|
On the second snapshopt I uploaded, aMule had been running for a day and 23 hours, but this time the failed stats are very diferent, for the first server shown I'd say something on the server wen't wrong for a period of time, but for the others I dunno.
As some aditional info Kry, I'll show you my iptables settings, please look at it to see if you find something that proves that this problem is firewall related. I leave out the ISP cuz with 2.0.3 I had no such problems.
IPTABLES RULES:
/sbin/iptables -A PREROUTING -s 10.1.0.0/255.255.255.0 -d ! 10.1.0.0/255.255.255.0 -j RETURN
/sbin/iptables -A POSTROUTING -s 10.1.0.0/255.255.255.0 -o ppp0 -j MASQUERADE
/sbin/iptables -A FORWARD -p icmp -j MARK --set-mark 0x1
/sbin/iptables -A FORWARD -p tcp -m tcp --dport 22 -j MARK --set-mark 0x1
/sbin/iptables -A FORWARD -p ! tcp -j MARK --set-mark 0x1
/sbin/iptables -A FORWARD -p tcp -m tcp --dport 993 -j MARK --set-mark 0x2
/sbin/iptables -A FORWARD -p tcp -m tcp --dport 25 -j MARK --set-mark 0x2
/sbin/iptables -A FORWARD -p tcp -m tcp --dport 80 -j MARK --set-mark 0x3
/sbin/iptables -A FORWARD -p tcp -m tcp --dport 443 -j MARK --set-mark 0x3
/sbin/iptables -A FORWARD -p tcp -m length --length 1024:65535 -j MARK --set-mark 0x4
/sbin/iptables -A FORWARD -p tcp -m tos --tos Minimize-Delay -m mark --mark 0x0 -j MARK --set-mark 0x1
/sbin/iptables -A FORWARD -p tcp -m tos --tos Maximize-Throughput -m mark --mark 0x0 -j MARK --set-mark 0x2
/sbin/iptables -A FORWARD -p tcp -m tos --tos Minimize-Cost -m mark --mark 0x0 -j MARK --set-mark 0x4
/sbin/iptables -A FORWARD -p tcp -m connmark --mark 0x4 -j CONNMARK --restore-mark
/sbin/iptables -A FORWARD -p tcp -m mark ! --mark 0x0 -j ACCEPT
/sbin/iptables -A FORWARD -p tcp -j CONNMARK --save-mark
/sbin/iptables -A OUTPUT -p icmp -j MARK --set-mark 0x1
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 22 -j MARK --set-mark 0x1
/sbin/iptables -A OUTPUT -p ! tcp -j MARK --set-mark 0x1
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 993 -j MARK --set-mark 0x2
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 25 -j MARK --set-mark 0x2
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 80 -j MARK --set-mark 0x3
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 443 -j MARK --set-mark 0x3
/sbin/iptables -A OUTPUT -p icmp -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 20 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 20 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 22 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 20 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 25 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p udp -m udp --dport 53 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 63 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 80 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 110 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 113 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 123 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 143 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 443 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 993 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 995 -j TOS --set-tos 0x08
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 1080 -j TOS --set-tos 0x10
/sbin/iptables -A OUTPUT -p tcp -m tcp --dport 6000:6063 -j TOS --set-tos 0x08
/sbin/iptables -A POSTROUTING -j NATCLOAK
/sbin/iptables -A POSTROUTING -p tcp -m tcp --dport 22 -j MARK --set-mark 0x1
/sbin/iptables -A NATCLOAK -p udp -m udp --dport 33434:33500 -m length --length 38 -j RETURN
/sbin/iptables -A NATCLOAK -p icmp -m icmp --icmp-type 8 -m length --length 92 -j RETURN
/sbin/iptables -A NATCLOAK -j TTL --ttl-set 126
/sbin/iptables -A INPUT -s 69.60.121.185 -j DROP
/sbin/iptables -A INPUT -s 213.58.135.0/255.255.255.0 -p tcp -m tcp --dport 22
/sbin/iptables -A INPUT -s 81.56.215.125 -p tcp -m tcp --dport 22
/sbin/iptables -A INPUT -s 222.234.2.94 -j DROP
/sbin/iptables -A INPUT -s 84.246.224.195 -j DROP
/sbin/iptables -A INPUT -s 220.247.217.189 -j DROP
/sbin/iptables -A INPUT -s 66.34.134.223 -j DROP
/sbin/iptables -A INPUT -s 144.16.72.194 -j DROP
/sbin/iptables -A INPUT -s 193.198.20.51 -j DROP
/sbin/iptables -A INPUT -s 212.27.35.89 -j DROP
/sbin/iptables -A INPUT -s 64.202.167.129 -j DROP
/sbin/iptables -A INPUT -s 200.46.192.133 -j DROP
/sbin/iptables -A INPUT -s 81.233.245.217 -j DROP
/sbin/iptables -A INPUT -s 165.229.167.184 -j DROP
/sbin/iptables -A INPUT -s 210.196.130.229 -j DROP
/sbin/iptables -A INPUT -s 61.183.207.75 -j DROP
/sbin/iptables -A INPUT -s 202.170.95.5 -j DROP
/sbin/iptables -A INPUT -s 84.244.6.93 -j DROP
/sbin/iptables -A INPUT -s 213.223.64.10 -j DROP
/sbin/iptables -A INPUT -s 129.255.41.244 -j DROP
/sbin/iptables -A INPUT -s 62.89.253.51 -j DROP
/sbin/iptables -A INPUT -s 203.84.237.70 -j DROP
/sbin/iptables -A INPUT -s 217.199.179.132 -j DROP
/sbin/iptables -A INPUT -s 65.173.161.240 -j DROP
/sbin/iptables -A INPUT -s 203.131.168.19 -j DROP
/sbin/iptables -A INPUT -s 200.25.146.174 -j DROP
/sbin/iptables -A INPUT -s 203.232.183.98 -j DROP
/sbin/iptables -A INPUT -s 220.130.163.6 -j DROP
/sbin/iptables -A INPUT -s 24.77.25.183 -j DROP
/sbin/iptables -A INPUT -s 200.54.64.28 -j DROP
/sbin/iptables -A INPUT -s 61.111.255.133 -j DROP
/sbin/iptables -A INPUT -s 81.233.41.246 -j DROP
/sbin/iptables -A INPUT -s 193.82.97.2 -j DROP
/sbin/iptables -A INPUT -s 200.46.17.88 -j DROP
/sbin/iptables -A INPUT -s 85.17.1.53 -j DROP
/sbin/iptables -A INPUT -s 218.4.45.14 -j DROP
/sbin/iptables -A INPUT -s 80.55.51.150 -j DROP
/sbin/iptables -A INPUT -s 59.120.175.194 -j DROP
/sbin/iptables -A INPUT -s 62.220.134.143 -j DROP
/sbin/iptables -A INPUT -s 144.16.79.70 -j DROP
/sbin/iptables -A INPUT -s 218.153.147.92 -j DROP
/sbin/iptables -A INPUT -s 85.36.253.29 -j DROP
/sbin/iptables -A INPUT -s 61.97.32.29 -j DROP
/sbin/iptables -A INPUT -s 147.202.40.223 -j DROP
/sbin/iptables -A INPUT -s 10.1.0.0/255.255.255.0 -i eth1 -m state --state NEW -j ACCEPT
/sbin/iptables -A INPUT -i lo -m state --state NEW -j ACCEPT
/sbin/iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A INPUT -s 0.0.0.1 -i eth1 -j LOG --log-prefix "IPKF_IPKungFu "
/sbin/iptables -A INPUT -m recent --rcheck --seconds 120 --name badguy --rsource -j DROP
/sbin/iptables -A INPUT -s 10.1.0.0/255.255.255.0 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_ALL: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_NONE: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_PORTSCAN_nmap_XMAS: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -m limit --limit 3/sec -j LOG --log-prefix "IPKF_PORTSCAN_nmap_FIN: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_SYN_FIN: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_SYN_RST: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_SYN_RST_ACK_FIN_URG: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m limit --limit 3/sec -j LOG --log-prefix "IPKF_PORTSCAN_nmap_NULL: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
/sbin/iptables -A INPUT -p tcp -m state --state INVALID -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Invalid_TCP_Flag: "
/sbin/iptables -A INPUT -m state --state INVALID -j DROP
/sbin/iptables -A INPUT -i ppp0 -p icmp -m icmp --icmp-type 13 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_ICMP_Timestamp: "
/sbin/iptables -A INPUT -i ppp0 -p icmp -m icmp --icmp-type 13 -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn-flood
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -m limit --limit 3/sec -j LOG --log-prefix "IPKF_New_Not_SYN: "
/sbin/iptables -A INPUT -i ppp0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m multiport --dports 137,6666 -j DROP
/sbin/iptables -A INPUT -i ppp0 -p udp -m multiport --dports 1434 -j DROP
/sbin/iptables -A INPUT -s 10.0.0.0/255.0.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 172.16.0.0/255.240.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 192.168.0.0/255.255.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 127.0.0.0/255.255.255.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 169.254.0.0/255.255.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 192.0.2.0/255.255.255.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 198.18.0.0/255.254.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 255.255.255.255 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A INPUT -s 10.0.0.0/255.0.0.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 172.16.0.0/255.240.0.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 192.168.0.0/255.255.0.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 127.0.0.0/255.255.255.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 169.254.0.0/255.255.0.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 192.0.2.0/255.255.255.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 198.18.0.0/255.254.0.0 -i ppp0 -j DROP
/sbin/iptables -A INPUT -s 255.255.255.255 -i ppp0 -j DROP
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 783 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 873 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 993 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 995 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 2703 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p udp -m state --state NEW -m udp --dport 6277 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 24662 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p udp -m state --state NEW -m udp --dport 24665 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 24665 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p udp -m state --state NEW -m udp --dport 24672 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 24672 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 6667 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p udp -m state --state NEW -m udp --dport 6667 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p tcp -m state --state NEW -m tcp --dport 24441 -j ACCEPT
/sbin/iptables -A INPUT -i ppp0 -p udp -m state --state NEW -m udp --dport 24441 -j ACCEPT
/sbin/iptables -A INPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with tcp-reset
/sbin/iptables -A INPUT -p ! icmp -m limit --limit 3/sec -j LOG --log-prefix " IPKF_INPUT_Catch-all: "
/sbin/iptables -A INPUT -j DROP
/sbin/iptables -A FORWARD -s 10.1.0.0/255.255.255.0 -i eth1 -m state --state NEW -j ACCEPT
/sbin/iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A FORWARD -i ppp0 -m recent --rcheck --seconds 120 --name badguy --rsource -j DROP
/sbin/iptables -A FORWARD -s 10.1.0.0/255.255.255.0 -i ppp0 -j ACCEPT
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_ALL: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_NONE: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_FIN_URG_PSH: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -m limit --limit 3/sec -j LOG --log-prefix "IPKF_PORTSCAN_nmap_XMAS: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_SYN_FIN: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -m limit --limit 3/sec -j LOG --log-prefix "IPKF_flags_SYN_RST: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -m limit --limit 3/sec -j LOG --log-prefix "IPKF_SYN_RST_ACK_FIN_URG: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m limit --limit 3/sec -j LOG --log-prefix "IPKF_PORTSCAN_nmap_NULL: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,ACK,URG -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m state --state INVALID -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Invalid_TCP_flag: "
/sbin/iptables -A FORWARD -i ppp0 -m state --state INVALID -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p icmp -m icmp --icmp-type 13 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_ICMP_Timestamp: "
/sbin/iptables -A FORWARD -i ppp0 -p icmp -m icmp --icmp-type 13 -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn-flood
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -m limit --limit 3/sec -j LOG --log-prefix "IPKF_New_Not_SYN: "
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m multiport --dports 137,6666 -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p udp -m multiport --dports 1434 -j DROP
/sbin/iptables -A FORWARD -s 10.0.0.0/255.0.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 172.16.0.0/255.240.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 192.168.0.0/255.255.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 127.0.0.0/255.255.255.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 169.254.0.0/255.255.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 192.0.2.0/255.255.255.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 198.18.0.0/255.254.0.0 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 255.255.255.255 -i ppp0 -m limit --limit 3/sec -j LOG --log-prefix "IPKF_Spoof: "
/sbin/iptables -A FORWARD -s 10.0.0.0/255.0.0.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 172.16.0.0/255.240.0.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 192.168.0.0/255.255.0.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 127.0.0.0/255.255.255.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 169.254.0.0/255.255.0.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 192.0.2.0/255.255.255.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 198.18.0.0/255.254.0.0 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -s 255.255.255.255 -i ppp0 -j DROP
/sbin/iptables -A FORWARD -i ppp0 -p tcp -m tcp --dport 113 -j REJECT --reject-with tcp-reset
/sbin/iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A OUTPUT -m state --state NEW -j ACCEPT
/sbin/iptables -A syn-flood -m limit --limit 20/sec --limit-burst 48 -j RETURN
/sbin/iptables -A syn-flood -m limit --limit 3/sec -j LOG --log-prefix "IPKF_SYN_flood: "
/sbin/iptables -A syn-flood -j DROP
And also my PROC(/proc) settings:
/proc/sys/net/ipv4/conf/all/accept_redirects -> 0
/proc/sys/net/ipv4/conf/all/accept_source_route -> 0
/proc/sys/net/ipv4/conf/all/arp_announce -> 0
/proc/sys/net/ipv4/conf/all/arp_filter -> 0
/proc/sys/net/ipv4/conf/all/arp_ignore -> 0
/proc/sys/net/ipv4/conf/all/bootp_relay -> 0
/proc/sys/net/ipv4/conf/all/disable_policy -> 0
/proc/sys/net/ipv4/conf/all/disable_xfrm -> 0
/proc/sys/net/ipv4/conf/all/force_igmp_version -> 0
/proc/sys/net/ipv4/conf/all/forwarding -> 1
/proc/sys/net/ipv4/conf/all/log_martians -> 1
/proc/sys/net/ipv4/conf/all/mc_forwarding -> 0
/proc/sys/net/ipv4/conf/all/medium_id -> 0
/proc/sys/net/ipv4/conf/all/promote_secondaries -> 0
/proc/sys/net/ipv4/conf/all/proxy_arp -> 0
/proc/sys/net/ipv4/conf/all/rp_filter -> 1
/proc/sys/net/ipv4/conf/all/secure_redirects -> 1
/proc/sys/net/ipv4/conf/all/send_redirects -> 1
/proc/sys/net/ipv4/conf/all/shared_media -> 1
/proc/sys/net/ipv4/conf/all/tag -> 0
/proc/sys/net/ipv4/icmp_echo_ignore_all -> 1
/proc/sys/net/ipv4/icmp_echo_ignore_broadcasts -> 1
/proc/sys/net/ipv4/icmp_errors_use_inbound_ifaddr -> 0
/proc/sys/net/ipv4/icmp_ignore_bogus_error_responses -> 1
/proc/sys/net/ipv4/icmp_ratelimit -> 250
/proc/sys/net/ipv4/icmp_ratemask -> 6168
/proc/sys/net/ipv4/igmp_max_memberships -> 20
/proc/sys/net/ipv4/igmp_max_msf -> 10
/proc/sys/net/ipv4/inet_peer_gc_maxtime -> 120
/proc/sys/net/ipv4/inet_peer_gc_mintime -> 10
/proc/sys/net/ipv4/inet_peer_maxttl -> 600
/proc/sys/net/ipv4/inet_peer_minttl -> 120
/proc/sys/net/ipv4/inet_peer_threshold -> 65664
/proc/sys/net/ipv4/ip_autoconfig -> 0
/proc/sys/net/ipv4/ip_conntrack_max -> 49144
/proc/sys/net/ipv4/ip_default_ttl -> 64
/proc/sys/net/ipv4/ip_dynaddr -> 0
/proc/sys/net/ipv4/ip_forward -> 1
/proc/sys/net/ipv4/ipfrag_high_thresh -> 262144
/proc/sys/net/ipv4/ipfrag_low_thresh -> 196608
/proc/sys/net/ipv4/ipfrag_secret_interval -> 600
/proc/sys/net/ipv4/ipfrag_time -> 30
/proc/sys/net/ipv4/ip_local_port_range -> 32768 61000
/proc/sys/net/ipv4/ip_nonlocal_bind -> 0
/proc/sys/net/ipv4/ip_no_pmtu_disc -> 0
/proc/sys/net/ipv4/ip_queue_maxlen -> 1024
/proc/sys/net/ipv4/tcp_abort_on_overflow -> 0
/proc/sys/net/ipv4/tcp_adv_win_scale -> 2
/proc/sys/net/ipv4/tcp_app_win -> 31
/proc/sys/net/ipv4/tcp_congestion_control -> bic
/proc/sys/net/ipv4/tcp_dsack -> 1
/proc/sys/net/ipv4/tcp_ecn -> 0
/proc/sys/net/ipv4/tcp_fack -> 1
/proc/sys/net/ipv4/tcp_fin_timeout -> 30
/proc/sys/net/ipv4/tcp_frto -> 0
/proc/sys/net/ipv4/tcp_keepalive_intvl -> 1800
/proc/sys/net/ipv4/tcp_keepalive_probes -> 9
/proc/sys/net/ipv4/tcp_keepalive_time -> 1800
/proc/sys/net/ipv4/tcp_low_latency -> 0
/proc/sys/net/ipv4/tcp_max_orphans -> 32768
/proc/sys/net/ipv4/tcp_max_syn_backlog -> 1280
/proc/sys/net/ipv4/tcp_max_tw_buckets -> 180000
/proc/sys/net/ipv4/tcp_mem -> 98304 131072 196608
/proc/sys/net/ipv4/tcp_moderate_rcvbuf -> 1
/proc/sys/net/ipv4/tcp_no_metrics_save -> 0
/proc/sys/net/ipv4/tcp_orphan_retries -> 0
/proc/sys/net/ipv4/tcp_reordering -> 3
/proc/sys/net/ipv4/tcp_retrans_collapse -> 1
/proc/sys/net/ipv4/tcp_retries1 -> 3
/proc/sys/net/ipv4/tcp_retries2 -> 15
/proc/sys/net/ipv4/tcp_rfc1337 -> 0
/proc/sys/net/ipv4/tcp_rmem -> 4096 87380 174760
/proc/sys/net/ipv4/tcp_sack -> 0
/proc/sys/net/ipv4/tcp_stdurg -> 0
/proc/sys/net/ipv4/tcp_synack_retries -> 5
/proc/sys/net/ipv4/tcp_syncookies -> 1
/proc/sys/net/ipv4/tcp_syn_retries -> 5
/proc/sys/net/ipv4/tcp_timestamps -> 1
/proc/sys/net/ipv4/tcp_tso_win_divisor -> 3
/proc/sys/net/ipv4/tcp_tw_recycle -> 0
/proc/sys/net/ipv4/tcp_tw_reuse -> 0
/proc/sys/net/ipv4/tcp_window_scaling -> 1
/proc/sys/net/ipv4/tcp_wmem -> 4096 16384 131072
/proc/sys/net/ipv4/route/error_burst -> 1250
/proc/sys/net/ipv4/route/error_cost -> 250
/proc/sys/net/ipv4/route/gc_elasticity -> 8
/proc/sys/net/ipv4/route/gc_interval -> 60
/proc/sys/net/ipv4/route/gc_min_interval -> 0
/proc/sys/net/ipv4/route/gc_min_interval_ms -> 500
/proc/sys/net/ipv4/route/gc_thresh -> 32768
/proc/sys/net/ipv4/route/gc_timeout -> 300
/proc/sys/net/ipv4/route/max_delay -> 10
/proc/sys/net/ipv4/route/max_size -> 524288
/proc/sys/net/ipv4/route/min_adv_mss -> 256
/proc/sys/net/ipv4/route/min_delay -> 2
/proc/sys/net/ipv4/route/min_pmtu -> 552
/proc/sys/net/ipv4/route/mtu_expires -> 600
/proc/sys/net/ipv4/route/redirect_load -> 5
/proc/sys/net/ipv4/route/redirect_number -> 9
/proc/sys/net/ipv4/route/redirect_silence -> 5120
/proc/sys/net/ipv4/route/secret_interval -> 600
/proc/sys/net/ipv4/netfilter/ip_conntrack_buckets -> 6143
/proc/sys/net/ipv4/netfilter/ip_conntrack_count -> 479
/proc/sys/net/ipv4/netfilter/ip_conntrack_generic_timeout -> 600
/proc/sys/net/ipv4/netfilter/ip_conntrack_icmp_timeout -> 30
/proc/sys/net/ipv4/netfilter/ip_conntrack_log_invalid -> 0
/proc/sys/net/ipv4/netfilter/ip_conntrack_max -> 49144
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_closed -> 10
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_cookie_echoed -> 3
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_cookie_wait -> 3
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_established -> 432000
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_shutdown_ack_sent -> 3
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_shutdown_recd -> 0
/proc/sys/net/ipv4/netfilter/ip_conntrack_sctp_timeout_shutdown_sent -> 0
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_be_liberal -> 0
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_loose -> 3
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_max_retrans -> 3
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_close -> 10
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_close_wait -> 60
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_established -> 432000
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_fin_wait -> 120
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_last_ack -> 30
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_max_retrans -> 300
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_syn_recv -> 60
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_syn_sent -> 120
/proc/sys/net/ipv4/netfilter/ip_conntrack_tcp_timeout_time_wait -> 120
/proc/sys/net/ipv4/netfilter/ip_conntrack_udp_timeout -> 30
/proc/sys/net/ipv4/netfilter/ip_conntrack_udp_timeout_stream -> 180 |
|