Skip to content

Commit fa899f7

Browse files
authored
Update rules-v4.txt
1 parent 2fc6677 commit fa899f7

1 file changed

Lines changed: 1 addition & 4 deletions

File tree

modules/iptables/rules-v4.txt

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -23,9 +23,6 @@
2323
# allow established and related connections
2424
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
2525

26-
# allow SSH (port 22)
27-
-A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -j ACCEPT
28-
2926
# allow HTTP and HTTPS
3027
-A INPUT -p tcp -m multiport --dports 80,443 -m conntrack --ctstate NEW -j ACCEPT
3128

@@ -41,7 +38,7 @@
4138
# logging denied packets
4239
-A INPUT -m limit --limit 3/min --limit-burst 10 -j LOG --log-prefix "[IPTABLES BLOCK] "
4340

44-
# rate limiting (prevent brute-force attacks)
41+
# rate limit SSH connections
4542
-A INPUT -p tcp --dport 22 -m limit --limit 3/min --limit-burst 5 -j ACCEPT
4643
-A INPUT -p tcp --dport 22 -j REJECT
4744

0 commit comments

Comments
 (0)