Advertisement
Guest User

Untitled

a guest
Feb 13th, 2016
61
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.13 KB | None | 0 0
  1. *nat
  2. :PREROUTING ACCEPT [314:38348]
  3. :POSTROUTING ACCEPT [0:0]
  4. :OUTPUT ACCEPT [20:1469]
  5. :WANPREROUTING - [0:0]
  6. :upnp - [0:0]
  7. -A PREROUTING -d 98.176.81.170 -j WANPREROUTING
  8. -A PREROUTING -d 192.168.1.0/255.255.255.0 -i vlan2 -j DROP
  9. -A PREROUTING -d 98.176.81.170 -j upnp
  10. -A POSTROUTING -o vlan2 -j MASQUERADE
  11. -A POSTROUTING -s 192.168.1.0/255.255.255.0 -d 192.168.1.0/255.255.255.0 -o br0 -j SNAT --to-source 192.168.1.1
  12. -A WANPREROUTING -p icmp -j DNAT --to-destination 192.168.1.1
  13. -A WANPREROUTING -p tcp -m tcp --dport 7700 -j DNAT --to-destination 192.168.1.50:80
  14. -A WANPREROUTING -p tcp -m tcp --dport 35729 -j DNAT --to-destination 192.168.1.10:35729
  15. -A WANPREROUTING -p udp -m udp --dport 1194 -j DNAT --to-destination 192.168.1.31
  16. -A WANPREROUTING -p tcp -m multiport --dports 18671,20443 -j DNAT --to-destination 192.168.1.34
  17. -A WANPREROUTING -p udp -m multiport --dports 9305,9306 -j DNAT --to-destination 192.168.1.34
  18. -A WANPREROUTING -p tcp -m tcp --dport 5000 -j DNAT --to-destination 192.168.1.10:80
  19. -A WANPREROUTING -p tcp -m tcp --dport 3000 -j DNAT --to-destination 192.168.1.10:3000
  20. -A upnp -p tcp -m tcp --dport 21052 -j DNAT --to-destination 192.168.1.10:21052
  21. -A upnp -p udp -m udp --dport 49570 -j DNAT --to-destination 192.168.1.184:16402
  22. -A upnp -p tcp -m tcp --dport 38388 -j DNAT --to-destination 192.168.1.31:38388
  23. -A upnp -p udp -m udp --dport 38388 -j DNAT --to-destination 192.168.1.31:38388
  24. -A upnp -p tcp -m tcp --dport 21053 -j DNAT --to-destination 192.168.1.12:21052
  25. -A upnp -p udp -m udp --dport 21052 -j DNAT --to-destination 192.168.1.12:21052
  26. -A upnp -p tcp -m tcp --dport 5111 -j DNAT --to-destination 192.168.1.90:5111
  27. COMMIT
  28. # Completed on Sat Feb 13 13:54:35 2016
  29. # Generated by iptables-save v1.3.8 on Sat Feb 13 13:54:35 2016
  30. *mangle
  31. :PREROUTING ACCEPT [36936285:30753154383]
  32. :INPUT ACCEPT [604170:71654258]
  33. :FORWARD ACCEPT [36172902:30642502640]
  34. :OUTPUT ACCEPT [478282:74935219]
  35. :POSTROUTING ACCEPT [36598005:30712808846]
  36. -A PREROUTING -i vlan2 -j DSCP --set-dscp 0x00
  37. COMMIT
  38. # Completed on Sat Feb 13 13:54:35 2016
  39. # Generated by iptables-save v1.3.8 on Sat Feb 13 13:54:35 2016
  40. *filter
  41. :INPUT DROP [6:360]
  42. :FORWARD DROP [0:0]
  43. :OUTPUT ACCEPT [413:52048]
  44. :logaccept - [0:0]
  45. :shlimit - [0:0]
  46. :upnp - [0:0]
  47. :wanin - [0:0]
  48. :wanout - [0:0]
  49. -A INPUT -m state --state INVALID -j DROP
  50. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  51. -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j shlimit
  52. -A INPUT -i lo -j ACCEPT
  53. -A INPUT -i br0 -j ACCEPT
  54. -A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
  55. -A FORWARD -m account --aaddr 192.168.1.0/255.255.255.0 --aname lan
  56. -A FORWARD -i br0 -o br0 -j ACCEPT
  57. -A FORWARD -m state --state INVALID -j DROP
  58. -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
  59. -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
  60. -A FORWARD -i vlan2 -j wanin
  61. -A FORWARD -o vlan2 -j wanout
  62. -A FORWARD -i br0 -j logaccept
  63. -A FORWARD -i vlan2 -j upnp
  64. -A logaccept -m state --state NEW -m limit --limit 1/sec -j LOG
  65. -A logaccept -j ACCEPT
  66. -A shlimit -m recent --set --name shlimit --rsource
  67. -A shlimit -m recent --update --seconds 60 --hitcount 4 --name shlimit --rsource -j DROP
  68. -A upnp -d 192.168.1.10 -p tcp -m tcp --dport 21052 -j ACCEPT
  69. -A upnp -d 192.168.1.184 -p udp -m udp --dport 16402 -j ACCEPT
  70. -A upnp -d 192.168.1.31 -p tcp -m tcp --dport 38388 -j ACCEPT
  71. -A upnp -d 192.168.1.31 -p udp -m udp --dport 38388 -j ACCEPT
  72. -A upnp -d 192.168.1.12 -p tcp -m tcp --dport 21052 -j ACCEPT
  73. -A upnp -d 192.168.1.12 -p udp -m udp --dport 21052 -j ACCEPT
  74. -A upnp -d 192.168.1.90 -p tcp -m tcp --dport 5111 -j ACCEPT
  75. -A wanin -d 192.168.1.50 -p tcp -m tcp --dport 80 -j ACCEPT
  76. -A wanin -d 192.168.1.10 -p tcp -m tcp --dport 35729 -j ACCEPT
  77. -A wanin -d 192.168.1.31 -p udp -m udp --dport 1194 -j ACCEPT
  78. -A wanin -d 192.168.1.34 -p tcp -m tcp -m multiport --dports 18671,20443 -j ACCEPT
  79. -A wanin -d 192.168.1.34 -p udp -m udp -m multiport --dports 9305,9306 -j ACCEPT
  80. -A wanin -d 192.168.1.10 -p tcp -m tcp --dport 80 -j ACCEPT
  81. -A wanin -d 192.168.1.10 -p tcp -m tcp --dport 3000 -j ACCEPT
  82. COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement