/etc/pyroman/00_iptables-defaults.py is in pyroman 0.5.0-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | """
These are the iptables builtin chains.
In order to use the builtins in Pyroman, we need to define objects for them.
Note how we set chain policies!
"""
add_chain("INPUT",                     default="DROP")
add_chain("OUTPUT",                    default="DROP")
add_chain("FORWARD",                   default="DROP")
add_chain("OUTPUT",      id="natOUT",  default="ACCEPT", table="nat")
add_chain("PREROUTING",  id="natPRE",  default="ACCEPT", table="nat")
add_chain("POSTROUTING", id="natPOST", default="ACCEPT", table="nat")
add_chain("INPUT",       id="manIN",   default="ACCEPT", table="mangle")
add_chain("OUTPUT",      id="manOUT",  default="ACCEPT", table="mangle")
add_chain("FORWARD",     id="manFWD",  default="ACCEPT", table="mangle")
add_chain("PREROUTING",  id="manPRE",  default="ACCEPT", table="mangle")
add_chain("POSTROUTING", id="manPOST", default="ACCEPT", table="mangle")
 |