[root@web sysconfig]# cat /etc/sysconfig/iptables
# Generated by iptables-save v1.4.5 on Sun Dec 13 03:31:22 2009
*filter
:INPUT ACCEPT [296:18556]
:FORWARD ACCEPT [15:720]
:OUTPUT ACCEPT [401:24654]
-A INPUT -f -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -j ULOG --ulog-prefix "icount" --ulog-cprange 48 --ulog-qthreshold 50
-A INPUT -i breth1 -p tcp -m tcp --dport 8080 -j ACCEPT
-A INPUT -i breth1 -p udp -m udp --dport 1194 -j ACCEPT
-A INPUT -i breth1 -p tcp -m tcp --dport 1194 -j ACCEPT
-A INPUT -i breth1 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i breth1 -p udp -m udp --dport 22 -j ACCEPT
-A INPUT -i breth1 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i breth1 -p udp -m udp --dport 80 -j ACCEPT
-A INPUT -i breth1 -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -i breth1 -p udp -m udp --dport 443 -j ACCEPT
-A INPUT -i breth1 -p icmp -j ACCEPT
-A INPUT -i breth1 -j DROP
-A INPUT -s 192.168.0.0/24 -i breth0 -j ACCEPT
-A INPUT -s 192.168.0.0/24 -p tcp -m tcp --dport 3128 -j ACCEPT
-A FORWARD -f -j DROP
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j ULOG --ulog-prefix "fcount" --ulog-cprange 48 --ulog-qthreshold 50
-A FORWARD -d 192.168.1.0/24 -i breth1 -j ACCEPT
-A FORWARD -m physdev --physdev-is-bridged -j ACCEPT
-A FORWARD -i breth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i breth1 -j DROP
-A OUTPUT -f -j DROP
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -j ULOG --ulog-prefix "ocount" --ulog-cprange 48 --ulog-qthreshold 50
COMMIT
# Completed on Sun Dec 13 03:31:22 2009
# Generated by iptables-save v1.4.5 on Sun Dec 13 03:31:22 2009
*mangle
:PREROUTING ACCEPT [4074:2287922]
:INPUT ACCEPT [4031:2284076]
:FORWARD ACCEPT [15:720]
:OUTPUT ACCEPT [4288:390558]
:POSTROUTING ACCEPT [4452:422672]
COMMIT
# Completed on Sun Dec 13 03:31:22 2009
# Generated by iptables-save v1.4.5 on Sun Dec 13 03:31:22 2009
*nat
:PREROUTING ACCEPT [44:4459]
:POSTROUTING ACCEPT [544:36792]
:OUTPUT ACCEPT [539:36552]
-A PREROUTING -i breth0 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A PREROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A OUTPUT -p tcp -m owner --uid-owner squid -j ACCEPT
-A OUTPUT -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
COMMIT
# Completed on Sun Dec 13 03:31:22 2009
[root@web sysconfig]# cat /etc/sysconfig/iptables_params
# Save current iptables firewall rules on stop.
# Value: yes|no, default: no
IPTABLES_SAVE_ON_STOP=no
# Save current iptables firewall rules on restart.
# Value: yes|no, default: no
IPTABLES_SAVE_ON_RESTART=no
# Additional options to iptables-restore.
# Value: string, default:
IPTABLES_RESTORE_ARGS=
# Additional options to iptables-save.
# Value: string, default:
IPTABLES_SAVE_ARGS=
# Additional options to iptables --list.
# Value: string, default:
IPTABLES_STATUS_ARGS=