Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.4.15 on Thu Apr 17 15:31:59 2025
- *raw
- :PREROUTING ACCEPT [48110:11042834]
- :OUTPUT ACCEPT [24595:14286242]
- COMMIT
- # Completed on Thu Apr 17 15:31:59 2025
- # Generated by iptables-save v1.4.15 on Thu Apr 17 15:31:59 2025
- *nat
- :PREROUTING ACCEPT [5287:592911]
- :INPUT ACCEPT [2547:160379]
- :OUTPUT ACCEPT [103:18632]
- :POSTROUTING ACCEPT [217:17928]
- :DNSFILTER - [0:0]
- :GAME_VSERVER - [0:0]
- :LOCALSRV - [0:0]
- :MAPE - [0:0]
- :PCREDIRECT - [0:0]
- :PUPNP - [0:0]
- :VSERVER - [0:0]
- :VUPNP - [0:0]
- [0:0] -A PREROUTING -p udp -m udp --dport 1194 -j ACCEPT
- [945:51413] -A PREROUTING -d 119.224.63.27/32 -j GAME_VSERVER
- [945:51413] -A PREROUTING -d 119.224.63.27/32 -j VSERVER
- [2551:426091] -A POSTROUTING -o vlan10 -j PUPNP
- [0:0] -A POSTROUTING -m policy --dir out --pol ipsec -j ACCEPT
- [2489:420838] -A POSTROUTING ! -s 119.224.63.27/32 -o vlan10 -j MASQUERADE
- [32:7937] -A POSTROUTING -s 192.168.1.0/24 -d 192.168.1.0/24 -o br0 -j MASQUERADE
- [0:0] -A VSERVER -p tcp -m tcp --dport 2xxxx -j DNAT --to-destination 192.168.1.4:2xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 2xxxx -j DNAT --to-destination 192.168.1.4:2xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 2xxxx -j DNAT --to-destination 192.168.1.4:2xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 2xxxx -j DNAT --to-destination 192.168.1.4:2xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 5xxxx -j DNAT --to-destination 192.168.1.3:5xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 5xxxx -j DNAT --to-destination 192.168.1.3:5xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 4xxxx -j DNAT --to-destination 192.168.1.4:4xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 4xxxx -j DNAT --to-destination 192.168.1.4:4xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 2xxxx -j DNAT --to-destination 192.168.1.3:2xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 2xxxx -j DNAT --to-destination 192.168.1.3:2xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 2xxxx -j DNAT --to-destination 192.168.1.3:2xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 2xxxx -j DNAT --to-destination 192.168.1.3:2xxxx
- [0:0] -A VSERVER -p tcp -m tcp --dport 1xxxx -j DNAT --to-destination 192.168.1.4:1xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 1xxxx -j DNAT --to-destination 192.168.1.4:1xxxx
- [4:200] -A VSERVER -p tcp -m tcp --dport 10xx:11xxx -j DNAT --to-destination 192.168.1.250
- [0:0] -A VSERVER -p udp -m udp --dport 10xxx:11xxx -j DNAT --to-destination 192.168.1.250
- [0:0] -A VSERVER -p tcp -m tcp --dport 3xxxx -j DNAT --to-destination 192.168.1.3:3xxxx
- [0:0] -A VSERVER -p udp -m udp --dport 3xxxx -j DNAT --to-destination 192.168.1.3:3xxxx
- [20:864] -A VSERVER -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.3
- [19:776] -A VSERVER -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.1.3
- [96:4997] -A VSERVER -p tcp -m tcp --dport xxxx -j DNAT --to-destination 192.168.1.3
- [806:44576] -A VSERVER -j VUPNP
- COMMIT
- # Completed on Thu Apr 17 15:31:59 2025
- # Generated by iptables-save v1.4.15 on Thu Apr 17 15:31:59 2025
- *mangle
- :PREROUTING ACCEPT [36914:8310623]
- :INPUT ACCEPT [13454:3496649]
- :FORWARD ACCEPT [23216:4802676]
- :OUTPUT ACCEPT [19668:12222218]
- :POSTROUTING ACCEPT [42806:17027820]
- [0:0] -A FORWARD -p tcp -m policy --dir in --pol ipsec -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1361:1536 -j TCPMSS --set-mss 1360
- [0:0] -A FORWARD -p tcp -m policy --dir out --pol ipsec -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1361:1536 -j TCPMSS --set-mss 1360
- COMMIT
- # Completed on Thu Apr 17 15:31:59 2025
- # Generated by iptables-save v1.4.15 on Thu Apr 17 15:31:59 2025
- *filter
- :INPUT ACCEPT [13453:3496066]
- :FORWARD ACCEPT [7490:1043260]
- :OUTPUT ACCEPT [19643:12219662]
- :ACCESS_RESTRICTION - [0:0]
- :DNSFILTER_DOT - [0:0]
- :FUPNP - [0:0]
- :IControls - [0:0]
- :INPUT_ICMP - [0:0]
- :INPUT_PING - [0:0]
- :IPSEC_DROP_SUBNET_ICMP - [0:0]
- :IPSEC_STRONGSWAN - [0:0]
- :OUTPUT_DNS - [0:0]
- :OUTPUT_IP - [0:0]
- :OVPNCF - [0:0]
- :OVPNCI - [0:0]
- :OVPNSF - [0:0]
- :OVPNSI - [0:0]
- :PControls - [0:0]
- :PTCSRVLAN - [0:0]
- :PTCSRVWAN - [0:0]
- :SECURITY - [0:0]
- :VPNCF - [0:0]
- :VPNCI - [0:0]
- :WGCF - [0:0]
- :WGCI - [0:0]
- :WGNPControls - [0:0]
- :WGSF - [0:0]
- :WGSI - [0:0]
- :default_block - [0:0]
- :logaccept - [0:0]
- :logdrop - [0:0]
- :logdrop_dns - [0:0]
- :logdrop_ip - [0:0]
- [23218:4802768] -A FORWARD -j IPSEC_DROP_SUBNET_ICMP
- [23218:4802768] -A FORWARD -j IPSEC_STRONGSWAN
- [15420:3745084] -A FORWARD -m state --state RELATED,ESTABLISHED -j logaccept
- [0:0] -A FORWARD -m policy --dir in --pol ipsec -j ACCEPT
- [7798:1057684] -A FORWARD -j WGSF
- [7798:1057684] -A FORWARD -j OVPNSF
- [0:0] -A FORWARD ! -i br0 -o vlan10 -j DROP
- [8:416] -A FORWARD -i br0 -o br0 -j logaccept
- [117:4791] -A FORWARD -m state --state INVALID -j DROP
- [131:6421] -A FORWARD -m conntrack --ctstate DNAT -j logaccept
- [7490:1043260] -A FORWARD -j WGCF
- [7490:1043260] -A FORWARD -j OVPNCF
- [7490:1043260] -A FORWARD -j VPNCF
- [55:3977] -A OUTPUT -p udp -m udp --dport 53 -m u32 --u32 "0x0>>0x16&0x3c@0x8>>0xf&0x1=0x0" -j OUTPUT_DNS
- [0:0] -A OUTPUT -p tcp -m tcp --dport 53 -m u32 --u32 "0x0>>0x16&0x3c@0xc>>0x1a&0x3c@0x8>>0xf&0x1=0x0" -j OUTPUT_DNS
- [19643:12219662] -A OUTPUT -j OUTPUT_IP
- [0:0] -A OUTPUT_DNS -m string --hex-string "|10706f697579747975696f706b6a666e6603636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0d72666a656a6e666a6e65666a6503636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|1131306166646d617361787373736171726b03636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0f376d667364666173646d6b676d726b03636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0d386d617361787373736171726b03636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0f3966646d617361787373736171726b03636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|1265666274686d6f6975796b6d6b6a6b6a677403636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|086861636b7563647403636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|076c696e77756469056633333232036e657400|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0f6c6b6a68676664736174727975696f03636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0b6d6e627663787a7a7a313203636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|077131313133333303746f7000|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|057371353230056633333232036e657400|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|077563746b6f6e6503636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0e7a786376626d6e6e666a6a66777103636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_DNS -m string --hex-string "|0a65756d6d6167766e627003636f6d00|" --algo bm --to 65535 --icase -j logdrop_dns
- [0:0] -A OUTPUT_IP -d 193.201.224.0/24 -j logdrop_ip
- [0:0] -A OUTPUT_IP -d 51.15.120.245/32 -j logdrop_ip
- [0:0] -A OUTPUT_IP -d 45.33.73.134/32 -j logdrop_ip
- [0:0] -A OUTPUT_IP -d 190.115.18.28/32 -j logdrop_ip
- [0:0] -A OUTPUT_IP -d 51.159.52.250/32 -j logdrop_ip
- [0:0] -A OUTPUT_IP -d 190.115.18.86/32 -j logdrop_ip
- [52:2796] -A OVPNSF -o tun21 -j ACCEPT
- [0:0] -A OVPNSF -i tun21 -j ACCEPT
- [0:0] -A OVPNSI -i tun21 -j ACCEPT
- [0:0] -A OVPNSI -p udp -m udp --dport 1194 -j ACCEPT
- [0:0] -A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN
- [0:0] -A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
- [0:0] -A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN
- [0:0] -A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -j DROP
- [0:0] -A SECURITY -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j RETURN
- [0:0] -A SECURITY -p icmp -m icmp --icmp-type 8 -j DROP
- [0:0] -A SECURITY -j RETURN
- [139:6837] -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
- [15559:3751921] -A logaccept -j ACCEPT
- [0:0] -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
- [0:0] -A logdrop -j DROP
- [0:0] -A logdrop_dns -j LOG --log-prefix "DROP_DNS " --log-tcp-sequence --log-tcp-options --log-ip-options
- [0:0] -A logdrop_dns -j DROP
- [0:0] -A logdrop_ip -j LOG --log-prefix "DROP_IP " --log-tcp-sequence --log-tcp-options --log-ip-options
- [0:0] -A logdrop_ip -j DROP
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement