhere anywhere
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 16 packets, 1216 bytes)
pkts bytes target prot opt in out source destination
70 3826 ACCEPT all -- any lo anywhere anywhere
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:31337 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:31337 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:33270 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:33270 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:1234 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:6711 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:16660 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:60001 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:135 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:135 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:ingreslock limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:27665 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:27444 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:31335 limit: avg 2/min burst 5
0 0 LD all -- any any BASE-ADDRESS.MCAST.NET/8 anywhere
0 0 LD all -- any any anywhere BASE-ADDRESS.MCAST.NET/8
0 0 LD all -- any any 255.255.255.255 anywhere
0 0 LD all -- any any anywhere 0.0.0.0
0 0 DROP tcp -- any any anywhere anywhere tcp flags:!SYN,RST,ACK/SYN state NEW
0 0 DROP all -- any any anywhere anywhere state INVALID
1115 110K all -- any any anywhere anywhere TTL match TTL == 64
1 96 ACCEPT icmp -- any eth0 192.168.1.0/24 anywhere
1114 110K ACCEPT all -- any any anywhere anywhere
Chain LD (137 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- any any anywhere anywhere LOG level info
0 0 DROP all -- any any anywhere anywhere
Chain NR (1 references)
pkts bytes target prot opt in out source destination
0 0 LD all -- eth0 any 0.0.0.0/8 192.168.1.0/24
0 0 LD all -- eth0 any 1.0.0.0/8 192.168.1.0/24
0 0 LD all -- eth0 any 2.0.0.0/8 192.168.1.0/24
...etc.
This is what /sbin/iptables -L -v gives:
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- any any dslrouter anywhere tcp flags:!SYN,RST,ACK/SYN
706 93004 ACCEPT udp -- any any dslrouter anywhere
0 0 ACCEPT tcp -- any any dslrouter anywhere tcp flags:!SYN,RST,ACK/SYN
0 0 ACCEPT udp -- any any dslrouter anywhere
0 0 ACCEPT all -- any any clock2.redhat.com anywhere
0 0 DROP tcp -- any any anywhere anywhere tcp dpt:33270
0 0 DROP udp -- any any anywhere anywhere udp dpt:33270
70 3826 ACCEPT all -- lo any anywhere anywhere
0 0 ACCEPT icmp -- any any anywhere 192.168.1.0/24 limit: avg 10/sec burst 5
348 181K NR all -- eth0 any !192.168.1.0/24 anywhere
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:31337 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:31337 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:33270 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:33270 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:1234 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:6711 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:16660 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:60001 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:135 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:135 limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:ingreslock limit: avg 2/min burst 5
0 0 LD tcp -- any any anywhere 192.168.1.0/24 tcp dpt:27665 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:27444 limit: avg 2/min burst 5
0 0 LD udp -- any any anywhere 192.168.1.0/24 udp dpt:31335 limit: avg 2/min burst 5
0 0 LD all -- any any BASE-ADDRESS.MCAST.NET/8 anywhere
0 0 LD all -- any any anywhere BASE-ADDRESS.MCAST.NET/8
0 0 LD all -- any any 255.255.255.255 anywhere
0 0 LD all -- any any anywhere 0.0.0.0
0 0 DROP all -- any any anywhere anywhere state INVALID
0 0 LD all -f any any anywhere anywhere limit: avg 10/min burst 5
0 0 ACCEPT tcp -- eth0 any anywhere anywhere tcp dpts:bootps:bootpc
0 0 ACCEPT udp -- eth0 any anywhere anywhere udp dpts:bootps:bootpc
0 0 LD tcp -- any any anywhere anywhere tcp flags:!SYN,RST,ACK/SYN state NEW
348 181K STATE tcp -- any any anywhere 192.168.1.0/24 tcp dpts:1024:65535
0 0 ACCEPT udp -- any any anywhere 192.168.1.0/24 udp dpts:1023:65535
0 0 LD all -- any any anywhere anywhere
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 16 packets, 1216 bytes)
pkts bytes target prot opt in out source destination
70 3826 ACCEPT all -- any lo anywhere anywhere
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:31337 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:31337 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:33270 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:33270 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:1234 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:6711 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:16660 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:60001 flags:SYN,RST,ACK/SYN limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpts:12345:12346 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:135 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:135 limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:ingreslock limit: avg 2/min burst 5
0 0 LD tcp -- any any 192.168.1.0/24 anywhere tcp dpt:27665 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:27444 limit: avg 2/min burst 5
0 0 LD udp -- any any 192.168.1.0/24 anywhere udp dpt:31335 limit: avg 2/min burst 5
0 0 LD all -- any any BASE-ADDRESS.MCAST.NET/8 anywhere
0 0 LD all -- any any anywhere BASE-ADDRESS.MCAST.NET/8
0 0 LD all -- any any 255.255.255.255 anywhere
0 0 LD all -- any any anywhere 0.0.0.0
0 0 DROP tcp -- any any anywhere anywhere tcp flags:!SYN,RST,ACK/SYN state NEW
0 0 DROP all -- any any anywhere anywhere state INVALID
1115 110K all -- any any anywhere anywhere TTL match TTL == 64
1 96 ACCEPT icmp -- any eth0 192.168.1.0/24 anywhere
1114 110K ACCEPT all -- any any anywhere anywhere
Chain LD (137 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- any any anywhere anywhere LOG level info
0 0 DROP all -- any any anywhere anywhere
Chain NR (1 references)
pkts bytes target prot opt in out source destination
0 0 LD all -- eth0 any 0.0.0.0/8 192.168.1.0/24
0 0 LD all -- eth0 any 1.0.0.0/8 192.168.1.0/24
0 0 LD all -- eth0 any 2.0.0.0/8 192.168.1.0/24
...etc.