Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@r-18-VM:~# iptables-save
- # Generated by iptables-save v1.4.14 on Tue May 12 14:23:23 2015
- *mangle
- :PREROUTING ACCEPT [8758:9214728]
- :INPUT ACCEPT [353:48833]
- :FORWARD ACCEPT [7404:9124033]
- :OUTPUT ACCEPT [349:38480]
- :POSTROUTING ACCEPT [7753:9162513]
- :ACL_OUTBOUND_eth2 - [0:0]
- :VPN_STATS_eth1 - [0:0]
- -A PREROUTING -i eth1 -m state --state NEW -j CONNMARK --set-xmark 0x1/0xffffffff
- -A PREROUTING -i eth2 -m state --state RELATED,ESTABLISHED -j CONNMARK --restore-mark --nfmask 0xffffffff --ctmask 0xffffffff
- -A PREROUTING -s 10.10.10.0/24 ! -d 10.10.10.1/32 -i eth2 -m state --state NEW -j ACL_OUTBOUND_eth2
- -A FORWARD -j VPN_STATS_eth1
- -A OUTPUT -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A ACL_OUTBOUND_eth2 -j ACCEPT
- -A ACL_OUTBOUND_eth2 -j DROP
- -A VPN_STATS_eth1 -o eth1 -m mark --mark 0x525
- -A VPN_STATS_eth1 -i eth1 -m mark --mark 0x524
- COMMIT
- # Completed on Tue May 12 14:23:23 2015
- # Generated by iptables-save v1.4.14 on Tue May 12 14:23:23 2015
- *filter
- :INPUT DROP [1:118]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [389:42688]
- :ACL_INBOUND_eth2 - [0:0]
- :NETWORK_STATS_eth1 - [0:0]
- -A INPUT -d 224.0.0.18/32 -j ACCEPT
- -A INPUT -d 225.0.0.50/32 -j ACCEPT
- -A INPUT -p icmp -j ACCEPT
- -A INPUT -i lo -j ACCEPT
- -A INPUT -i eth0 -p tcp -m state --state NEW -m tcp --dport 3922 -j ACCEPT
- -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A INPUT -i eth2 -p udp -m udp --dport 67 -j ACCEPT
- -A INPUT -d 10.10.10.1/32 -i eth2 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -d 10.10.10.1/32 -i eth2 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -d 10.10.10.1/32 -i eth2 -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
- -A INPUT -d 10.10.10.1/32 -i eth2 -p tcp -m state --state NEW -m tcp --dport 8080 -j ACCEPT
- -A FORWARD -j NETWORK_STATS_eth1
- -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 10.0.0.0/8 ! -d 10.0.0.0/8 -j ACCEPT
- -A FORWARD -d 10.10.10.0/24 -o eth2 -j ACL_INBOUND_eth2
- -A ACL_INBOUND_eth2 -j ACCEPT
- -A ACL_INBOUND_eth2 -j DROP
- -A NETWORK_STATS_eth1 -s 10.0.0.0/8 -o eth1
- -A NETWORK_STATS_eth1 -d 10.0.0.0/8 -i eth1
- COMMIT
- # Completed on Tue May 12 14:23:23 2015
- # Generated by iptables-save v1.4.14 on Tue May 12 14:23:23 2015
- *nat
- :PREROUTING ACCEPT [982:43567]
- :INPUT ACCEPT [15:985]
- :OUTPUT ACCEPT [9:684]
- :POSTROUTING ACCEPT [0:0]
- -A PREROUTING -d XXX.39.228.156/32 -j DNAT --to-destination 10.10.10.10
- -A POSTROUTING -s 10.10.10.10/32 -o eth1 -j SNAT --to-source XXX.39.228.156
- -A POSTROUTING -o eth1 -j SNAT --to-source XXX.39.228.155
- -A POSTROUTING -o eth2 -j SNAT --to-source XXX.39.228.155
- -A POSTROUTING -s 10.10.10.0/24 -o eth2 -j SNAT --to-source 10.10.10.1
- COMMIT
- # Completed on Tue May 12 14:23:23 2015
Advertisement
Add Comment
Please, Sign In to add comment