/etc/pyroman/00_iptables-defaults.py is in pyroman 0.5.0-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | """
These are the iptables builtin chains.
In order to use the builtins in Pyroman, we need to define objects for them.
Note how we set chain policies!
"""
add_chain("INPUT", default="DROP")
add_chain("OUTPUT", default="DROP")
add_chain("FORWARD", default="DROP")
add_chain("OUTPUT", id="natOUT", default="ACCEPT", table="nat")
add_chain("PREROUTING", id="natPRE", default="ACCEPT", table="nat")
add_chain("POSTROUTING", id="natPOST", default="ACCEPT", table="nat")
add_chain("INPUT", id="manIN", default="ACCEPT", table="mangle")
add_chain("OUTPUT", id="manOUT", default="ACCEPT", table="mangle")
add_chain("FORWARD", id="manFWD", default="ACCEPT", table="mangle")
add_chain("PREROUTING", id="manPRE", default="ACCEPT", table="mangle")
add_chain("POSTROUTING", id="manPOST", default="ACCEPT", table="mangle")
|