# @package      hubzero-firewall
# @file         hubzero-iptables
# @author       David Benham <dbenham@purdue.edu>
# @copyright    Copyright (c) 2006-2012 HUBzero Foundation, LLC.
# @license      http://www.gnu.org/licenses/lgpl-3.0.html LGPLv3
#
# Copyright (c) 2006-2012 HUBzero Foundation, LLC.
#
# This file is part of: The HUBzero(R) Platform for Scientific Collaboration
#
# The HUBzero(R) Platform for Scientific Collaboration (HUBzero) is free
# software: you can redistribute it and/or modify it under the terms of
# the GNU Lesser General Public License as published by the Free Software
# Foundation, either version 3 of the License, or (at your option) any
# later version.
#
# HUBzero is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU Lesser General Public License for more details.
#
# You should have received a copy of the GNU Lesser General Public License
# along with this program.  If not, see <http://www.gnu.org/licenses/>.
#
# HUBzero is a registered trademark of HUBzero Foundation, LLC.
#
# Generated by iptables-save v1.4.7 on Fri Apr 12 10:11:25 2013 from the 
# rules created by the iptables_on script.
# 
#
*mangle
:PREROUTING ACCEPT [105:7860]
:INPUT ACCEPT [105:7860]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [57:6804]
:POSTROUTING ACCEPT [57:6804]
COMMIT
# Completed on Fri Apr 12 10:11:25 2013
# Generated by iptables-save v1.4.7 on Fri Apr 12 10:11:25 2013
*nat
:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A POSTROUTING -s 10.0.0.0/8 -o eth0 -p tcp -j MASQUERADE --to-ports 10000-50000 
-A POSTROUTING -s 10.0.0.0/8 -o eth0 -p udp -j MASQUERADE --to-ports 10000-50000 
-A POSTROUTING -s 10.0.0.0/8 -o eth0 -p icmp -j MASQUERADE 
COMMIT
# Completed on Fri Apr 12 10:11:25 2013
# Generated by iptables-save v1.4.7 on Fri Apr 12 10:11:25 2013
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [57:6804]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -p icmp -j ACCEPT 
-A INPUT -i lo -j ACCEPT 
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT 
-A INPUT -j REJECT --reject-with icmp-host-prohibited 
-A INPUT -i lo -j ACCEPT 
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 25 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 3306 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 389 -j ACCEPT 
-A INPUT -i venet0 -p tcp -m tcp --dport 80 -j ACCEPT 
-A INPUT -i venet0 -p tcp -m tcp --dport 443 -j ACCEPT 
-A INPUT -i venet0 -p tcp -m tcp --dport 8080 -j ACCEPT 
-A INPUT -i venet0 -p tcp -m tcp --dport 830:831 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 8080 -j ACCEPT 
-A INPUT -p tcp -m tcp --dport 1170 -j ACCEPT 
-A INPUT -p icmp -j ACCEPT 
-A FORWARD -j REJECT --reject-with icmp-host-prohibited 
-A FORWARD -s 10.0.0.0/8 -i venet0 -j ACCEPT 
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT 
-A FORWARD -i venet0 -o eth0 -p tcp -m tcp --dport 830:831 -j ACCEPT 
-A FORWARD -i venet0 -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT 
-A FORWARD -i venet0 -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT 
-A FORWARD -i venet0 -o eth0 -p udp -m udp --dport 53 -j ACCEPT 
COMMIT
# Completed on Fri Apr 12 10:11:25 2013
