SPECS/iptables/ip6save
7a6a95b3
 # init
 *filter
 :INPUT DROP [0:0]
 :FORWARD DROP [0:0]
 :OUTPUT DROP [0:0]
 # Allow local-only connections
 -A INPUT -i lo -j ACCEPT
 -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
78005de2
 #keep commented till upgrade issues are sorted
 #-A INPUT -j LOG --log-prefix "FIREWALL:INPUT "
7a6a95b3
 -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
 -A OUTPUT -j ACCEPT
 COMMIT