*/
object Endpoint "ns1.uhu-banane.de" {
- host = "ns1.uhu-banane.de"
- port = "5665"
}
-object Zone "master" {
- endpoints = [ "ns1.uhu-banane.de" ]
-}
-
-object Endpoint NodeName {
+object Endpoint "ns3.uhu-banane.de" {
}
-object Endpoint "sarah.uhu-banane.de" {
- host = "sarah.uhu-banane.de"
- port = "5665"
+object Zone "master" {
+ endpoints = [ "ns1.uhu-banane.de" ]
}
-object Zone "icinga_clients_de" {
- endpoints = [ NodeName, "sarah.uhu-banane.de" ]
+object Zone "ns3.uhu-banane.de" {
+ endpoints = [ "n3.uhu-banane.de" ]
parent = "master"
}
-# Generated by iptables-save v1.6.0 on Tue Oct 10 22:26:19 2017
+# Generated by iptables-save v1.6.0 on Thu Oct 12 22:55:37 2017
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
-:OUTPUT ACCEPT [6873:1266143]
+:OUTPUT ACCEPT [75:29607]
:f2b-apache - [0:0]
:f2b-apache-modsecurity - [0:0]
:f2b-apache-nohome - [0:0]
:f2b-postfix - [0:0]
:f2b-ssh - [0:0]
:f2b-sshd - [0:0]
+:icinga2 - [0:0]
:rejects - [0:0]
:salt-master - [0:0]
-A INPUT -p tcp -m multiport --dports 22 -j f2b-ssh
-A INPUT -p udp -m multiport --dports 389,636 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 4505 -j salt-master
-A INPUT -p tcp -m tcp --dport 4506 -j salt-master
+-A INPUT -p tcp -m tcp --dport 5665 -j icinga2
-A INPUT -j rejects
-A INPUT -j NFLOG --nflog-prefix "IPv4 INPUT Reject " --nflog-threshold 1
-A INPUT -j REJECT --reject-with icmp-port-unreachable
-A f2b-apache -j RETURN
+-A f2b-apache -j RETURN
+-A f2b-apache-modsecurity -j RETURN
-A f2b-apache-modsecurity -j RETURN
-A f2b-apache-nohome -j RETURN
+-A f2b-apache-nohome -j RETURN
+-A f2b-apache-noscript -j RETURN
-A f2b-apache-noscript -j RETURN
-A f2b-apache-overflows -j RETURN
+-A f2b-apache-overflows -j RETURN
+-A f2b-postfix -j RETURN
-A f2b-postfix -j RETURN
+-A f2b-ssh -s 58.242.83.8/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-ssh -j RETURN
+-A f2b-ssh -j RETURN
+-A f2b-sshd -j RETURN
-A f2b-sshd -j RETURN
+-A icinga2 -s 185.102.95.107/32 -j ACCEPT
+-A icinga2 -s 162.254.24.33/32 -j ACCEPT
+-A icinga2 -s 185.48.118.128/32 -j ACCEPT
+-A icinga2 -s 185.48.118.130/32 -j ACCEPT
-A rejects -s 134.119.179.226/32 -j REJECT --reject-with icmp-port-unreachable
-A rejects -p tcp -m tcp --dport 23 -j REJECT --reject-with icmp-port-unreachable
-A rejects -p udp -m udp --dport 137 -j REJECT --reject-with icmp-port-unreachable
-A salt-master -j NFLOG --nflog-prefix "IPv4 Salt Reject " --nflog-threshold 1
-A salt-master -j REJECT --reject-with icmp-port-unreachable
COMMIT
-# Completed on Tue Oct 10 22:26:19 2017
+# Completed on Thu Oct 12 22:55:37 2017
-# Generated by ip6tables-save v1.6.0 on Tue Oct 10 22:26:19 2017
+# Generated by ip6tables-save v1.6.0 on Thu Oct 12 22:55:37 2017
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
-:OUTPUT ACCEPT [938318:240511532]
+:OUTPUT ACCEPT [50653:5978817]
:salt-master - [0:0]
-A INPUT -m conntrack --ctstate ESTABLISHED -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED -j ACCEPT
-A salt-master -j NFLOG --nflog-prefix "IPv6 Salt Reject " --nflog-threshold 1
-A salt-master -j REJECT --reject-with icmp6-port-unreachable
COMMIT
-# Completed on Tue Oct 10 22:26:19 2017
+# Completed on Thu Oct 12 22:55:37 2017