I am trying to allow snmp traps to be sent to a remote machine for cacti graphing. This is what I have now, but it's not working:
Chain INPUT (policy DROP) ACCEPT udp -- 0.0.0.0/0 x.x.x.x udp dpt:161 ACCEPT udp -- 0.0.0.0/0 x.x.x.x udp dpt:162 ACCEPT udp -- 0.0.0.0/0 x.x.x.x udp spts:1023:2999
The last line is something someone suggested but it didn't help. I thought this would be simple, and I've done lots of googling, but I've run into a wall.
Thanks for any pointers!
EDIT: Here is the output of iptables -L -n -v:
Chain INPUT (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.134.14 udp spts:1023:2999 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.135.57 udp spts:1023:2999 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.135.57 udp dpt:161 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.134.14 udp dpt:161 2678 195K fail2ban-SSH tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 2585 188K fail2ban-ssh tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 37790 5151K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 0 0 REJECT all -- * * 67.210.96.146 0.0.0.0/0 reject-with icmp-port-unreachable 2585 188K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 27 8856 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:67 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68 229K 77M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:20 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:21 5096 256K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:25 695 44360 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:53 125 6648 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:80 4 160 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:123 10 600 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:443 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:514 63 3780 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:110 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:143 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:220 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:993 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:143 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:220 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:993 3 144 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:995 50 3088 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:587 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:873 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:5038 1 40 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpts:32768:65535 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:20 0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:21 20839 1442K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:53 86707 6588K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:123 1 48 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:10000 4244 619K ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW 18386 1220K LOGDROP all -- * * 0.0.0.0/0 0.0.0.0/0 Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.134.14 udp dpt:161 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.134.14 udp dpt:162 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.135.57 udp dpt:161 0 0 ACCEPT udp -- * * 0.0.0.0/0 184.105.135.57 udp dpt:162 37790 5151K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 279K 82M ACCEPT all -- * eth0 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 29306 2262K ACCEPT all -- * eth0 0.0.0.0/0 0.0.0.0/0 Chain LOGDROP (1 references) pkts bytes target prot opt in out source destination 18386 1220K LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 4 prefix `\'*IPT*\'' 18386 1220K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 Chain fail2ban-SSH (1 references) pkts bytes target prot opt in out source destination 2585 188K RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 Chain fail2ban-ssh (1 references) pkts bytes target prot opt in out source destination 2585 188K RETURN all -- * * 0.0.0.0/0 0.0.0.0/0