View Single Post
Chewgum
New Member
Join Date: Jan 2012
Old 06-06-2012 , 15:39   Re: Protecting your server!
Reply With Quote #59

The following commented stuff in this, if they're enabled, you can't connect to your ftp server if it's hosted on the same machine.

Code:
#$IPT -A INPUT -p tcp --syn -j DROP
#$IPT -A INPUT -m conntrack --ctstate NEW -p tcp --tcp-flags SYN,RST,ACK,FIN,URG,PSH SYN -j DROP
#$IPT -A INPUT -m conntrack --ctstate NEW -p tcp --tcp-flags SYN,RST,ACK,FIN,URG,PSH FIN -j DROP
#$IPT -A INPUT -m conntrack --ctstate NEW -p tcp --tcp-flags SYN,RST,ACK,FIN,URG,PSH ACK -j DROP
#$IPT -A INPUT -m conntrack --ctstate INVALID -p tcp ! --tcp-flags SYN,RST,ACK,FIN,URG,PSH SYN,RST,ACK,FIN,URG,PSH -j DROP
#$IPT -A INPUT -m conntrack --ctstate NEW -p tcp --tcp-flags SYN,RST,ACK,FIN,URG,PSH FIN,URG,PSH -j DROP
#$IPT -A INPUT -p UDP -f -j DROP
#$IPT -A INPUT -p TCP --syn -m iplimit --iplimit-above 9 -j DROP
#$IPT -A INPUT -m pkttype --pkt-type broadcast -j DROP
#$IPT -A INPUT -p ICMP --icmp-type echo-request -m pkttype --pkttype broadcast -j DROP
$IPT -A INPUT -p ICMP --icmp-type echo-request -m limit --limit 3/s -j ACCEPT
#$IPT -A INPUT -p TCP --syn -m iplimit --iplimit-above 3 -j DROP
#$IPT -A INPUT -p UDP -m pkttype --pkt-type broadcast -j DROP
$IPT -A INPUT -p UDP -m limit --limit 3/s -j ACCEPT
#$IPT -A INPUT -p ICMP -f -j DROP
Maybe I setup something wrong though.
Chewgum is offline