All pastes #1802842 Raw Edit

enzotib

public text v1 · immutable
#1802842 ·published 2010-02-19 17:44 UTC
rendered paste body
#!/bin/bash# my remote shell (blinkenshell, titan.blinkenshell.org) ip addresstitan_ip="85.8.24.245"# my laptop static ip addresstibullomobile_ip="193.205.163.76"# my laptop current dynamic ip address at homehome_ip="79.2.146.98"allowed_ips=(  $titan_ip  $tibullomobile_ip  $home_ip)amule_port="8080"deluge_port="8081"allowed_ports=(  $amule_port  $deluge_port)# remove all rules from all chainsiptables -F# block every ICMP incoming packetsiptables -A INPUT -p icmp -j DROP# allow incoming connection only from known addressesfor ip in ${allowed_ips[*]}; do  iptables -A INPUT -m state --state NEW -s $ip -j ACCEPTdone# allow incoming connection to known portsfor port in ${allowed_ports[*]}; do  iptables -A INPUT -p tcp --dport $port -j ACCEPT  iptables -A INPUT -p udp --dport $port -j ACCEPTdone# deny incoming connection from every other addressiptables -A INPUT -m state --state NEW -i eth0 -j DROP