Chain INPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 1614 165K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 339K 51M ACCEPT all -- eth0 * 192.168.0.0/24 0.0.0.0/0 0 0 drop-and-log-it all -- eth1 * 192.168.0.0/24 0.0.0.0/0 5577 489K ACCEPT icmp -- eth1 * 0.0.0.0/0 xxx.xxx.xxx.xxx 756K 1092M ACCEPT all -- eth1 * 0.0.0.0/0 xxx.xxx.xxx.xxx state RELATED,ESTABLISHED 0 0 ACCEPT tcp -- eth1 * 0.0.0.0/0 0.0.0.0/0 tcp spt:123 dpt:123 0 0 ACCEPT udp -- eth1 * 0.0.0.0/0 0.0.0.0/0 udp spt:123 dpt:123 1358 66864 ACCEPT tcp -- eth1 * 0.0.0.0/0 xxx.xxx.xxx.xxx state NEW,RELATED,ESTABLISHED tcp dpt:80 62 2232 ACCEPT udp -- eth1 * 0.0.0.0/0 xxx.xxx.xxx.xxx udp spt:6112 0 0 ACCEPT udp -- eth1 * 0.0.0.0/0 xxx.xxx.xxx.xxx udp dpt:6112 358K 127M drop-and-log-it all -- * * 0.0.0.0/0 0.0.0.0/0 Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 19540 1801K ACCEPT tcp -- eth1 eth0 0.0.0.0/0 0.0.0.0/0 tcp dpt:6112 state NEW,RELATED,ESTABLISHED 2210 109K ACCEPT tcp -- eth1 eth0 0.0.0.0/0 0.0.0.0/0 tcp dpt:6113 state NEW,RELATED,ESTABLISHED 3773K 2726M ACCEPT all -- eth1 eth0 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 3785K 2010M ACCEPT all -- eth0 eth1 0.0.0.0/0 0.0.0.0/0 0 0 drop-and-log-it all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy DROP 4 packets, 960 bytes) pkts bytes target prot opt in out source destination 1614 165K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 564 443K ACCEPT all -- * eth0 xxx.xxx.xxx.xxx 192.168.0.0/24 423K 1093M ACCEPT all -- * eth0 192.168.0.0/24 192.168.0.0/24 0 0 drop-and-log-it all -- * eth1 0.0.0.0/0 192.168.0.0/24 645K 39M ACCEPT all -- * eth1 xxx.xxx.xxx.xxx 0.0.0.0/0 0 0 ACCEPT tcp -- * eth0 0.0.0.0/0 0.0.0.0/0 tcp spt:123 dpt:123 0 0 ACCEPT udp -- * eth0 0.0.0.0/0 0.0.0.0/0 udp spt:123 dpt:123 0 0 drop-and-log-it all -- * * 0.0.0.0/0 0.0.0.0/0 Chain drop-and-log-it (5 references) pkts bytes target prot opt in out source destination 358K 127M LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 358K 127M REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable