Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.10 on Mon Jul 25 12:06:11 2016
- *raw
- :PREROUTING ACCEPT [2477314:253492469]
- :OUTPUT ACCEPT [1299014:192455111]
- :STD_OUTPUT - [0:0]
- :STD_PREROUTING - [0:0]
- -A PREROUTING -j STD_PREROUTING
- -A OUTPUT -j STD_OUTPUT
- COMMIT
- # Completed on Mon Jul 25 12:06:11 2016
- # Generated by iptables-save v1.4.10 on Mon Jul 25 12:06:11 2016
- *nat
- :PREROUTING ACCEPT [384492:32303572]
- :INPUT ACCEPT [35:7720]
- :OUTPUT ACCEPT [129190:7754722]
- :POSTROUTING ACCEPT [129153:7752100]
- :STD_OUTPUT - [0:0]
- :STD_POSTROUTING - [0:0]
- :STD_PREROUTING - [0:0]
- -A PREROUTING -j STD_PREROUTING
- -A OUTPUT -j STD_OUTPUT
- -A POSTROUTING -j STD_POSTROUTING
- COMMIT
- # Completed on Mon Jul 25 12:06:11 2016
- # Generated by iptables-save v1.4.10 on Mon Jul 25 12:06:11 2016
- *mangle
- :PREROUTING ACCEPT [2477317:253492589]
- :INPUT ACCEPT [1246924:150139633]
- :FORWARD ACCEPT [695948:58459632]
- :OUTPUT ACCEPT [1299017:192455291]
- :POSTROUTING ACCEPT [1994890:250909109]
- :STD_FORWARD - [0:0]
- :STD_INPUT - [0:0]
- :STD_OUTPUT - [0:0]
- :STD_POSTROUTING - [0:0]
- :STD_PREROUTING - [0:0]
- -A PREROUTING -j STD_PREROUTING
- -A INPUT -j STD_INPUT
- -A FORWARD -j STD_FORWARD
- -A OUTPUT -j STD_OUTPUT
- -A POSTROUTING -j STD_POSTROUTING
- COMMIT
- # Completed on Mon Jul 25 12:06:11 2016
- # Generated by iptables-save v1.4.10 on Mon Jul 25 12:06:11 2016
- *filter
- :INPUT DROP [252:22688]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [75:5814]
- :LOCAL_RED_ - [0:0]
- :MCAST_ - [0:0]
- :PEERS_ - [0:0]
- :REGAUTH_ - [0:0]
- :REMOTE_RED_ - [0:0]
- :STD_FORWARD - [0:0]
- :STD_INPUT - [0:0]
- :STD_OUTPUT - [0:0]
- :TUNNEL_ - [0:0]
- :USER_FORWARD - [0:0]
- :USER_INPUT - [0:0]
- :USER_OUTPUT - [0:0]
- -A INPUT -j USER_INPUT
- -A INPUT -j STD_INPUT
- -A INPUT -i dbg -j ACCEPT
- -A FORWARD -j USER_FORWARD
- -A FORWARD -j STD_FORWARD
- -A OUTPUT -j USER_OUTPUT
- -A OUTPUT -j STD_OUTPUT
- -A OUTPUT -o dbg -j ACCEPT
- -A LOCAL_RED_ -s 192.168.3.0/24 -j MARK --set-xmark 0x1/0x1
- -A LOCAL_RED_ -d 192.168.3.0/24 -j MARK --set-xmark 0x2/0x2
- -A MCAST_ -s 224.0.0.0/4 -j MARK --set-xmark 0x1/0x1
- -A MCAST_ -d 224.0.0.0/4 -j MARK --set-xmark 0x2/0x2
- -A PEERS_ -s xy.189.68.250/32 -j MARK --set-xmark 0x1/0x1
- -A PEERS_ -d xy.189.68.250/32 -j MARK --set-xmark 0x2/0x2
- -A PEERS_ -s abc.138.78.6/32 -j MARK --set-xmark 0x1/0x1
- -A PEERS_ -d abc.138.78.6/32 -j MARK --set-xmark 0x2/0x2
- -A PEERS_ -s gh.0.0.2/32 -j MARK --set-xmark 0x1/0x1
- -A PEERS_ -d gh.0.0.2/32 -j MARK --set-xmark 0x2/0x2
- -A REGAUTH_ -s xy.189.68.250/32 -j MARK --set-xmark 0x1/0x1
- -A REGAUTH_ -d xy.189.68.250/32 -j MARK --set-xmark 0x2/0x2
- -A REMOTE_RED_ -s 192.168.99.0/24 -j MARK --set-xmark 0x1/0x1
- -A REMOTE_RED_ -d 192.168.99.0/24 -j MARK --set-xmark 0x2/0x2
- -A REMOTE_RED_ -s 192.168.111.0/24 -j MARK --set-xmark 0x1/0x1
- -A REMOTE_RED_ -d 192.168.111.0/24 -j MARK --set-xmark 0x2/0x2
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j MARK --set-xmark 0x8/0xffffffff
- -A STD_FORWARD -j REMOTE_RED_
- -A STD_FORWARD -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_FORWARD -j LOCAL_RED_
- -A STD_FORWARD -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j MARK --set-xmark 0x8/0xffffffff
- -A STD_FORWARD -j LOCAL_RED_
- -A STD_FORWARD -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_FORWARD -j REMOTE_RED_
- -A STD_FORWARD -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j MARK --set-xmark 0x8/0xffffffff
- -A STD_FORWARD -j LOCAL_RED_
- -A STD_FORWARD -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_FORWARD -j MCAST_
- -A STD_FORWARD -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j MARK --set-xmark 0x8/0xffffffff
- -A STD_FORWARD -j REMOTE_RED_
- -A STD_FORWARD -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_FORWARD -j MCAST_
- -A STD_FORWARD -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j TUNNEL_
- -A STD_FORWARD -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_FORWARD -j MARK --set-xmark 0x0/0xffffffff
- -A STD_FORWARD -j TUNNEL_
- -A STD_FORWARD -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_INPUT -p icmp -m limit --limit 1/sec -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p esp -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p ipencap -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 500 -m state --state NEW -m recent --rcheck --seconds 60 --hitcount 2 --rttl --name PEERIPSEC --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 500 -m state --state NEW -m recent --set --name PEERIPSEC --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 500 -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p udp -m udp --dport 500 -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 4500 -m state --state NEW -m recent --rcheck --seconds 60 --hitcount 2 --rttl --name PEERIPSECNAT --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 4500 -m state --state NEW -m recent --set --name PEERIPSECNAT --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 4500 -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p udp -m udp --dport 4500 -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i red -j MCAST_
- -A STD_INPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i gre+ -j MCAST_
- -A STD_INPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p igmp -j MARK --set-xmark 0x8/0xffffffff
- -A STD_INPUT -j TUNNEL_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_INPUT -j MCAST_
- -A STD_INPUT -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i gre+ -j TUNNEL_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p gre -j MARK --set-xmark 0x8/0xffffffff
- -A STD_INPUT -j REMOTE_RED_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_INPUT -j LOCAL_RED_
- -A STD_INPUT -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --sport 10003 -m state --state ESTABLISHED -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 3 --connlimit-mask 32 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -m state --state NEW -m recent --rcheck --seconds 30 --hitcount 2 --rttl --name REGMNGT --rsource -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -m state --state NEW -m recent --set --name REGMNGT --rsource -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -m state --state NEW -m recent --rcheck --seconds 30 --hitcount 2 --rttl --name PEERMNGT --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -m state --state NEW -m recent --set --name PEERMNGT --rsource -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10003 -j PEERS_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --sport 10002 -m state --state ESTABLISHED -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -i black -p tcp -m tcp --dport 10004 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 3 --connlimit-mask 32 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10004 -m state --state NEW -m recent --rcheck --seconds 30 --hitcount 2 --rttl --name REGMNGT --rsource -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j DROP
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10004 -m state --state NEW -m recent --set --name REGMNGT --rsource -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --dport 10004 -m state --state NEW,ESTABLISHED -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_INPUT -i black -p tcp -m tcp --sport 10001 -m state --state ESTABLISHED -j REGAUTH_
- -A STD_INPUT -m mark --mark 0x1/0x1 -j ACCEPT
- -A STD_INPUT -i man -p tcp -m tcp --dport 80 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 10 --connlimit-mask 32 -j DROP
- -A STD_INPUT -i man -p tcp -m tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -i man -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 3 --connlimit-mask 32 -j DROP
- -A STD_INPUT -i man -p tcp -m state --state NEW -m recent --rcheck --seconds 60 --hitcount 3 --rttl --name MNGT --rsource -j DROP
- -A STD_INPUT -i man -p tcp -m state --state NEW -m recent --set --name MNGT --rsource
- -A STD_INPUT -i man -p tcp -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -p tcp -m tcp --dport 10161 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 1 --connlimit-mask 32 -j DROP
- -A STD_INPUT -p tcp -m tcp --dport 10161 -m state --state NEW -m recent --rcheck --seconds 60 --hitcount 3 --rttl --name SNMP --rsource -j DROP
- -A STD_INPUT -p tcp -m tcp --dport 10161 -m state --state NEW -m recent --set --name SNMP --rsource
- -A STD_INPUT -p tcp -m tcp --dport 10161 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -p udp -m udp --dport 10161 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -i dbg -p udp -m udp --sport 67 --dport 68 -m state --state ESTABLISHED -j ACCEPT
- -A STD_INPUT -i man -p udp -m udp --sport 67 --dport 68 -m state --state ESTABLISHED -j ACCEPT
- -A STD_INPUT -i black -p udp -m udp --sport 67 --dport 68 -m state --state ESTABLISHED -j ACCEPT
- -A STD_INPUT -i red -p udp -m udp --sport 68 --dport 67 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -i red -p udp -m udp --sport 53 --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_INPUT -i lo+ -j ACCEPT
- -A STD_OUTPUT -p icmp -m limit --limit 1/sec -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p esp -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p ipencap -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --sport 500 -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p udp -m udp --sport 500 -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --sport 4500 -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p udp -m udp --sport 4500 -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o red -j MCAST_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o gre+ -j MCAST_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p igmp -j MARK --set-xmark 0x8/0xffffffff
- -A STD_OUTPUT -j TUNNEL_
- -A STD_OUTPUT -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_OUTPUT -j MCAST_
- -A STD_OUTPUT -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o gre+ -j TUNNEL_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p gre -j MARK --set-xmark 0x8/0xffffffff
- -A STD_OUTPUT -j LOCAL_RED_
- -A STD_OUTPUT -m mark --mark 0x1/0x1 -j MARK --set-xmark 0x4/0x4
- -A STD_OUTPUT -j REMOTE_RED_
- -A STD_OUTPUT -m mark --mark 0xe/0xe -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --dport 10003 -m state --state NEW,ESTABLISHED -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --sport 10003 -m state --state ESTABLISHED -j REGAUTH_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --sport 10003 -m state --state ESTABLISHED -j PEERS_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --dport 10002 -m state --state NEW,ESTABLISHED -j REGAUTH_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --sport 10004 -m state --state ESTABLISHED -j REGAUTH_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -j MARK --set-xmark 0x0/0xffffffff
- -A STD_OUTPUT -o black -p tcp -m tcp --dport 10001 -m state --state NEW,ESTABLISHED -j REGAUTH_
- -A STD_OUTPUT -m mark --mark 0x2/0x2 -j ACCEPT
- -A STD_OUTPUT -o man -p tcp -m tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -o man -p tcp -m state --state ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -p tcp -m tcp --sport 10161 -m state --state ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -p udp -m udp --sport 10161 -m state --state ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -o dbg -p udp -m udp --sport 68 --dport 67 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -o man -p udp -m udp --sport 68 --dport 67 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -o black -p udp -m udp --sport 68 --dport 67 -m state --state NEW,ESTABLISHED -j ACCEPT
- -A STD_OUTPUT -o red -p udp -m udp --sport 67 --dport 68 -j ACCEPT
- -A STD_OUTPUT -o red -p udp -m udp --sport 53 --dport 53 -j ACCEPT
- -A STD_OUTPUT -o lo+ -j ACCEPT
- -A TUNNEL_ -s 220.0.0.0/6 -j MARK --set-xmark 0x1/0x1
- -A TUNNEL_ -d 220.0.0.0/6 -j MARK --set-xmark 0x2/0x2
- COMMIT
- # Completed on Mon Jul 25 12:06:11 2016
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement