30
30
-A ufw-before-input -m conntrack --ctstate INVALID -j ufw-logging-deny
31
31
-A ufw-before-input -m conntrack --ctstate INVALID -j DROP
34
34
-A ufw-before-input -p icmp --icmp-type destination-unreachable -j ACCEPT
35
35
-A ufw-before-input -p icmp --icmp-type source-quench -j ACCEPT
36
36
-A ufw-before-input -p icmp --icmp-type time-exceeded -j ACCEPT
37
37
-A ufw-before-input -p icmp --icmp-type parameter-problem -j ACCEPT
38
38
-A ufw-before-input -p icmp --icmp-type echo-request -j ACCEPT
40
47
# allow dhcp client to work
41
48
-A ufw-before-input -p udp --sport 67 --dport 68 -j ACCEPT