Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.21 on Sun Jan 31 15:31:10 2016
- *nat
- :PREROUTING ACCEPT [569:59885]
- :INPUT ACCEPT [578:39478]
- :OUTPUT ACCEPT [510:36499]
- :POSTROUTING ACCEPT [91:7244]
- :SS_SPEC_WAN_AC - [0:0]
- :SS_SPEC_WAN_FW - [0:0]
- :delegate_postrouting - [0:0]
- :delegate_prerouting - [0:0]
- :postrouting_lan_rule - [0:0]
- :postrouting_rule - [0:0]
- :postrouting_wan_rule - [0:0]
- :prerouting_lan_rule - [0:0]
- :prerouting_rule - [0:0]
- :prerouting_wan_rule - [0:0]
- :zone_lan_postrouting - [0:0]
- :zone_lan_prerouting - [0:0]
- :zone_wan_postrouting - [0:0]
- :zone_wan_prerouting - [0:0]
- -A PREROUTING -i br-lan -p tcp -m comment --comment _SS_SPEC_RULE_ -j SS_SPEC_WAN_AC
- -A PREROUTING -j delegate_prerouting
- -A OUTPUT -p tcp -m comment --comment _SS_SPEC_RULE_ -j SS_SPEC_WAN_AC
- -A POSTROUTING -j delegate_postrouting
- -A SS_SPEC_WAN_AC -m set --match-set ss_spec_wan_ac dst -j RETURN
- -A SS_SPEC_WAN_AC -j SS_SPEC_WAN_FW
- -A SS_SPEC_WAN_FW -p tcp -j REDIRECT --to-ports 1080
- -A delegate_postrouting -m comment --comment "user chain for postrouting" -j postrouting_rule
- -A delegate_postrouting -o br-lan -j zone_lan_postrouting
- -A delegate_postrouting -o eth0 -j zone_wan_postrouting
- -A delegate_postrouting -o wlan0 -j zone_wan_postrouting
- -A delegate_prerouting -m comment --comment "user chain for prerouting" -j prerouting_rule
- -A delegate_prerouting -i br-lan -j zone_lan_prerouting
- -A delegate_prerouting -i eth0 -j zone_wan_prerouting
- -A delegate_prerouting -i wlan0 -j zone_wan_prerouting
- -A zone_lan_postrouting -m comment --comment "user chain for postrouting" -j postrouting_lan_rule
- -A zone_lan_prerouting -m comment --comment "user chain for prerouting" -j prerouting_lan_rule
- -A zone_wan_postrouting -m comment --comment "user chain for postrouting" -j postrouting_wan_rule
- -A zone_wan_postrouting -j MASQUERADE
- -A zone_wan_prerouting -m comment --comment "user chain for prerouting" -j prerouting_wan_rule
- COMMIT
- # Completed on Sun Jan 31 15:31:10 2016
- # Generated by iptables-save v1.4.21 on Sun Jan 31 15:31:10 2016
- *raw
- :PREROUTING ACCEPT [10235:2719708]
- :OUTPUT ACCEPT [9578:3316689]
- :delegate_notrack - [0:0]
- -A PREROUTING -j delegate_notrack
- COMMIT
- # Completed on Sun Jan 31 15:31:10 2016
- # Generated by iptables-save v1.4.21 on Sun Jan 31 15:31:10 2016
- *mangle
- :PREROUTING ACCEPT [9897:2692995]
- :INPUT ACCEPT [8597:2120404]
- :FORWARD ACCEPT [1532:576239]
- :OUTPUT ACCEPT [9578:3316689]
- :POSTROUTING ACCEPT [11110:3892928]
- :SS_SPEC_TPROXY - [0:0]
- :fwmark - [0:0]
- :mssfix - [0:0]
- -A PREROUTING -i br-lan -p udp -m comment --comment _SS_SPEC_RULE_ -j SS_SPEC_TPROXY
- -A PREROUTING -j fwmark
- -A FORWARD -j mssfix
- -A SS_SPEC_TPROXY -p udp -m set ! --match-set ss_spec_wan_ac dst -j TPROXY --on-port 1080 --on-ip 0.0.0.0 --tproxy-mark 0x1/0x1
- -A mssfix -o eth0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "wan (mtu_fix)" -j TCPMSS --clamp-mss-to-pmtu
- -A mssfix -o wlan0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "wan (mtu_fix)" -j TCPMSS --clamp-mss-to-pmtu
- COMMIT
- # Completed on Sun Jan 31 15:31:10 2016
- # Generated by iptables-save v1.4.21 on Sun Jan 31 15:31:10 2016
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- :delegate_forward - [0:0]
- :delegate_input - [0:0]
- :delegate_output - [0:0]
- :forwarding_lan_rule - [0:0]
- :forwarding_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- :input_lan_rule - [0:0]
- :input_rule - [0:0]
- :input_wan_rule - [0:0]
- :output_lan_rule - [0:0]
- :output_rule - [0:0]
- :output_wan_rule - [0:0]
- :reject - [0:0]
- :syn_flood - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_src_REJECT - [0:0]
- -A INPUT -j delegate_input
- -A FORWARD -j delegate_forward
- -A OUTPUT -j delegate_output
- -A delegate_forward -m comment --comment "user chain for forwarding" -j forwarding_rule
- -A delegate_forward -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A delegate_forward -i br-lan -j zone_lan_forward
- -A delegate_forward -i eth0 -j zone_wan_forward
- -A delegate_forward -i wlan0 -j zone_wan_forward
- -A delegate_forward -j reject
- -A delegate_input -i lo -j ACCEPT
- -A delegate_input -m comment --comment "user chain for input" -j input_rule
- -A delegate_input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A delegate_input -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn_flood
- -A delegate_input -i br-lan -j zone_lan_input
- -A delegate_input -i eth0 -j zone_wan_input
- -A delegate_input -i wlan0 -j zone_wan_input
- -A delegate_output -o lo -j ACCEPT
- -A delegate_output -m comment --comment "user chain for output" -j output_rule
- -A delegate_output -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A delegate_output -o br-lan -j zone_lan_output
- -A delegate_output -o eth0 -j zone_wan_output
- -A delegate_output -o wlan0 -j zone_wan_output
- -A reject -p tcp -j REJECT --reject-with tcp-reset
- -A reject -j REJECT --reject-with icmp-port-unreachable
- -A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -j RETURN
- -A syn_flood -j DROP
- -A zone_lan_dest_ACCEPT -o br-lan -j ACCEPT
- -A zone_lan_forward -m comment --comment "user chain for forwarding" -j forwarding_lan_rule
- -A zone_lan_forward -m comment --comment "forwarding lan -> wan" -j zone_wan_dest_ACCEPT
- -A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "Accept port forwards" -j ACCEPT
- -A zone_lan_forward -j zone_lan_dest_ACCEPT
- -A zone_lan_input -m comment --comment "user chain for input" -j input_lan_rule
- -A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "Accept port redirections" -j ACCEPT
- -A zone_lan_input -j zone_lan_src_ACCEPT
- -A zone_lan_output -m comment --comment "user chain for output" -j output_lan_rule
- -A zone_lan_output -j zone_lan_dest_ACCEPT
- -A zone_lan_src_ACCEPT -i br-lan -j ACCEPT
- -A zone_wan_dest_ACCEPT -o eth0 -j ACCEPT
- -A zone_wan_dest_ACCEPT -o wlan0 -j ACCEPT
- -A zone_wan_dest_REJECT -o eth0 -j reject
- -A zone_wan_dest_REJECT -o wlan0 -j reject
- -A zone_wan_forward -m comment --comment "user chain for forwarding" -j forwarding_wan_rule
- -A zone_wan_forward -p esp -m comment --comment "@rule[7]" -j zone_lan_dest_ACCEPT
- -A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "@rule[8]" -j zone_lan_dest_ACCEPT
- -A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "Accept port forwards" -j ACCEPT
- -A zone_wan_forward -j zone_wan_dest_REJECT
- -A zone_wan_input -m comment --comment "user chain for input" -j input_wan_rule
- -A zone_wan_input -p udp -m udp --dport 68 -m comment --comment Allow-DHCP-Renew -j ACCEPT
- -A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment Allow-Ping -j ACCEPT
- -A zone_wan_input -p igmp -m comment --comment Allow-IGMP -j ACCEPT
- -A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "Accept port redirections" -j ACCEPT
- -A zone_wan_input -j zone_wan_src_REJECT
- -A zone_wan_output -m comment --comment "user chain for output" -j output_wan_rule
- -A zone_wan_output -j zone_wan_dest_ACCEPT
- -A zone_wan_src_REJECT -i eth0 -j reject
- -A zone_wan_src_REJECT -i wlan0 -j reject
- COMMIT
- # Completed on Sun Jan 31 15:31:10 2016
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement