-p INPUT DROP -p OUTPUT DROP -p FORWARD DROP #allow all traffic on loopback adapter -A INPUT -i lo -j ACCEPT -A OUTPUT -o lo -j ACCEPT # allow incoming ssh connections only -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT -A INOUT -o eth0 -p tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT # port 80/443 - incoming -A INPUT -i eth0 -p tcp -m multiport --dports 80,443 -m state --state NEW,ESTABLISHED -j ACCEPT -A OUTPUT -o eth0 -p tcp -m multiport --sports 80,443 -m state --state ESTABLISHED -j ACCEPT # port 80/443 - outgoing -A OUTPUT -o eth0 -p tcp --dport 80 -j ACCEPT -A INPUT -i eth0 -p tcp --sport 80 -j ACCEPT -A INPUT -j DROP -A OUTPUT -j DROP
Feel free to suggest alternatives but please explain things and not just post the solution.
Thanks







