Friday, 24 November 2023

reload csf firewall

 # csf -r

perl: warning: Setting locale failed.

perl: warning: Please check that your locale settings:

LANGUAGE = "en_US:en",

LC_ALL = (unset),

LC_ADDRESS = "id_ID.UTF-8",

LC_NAME = "id_ID.UTF-8",

LC_MONETARY = "id_ID.UTF-8",

LC_PAPER = "id_ID.UTF-8",

LC_IDENTIFICATION = "id_ID.UTF-8",

LC_TELEPHONE = "id_ID.UTF-8",

LC_MEASUREMENT = "id_ID.UTF-8",

LC_TIME = "id_ID.UTF-8",

LC_NUMERIC = "id_ID.UTF-8",

LANG = "en_US.UTF-8"

    are supported and installed on your system.

perl: warning: Falling back to a fallback locale ("en_US.UTF-8").

Flushing chain `INPUT'

Flushing chain `FORWARD'

Flushing chain `OUTPUT'

Flushing chain `LOGDROPIN'

Flushing chain `LOGDROPOUT'

Flushing chain `DENYIN'

Flushing chain `DENYOUT'

Flushing chain `ALLOWIN'

Flushing chain `ALLOWOUT'

Flushing chain `LOCALINPUT'

Flushing chain `LOCALOUTPUT'

Flushing chain `INVDROP'

Flushing chain `INVALID'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Flushing chain `PREROUTING'

Flushing chain `INPUT'

Flushing chain `POSTROUTING'

Flushing chain `OUTPUT'

Flushing chain `PREROUTING'

Flushing chain `OUTPUT'

Flushing chain `PREROUTING'

Flushing chain `INPUT'

Flushing chain `FORWARD'

Flushing chain `OUTPUT'

Flushing chain `POSTROUTING'

Flushing chain `INPUT'

Flushing chain `FORWARD'

Flushing chain `OUTPUT'

Flushing chain `LOGDROPIN'

Flushing chain `LOGDROPOUT'

Flushing chain `DENYIN'

Flushing chain `DENYOUT'

Flushing chain `ALLOWIN'

Flushing chain `ALLOWOUT'

Flushing chain `LOCALINPUT'

Flushing chain `LOCALOUTPUT'

Flushing chain `INVDROP'

Flushing chain `INVALID'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Deleting chain `(null)'

Flushing chain `PREROUTING'

Flushing chain `INPUT'

Flushing chain `POSTROUTING'

Flushing chain `OUTPUT'

Flushing chain `PREROUTING'

Flushing chain `OUTPUT'

Flushing chain `PREROUTING'

Flushing chain `INPUT'

Flushing chain `FORWARD'

Flushing chain `OUTPUT'

Flushing chain `POSTROUTING'

csf: FASTSTART loading DROP no logging (IPv4)

csf: FASTSTART loading DROP no logging (IPv6)

LOG  tcp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *TCP_IN Blocked* "

LOG  tcp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   tcp flags:0x17/0x02 limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *TCP_OUT Blocked* "

LOG  udp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *UDP_IN Blocked* "

LOG  udp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *UDP_OUT Blocked* "

LOG  icmp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *ICMP_IN Blocked* "

LOG  icmp opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *ICMP_OUT Blocked* "

LOG  tcp opt    in * out *  ::/0  -> ::/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *TCP6IN Blocked* "

LOG  tcp opt    in * out *  ::/0  -> ::/0   tcp flags:0x17/0x02 limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *TCP6OUT Blocked* "

LOG  udp opt    in * out *  ::/0  -> ::/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *UDP6IN Blocked* "

LOG  udp opt    in * out *  ::/0  -> ::/0   limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *UDP6OUT Blocked* "

LOG  icmpv6 opt    in * out *  ::/0  -> ::/0   limit: avg 30/min burst 5 LOG flags 0 level 4 prefix "Firewall: *ICMP6IN Blocked* "

LOG  icmpv6 opt    in * out *  ::/0  -> ::/0   limit: avg 30/min burst 5 LOG flags 8 level 4 prefix "Firewall: *ICMP6OUT Blocked* "

DROP  all opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0  

REJECT  all opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0   reject-with icmp-port-unreachable

DROP  all opt    in * out *  ::/0  -> ::/0  

REJECT  all opt    in * out *  ::/0  -> ::/0   reject-with icmp6-port-unreachable

DENYOUT  all opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

DENYIN  all opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

ALLOWOUT  all opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

ALLOWIN  all opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

DENYOUT  all opt    in * out !lo  ::/0  -> ::/0  

DENYIN  all opt    in !lo out *  ::/0  -> ::/0  

ALLOWOUT  all opt    in * out !lo  ::/0  -> ::/0  

ALLOWIN  all opt    in !lo out *  ::/0  -> ::/0  

csf: FASTSTART loading Packet Filter (IPv4)

csf: FASTSTART loading Packet Filter (IPv6)

DROP  all opt -- in * out *  0.0.0.0/0  -> 0.0.0.0/0  

INVALID  tcp opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

INVALID  tcp opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

DROP  all opt    in * out *  ::/0  -> ::/0  

INVALID  tcp opt    in !lo out *  ::/0  -> ::/0  

INVALID  tcp opt    in * out !lo  ::/0  -> ::/0  

csf: FASTSTART loading csf.deny (IPv4)

csf: FASTSTART loading csf.allow (IPv4)

ACCEPT  icmp opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0   icmptype 8 limit: avg 1/sec burst 5

LOGDROPIN  icmp opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0   icmptype 8

ACCEPT  icmp opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

ACCEPT  icmp opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

ACCEPT  icmpv6 opt    in !lo out *  ::/0  -> ::/0  

ACCEPT  icmpv6 opt    in * out !lo  ::/0  -> ::/0  

ACCEPT  all opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0   ctstate RELATED,ESTABLISHED

ACCEPT  all opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0   ctstate RELATED,ESTABLISHED

ACCEPT  all opt    in !lo out *  ::/0  -> ::/0   ctstate RELATED,ESTABLISHED

ACCEPT  all opt    in * out !lo  ::/0  -> ::/0   ctstate RELATED,ESTABLISHED

csf: FASTSTART loading TCP_IN (IPv4)

csf: FASTSTART loading TCP6_IN (IPv6)

csf: FASTSTART loading TCP_OUT (IPv4)

csf: FASTSTART loading TCP6_OUT (IPv6)

csf: FASTSTART loading UDP_IN (IPv4)

csf: FASTSTART loading UDP6_IN (IPv6)

csf: FASTSTART loading UDP_OUT (IPv4)

csf: FASTSTART loading UDP6_OUT (IPv6)

ACCEPT  all opt -- in lo out *  0.0.0.0/0  -> 0.0.0.0/0  

ACCEPT  all opt -- in * out lo  0.0.0.0/0  -> 0.0.0.0/0  

LOGDROPOUT  all opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

LOGDROPIN  all opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

ACCEPT  all opt    in lo out *  ::/0  -> ::/0  

ACCEPT  all opt    in * out lo  ::/0  -> ::/0  

LOGDROPOUT  all opt    in * out !lo  ::/0  -> ::/0  

LOGDROPIN  all opt    in !lo out *  ::/0  -> ::/0  

csf: FASTSTART loading DNS (IPv4)

csf: FASTSTART loading DNS (IPv6)

LOCALOUTPUT  all opt -- in * out !lo  0.0.0.0/0  -> 0.0.0.0/0  

LOCALINPUT  all opt -- in !lo out *  0.0.0.0/0  -> 0.0.0.0/0  

LOCALOUTPUT  all opt    in * out !lo  ::/0  -> ::/0  

LOCALINPUT  all opt    in !lo out *  ::/0  -> ::/0  

*WARNING* Binary location for [SENDMAIL] [/usr/sbin/sendmail] in /etc/csf/csf.conf is either incorrect, is not installed or is not executable

*WARNING* Missing or incorrect binary locations will break csf and lfd functionality


*WARNING* RESTRICT_SYSLOG is disabled. See SECURITY WARNING in /etc/csf/csf.conf.


Share:

0 comments:

Post a Comment