1. Shorewall 4.4.20.3 Dump at cyber-master - Thu Jun 30 01:26:26 ART 2011
  2.  
  3. Counters reset Thu Jun 30 01:26:21 ART 2011
  4.  
  5. Chain INPUT (policy DROP 0 packets, 0 bytes)
  6. pkts bytes target prot opt in out source destination
  7. 329 17193 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  8. 371 20339 lan2fw all -- eth5 * 0.0.0.0/0 0.0.0.0/0
  9. 127 53886 inet2fw all -- eth4 * 0.0.0.0/0 0.0.0.0/0
  10. 8 1654 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
  11. 0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
  12. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:INPUT:REJECT:"
  13. 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
  14.  
  15. Chain FORWARD (policy DROP 0 packets, 0 bytes)
  16. pkts bytes target prot opt in out source destination
  17. 1738 225K lan2inet all -- eth5 eth4 0.0.0.0/0 0.0.0.0/0
  18. 1942 1898K inet_frwd all -- eth4 * 0.0.0.0/0 0.0.0.0/0
  19. 0 0 lo_fwd all -- lo * 0.0.0.0/0 0.0.0.0/0
  20. 0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
  21. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:FORWARD:REJECT:"
  22. 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
  23.  
  24. Chain OUTPUT (policy DROP 0 packets, 0 bytes)
  25. pkts bytes target prot opt in out source destination
  26. 322 21738 fw2lan all -- * eth5 0.0.0.0/0 0.0.0.0/0
  27. 49 3783 fw2inet all -- * eth4 0.0.0.0/0 0.0.0.0/0
  28. 8 1654 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
  29. 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
  30.  
  31. Chain Drop (0 references)
  32. pkts bytes target prot opt in out source destination
  33. 0 0 all -- * * 0.0.0.0/0 0.0.0.0/0
  34. 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:113 /* Auth */
  35. 0 0 dropBcast all -- * * 0.0.0.0/0 0.0.0.0/0
  36. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 3 code 4 /* Needed ICMP types */
  37. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 11 /* Needed ICMP types */
  38. 0 0 dropInvalid all -- * * 0.0.0.0/0 0.0.0.0/0
  39. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,445 /* SMB */
  40. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:137:139 /* SMB */
  41. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137 dpts:1024:65535 /* SMB */
  42. 0 0 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,139,445 /* SMB */
  43. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1900 /* UPnP */
  44. 0 0 dropNotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
  45. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:53 /* Late DNS Replies */
  46.  
  47. Chain Reject (5 references)
  48. pkts bytes target prot opt in out source destination
  49. 307 15676 all -- * * 0.0.0.0/0 0.0.0.0/0
  50. 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:113 /* Auth */
  51. 307 15676 dropBcast all -- * * 0.0.0.0/0 0.0.0.0/0
  52. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 3 code 4 /* Needed ICMP types */
  53. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 11 /* Needed ICMP types */
  54. 306 15572 dropInvalid all -- * * 0.0.0.0/0 0.0.0.0/0
  55. 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,445 /* SMB */
  56. 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:137:139 /* SMB */
  57. 0 0 reject udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:137 dpts:1024:65535 /* SMB */
  58. 0 0 reject tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 135,139,445 /* SMB */
  59. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1900 /* UPnP */
  60. 263 13061 dropNotSyn tcp -- * * 0.0.0.0/0 0.0.0.0/0
  61. 0 0 DROP udp -- * * 0.0.0.0/0 0.0.0.0/0 udp spt:53 /* Late DNS Replies */
  62.  
  63. Chain dropBcast (2 references)
  64. pkts bytes target prot opt in out source destination
  65. 1 104 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
  66. 0 0 DROP all -- * * 0.0.0.0/0 224.0.0.0/4
  67.  
  68. Chain dropInvalid (2 references)
  69. pkts bytes target prot opt in out source destination
  70. 43 2511 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID
  71.  
  72. Chain dropNotSyn (2 references)
  73. pkts bytes target prot opt in out source destination
  74. 1 41 DROP tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcpflags:! 0x17/0x02
  75.  
  76. Chain dynamic (7 references)
  77. pkts bytes target prot opt in out source destination
  78.  
  79. Chain fw2inet (1 references)
  80. pkts bytes target prot opt in out source destination
  81. 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  82. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  83. 49 3783 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
  84.  
  85. Chain fw2lan (1 references)
  86. pkts bytes target prot opt in out source destination
  87. 322 21738 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  88. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  89. 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
  90.  
  91. Chain inet2fw (1 references)
  92. pkts bytes target prot opt in out source destination
  93. 2 144 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  94. 2 144 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  95. 1 40 tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
  96. 125 53742 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  97. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 22,10026
  98. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  99. 2 144 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
  100. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:inet2fw:REJECT:"
  101. 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
  102.  
  103. Chain inet2lan (1 references)
  104. pkts bytes target prot opt in out source destination
  105. 1942 1898K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  106. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:9055
  107. 0 0 ACCEPT udp -- * * 0.0.0.0/0 10.0.0.58 udp dpt:5000
  108. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:9022
  109. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:4899
  110. 0 0 ACCEPT udp -- * * 0.0.0.0/0 10.0.0.58 udp dpt:1194
  111. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3390
  112. 0 0 ACCEPT udp -- * * 0.0.0.0/0 10.0.0.58 udp dpt:3390
  113. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3060
  114. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3061
  115. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3070
  116. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1500
  117. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:8085
  118. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:8065
  119. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:6022
  120. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3306
  121. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:8080
  122. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:5900
  123. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3180
  124. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:60443
  125. 0 0 ACCEPT udp -- * * 0.0.0.0/0 10.0.0.58 udp dpt:60443
  126. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1433
  127. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3389
  128. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1080
  129. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1081
  130. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:8481
  131. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:5905
  132. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:5906
  133. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:5907
  134. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1030
  135. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1031
  136. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:10025
  137. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1035
  138. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1036
  139. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1032
  140. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1040
  141. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2130
  142. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2131
  143. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2132
  144. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2133
  145. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:213
  146. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2135
  147. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1037
  148. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1038
  149. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1041
  150. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1042
  151. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1043
  152. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1044
  153. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1045
  154. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:1046
  155. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:2106
  156. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:7777
  157. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:5901
  158. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:3388
  159. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:34567
  160. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:7010
  161. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:7011
  162. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 10.0.0.58 tcp dpt:7012
  163. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  164. 0 0 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
  165. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:inet2lan:REJECT:"
  166. 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
  167.  
  168. Chain inet_frwd (1 references)
  169. pkts bytes target prot opt in out source destination
  170. 0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  171. 0 0 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  172. 1561 1662K tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
  173. 1942 1898K inet2lan all -- * eth5 0.0.0.0/0 0.0.0.0/0
  174. 0 0 ACCEPT all -- * eth4 0.0.0.0/0 0.0.0.0/0
  175.  
  176. Chain lan2fw (1 references)
  177. pkts bytes target prot opt in out source destination
  178. 327 17049 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  179. 327 17049 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  180. 341 18428 tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
  181. 44 3290 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  182. 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  183. 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 22,24,53,81,111,3128,8081,10000
  184. 22 1517 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 53,111,123
  185. 305 15532 Reject all -- * * 0.0.0.0/0 0.0.0.0/0
  186. 262 13020 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:lan2fw:REJECT:"
  187. 262 13020 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
  188.  
  189. Chain lan2inet (1 references)
  190. pkts bytes target prot opt in out source destination
  191. 0 0 sfilter all -- * eth5 0.0.0.0/0 0.0.0.0/0 [goto]
  192. 299 19095 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  193. 299 19095 smurfs all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  194. 1241 155K tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
  195. 1439 206K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
  196. 5 520 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
  197. 294 18575 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
  198.  
  199. Chain lo_fwd (1 references)
  200. pkts bytes target prot opt in out source destination
  201. 0 0 sfilter all -- * lo 0.0.0.0/0 0.0.0.0/0 [goto]
  202. 0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  203.  
  204. Chain lo_in (0 references)
  205. pkts bytes target prot opt in out source destination
  206. 0 0 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW
  207.  
  208. Chain logdrop (0 references)
  209. pkts bytes target prot opt in out source destination
  210. 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
  211.  
  212. Chain logflags (5 references)
  213. pkts bytes target prot opt in out source destination
  214. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 4 level 6 prefix "Shorewall:logflags:DROP:"
  215. 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
  216.  
  217. Chain logreject (0 references)
  218. pkts bytes target prot opt in out source destination
  219. 0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
  220.  
  221. Chain reject (12 references)
  222. pkts bytes target prot opt in out source destination
  223. 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match src-type BROADCAST
  224. 0 0 DROP all -- * * 224.0.0.0/4 0.0.0.0/0
  225. 0 0 DROP 2 -- * * 0.0.0.0/0 0.0.0.0/0
  226. 262 13020 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
  227. 0 0 REJECT udp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
  228. 0 0 REJECT icmp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-unreachable
  229. 0 0 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
  230.  
  231. Chain sfilter (2 references)
  232. pkts bytes target prot opt in out source destination
  233. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:sfilter:DROP:"
  234. 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
  235.  
  236. Chain shorewall (0 references)
  237. pkts bytes target prot opt in out source destination
  238.  
  239. Chain smurflog (2 references)
  240. pkts bytes target prot opt in out source destination
  241. 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 0 level 6 prefix "Shorewall:smurfs:DROP:"
  242. 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
  243.  
  244. Chain smurfs (4 references)
  245. pkts bytes target prot opt in out source destination
  246. 0 0 RETURN all -- * * 0.0.0.0 0.0.0.0/0
  247. 0 0 smurflog all -- * * 0.0.0.0/0 0.0.0.0/0 [goto] ADDRTYPE match src-type BROADCAST
  248. 0 0 smurflog all -- * * 224.0.0.0/4 0.0.0.0/0 [goto]
  249.  
  250. Chain tcpflags (4 references)
  251. pkts bytes target prot opt in out source destination
  252. 0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] tcpflags: 0x3F/0x29
  253. 0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] tcpflags: 0x3F/0x00
  254. 0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] tcpflags: 0x06/0x06
  255. 0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] tcpflags: 0x03/0x03
  256. 0 0 logflags tcp -- * * 0.0.0.0/0 0.0.0.0/0 [goto] tcp spt:0flags: 0x17/0x02
  257.  
  258. Log (/var/log/messages)
  259.  
  260.  
  261. NAT Table
  262.  
  263. Chain PREROUTING (policy ACCEPT 464 packets, 26996 bytes)
  264. pkts bytes target prot opt in out source destination
  265. 464 26996 dnat all -- * * 0.0.0.0/0 0.0.0.0/0
  266.  
  267. Chain INPUT (policy ACCEPT 22 packets, 1517 bytes)
  268. pkts bytes target prot opt in out source destination
  269.  
  270. Chain OUTPUT (policy ACCEPT 49 packets, 3783 bytes)
  271. pkts bytes target prot opt in out source destination
  272.  
  273. Chain POSTROUTING (policy ACCEPT 272 packets, 12703 bytes)
  274. pkts bytes target prot opt in out source destination
  275. 267 18018 eth4_masq all -- * eth4 0.0.0.0/0 0.0.0.0/0
  276.  
  277. Chain dnat (1 references)
  278. pkts bytes target prot opt in out source destination
  279. 1 104 inet_dnat all -- eth4 * 0.0.0.0/0 0.0.0.0/0
  280.  
  281. Chain eth4_masq (1 references)
  282. pkts bytes target prot opt in out source destination
  283. 218 14235 SNAT all -- * * 10.0.0.0/24 0.0.0.0/0 to:192.168.150.99
  284.  
  285. Chain inet_dnat (1 references)
  286. pkts bytes target prot opt in out source destination
  287. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9055 to:10.0.0.58
  288. 0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:5000 to:10.0.0.58
  289. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9022 to:10.0.0.58
  290. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:4899 to:10.0.0.58
  291. 0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:1194 to:10.0.0.58
  292. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3390 to:10.0.0.58
  293. 0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:3390 to:10.0.0.58
  294. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3060 to:10.0.0.58
  295. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3061 to:10.0.0.58
  296. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3070 to:10.0.0.58
  297. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1500 to:10.0.0.58
  298. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8085 to:10.0.0.58
  299. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8065 to:10.0.0.58
  300. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:6022 to:10.0.0.58
  301. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306 to:10.0.0.58
  302. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8080 to:10.0.0.58
  303. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5900 to:10.0.0.58
  304. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3180 to:10.0.0.58
  305. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:60443 to:10.0.0.58
  306. 0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:60443 to:10.0.0.58
  307. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1433 to:10.0.0.58
  308. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3389 to:10.0.0.58
  309. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1080 to:10.0.0.58
  310. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1081 to:10.0.0.58
  311. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8481 to:10.0.0.58
  312. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5905 to:10.0.0.58
  313. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5906 to:10.0.0.58
  314. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5907 to:10.0.0.58
  315. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1030 to:10.0.0.58
  316. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1031 to:10.0.0.58
  317. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:10025 to:10.0.0.58
  318. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1035 to:10.0.0.58
  319. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1036 to:10.0.0.58
  320. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1032 to:10.0.0.58
  321. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1040 to:10.0.0.58
  322. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2130 to:10.0.0.58
  323. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2131 to:10.0.0.58
  324. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2132 to:10.0.0.58
  325. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2133 to:10.0.0.58
  326. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:213 to:10.0.0.58
  327. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2135 to:10.0.0.58
  328. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1037 to:10.0.0.58
  329. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1038 to:10.0.0.58
  330. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1041 to:10.0.0.58
  331. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1042 to:10.0.0.58
  332. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1043 to:10.0.0.58
  333. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1044 to:10.0.0.58
  334. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1045 to:10.0.0.58
  335. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1046 to:10.0.0.58
  336. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:2106 to:10.0.0.58
  337. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7777 to:10.0.0.58
  338. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5901 to:10.0.0.58
  339. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3388 to:10.0.0.58
  340. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:34567 to:10.0.0.58
  341. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7010 to:10.0.0.58
  342. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7011 to:10.0.0.58
  343. 0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7012 to:10.0.0.58
  344.  
  345. Mangle Table
  346.  
  347. Chain PREROUTING (policy ACCEPT 3909 packets, 2206K bytes)
  348. pkts bytes target prot opt in out source destination
  349. 3391 2148K CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0 connmark match ! 0x0/0xff CONNMARK restore mask 0xff
  350. 152 33001 routemark all -- eth4 * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff
  351. 2087 1974K tcpre all -- eth4 * 0.0.0.0/0 0.0.0.0/0
  352. 672 40911 tcpre all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff
  353.  
  354. Chain INPUT (policy ACCEPT 507 packets, 76004 bytes)
  355. pkts bytes target prot opt in out source destination
  356. 507 76004 tcin all -- * * 0.0.0.0/0 0.0.0.0/0
  357.  
  358. Chain FORWARD (policy ACCEPT 3707 packets, 2146K bytes)
  359. pkts bytes target prot opt in out source destination
  360. 3707 2146K MARK all -- * * 0.0.0.0/0 0.0.0.0/0 MARK and 0xffffff00
  361. 3707 2146K tcfor all -- * * 0.0.0.0/0 0.0.0.0/0
  362.  
  363. Chain OUTPUT (policy ACCEPT 381 packets, 27333 bytes)
  364. pkts bytes target prot opt in out source destination
  365. 0 0 CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0 connmark match ! 0x0/0xff CONNMARK restore mask 0xff
  366. 381 27333 tcout all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff
  367.  
  368. Chain POSTROUTING (policy ACCEPT 4088 packets, 2173K bytes)
  369. pkts bytes target prot opt in out source destination
  370. 4088 2173K tcpost all -- * * 0.0.0.0/0 0.0.0.0/0
  371.  
  372. Chain routemark (1 references)
  373. pkts bytes target prot opt in out source destination
  374. 26 3465 MARK all -- eth4 * 0.0.0.0/0 0.0.0.0/0 MAC 00:0C:42:07:54:58 MARK set 0x2
  375. 125 29432 MARK all -- eth4 * 0.0.0.0/0 0.0.0.0/0 MAC 00:0C:42:07:54:4D MARK set 0x3
  376. 151 32897 CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match ! 0x0/0xff CONNMARK save mask 0xff
  377.  
  378. Chain tcfor (1 references)
  379. pkts bytes target prot opt in out source destination
  380.  
  381. Chain tcin (1 references)
  382. pkts bytes target prot opt in out source destination
  383.  
  384. Chain tcout (1 references)
  385. pkts bytes target prot opt in out source destination
  386. 0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 1030,1031,1037,1038 MARK set 0x2
  387. 0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 53,1023,9187,25,465,995,3306,10019,10020,10027,26000,443,1863,7001 MARK set 0x3
  388. 0 0 MARK tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 6891:6900,1503,3389,5061,5050,5100 MARK set 0x3
  389. 51 3941 MARK udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 9,53,7001,5000,5004,49152 MARK set 0x3
  390.  
  391. Chain tcpost (1 references)
  392. pkts bytes target prot opt in out source destination
  393.  
  394. Chain tcpre (2 references)
  395. pkts bytes target prot opt in out source destination
  396. 305 15532 TPROXY tcp -- eth5 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 TPROXY redirect 0.0.0.0:3128 mark 0x1/0xffffffff
  397. 0 0 MARK tcp -- * * 10.0.0.0/24 0.0.0.0/0 multiport dports 1030,1031,1037,1038 MARK set 0x2
  398. 1 48 MARK tcp -- * * 10.0.0.0/24 0.0.0.0/0 multiport dports 53,1023,9187,25,465,995,3306,10019,10020,10027,26000,443,1863,7001 MARK set 0x3
  399. 0 0 MARK tcp -- * * 10.0.0.0/24 0.0.0.0/0 multiport dports 6891:6900,1503,3389,5061,5050,5100 MARK set 0x3
  400. 28 1915 MARK udp -- * * 10.0.0.0/24 0.0.0.0/0 multiport dports 9,53,7001,5000,5004,49152 MARK set 0x3
  401.  
  402. Raw Table
  403.  
  404. Chain PREROUTING (policy ACCEPT 4228 packets, 2224K bytes)
  405. pkts bytes target prot opt in out source destination
  406.  
  407. Chain OUTPUT (policy ACCEPT 381 packets, 27333 bytes)
  408. pkts bytes target prot opt in out source destination
  409.  
  410. Conntrack Table (18200 out of 131072)
  411.  
  412. ipv4 2 udp 17 7 src=10.0.0.58 dst=172.162.114.102 sport=20708 dport=38767 [UNREPLIED] src=172.162.114.102 dst=192.168.150.99 sport=38767 dport=20708 mark=0 zone=0 use=2
  413. ipv4 2 tcp 6 66 TIME_WAIT src=10.0.0.58 dst=72.14.204.105 sport=2797 dport=80 src=72.14.204.105 dst=192.168.150.99 sport=80 dport=2797 [ASSURED] mark=3 zone=0 use=2
  414. ipv4 2 tcp 6 424757 ESTABLISHED src=10.0.0.58 dst=72.14.204.164 sport=1796 dport=80 [UNREPLIED] src=72.14.204.164 dst=192.168.150.99 sport=80 dport=1796 mark=0 zone=0 use=2
  415. ipv4 2 tcp 6 162613 ESTABLISHED src=23.2.17.98 dst=192.168.127.102 sport=80 dport=4533 [UNREPLIED] src=192.168.127.102 dst=23.2.17.98 sport=4533 dport=80 mark=0 zone=0 use=2
  416. ipv4 2 tcp 6 83880 ESTABLISHED src=10.0.0.58 dst=192.168.31.99 sport=63666 dport=53 [UNREPLIED] src=192.168.31.99 dst=192.168.150.99 sport=53 dport=63666 mark=0 zone=0 use=2
  417. ipv4 2 tcp 6 236818 ESTABLISHED src=66.220.151.85 dst=192.168.110.236 sport=80 dport=1520 [UNREPLIED] src=192.168.110.236 dst=66.220.151.85 sport=1520 dport=80 mark=0 zone=0 use=2
  418. ipv4 2 tcp 6 124913 ESTABLISHED src=10.0.0.58 dst=79.183.193.139 sport=49260 dport=30574 src=79.183.193.139 dst=192.168.150.99 sport=30574 dport=49260 [ASSURED] mark=2 zone=0 use=2
  419. ipv4 2 tcp 6 82513 ESTABLISHED src=69.171.242.39 dst=192.168.127.102 sport=80 dport=1429 [UNREPLIED] src=192.168.127.102 dst=69.171.242.39 sport=1429 dport=80 mark=0 zone=0 use=2
  420. ipv4 2 tcp 6 238381 ESTABLISHED src=10.0.0.58 dst=200.125.75.73 sport=4811 dport=44322 src=200.125.75.73 dst=192.168.150.99 sport=44322 dport=4811 [ASSURED] mark=2 zone=0 use=2
  421. ipv4 2 udp 17 66 src=10.0.0.58 dst=186.19.153.217 sport=11097 dport=40775 src=186.19.153.217 dst=192.168.150.99 sport=40775 dport=11097 [ASSURED] mark=2 zone=0 use=2
  422. ipv4 2 tcp 6 431986 ESTABLISHED src=10.0.0.58 dst=201.233.21.138 sport=3747 dport=46885 src=201.233.21.138 dst=192.168.150.99 sport=46885 dport=3747 [ASSURED] mark=3 zone=0 use=2
  423. ipv4 2 tcp 6 14 TIME_WAIT src=10.0.0.58 dst=65.55.175.183 sport=2942 dport=80 src=65.55.175.183 dst=192.168.150.99 sport=80 dport=2942 [ASSURED] mark=3 zone=0 use=2
  424. ipv4 2 tcp 6 169043 ESTABLISHED src=72.246.64.16 dst=192.168.8.7 sport=80 dport=1357 [UNREPLIED] src=192.168.8.7 dst=72.246.64.16 sport=1357 dport=80 mark=0 zone=0 use=2
  425. ipv4 2 tcp 6 414666 ESTABLISHED src=10.0.0.58 dst=173.45.106.130 sport=1375 dport=80 [UNREPLIED] src=173.45.106.130 dst=192.168.150.99 sport=80 dport=1375 mark=0 zone=0 use=2
  426. ipv4 2 tcp 6 70758 ESTABLISHED src=174.132.198.202 dst=192.168.127.102 sport=80 dport=2004 [UNREPLIED] src=192.168.127.102 dst=174.132.198.202 sport=2004 dport=80 mark=0 zone=0 use=2
  427. ipv4 2 tcp 6 67173 ESTABLISHED src=201.211.78.254 dst=192.168.29.100 sport=61863 dport=50161 [UNREPLIED] src=192.168.29.100 dst=201.211.78.254 sport=50161 dport=61863 mark=0 zone=0 use=2
  428. ipv4 2 tcp 6 426855 ESTABLISHED src=10.0.0.58 dst=66.94.241.1 sport=1900 dport=80 [UNREPLIED] src=66.94.241.1 dst=192.168.150.99 sport=80 dport=1900 mark=0 zone=0 use=2
  429. ipv4 2 udp 17 27 src=192.168.150.99 dst=82.207.67.6 sport=23174 dport=53 src=82.207.67.6 dst=192.168.150.99 sport=53 dport=23174 mark=3 zone=0 use=2
  430. ipv4 2 tcp 6 64614 ESTABLISHED src=10.0.0.58 dst=208.99.200.2 sport=19642 dport=21512 src=208.99.200.2 dst=192.168.150.99 sport=21512 dport=19642 [ASSURED] mark=2 zone=0 use=2
  431. ipv4 2 tcp 6 293816 ESTABLISHED src=10.0.0.58 dst=69.171.242.13 sport=3315 dport=80 [UNREPLIED] src=69.171.242.13 dst=192.168.150.99 sport=80 dport=3315 mark=0 zone=0 use=2
  432. ipv4 2 tcp 6 66814 ESTABLISHED src=10.0.0.58 dst=99.235.6.177 sport=20308 dport=23856 src=99.235.6.177 dst=192.168.150.99 sport=23856 dport=20308 [ASSURED] mark=2 zone=0 use=2
  433. ipv4 2 tcp 6 75 TIME_WAIT src=10.0.0.58 dst=188.165.217.211 sport=4643 dport=80 src=188.165.217.211 dst=192.168.150.99 sport=80 dport=4643 [ASSURED] mark=3 zone=0 use=2
  434. ipv4 2 udp 17 16 src=10.0.0.58 dst=190.175.146.171 sport=9877 dport=10319 [UNREPLIED] src=190.175.146.171 dst=192.168.150.99 sport=10319 dport=9877 mark=0 zone=0 use=2
  435. ipv4 2 tcp 6 110 SYN_SENT src=10.0.0.58 dst=83.22.178.172 sport=3022 dport=6881 [UNREPLIED] src=83.22.178.172 dst=192.168.150.99 sport=6881 dport=3022 mark=3 zone=0 use=2
  436. ipv4 2 tcp 6 163704 ESTABLISHED src=174.36.96.28 dst=192.168.127.102 sport=80 dport=1356 [UNREPLIED] src=192.168.127.102 dst=174.36.96.28 sport=1356 dport=80 mark=0 zone=0 use=2
  437. ipv4 2 tcp 6 431960 ESTABLISHED src=10.0.0.58 dst=69.171.242.11 sport=1147 dport=80 src=69.171.242.11 dst=192.168.150.99 sport=80 dport=1147 [ASSURED] mark=2 zone=0 use=2
  438. ipv4 2 tcp 6 22 TIME_WAIT src=10.0.0.58 dst=188.165.217.211 sport=4450 dport=80 src=188.165.217.211 dst=192.168.150.99 sport=80 dport=4450 [ASSURED] mark=3 zone=0 use=2
  439. ipv4 2 udp 17 147 src=10.0.0.58 dst=184.147.52.190 sport=20708 dport=44867 src=184.147.52.190 dst=192.168.150.99 sport=44867 dport=20708 [ASSURED] mark=2 zone=0 use=2
  440. ipv4 2 tcp 6 63261 ESTABLISHED src=68.180.158.155 dst=192.168.29.11 sport=80 dport=60303 [UNREPLIED] src=192.168.29.11 dst=68.180.158.155 sport=60303 dport=80 mark=0 zone=0 use=2
  441. ipv4 2 tcp 6 294873 ESTABLISHED src=184.84.247.35 dst=192.168.8.3 sport=80 dport=2947 [UNREPLIED] src=192.168.8.3 dst=184.84.247.35 sport=2947 dport=80 mark=0 zone=0 use=2
  442. ipv4 2 tcp 6 229955 ESTABLISHED src=10.0.0.58 dst=192.168.118.99 sport=33296 dport=53 [UNREPLIED] src=192.168.118.99 dst=192.168.150.99 sport=53 dport=33296 mark=0 zone=0 use=2
  443. ipv4 2 tcp 6 105 TIME_WAIT src=10.0.0.58 dst=72.246.64.41 sport=4710 dport=80 src=72.246.64.41 dst=192.168.150.99 sport=80 dport=4710 [ASSURED] mark=3 zone=0 use=2
  444. ipv4 2 tcp 6 250308 ESTABLISHED src=209.87.178.183 dst=192.168.0.2 sport=443 dport=2067 [UNREPLIED] src=192.168.0.2 dst=209.87.178.183 sport=2067 dport=443 mark=0 zone=0 use=2
  445. ipv4 2 tcp 6 431969 ESTABLISHED src=10.0.0.58 dst=72.246.64.107 sport=60274 dport=80 src=72.246.64.107 dst=192.168.150.99 sport=80 dport=60274 [ASSURED] mark=3 zone=0 use=2
  446. ipv4 2 tcp 6 204556 ESTABLISHED src=74.125.45.83 dst=192.168.29.106 sport=443 dport=1228 [UNREPLIED] src=192.168.29.106 dst=74.125.45.83 sport=1228 dport=443 mark=0 zone=0 use=2
  447. ipv4 2 udp 17 179 src=10.0.0.58 dst=190.26.165.41 sport=48760 dport=40523 src=190.26.165.41 dst=192.168.150.99 sport=40523 dport=48760 [ASSURED] mark=3 zone=0 use=2
  448. ipv4 2 tcp 6 32 TIME_WAIT src=10.0.0.58 dst=94.198.224.153 sport=2381 dport=80 src=94.198.224.153 dst=192.168.150.99 sport=80 dport=2381 [ASSURED] mark=3 zone=0 use=2
  449. ipv4 2 udp 17 5 src=10.0.0.58 dst=190.205.125.71 sport=18317 dport=9294 [UNREPLIED] src=190.205.125.71 dst=192.168.150.99 sport=9294 dport=18317 mark=0 zone=0 use=2
  450. ipv4 2 tcp 6 157525 ESTABLISHED src=10.0.0.58 dst=190.73.21.25 sport=47544 dport=51077 src=190.73.21.25 dst=192.168.150.99 sport=51077 dport=47544 [ASSURED] mark=2 zone=0 use=2
  451. ipv4 2 udp 17 173 src=10.0.0.58 dst=186.22.26.47 sport=11512 dport=27419 src=186.22.26.47 dst=192.168.150.99 sport=27419 dport=11512 [ASSURED] mark=3 zone=0 use=2
  452. ipv4 2 tcp 6 246917 ESTABLISHED src=10.0.0.58 dst=74.125.229.114 sport=3571 dport=80 [UNREPLIED] src=74.125.229.114 dst=192.168.150.99 sport=80 dport=3571 mark=0 zone=0 use=2
  453. ipv4 2 udp 17 4 src=10.0.0.58 dst=92.21.200.210 sport=49644 dport=21877 [UNREPLIED] src=92.21.200.210 dst=192.168.150.99 sport=21877 dport=49644 mark=0 zone=0 use=2
  454. ipv4 2 tcp 6 407980 ESTABLISHED src=10.0.0.58 dst=66.220.151.77 sport=2305 dport=80 [UNREPLIED] src=66.220.151.77 dst=192.168.150.99 sport=80 dport=2305 mark=0 zone=0 use=2
  455. ipv4 2 tcp 6 210848 ESTABLISHED src=10.0.0.58 dst=197.1.104.62 sport=25759 dport=6881 [UNREPLIED] src=197.1.104.62 dst=192.168.150.99 sport=6881 dport=25759 mark=0 zone=0 use=2
  456. ipv4 2 tcp 6 157371 ESTABLISHED src=74.125.229.37 dst=192.168.127.102 sport=80 dport=2380 [UNREPLIED] src=192.168.127.102 dst=74.125.229.37 sport=2380 dport=80 mark=0 zone=0 use=2
  457. ipv4 2 tcp 6 280206 ESTABLISHED src=10.0.0.58 dst=98.137.51.254 sport=2299 dport=80 [UNREPLIED] src=98.137.51.254 dst=192.168.150.99 sport=80 dport=2299 mark=0 zone=0 use=2
  458. ipv4 2 tcp 6 141642 ESTABLISHED src=184.84.247.34 dst=192.168.127.100 sport=80 dport=62006 [UNREPLIED] src=192.168.127.100 dst=184.84.247.34 sport=62006 dport=80 mark=0 zone=0 use=2
  459. ipv4 2 tcp 6 76630 ESTABLISHED src=66.220.156.25 dst=192.168.127.100 sport=80 dport=62464 [UNREPLIED] src=192.168.127.100 dst=66.220.156.25 sport=62464 dport=80 mark=0 zone=0 use=2
  460. ipv4 2 tcp 6 82 TIME_WAIT src=10.0.0.58 dst=213.174.158.80 sport=2203 dport=80 src=213.174.158.80 dst=192.168.150.99 sport=80 dport=2203 [ASSURED] mark=3 zone=0 use=2
  461. ipv4 2 tcp 6 431791 ESTABLISHED src=190.175.194.110 dst=192.168.110.197 sport=9869 dport=59365 [UNREPLIED] src=192.168.110.197 dst=190.175.194.110 sport=59365 dport=9869 mark=0 zone=0 use=2
  462. ipv4 2 tcp 6 115 SYN_SENT src=10.0.0.58 dst=189.170.142.61 sport=50189 dport=18984 [UNREPLIED] src=189.170.142.61 dst=10.0.0.58 sport=18984 dport=50189 mark=0 zone=0 use=2
  463. ipv4 2 tcp 6 393226 ESTABLISHED src=23.2.17.98 dst=192.168.111.164 sport=80 dport=1259 [UNREPLIED] src=192.168.111.164 dst=23.2.17.98 sport=1259 dport=80 mark=0 zone=0 use=2
  464. ipv4 2 tcp 6 151686 ESTABLISHED src=10.0.0.58 dst=187.45.196.30 sport=3413 dport=1433 [UNREPLIED] src=187.45.196.30 dst=192.168.150.99 sport=1433 dport=3413 mark=0 zone=0 use=2
  465. ipv4 2 tcp 6 413476 ESTABLISHED src=10.0.0.58 dst=72.246.31.74 sport=1331 dport=80 [UNREPLIED] src=72.246.31.74 dst=192.168.150.99 sport=80 dport=1331 mark=0 zone=0 use=2
  466. ipv4 2 tcp 6 410054 ESTABLISHED src=10.0.0.58 dst=200.45.17.240 sport=1192 dport=443 [UNREPLIED] src=200.45.17.240 dst=192.168.150.99 sport=443 dport=1192 mark=0 zone=0 use=2
  467. ipv4 2 tcp 6 95 TIME_WAIT src=10.0.0.58 dst=72.246.64.48 sport=65114 dport=80 src=72.246.64.48 dst=192.168.150.99 sport=80 dport=65114 [ASSURED] mark=3 zone=0 use=2
  468. ipv4 2 udp 17 159 src=10.0.0.58 dst=69.124.7.15 sport=18317 dport=49965 src=69.124.7.15 dst=192.168.150.99 sport=49965 dport=18317 [ASSURED] mark=3 zone=0 use=2
  469. ipv4 2 udp 17 9 src=10.0.0.58 dst=201.34.212.78 sport=15114 dport=13480 src=201.34.212.78 dst=192.168.150.99 sport=13480 dport=15114 mark=3 zone=0 use=2