# Generated by ip6tables-save v1.8.5 on Mon Dec 15 15:59:27 2025
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [1311082:110554599]
:OUTPUT ACCEPT [21624518:1738375813]
COMMIT
# Completed on Mon Dec 15 15:59:27 2025
# Generated by ip6tables-save v1.8.5 on Mon Dec 15 15:59:27 2025
*raw
:PREROUTING ACCEPT [30181463:3833738666]
:OUTPUT ACCEPT [48853860:5352063882]
COMMIT
# Completed on Mon Dec 15 15:59:27 2025
# Generated by ip6tables-save v1.8.5 on Mon Dec 15 15:59:27 2025
*mangle
:PREROUTING ACCEPT [30181463:3833738666]
:INPUT ACCEPT [30181463:3833738666]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [48853860:5352063882]
:POSTROUTING ACCEPT [28540419:3724242197]
COMMIT
# Completed on Mon Dec 15 15:59:27 2025
# Generated by ip6tables-save v1.8.5 on Mon Dec 15 15:59:27 2025
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:LOGDROPIN - [0:0]
:LOGDROPOUT - [0:0]
:DENYIN - [0:0]
:DENYOUT - [0:0]
:ALLOWIN - [0:0]
:ALLOWOUT - [0:0]
:LOCALINPUT - [0:0]
:LOCALOUTPUT - [0:0]
:INVDROP - [0:0]
:INVALID - [0:0]
:SMTPOUTPUT - [0:0]
-A INPUT ! -i lo -j LOCALINPUT
-A INPUT -i lo -j ACCEPT
-A INPUT ! -i lo -p tcp -j INVALID
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 1 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 2 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 3 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 4 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 128 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 129 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 134 -m hl --hl-eq 255 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 135 -m hl --hl-eq 255 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 136 -m hl --hl-eq 255 -j ACCEPT
-A INPUT ! -i lo -p ipv6-icmp -m icmp6 --icmpv6-type 137 -m hl --hl-eq 255 -j ACCEPT
-A INPUT ! -i lo -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT ! -i lo -j LOGDROPIN
-A OUTPUT ! -o lo -j LOCALOUTPUT
-A OUTPUT ! -o lo -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT ! -o lo -p tcp -m tcp --sport 53 -j ACCEPT
-A OUTPUT ! -o lo -p udp -m udp --sport 53 -j ACCEPT
-A OUTPUT -j SMTPOUTPUT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT ! -o lo -p tcp -j INVALID
-A OUTPUT ! -o lo -p ipv6-icmp -j ACCEPT
-A OUTPUT ! -o lo -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT ! -o lo -j LOGDROPOUT
-A LOGDROPIN -p tcp -m tcp --dport 23 -j DROP
-A LOGDROPIN -p udp -m udp --dport 23 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 67 -j DROP
-A LOGDROPIN -p udp -m udp --dport 67 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 68 -j DROP
-A LOGDROPIN -p udp -m udp --dport 68 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 111 -j DROP
-A LOGDROPIN -p udp -m udp --dport 111 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 113 -j DROP
-A LOGDROPIN -p udp -m udp --dport 113 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 135:139 -j DROP
-A LOGDROPIN -p udp -m udp --dport 135:139 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 445 -j DROP
-A LOGDROPIN -p udp -m udp --dport 445 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 500 -j DROP
-A LOGDROPIN -p udp -m udp --dport 500 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 513 -j DROP
-A LOGDROPIN -p udp -m udp --dport 513 -j DROP
-A LOGDROPIN -p tcp -m tcp --dport 520 -j DROP
-A LOGDROPIN -p udp -m udp --dport 520 -j DROP
-A LOGDROPIN -p tcp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP6IN Blocked* "
-A LOGDROPIN -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP6IN Blocked* "
-A LOGDROPIN -p ipv6-icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP6IN Blocked* "
-A LOGDROPIN -j DROP
-A LOGDROPOUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 30/min -j LOG --log-prefix "Firewall: *TCP6OUT Blocked* " --log-uid
-A LOGDROPOUT -p udp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *UDP6OUT Blocked* " --log-uid
-A LOGDROPOUT -p ipv6-icmp -m limit --limit 30/min -j LOG --log-prefix "Firewall: *ICMP6OUT Blocked* " --log-uid
-A LOGDROPOUT -j REJECT --reject-with icmp6-port-unreachable
-A DENYIN -s 2001:7fd::1/128 ! -i lo -j DROP
-A DENYIN -s 2001:7fe::53/128 ! -i lo -j DROP
-A DENYOUT -d 2001:7fd::1/128 ! -o lo -j LOGDROPOUT
-A DENYOUT -d 2001:7fe::53/128 ! -o lo -j LOGDROPOUT
-A ALLOWIN -s 2a02:1788:400:1ce4::/64 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 2a02:1788:400:1ce4::/64 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 2a02:1788:400:1ce4::/64 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A ALLOWIN -s 2a02:1788:402:1c80::/64 ! -i lo -p tcp -m tcp --dport 53 -j ACCEPT
-A ALLOWIN -s 2a02:1788:402:1c80::/64 ! -i lo -p tcp -m tcp --dport 443 -j ACCEPT
-A ALLOWIN -s 2a02:1788:402:1c80::/64 ! -i lo -p tcp -m tcp --dport 80 -j ACCEPT
-A LOCALINPUT ! -i lo -j ALLOWIN
-A LOCALINPUT ! -i lo -j DENYIN
-A LOCALOUTPUT ! -o lo -j ALLOWOUT
-A LOCALOUTPUT ! -o lo -j DENYOUT
-A INVDROP -j DROP
-A INVALID -m conntrack --ctstate INVALID -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags FIN,ACK FIN -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags PSH,ACK PSH -j INVDROP
-A INVALID -p tcp -m tcp --tcp-flags ACK,URG URG -j INVDROP
-A INVALID -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m conntrack --ctstate NEW -j INVDROP
-A SMTPOUTPUT -o lo -p tcp -m multiport --dports 26,25,465,587 -j ACCEPT
-A SMTPOUTPUT -p tcp -m multiport --dports 26,25,465,587 -m owner --gid-owner 983 -j ACCEPT
-A SMTPOUTPUT -p tcp -m multiport --dports 26,25,465,587 -m owner --gid-owner 12 -j ACCEPT
-A SMTPOUTPUT -p tcp -m multiport --dports 26,25,465,587 -m owner --uid-owner 988 -j ACCEPT
-A SMTPOUTPUT -p tcp -m multiport --dports 26,25,465,587 -m owner --uid-owner 0 -j ACCEPT
-A SMTPOUTPUT -p tcp -m multiport --dports 26,25,465,587 -j LOGDROPOUT
COMMIT
# Completed on Mon Dec 15 15:59:27 2025
# Generated by ip6tables-save v1.8.5 on Mon Dec 15 15:59:27 2025
*security
:INPUT ACCEPT [30181463:3833738666]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [28540419:3724242197]
COMMIT
# Completed on Mon Dec 15 15:59:27 2025
