apt-get install iptables-persistent
+
iptables-save > /etc/iptables/rules.v4
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:logging - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/24 -d 224.0.0.0/4 -i eth0 -p igmp -j ACCEPT
-A INPUT -s 192.168.0.0/24 -d 239.0.0.0/8 -i eth0 -p igmp -j ACCEPT
-A INPUT -s 192.168.0.0/24 -i eth0 -j ACCEPT
-A INPUT -i tun0 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 1194 -j ACCEPT
-A INPUT -j logging
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -s 192.168.0.0/24 -d 224.0.0.0/4 -o eth0 -p igmp -j ACCEPT
-A OUTPUT -s 192.168.0.0/24 -d 239.255.255.250/32 -o eth0 -p udp -m udp --dport 1900 -j ACCEPT
-A OUTPUT -d 192.168.0.0/24 -o eth0 -j ACCEPT
-A OUTPUT -o tun0 -j ACCEPT
-A OUTPUT -o eth0 -p udp -m udp --dport 1194 -j ACCEPT
-A OUTPUT -j logging
-A logging -m limit --limit 2/min -j LOG --log-prefix "IPTables general: " --log-level 7
-A logging -j DROP
COMMIT
# Completed on Sun Oct 7 17:58:39 2018
# Generated by iptables-save v1.6.0 on Sun Oct 7 17:58:39 2018
*nat
REROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
OSTROUTING ACCEPT [0:0]
COMMIT
# Completed on Sun Oct 7 17:58:39 2018
# Generated by iptables-save v1.6.0 on Sun Oct 7 17:58:39 2018
*mangle
REROUTING ACCEPT [58873:7962733]
:INPUT ACCEPT [58873:7962733]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [52231:7048563]
OSTROUTING ACCEPT [52215:7044919]
COMMIT
# Completed on Sun Oct 7 17:58:39 2018