*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [31651:96097871]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 60158 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -s 10.10.0.0/16 -j ACCEPT
-A INPUT -s 10.20.0.0/16 -j ACCEPT
-A INPUT -s 10.30.0.0/16 -j ACCEPT
-A INPUT -s 10.40.0.0/16 -j ACCEPT
-A INPUT -s 10.50.0.0/16 -j ACCEPT
-A INPUT -s 10.60.0.0/16 -j ACCEPT
-A INPUT -s 10.100.0.0/16 -j ACCEPT
-A INPUT -s 111.207.151.64/27 -j ACCEPT
-A INPUT -s 114.251.42.98/27 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 995 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 465 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 587 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 993 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 1080 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 20000 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10001 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10002 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 24000 -j ACCEPT
-A INPUT -m set --match-set banthis src -j DROP
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A INPUT -m set --match-set banthis src -j DROP
-A INPUT -p tcp -m tcp --sport 110 -m limit --limit 2000/sec --limit-burst 100 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 995 -m limit --limit 2000/sec --limit-burst 100 -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [31651:96097871]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 60158 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -s 10.10.0.0/16 -j ACCEPT
-A INPUT -s 10.20.0.0/16 -j ACCEPT
-A INPUT -s 10.30.0.0/16 -j ACCEPT
-A INPUT -s 10.40.0.0/16 -j ACCEPT
-A INPUT -s 10.50.0.0/16 -j ACCEPT
-A INPUT -s 10.60.0.0/16 -j ACCEPT
-A INPUT -s 10.100.0.0/16 -j ACCEPT
-A INPUT -s 111.207.151.64/27 -j ACCEPT
-A INPUT -s 114.251.42.98/27 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 110 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 995 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 25 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 465 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 587 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 143 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 993 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 1080 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 20000 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10001 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10002 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 24000 -j ACCEPT
-A INPUT -m set --match-set banthis src -j DROP
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A INPUT -m set --match-set banthis src -j DROP
-A INPUT -p tcp -m tcp --sport 110 -m limit --limit 2000/sec --limit-burst 100 -j ACCEPT
-A INPUT -p tcp -m tcp --sport 995 -m limit --limit 2000/sec --limit-burst 100 -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT