The bind logs is from hostname rambutan/rambutan4. I did not specify the IP address for bind9 as it is set to listen to any.
If I set the listen to specific, bind9 would fail to listen. Example.
Anyhow, the defaults for the ufw was to deny incoming and deny outgoing. Below is the iptables -L output.
Chain INPUT (policy DROP)
target prot opt source destination
ufw-before-logging-input all -- anywhere anyw
here
ufw-before-input all -- anywhere anywhere
ufw-after-input all -- anywhere anywhere
ufw-after-logging-input all -- anywhere anywh
ere
ufw-reject-input all -- anywhere anywhere
ufw-track-input all -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
ufw-before-logging-forward all -- anywhere an
ywhere
ufw-before-forward all -- anywhere anywhere
ufw-after-forward all -- anywhere anywhere
ufw-after-logging-forward all -- anywhere any
where
ufw-reject-forward all -- anywhere anywhere
ufw-track-forward all -- anywhere anywhere
Chain OUTPUT (policy DROP)
target prot opt source destination
ufw-before-logging-output all -- anywhere any
where
ufw-before-output all -- anywhere anywhere
ufw-after-output all -- anywhere anywhere
ufw-after-logging-output all -- anywhere anyw
here
ufw-reject-output all -- anywhere anywhere
ufw-track-output all -- anywhere anywhere
Chain ufw-after-forward (1 references)
target prot opt source destination
Chain ufw-after-input (1 references)
target prot opt source destination
ufw-skip-to-policy-input udp -- anywhere anyw
here udp dpt:netbios-ns
ufw-skip-to-policy-input udp -- anywhere anyw
here udp dpt:netbios-dgm
ufw-skip-to-policy-input tcp -- anywhere anyw
here tcp dpt:netbios-ssn
ufw-skip-to-policy-input tcp -- anywhere anyw
here tcp dpt:microsoft-ds
ufw-skip-to-policy-input udp -- anywhere anyw
here udp dpt:bootps
ufw-skip-to-policy-input udp -- anywhere anyw
here udp dpt:bootpc
ufw-skip-to-policy-input all -- anywhere anyw
here ADDRTYPE match dst-type BROADCAST
Chain ufw-after-logging-forward (1 references)
target prot opt source destination
Chain ufw-after-logging-input (1 references)
target prot opt source destination
Chain ufw-after-logging-output (1 references)
target prot opt source destination
Chain ufw-after-output (1 references)
target prot opt source destination
Chain ufw-before-forward (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ctstate RELATED,ESTABLISHED
ACCEPT icmp -- anywhere anywhere
icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere
icmp time-exceeded
ACCEPT icmp -- anywhere anywhere
icmp parameter-problem
ACCEPT icmp -- anywhere anywhere
icmp echo-request
ufw-user-forward all -- anywhere anywhere
Chain ufw-before-input (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ctstate RELATED,ESTABLISHED
ufw-logging-deny all -- anywhere anywhere
ctstate INVALID
DROP all -- anywhere anywhere
ctstate INVALID
ACCEPT icmp -- anywhere anywhere
icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere
icmp time-exceeded
ACCEPT icmp -- anywhere anywhere
icmp parameter-problem
ACCEPT icmp -- anywhere anywhere
icmp echo-request
ACCEPT udp -- anywhere anywhere
udp spt:bootps dpt:bootpc
ufw-not-local all -- anywhere anywhere
ACCEPT udp -- anywhere 224.0.0.251
udp dpt:mdns
ACCEPT udp -- anywhere 239.255.255.250
udp dpt:1900
ufw-user-input all -- anywhere anywhere
Chain ufw-before-logging-forward (1 references)
target prot opt source destination
Chain ufw-before-logging-input (1 references)
target prot opt source destination
Chain ufw-before-logging-output (1 references)
target prot opt source destination
Chain ufw-before-output (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ctstate RELATED,ESTABLISHED
ufw-user-output all -- anywhere anywhere
Chain ufw-logging-allow (0 references)
target prot opt source destination
Chain ufw-logging-deny (2 references)
target prot opt source destination
Chain ufw-not-local (1 references)
target prot opt source destination
RETURN all -- anywhere anywhere
ADDRTYPE match dst-type LOCAL
RETURN all -- anywhere anywhere
ADDRTYPE match dst-type MULTICAST
RETURN all -- anywhere anywhere
ADDRTYPE match dst-type BROADCAST
ufw-logging-deny all -- anywhere anywhere
limit: avg 3/min burst 10
DROP all -- anywhere anywhere
Chain ufw-reject-forward (1 references)
target prot opt source destination
Chain ufw-reject-input (1 references)
target prot opt source destination
Chain ufw-reject-output (1 references)
target prot opt source destination
Chain ufw-skip-to-policy-forward (0 references)
target prot opt source destination
DROP all -- anywhere anywhere
Chain ufw-skip-to-policy-input (7 references)
target prot opt source destination
DROP all -- anywhere anywhere
Chain ufw-skip-to-policy-output (0 references)
target prot opt source destination
DROP all -- anywhere anywhere
Chain ufw-track-forward (1 references)
target prot opt source destination
Chain ufw-track-input (1 references)
target prot opt source destination
Chain ufw-track-output (1 references)
target prot opt source destination
Chain ufw-user-forward (1 references)
target prot opt source destination
Chain ufw-user-input (1 references)
target prot opt source destination
tcp -- anywhere rambutan.zystro.xyz
tcp dpt:22 ctstate NEW recent: SET name: DEFAULT side:
source mask: 255.255.255.255
ufw-user-limit tcp -- anywhere rambutan.zystr
o.xyz tcp dpt:22 ctstate NEW recent: UPDATE seconds: 30
hit_count: 6 name: DEFAULT side: source mask: 255.255.255.25
5
ufw-user-limit-accept tcp -- anywhere rambuta
n.zystro.xyz tcp dpt:22
tcp -- anywhere rambutan.zystro.xyz
tcp dpt:ssh ctstate NEW recent: SET name: DEFAULT side: so
urce mask: 255.255.255.255
ufw-user-limit tcp -- anywhere rambutan.zystr
o.xyz tcp dpt:ssh ctstate NEW recent: UPDATE seconds: 30 hi
t_count: 6 name: DEFAULT side: source mask: 255.255.255.255
ufw-user-limit-accept tcp -- anywhere rambuta
n.zystro.xyz tcp dpt:ssh
ACCEPT udp -- anywhere anywhere
udp dpt:domain
ACCEPT tcp -- anywhere anywhere
tcp dpt:domain
Chain ufw-user-limit (2 references)
target prot opt source destination
REJECT all -- anywhere anywhere
reject-with icmp-port-unreachable
Chain ufw-user-limit-accept (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
Chain ufw-user-logging-forward (0 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain ufw-user-logging-input (0 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain ufw-user-logging-output (0 references)
target prot opt source destination
RETURN all -- anywhere anywhere
Chain ufw-user-output (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere rambutan.zystro.xyz
tcp dpt:22
ACCEPT udp -- anywhere anywhere
udp dpt:ntp
ACCEPT tcp -- anywhere anywhere
tcp dpt:http
ACCEPT tcp -- anywhere anywhere
tcp dpt:https
ACCEPT tcp -- anywhere anywhere
tcp dpt:domain
ACCEPT udp -- anywhere anywhere
udp dpt:domain