#
-# Copyright (c) 2015 Samsung Electronics Co., Ltd All Rights Reserved
+# Copyright (c) 2015 - 2017 Samsung Electronics Co., Ltd All Rights Reserved
#
# Contact: Roman Kubiak (r.kubiak@samsung.com)
#
:FORWARD ACCEPT
:OUTPUT ACCEPT
:POSTROUTING ACCEPT
+:CHECK-LOCALHOST -
-A INPUT ! -i lo -j SECMARK --selctx System
--A OUTPUT -o lo -j ACCEPT
+-A OUTPUT -o lo -j CHECK-LOCALHOST
-A OUTPUT -m conntrack --ctstate NEW ! --ctstatus CONFIRMED -j NFQUEUE --queue-num 0 --queue-bypass
+-A OUTPUT -p udplite -j NFQUEUE --queue-num 0 --queue-bypass
+-A CHECK-LOCALHOST -p udp --dport 53 -j RETURN
+-A CHECK-LOCALHOST -p tcp --dport 53 -j RETURN
+-A CHECK-LOCALHOST -j ACCEPT
COMMIT
*filter
:INPUT ACCEPT
:OUTPUT ACCEPT
:NETHER-ALLOWLOG -
:NETHER-DENY -
--A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m mark --mark 0x3 -j NETHER-DENY
-A OUTPUT -m mark --mark 0x4 -j NETHER-ALLOWLOG
-A NETHER-ALLOWLOG -j AUDIT --type accept