Toi, tu dois être MOA ou MOE ou chef de projet ou instit, vu le ton de tes réponses !!!
MDR


Voici :
# Generated by iptables-save v1.6.0 on Fri Jul 6 19:01:32 2018
*nat
:PREROUTING ACCEPT [76002:5360600]
:INPUT ACCEPT [2:104]
:OUTPUT ACCEPT [988:236525]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40001 -j DNAT --to-destination 192.168.1.161:40001
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40002 -j DNAT --to-destination 192.168.1.162:40002
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40003 -j DNAT --to-destination 192.168.1.164:40003
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40004 -j DNAT --to-destination 192.168.1.169:40004
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40006 -j DNAT --to-destination 192.168.1.166:40006
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40010 -j DNAT --to-destination 192.168.1.164:40010
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40021 -j DNAT --to-destination 192.168.1.166:40021
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40022 -j DNAT --to-destination 192.168.1.166:40022
-A PREROUTING -i eth0 -p tcp -m tcp --dport 40030 -j DNAT --to-destination 192.168.1.160:40030
-A PREROUTING -i eth0 -p tcp -m tcp --dport 614 -j DNAT --to-destination 192.168.1.160:614
-A PREROUTING -i eth0 -p tcp -m tcp --dport 615 -j DNAT --to-destination 192.168.1.161:615
-A PREROUTING -i eth0 -p tcp -m tcp --dport 616 -j DNAT --to-destination 192.168.1.162:616
-A PREROUTING -i eth0 -p tcp -m tcp --dport 617 -j DNAT --to-destination 192.168.1.164:617
-A PREROUTING -i eth0 -p tcp -m tcp --dport 619 -j DNAT --to-destination 192.168.1.169:619
-A POSTROUTING -j MASQUERADE
COMMIT
# Completed on Fri Jul 6 19:01:32 2018
# Generated by iptables-save v1.6.0 on Fri Jul 6 19:01:32 2018
*filter
:INPUT DROP [75511:5334948]
:FORWARD DROP [0:0]
:OUTPUT DROP [565:204275]
:CountryDrop - [0:0]
:DNSIn - [0:0]
:DNSOut - [0:0]
:EstablishedConn - [0:0]
:FTPOut - [0:0]
:HTTPIn - [0:0]
:HTTPOut - [0:0]
:HTTPSIn - [0:0]
:IncomingFrag - [0:0]
:IncomingNULL - [0:0]
:IncomingXMAS - [0:0]
:IntrusionDrop - [0:0]
:LocalBoucle - [0:0]
:MailServerHTTPS - [0:0]
:MailServerIn - [0:0]
:MailServerPingIn - [0:0]
:MailServerRoundcube - [0:0]
:MailServerSMTPExt - [0:0]
:MailServerSSHIn - [0:0]
:MySQLOut - [0:0]
:NFSOut - [0:0]
:NTPIn - [0:0]
:NTPOut - [0:0]
:NoScan - [0:0]
:PingIn - [0:0]
:PingOut - [0:0]
:SMTP - [0:0]
:SSHIn - [0:0]
:SYNPackets - [0:0]
-A INPUT -j IntrusionDrop
-A INPUT -j MailServerIn
-A INPUT -j MailServerHTTPS
-A INPUT -j MailServerSSHIn
-A INPUT -j MailServerPingIn
-A INPUT -j HTTPIn
-A INPUT -j HTTPSIn
-A INPUT -j NTPIn
-A INPUT -j DNSIn
-A INPUT -j SSHIn
-A INPUT -j PingIn
-A INPUT -j IncomingNULL
-A INPUT -j IncomingXMAS
-A INPUT -j IncomingFrag
-A INPUT -j SYNPackets
-A INPUT -j NoScan
-A INPUT -j CountryDrop
-A INPUT -j LocalBoucle
-A INPUT -j EstablishedConn
-A FORWARD -j IntrusionDrop
-A FORWARD -j CountryDrop
-A FORWARD -i eth0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j LOG --log-prefix "IPTables:"
-A FORWARD -j EstablishedConn
-A FORWARD -d 192.168.1.161/32 -p tcp -m tcp --dport 40001 -j ACCEPT
-A FORWARD -d 192.168.1.162/32 -p tcp -m tcp --dport 40002 -j ACCEPT
-A FORWARD -d 192.168.1.164/32 -p tcp -m tcp --dport 40003 -j ACCEPT
-A FORWARD -d 192.168.1.169/32 -p tcp -m tcp --dport 40004 -j ACCEPT
-A FORWARD -d 192.168.1.166/32 -p tcp -m tcp --dport 40006 -j ACCEPT
-A FORWARD -d 192.168.1.164/32 -p tcp -m tcp --dport 40010 -j ACCEPT
-A FORWARD -d 192.168.1.166/32 -p tcp -m tcp --dport 40021 -j ACCEPT
-A FORWARD -d 192.168.1.166/32 -p tcp -m tcp --dport 40022 -j ACCEPT
-A FORWARD -d 192.168.1.160/32 -p tcp -m tcp --dport 40030 -j ACCEPT
-A FORWARD -d 192.168.1.160/32 -p tcp -m tcp --dport 614 -j ACCEPT
-A FORWARD -d 192.168.1.161/32 -p tcp -m tcp --dport 615 -j ACCEPT
-A FORWARD -d 192.168.1.162/32 -p tcp -m tcp --dport 616 -j ACCEPT
-A FORWARD -d 192.168.1.164/32 -p tcp -m tcp --dport 617 -j ACCEPT
-A FORWARD -d 192.168.1.169/32 -p tcp -m tcp --dport 619 -j ACCEPT
-A OUTPUT -j IntrusionDrop
-A OUTPUT -j MailServerSMTPExt
-A OUTPUT -j MailServerRoundcube
-A OUTPUT -j SMTP
-A OUTPUT -j NFSOut
-A OUTPUT -j FTPOut
-A OUTPUT -j HTTPOut
-A OUTPUT -j NTPOut
-A OUTPUT -j DNSOut
-A OUTPUT -j PingOut
-A OUTPUT -j CountryDrop
-A OUTPUT -j LocalBoucle
-A OUTPUT -j MySQLOut
-A OUTPUT -j EstablishedConn
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.160/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.161/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.162/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.164/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.169/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.199/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.167/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.160/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.161/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.162/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.164/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.169/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.199/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.166/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 192.168.1.1/32 -d 192.168.1.167/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.160/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.161/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.162/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.164/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.169/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.199/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.167/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.160/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.161/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.162/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.164/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.169/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.199/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.166/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSIn -s 1.1.1.1/32 -d 192.168.1.167/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSOut -s 192.168.1.199/32 -d 192.168.1.1/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSOut -s 192.168.1.199/32 -d 192.168.1.1/32 -p udp -m udp --dport 53 -j ACCEPT
-A DNSOut -s 192.168.1.199/32 -d 1.1.1.1/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A DNSOut -s 192.168.1.199/32 -d 1.1.1.1/32 -p udp -m udp --dport 53 -j ACCEPT
-A EstablishedConn -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FTPOut -s 192.168.1.161/32 -p tcp -m multiport --dports 20,21 -j ACCEPT
-A FTPOut -s 192.168.1.162/32 -p tcp -m multiport --dports 20,21 -j ACCEPT
-A FTPOut -s 192.168.1.164/32 -p tcp -m multiport --dports 20,21 -j ACCEPT
-A FTPOut -s 192.168.1.169/32 -p tcp -m multiport --dports 20,21 -j ACCEPT
-A FTPOut -s 192.168.1.199/32 -p tcp -m multiport --dports 20,21 -j ACCEPT
-A HTTPIn -d 192.168.1.160/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.161/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.162/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.164/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.169/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.199/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.166/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.167/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPIn -d 192.168.1.199/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPOut -s 192.168.1.199/32 -p tcp -m tcp --dport 80 -j ACCEPT
-A HTTPSIn -d 192.168.1.199/32 -p tcp -m tcp --dport 40099 -j ACCEPT
-A IncomingFrag -f -j DROP
-A IncomingNULL -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A IncomingXMAS -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A IntrusionDrop -s 103.207.37.40/32 -j DROP
-A IntrusionDrop -s 195.22.125.28/32 -j DROP
-A IntrusionDrop -s 103.207.38.153/32 -j DROP
-A IntrusionDrop -s 124.29.246.106/32 -j DROP
-A IntrusionDrop -s 103.207.38.156/32 -j DROP
-A IntrusionDrop -s 190.120.191.18/32 -j DROP
-A IntrusionDrop -s 189.198.156.86/32 -j DROP
-A IntrusionDrop -s 177.241.45.125/32 -j DROP
-A IntrusionDrop -s 203.81.71.8/32 -j DROP
-A IntrusionDrop -s 80.82.70.118/32 -j DROP
-A IntrusionDrop -s 80.211.144.224/32 -j DROP
-A IntrusionDrop -s 179.145.4.47/32 -j DROP
-A IntrusionDrop -s 177.143.177.73/32 -j DROP
-A IntrusionDrop -s 190.94.207.55/32 -j DROP
-A IntrusionDrop -s 195.22.125.27/32 -j DROP
-A IntrusionDrop -s 201.240.21.238/32 -j DROP
-A IntrusionDrop -s 201.141.38.55/32 -j DROP
-A IntrusionDrop -s 104.152.52.23/32 -j DROP
-A IntrusionDrop -s 186.237.60.151/32 -j DROP
-A IntrusionDrop -s 192.241.192.50/32 -j DROP
-A IntrusionDrop -s 93.88.76.73/32 -j DROP
-A IntrusionDrop -s 188.166.164.162/32 -j DROP
-A IntrusionDrop -s 107.170.230.58/32 -j DROP
-A IntrusionDrop -s 37.49.224.67/32 -j DROP
-A IntrusionDrop -s 193.169.252.20/32 -j DROP
-A IntrusionDrop -s 107.170.228.78/32 -j DROP
-A IntrusionDrop -s 193.169.252.21/32 -j DROP
-A IntrusionDrop -s 185.234.216.190/32 -j DROP
-A IntrusionDrop -s 192.241.234.202/32 -j DROP
-A IntrusionDrop -s 37.49.227.115/32 -j DROP
-A IntrusionDrop -s 91.234.99.217/32 -j DROP
-A IntrusionDrop -s 107.170.253.114/32 -j DROP
-A IntrusionDrop -s 107.170.228.177/32 -j DROP
-A IntrusionDrop -s 36.108.169.195/32 -j DROP
-A IntrusionDrop -s 162.243.131.219/32 -j DROP
-A IntrusionDrop -s 37.49.224.85/32 -j DROP
-A IntrusionDrop -s 107.170.228.237/32 -j DROP
-A IntrusionDrop -s 89.40.123.58/32 -j DROP
-A IntrusionDrop -s 37.49.227.18/32 -j DROP
-A IntrusionDrop -s 107.170.232.18/32 -j DROP
-A IntrusionDrop -s 190.64.208.82/32 -j DROP
-A IntrusionDrop -s 107.170.231.162/32 -j DROP
-A IntrusionDrop -s 80.82.77.17/32 -j DROP
-A IntrusionDrop -s 37.49.227.8/32 -j DROP
-A IntrusionDrop -s 185.234.218.152/32 -j DROP
-A IntrusionDrop -s 107.170.230.111/32 -j DROP
-A IntrusionDrop -s 171.34.218.167/32 -j DROP
-A IntrusionDrop -s 124.243.245.66/32 -j DROP
-A IntrusionDrop -s 107.170.229.125/32 -j DROP
-A IntrusionDrop -s 192.241.208.242/32 -j DROP
-A IntrusionDrop -s 78.190.211.219/32 -j DROP
-A IntrusionDrop -s 190.216.251.102/32 -j DROP
-A IntrusionDrop -s 89.216.97.200/32 -j DROP
-A IntrusionDrop -s 143.0.253.238/32 -j DROP
-A IntrusionDrop -s 216.230.135.58/32 -j DROP
-A IntrusionDrop -s 148.244.195.230/32 -j DROP
-A IntrusionDrop -s 58.82.247.152/32 -j DROP
-A IntrusionDrop -s 195.216.244.171/32 -j DROP
-A IntrusionDrop -s 107.170.254.21/32 -j DROP
-A IntrusionDrop -s 177.189.229.21/32 -j DROP
-A IntrusionDrop -s 162.243.132.162/32 -j DROP
-A IntrusionDrop -s 37.49.224.117/32 -j DROP
-A IntrusionDrop -s 115.231.212.82/32 -j DROP
-A IntrusionDrop -s 210.14.78.91/32 -j DROP
-A IntrusionDrop -s 84.21.28.154/32 -j DROP
-A IntrusionDrop -s 107.170.229.36/32 -j DROP
-A IntrusionDrop -s 104.152.52.24/32 -j DROP
-A IntrusionDrop -s 192.241.210.75/32 -j DROP
-A IntrusionDrop -s 185.234.216.139/32 -j DROP
-A IntrusionDrop -s 205.209.234.98/32 -j DROP
-A IntrusionDrop -s 89.248.171.89/32 -j DROP
-A IntrusionDrop -s 195.22.126.39/32 -j DROP
-A IntrusionDrop -s 46.98.90.64/32 -j DROP
-A IntrusionDrop -s 117.5.147.77/32 -j DROP
-A IntrusionDrop -s 151.21.126.179/32 -j DROP
-A IntrusionDrop -s 89.248.160.156/32 -j DROP
-A IntrusionDrop -s 198.23.59.118/32 -j DROP
-A IntrusionDrop -s 107.170.230.160/32 -j DROP
-A IntrusionDrop -s 93.174.93.251/32 -j DROP
-A IntrusionDrop -s 107.170.231.45/32 -j DROP
-A IntrusionDrop -s 185.234.218.133/32 -j DROP
-A IntrusionDrop -s 217.61.20.236/32 -j DROP
-A IntrusionDrop -s 103.236.253.45/32 -j DROP
-A IntrusionDrop -s 91.234.99.212/32 -j DROP
-A IntrusionDrop -s 193.169.252.131/32 -j DROP
-A IntrusionDrop -s 193.169.252.130/32 -j DROP
-A IntrusionDrop -s 186.10.186.64/32 -j DROP
-A IntrusionDrop -s 192.241.232.150/32 -j DROP
-A IntrusionDrop -s 52.172.35.173/32 -j DROP
-A IntrusionDrop -s 107.170.254.144/32 -j DROP
-A IntrusionDrop -s 37.49.227.144/32 -j DROP
-A IntrusionDrop -s 89.248.171.134/32 -j DROP
-A IntrusionDrop -s 27.79.242.191/32 -j DROP
-A IntrusionDrop -s 203.202.246.49/32 -j DROP
-A IntrusionDrop -s 115.73.182.89/32 -j DROP
-A LocalBoucle -i lo -j ACCEPT
-A LocalBoucle -o lo -j ACCEPT
-A MailServerHTTPS -d 192.168.1.160/32 -p tcp -m tcp --dport 40030 -j ACCEPT
-A MailServerIn -d 192.168.1.160/32 -p tcp -m tcp --dport 25 -j ACCEPT
-A MailServerIn -d 192.168.1.160/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 993 -j ACCEPT
-A MailServerIn -d 192.168.1.160/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 587 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source D4:3D:7E:50:26:90 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source B8:27:EB:75:85:AD -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source B8:27:EB:FE:4C:A5 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source B8:27:EB:73:DE:B9 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source 00:11:32:68:6C:25 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source 00:11:32:68:6C:26 -j ACCEPT
-A MailServerPingIn -d 192.168.1.160/32 -p icmp -m mac --mac-source B8:27:EB:D9:81:01 -j ACCEPT
-A MailServerRoundcube -d 192.168.1.166/32 -p tcp -m tcp --dport 40006 -j ACCEPT
-A MailServerSMTPExt -s 192.168.1.160/32 -p tcp -m tcp --dport 25 -j ACCEPT
-A MailServerSMTPExt -s 192.168.1.160/32 -p tcp -m tcp --dport 587 -j ACCEPT
-A MailServerSSHIn -d 192.168.1.160/32 -p tcp -m mac --mac-source B8:27:EB:FE:4C:A5 -m tcp --dport 614 -j ACCEPT
-A MailServerSSHIn -d 192.168.1.160/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 614 -j ACCEPT
-A MySQLOut -s 192.168.1.160/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A MySQLOut -s 192.168.1.161/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A MySQLOut -s 192.168.1.162/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A MySQLOut -s 192.168.1.164/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A MySQLOut -s 192.168.1.169/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A MySQLOut -s 192.168.1.199/32 -d 192.168.1.166/32 -p tcp -m tcp --dport 3306 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p tcp -m tcp --dport 111 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p udp -m udp --dport 111 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p udp -m udp --dport 2049 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p tcp -m tcp --dport 2049 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p udp -m udp --dport 892 -j ACCEPT
-A NFSOut -s 192.168.1.199/32 -d 192.168.1.167/32 -p tcp -m tcp --dport 892 -j ACCEPT
-A NTPIn -d 192.168.1.160/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.161/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.162/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.164/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.169/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.199/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.166/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPIn -d 192.168.1.167/32 -p udp -m udp --sport 123 -j ACCEPT
-A NTPOut -s 192.168.1.199/32 -p udp -m udp --dport 123 -j ACCEPT
-A NoScan -i eth0 -p tcp -m tcp --tcp-flags FIN,PSH,URG FIN,PSH,URG -j DROP
-A NoScan -i eth0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A NoScan -i eth0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A NoScan -i eth0 -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
-A NoScan -i eth0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -j DROP
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source D4:3D:7E:50:26:90 -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source B8:27:EB:79:30:DB -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source B8:27:EB:75:85:AD -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source B8:27:EB:FE:4C:A5 -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source 00:11:32:68:6C:25 -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source 00:11:32:68:6C:26 -j ACCEPT
-A PingIn -d 192.168.1.199/32 -p icmp -m mac --mac-source B8:27:EB:73:DE:B9 -j ACCEPT
-A PingOut -s 192.168.1.199/32 -p icmp -j ACCEPT
-A SMTP -s 192.168.1.199/32 -d 192.168.1.160/32 -p tcp -m tcp --dport 25 -j ACCEPT
-A SSHIn -d 192.168.1.164/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 617 -j ACCEPT
-A SSHIn -d 192.168.1.164/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 617 -j ACCEPT
-A SSHIn -d 192.168.1.160/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 614 -j ACCEPT
-A SSHIn -d 192.168.1.160/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 614 -j ACCEPT
-A SSHIn -d 192.168.1.161/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 615 -j ACCEPT
-A SSHIn -d 192.168.1.161/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 615 -j ACCEPT
-A SSHIn -d 192.168.1.162/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 616 -j ACCEPT
-A SSHIn -d 192.168.1.162/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 616 -j ACCEPT
-A SSHIn -d 192.168.1.169/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 619 -j ACCEPT
-A SSHIn -d 192.168.1.169/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 619 -j DROP
-A SSHIn -d 192.168.1.199/32 -p tcp -m mac --mac-source D4:3D:7E:50:26:90 -m tcp --dport 699 -j ACCEPT
-A SSHIn -d 192.168.1.199/32 -p tcp -m mac --mac-source 64:7C:34:62:78:08 -m tcp --dport 699 -j ACCEPT
-A SSHIn -d 192.168.1.199/32 -p tcp -m mac --mac-source B8:27:EB:FE:4C:A5 -m tcp --dport 699 -j ACCEPT
-A SYNPackets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
COMMIT
# Completed on Fri Jul 6 19:01:32 2018