Hacker News new | past | comments | ask | show | jobs | submit login

I would add:

-A PROXY_OUT -d 127.0.0.0/8 -j DROP

-A PROXY_OUT -d 169.254.0.0/16 -j DROP

That seems to cover everything in IPv4, but if you have IPv6 enabled, you probably want fd00::/8, fe80::/10 and ::1/128 as well (disclaimer: my knowledge of IPv6 is rather limited.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: