Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ip route show table main
- X.Y.28.0/24 dev eth2.25 proto kernel scope link src X.Y.28.82
- X.Y.34.0/24 dev eth2.24 proto kernel scope link src X.Y.34.6
- 192.168.A.0/24 dev eth0 proto kernel scope link src 192.168.A.156
- 192.168.B.0/23 dev eth1 proto kernel scope link src 192.168.B.4
- ip route show table 24
- X.Y.34.0/24 dev eth2.24 proto kernel scope link src X.Y.34.6
- 192.168.A.0/24 dev eth0 proto kernel scope link src 192.168.A.156
- 192.168.B.0/23 dev eth1 proto kernel scope link src 192.168.B.4
- default via X.Y.34.1 dev eth2.24
- ip route show table 25
- X.Y.28.0/24 dev eth2.25 proto kernel scope link src X.Y.28.82
- 192.168.A.0/24 dev eth0 proto kernel scope link src 192.168.A.156
- 192.168.B.0/23 dev eth1 proto kernel scope link src 192.168.B.4
- default via X.Y.28.1 dev eth2.25
- ip rule show
- 0: from all lookup local
- 100: from all fwmark 0x1 lookup T24
- 101: from all fwmark 0x2 lookup T25
- 102: from all fwmark 0x3 lookup T24
- 103: from all fwmark 0x4 lookup T25
- 32767: from all lookup main
- iptables-save (some stuff edited out to keep it shorter)
- *mangle
- -A PREROUTING -j CONNMARK --restore-mark --nfmask 0xffffffff --ctmask 0xffffffff
- -A PREROUTING -m mark ! --mark 0x0 -j ACCEPT
- -A PREROUTING -m mark --mark 0x0 -m statistic --mode nth --every 4 -j MARK --set-xmark 0x1/0xffffffff
- -A PREROUTING -m mark --mark 0x0 -m statistic --mode nth --every 4 --packet 1 -j MARK --set-xmark 0x2/0xffffffff
- -A PREROUTING -m mark --mark 0x0 -m statistic --mode nth --every 4 --packet 2 -j MARK --set-xmark 0x3/0xffffffff
- -A PREROUTING -m mark --mark 0x0 -m statistic --mode nth --every 4 --packet 3 -j MARK --set-xmark 0x4/0xffffffff
- -A PREROUTING -j CONNMARK --save-mark --nfmask 0xffffffff --ctmask 0xffffffff
- *nat
- -A POSTROUTING -o eth2.24 -j MASQUERADE
- -A POSTROUTING -o eth2.25 -j MASQUERADE
- -A POSTROUTING -o eth2.26 -j MASQUERADE
- -A POSTROUTING -o eth2.27 -j MASQUERADE
- *filter
- -A INPUT -s 127.0.0.1/32 -i lo -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i eth1 -p icmp -m icmp --icmp-type any -j ACCEPT
- -A FORWARD ! -s 192.168.B.0/23 -i eth2.24 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD ! -s 192.168.B.0/23 -i eth2.25 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD ! -s 192.168.B.0/23 -i eth2.26 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD ! -s 192.168.B.0/23 -i eth2.27 -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 192.168.B.0/23 -i eth1 -o eth2.24 -j ACCEPT
- -A FORWARD -s 192.168.B.0/23 -i eth1 -o eth2.25 -j ACCEPT
- -A FORWARD -s 192.168.B.0/23 -i eth1 -o eth2.26 -j ACCEPT
- -A FORWARD -s 192.168.B.0/23 -i eth1 -o eth2.27 -j ACCEPT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement