user.rules 1.7 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647
  1. *filter
  2. :ufw-user-input - [0:0]
  3. :ufw-user-output - [0:0]
  4. :ufw-user-forward - [0:0]
  5. :ufw-before-logging-input - [0:0]
  6. :ufw-before-logging-output - [0:0]
  7. :ufw-before-logging-forward - [0:0]
  8. :ufw-user-logging-input - [0:0]
  9. :ufw-user-logging-output - [0:0]
  10. :ufw-user-logging-forward - [0:0]
  11. :ufw-after-logging-input - [0:0]
  12. :ufw-after-logging-output - [0:0]
  13. :ufw-after-logging-forward - [0:0]
  14. :ufw-logging-deny - [0:0]
  15. :ufw-logging-allow - [0:0]
  16. :ufw-user-limit - [0:0]
  17. :ufw-user-limit-accept - [0:0]
  18. ### RULES ###
  19. ### tuple ### allow any 22 0.0.0.0/0 any 0.0.0.0/0 in
  20. -A ufw-user-input -p tcp --dport 22 -j ACCEPT
  21. -A ufw-user-input -p udp --dport 22 -j ACCEPT
  22. ### tuple ### allow any 80 0.0.0.0/0 any 0.0.0.0/0 in
  23. -A ufw-user-input -p tcp --dport 80 -j ACCEPT
  24. -A ufw-user-input -p udp --dport 80 -j ACCEPT
  25. ### tuple ### allow any 443 0.0.0.0/0 any 0.0.0.0/0 in
  26. -A ufw-user-input -p tcp --dport 443 -j ACCEPT
  27. -A ufw-user-input -p udp --dport 443 -j ACCEPT
  28. ### END RULES ###
  29. ### LOGGING ###
  30. -A ufw-after-logging-input -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
  31. -A ufw-after-logging-forward -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
  32. -I ufw-logging-deny -m state --state INVALID -j RETURN -m limit --limit 3/min --limit-burst 10
  33. -A ufw-logging-deny -j LOG --log-prefix "[UFW BLOCK] " -m limit --limit 3/min --limit-burst 10
  34. -A ufw-logging-allow -j LOG --log-prefix "[UFW ALLOW] " -m limit --limit 3/min --limit-burst 10
  35. ### END LOGGING ###
  36. ### RATE LIMITING ###
  37. -A ufw-user-limit -m limit --limit 3/minute -j LOG --log-prefix "[UFW LIMIT BLOCK] "
  38. -A ufw-user-limit -j REJECT
  39. -A ufw-user-limit-accept -j ACCEPT
  40. ### END RATE LIMITING ###
  41. COMMIT