Hmmm, Havent gotten the first email related to bandmin not working. Also the ruleset is still up and running on the firewall for over 25 hours now and all is well. Here is from iptables -L -n command...
Part 1 of 2....
[email protected] [~]# iptables -L -n
Chain INPUT (policy DROP)
target prot opt source destination
acctboth all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x3F/0x00
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x03/0x03
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x06
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x05/0x05
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x11/0x01
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x18/0x08
DROP tcp -- 0.0.0.0/0 0.0.0.0/0 tcp flags:0x30/0x20
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
DROP all -- 0.0.0.0/0 0.0.0.0/0 state INVALID
DROP all -- 12.34.56.12 0.0.0.0/0
DROP all -- 12.34.56.13 0.0.0.0/0
DROP all -- 12.34.56.14 0.0.0.0/0
DROP all -- 12.34.56.15 0.0.0.0/0
DROP all -- 12.34.56.16 0.0.0.0/0
DROP all -- 10.0.0.0/8 0.0.0.0/0
DROP all -- 172.16.0.0/12 0.0.0.0/0
DROP all -- 192.168.0.0/16 0.0.0.0/0
DROP all -- 127.0.0.0/8 0.0.0.0/0
DROP all -- 255.255.255.255 0.0.0.0/0
DROP all -- 0.0.0.0/0 0.0.0.0
DROP all -- 0.0.0.0/0 12.34.56.0
DROP all -- 0.0.0.0/0 12.34.56.255
DROP all -- 0.0.0.0/0 255.255.255.255
DROP all -- 224.0.0.0/4 0.0.0.0/0
DROP !udp -- 0.0.0.0/0 224.0.0.0/4
ACCEPT udp -- 0.0.0.0/0 224.0.0.0/4
DROP all -- 240.0.0.0/5 0.0.0.0/0
DROP all -- 0.0.0.0/8 0.0.0.0/0
DROP all -- 169.254.0.0/16 0.0.0.0/0
DROP all -- 192.0.2.0/24 0.0.0.0/0
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:80
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:80
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:80
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:80
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:80
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:443
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:443
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:443
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:443
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:443
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:20
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:20
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:20
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:20
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:20
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:465
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:465
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:465
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:465
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:465
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:993
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:993
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:993
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:993
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:993
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:995
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:995
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:995
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:995
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:995
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpts:2080:2099
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpts:2080:2099
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpts:2080:2099
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpts:2080:2099
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpts:2080:2099
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 tcp spts:1024:65535 dpt:21 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 tcp spts:1024:65535 dpt:21 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 tcp spts:1024:65535 dpt:21 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 tcp spts:1024:65535 dpt:21 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 tcp spts:1024:65535 dpt:21 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:110
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:110
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:110
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:110
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:110
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:143
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:143
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:143
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:143
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:143
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 state NEW tcp spts:1024:65535 dpt:22
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 state NEW tcp spts:1024:65535 dpt:22
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 state NEW tcp spts:1024:65535 dpt:22
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 state NEW tcp spts:1024:65535 dpt:22
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 state NEW tcp spts:1024:65535 dpt:22
ACCEPT tcp -- 0.0.0.0/0 12.34.56.12 tcp spts:1024:65535 dpt:25 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.13 tcp spts:1024:65535 dpt:25 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.14 tcp spts:1024:65535 dpt:25 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.15 tcp spts:1024:65535 dpt:25 state NEW
ACCEPT tcp -- 0.0.0.0/0 12.34.56.16 tcp spts:1024:65535 dpt:25 state NEW
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp spts:1024:65535 dpt:53 state NEW
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spts:1024:65535 dpt:53 state NEW
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp spt:53 dpt:53 state NEW
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spt:53 dpt:53 state NEW
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp spts:1024:65535 dpt:873 state NEW
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp spts:1024:65535 dpt:873 state NEW
Chain FORWARD (policy DROP)
target prot opt source destination