diff --git a/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v4 b/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v4 new file mode 100644 index 0000000..1f3bce0 --- /dev/null +++ b/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v4 @@ -0,0 +1,56 @@ +# Generated by iptables-save v1.6.1 on Thu Aug 22 02:25:12 2019 +*security +:INPUT ACCEPT [1978634:401612450] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [1760019:5887202636] +COMMIT +# Completed on Thu Aug 22 02:25:12 2019 +# Generated by iptables-save v1.6.1 on Thu Aug 22 02:25:12 2019 +*raw +:PREROUTING ACCEPT [1979278:401653128] +:OUTPUT ACCEPT [1816491:5891399408] +COMMIT +# Completed on Thu Aug 22 02:25:12 2019 +# Generated by iptables-save v1.6.1 on Thu Aug 22 02:25:12 2019 +*nat +:PREROUTING ACCEPT [8117:491527] +:INPUT ACCEPT [7525:453299] +:OUTPUT ACCEPT [88110:6323193] +:POSTROUTING ACCEPT [34162:2227657] +COMMIT +# Completed on Thu Aug 22 02:25:12 2019 +# Generated by iptables-save v1.6.1 on Thu Aug 22 02:25:12 2019 +*mangle +:PREROUTING ACCEPT [1979278:401653128] +:INPUT ACCEPT [1979278:401653128] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [1816491:5891399408] +:POSTROUTING ACCEPT [1760019:5887202636] +COMMIT +# Completed on Thu Aug 22 02:25:12 2019 +# Generated by iptables-save v1.6.1 on Thu Aug 22 02:25:12 2019 +*filter +:INPUT DROP [644:40678] +:FORWARD DROP [0:0] +:OUTPUT DROP [56472:4196772] +-A INPUT -s 185.6.8.3/32 -m comment --comment "domaincrawler.com aggressive crawler/bot" -j DROP +-A INPUT -s 185.6.8.7/32 -m comment --comment "domaincrawler.com aggressive crawler/bot" -j DROP +-A INPUT -s 173.244.135.0/24 -m comment --comment "infegy data collection" -j DROP +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -i lo -j ACCEPT +-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT +-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT +-A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT +-A INPUT -p tcp -m tcp --dport 5665 -j ACCEPT +-A INPUT -p tcp -m tcp --dport 4949 -j ACCEPT +-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A OUTPUT -o lo -j ACCEPT +-A OUTPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT +-A OUTPUT -p tcp -m multiport --dports 80,443 -j ACCEPT +-A OUTPUT -p udp -m udp --dport 53 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 587 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 5665 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT +COMMIT +# Completed on Thu Aug 22 02:25:12 2019 diff --git a/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v6 b/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v6 new file mode 100644 index 0000000..eee0c60 --- /dev/null +++ b/ubuntu/roles/firewall-ruleset-deploy/files/deirdre.asininetech.net.rules.v6 @@ -0,0 +1,62 @@ +# Generated by ip6tables-save v1.6.1 on Thu Aug 22 02:25:57 2019 +*nat +:PREROUTING ACCEPT [51379:4581191] +:INPUT ACCEPT [50755:4496846] +:OUTPUT ACCEPT [772065:72159452] +:POSTROUTING ACCEPT [245450:21607052] +COMMIT +# Completed on Thu Aug 22 02:25:57 2019 +# Generated by ip6tables-save v1.6.1 on Thu Aug 22 02:25:57 2019 +*security +:INPUT ACCEPT [5089056:5059987284] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [4713591:2067003702] +COMMIT +# Completed on Thu Aug 22 02:25:57 2019 +# Generated by ip6tables-save v1.6.1 on Thu Aug 22 02:25:57 2019 +*raw +:PREROUTING ACCEPT [5093764:5060319397] +:OUTPUT ACCEPT [5241795:2117654559] +COMMIT +# Completed on Thu Aug 22 02:25:57 2019 +# Generated by ip6tables-save v1.6.1 on Thu Aug 22 02:25:57 2019 +*mangle +:PREROUTING ACCEPT [5093767:5060319662] +:INPUT ACCEPT [5093720:5060315830] +:FORWARD ACCEPT [0:0] +:OUTPUT ACCEPT [5241798:2117654824] +:POSTROUTING ACCEPT [4713594:2067003967] +COMMIT +# Completed on Thu Aug 22 02:25:57 2019 +# Generated by ip6tables-save v1.6.1 on Thu Aug 22 02:25:57 2019 +*filter +:INPUT DROP [4661:328281] +:FORWARD DROP [0:0] +:OUTPUT DROP [528204:50650857] +:icmp_in - [0:0] +-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A INPUT -i lo -j ACCEPT +-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT +-A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT +-A INPUT -p tcp -m tcp --dport 5665 -j ACCEPT +-A INPUT -p tcp -m tcp --dport 4949 -j ACCEPT +-A INPUT -p ipv6-icmp -j icmp_in +-A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT +-A OUTPUT -o lo -j ACCEPT +-A OUTPUT -p tcp -m multiport --dports 80,443 -j ACCEPT +-A OUTPUT -p udp -m udp --dport 53 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 53 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 587 -j ACCEPT +-A OUTPUT -p ipv6-icmp -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 5665 -j ACCEPT +-A OUTPUT -p tcp -m tcp --dport 25 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 128 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 134 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 135 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 136 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 1 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 2 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 3 -j ACCEPT +-A icmp_in -p ipv6-icmp -m icmp6 --icmpv6-type 4 -j ACCEPT +COMMIT +# Completed on Thu Aug 22 02:25:57 2019