It's OK. How about this :-
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 5671,5672 -m comment --comment "001 amqp incoming amqp_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 5671,5672 -m comment --comment "001 amqp incoming amqp_192.168.1.137" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 8777 -m comment --comment "001 ceilometer-api incoming ceilometer_api" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 3260,8776 -m comment --comment "001 cinder incoming cinder_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 3260,8776 -m comment --comment "001 cinder incoming cinder_192.168.1.137" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 9292 -m comment --comment "001 glance incoming glance_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 9292 -m comment --comment "001 glance incoming glance_192.168.1.137" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 9697 -m comment --comment "001 metadata coming metadata_192.168.1.137" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 80 -m comment --comment "001 horizon 80 incoming" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 5000,35357 -m comment --comment "001 keystone incoming keystone" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 27017 -m comment --comment "001 mongodb-server incoming swift_storage_and_rsync_192.168.1.137" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 3306 -m comment --comment "001 mysql incoming mysql_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 3306 -m comment --comment "001 mysql incoming mysql_192.168.1.137" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 80 -m comment --comment "001 nagios incoming" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 5666 -m comment --comment "001 nagios-nrpe incoming nagios_nrpe" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 67 -m comment --comment "001 neutron dhcp in incoming neutron_dhcp_in_192.168.1.127_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 67 -m comment --comment "001 neutron dhcp in incoming neutron_dhcp_in_192.168.1.127_192.168.1.137" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 9696 -m comment --comment "001 neutron server incoming neutron_server_192.168.1.127_192.168.1.127" -j ACCEPT
-A INPUT -s 192.168.1.137/32 -p tcp -m multiport --dports 9696 -m comment --comment "001 neutron server incoming neutron_server_192.168.1.127_192.168.1.137" -j ACCEPT
-A INPUT -s 192.168.1.127/32 -p tcp -m multiport --dports 5900:5999 -m comment --comment "001 nova compute incoming nova_compute" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 8773,8774,8775 -m comment --comment "001 novaapi incoming" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 6080 -m comment --comment "001 novncproxy incoming" -j ACCEPT
-A INPUT -p tcp -m multiport --dports 8080 -m comment --comment "001 swift proxy incoming" -j ACCEPT
↧