Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- >>> ifconfig
- br0 Link encap:Ethernet HWaddr <MAC>
- inet addr:192.168.10.1 Bcast:192.168.10.255 Mask:255.255.255.0
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:233971 errors:0 dropped:10 overruns:0 frame:0
- TX packets:522071 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:25613585 (24.4 MiB) TX bytes:689924429 (657.9 MiB)
- eth0 Link encap:Ethernet HWaddr <MAC>
- inet addr:192.168.100.2 Bcast:192.168.100.3 Mask:255.255.255.252
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:748324 errors:0 dropped:66416 overruns:0 frame:0
- TX packets:339857 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:828799452 (790.4 MiB) TX bytes:131816213 (125.7 MiB)
- eth1 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:192501 errors:0 dropped:0 overruns:0 frame:0
- TX packets:436206 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:22761154 (21.7 MiB) TX bytes:589955072 (562.6 MiB)
- eth2 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- eth3 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- eth4 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- eth5 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:2371632 errors:0 dropped:0 overruns:0 frame:0
- TX packets:315742 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:3534859792 (3.2 GiB) TX bytes:36633687 (34.9 MiB)
- eth6 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- Interrupt:70
- eth7 Link encap:Ethernet HWaddr <MAC>
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:329659 errors:0 dropped:15 overruns:0 frame:0
- TX packets:2448390 errors:0 dropped:7 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:36979985 (35.2 MiB) TX bytes:3632496466 (3.3 GiB)
- lo Link encap:Local Loopback
- inet addr:127.0.0.1 Mask:255.0.0.0
- UP LOOPBACK RUNNING MULTICAST MTU:65536 Metric:1
- RX packets:19523 errors:0 dropped:0 overruns:0 frame:0
- TX packets:19523 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:4790909 (4.5 MiB) TX bytes:4790909 (4.5 MiB)
- lo:0 Link encap:Local Loopback
- inet addr:127.0.1.1 Mask:255.0.0.0
- UP LOOPBACK RUNNING MULTICAST MTU:65536 Metric:1
- spu_ds_dummy Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
- UP RUNNING NOARP MTU:2048 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:100
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- spu_us_dummy Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
- UP RUNNING NOARP MTU:2048 Metric:1
- RX packets:0 errors:0 dropped:0 overruns:0 frame:0
- TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:100
- RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
- tun12 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
- inet addr:10.100.0.2 P-t-P:10.100.0.2 Mask:255.255.255.0
- UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
- RX packets:158008 errors:0 dropped:0 overruns:0 frame:0
- TX packets:55721 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:190615902 (181.7 MiB) TX bytes:5724032 (5.4 MiB)
- wgs1 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
- inet addr:192.168.11.1 P-t-P:192.168.11.1 Mask:255.255.255.255
- UP POINTOPOINT RUNNING NOARP MTU:1420 Metric:1
- RX packets:24959 errors:0 dropped:0 overruns:0 frame:0
- TX packets:76872 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:2557972 (2.4 MiB) TX bytes:94575420 (90.1 MiB)
- wl1.2 Link encap:Ethernet HWaddr C8:7F:54:DD:0A:AE
- UP BROADCAST RUNNING ALLMULTI MULTICAST MTU:1500 Metric:1
- RX packets:0 errors:0 dropped:1 overruns:0 frame:0
- TX packets:6072 errors:0 dropped:0 overruns:0 carrier:0
- collisions:0 txqueuelen:1000
- RX bytes:0 (0.0 B) TX bytes:1193306 (1.1 MiB)
- >>> brctl show
- bridge name bridge id STP enabled interfaces
- br0 8000.<REMOVED> no eth1
- eth2
- eth3
- eth4
- eth5
- eth6
- eth7
- wl1.2
- >>> ip route show table main
- default via 192.168.100.1 dev eth0
- 1.0.0.2 via 192.168.100.1 dev eth0 metric 1
- 1.1.1.2 via 192.168.100.1 dev eth0 metric 1
- 10.100.0.0/24 dev tun12 proto kernel scope link src 10.100.0.2
- 127.0.0.0/8 dev lo scope link
- 192.168.10.0/24 dev br0 proto kernel scope link src 192.168.10.1
- 192.168.11.2 dev wgs1 scope link
- 192.168.11.3 dev wgs1 scope link
- 192.168.100.0/30 dev eth0 proto kernel scope link src 192.168.100.2
- 192.168.100.1 dev eth0 proto kernel scope link
- >>> ip route show table ovpnc1
- >>> ip route show table ovpnc2
- default via 10.100.0.1 dev tun12
- 1.0.0.2 via 192.168.100.1 dev eth0 metric 1
- 1.1.1.2 via 192.168.100.1 dev eth0 metric 1
- 10.100.0.0/24 dev tun12 proto kernel scope link src 10.100.0.2
- 127.0.0.0/8 dev lo scope link
- <WANVPNIP2> via 192.168.100.1 dev eth0
- 192.168.10.0/24 dev br0 proto kernel scope link src 192.168.10.1
- 192.168.11.2 dev wgs1 scope link
- 192.168.11.3 dev wgs1 scope link
- 192.168.100.0/30 dev eth0 proto kernel scope link src 192.168.100.2
- 192.168.100.1 dev eth0 proto kernel scope link
- >>> ip rule
- 0: from all lookup local
- 90: from all to 192.168.11.2 lookup main
- 90: from all to 192.168.11.3 lookup main
- 10010: from 192.168.10.0/24 to 192.168.10.0/24 lookup main
- 10011: from 192.168.10.0/24 to 192.168.11.3 lookup main
- 10012: from 192.168.10.10 lookup main
- 10013: from 192.168.10.1 lookup main
- 10410: from 192.168.11.0/24 lookup ovpnc2
- 10411: from 192.168.10.0/24 lookup ovpnc2
- 12210: from 192.168.10.2 prohibit
- 12211: from 192.168.11.0/24 prohibit
- 12211: from 192.168.10.0/24 prohibit
- 32766: from all lookup main
- 32767: from all lookup default
- >>> iptables -t mangle -vnL
- Chain PREROUTING (policy ACCEPT 459K packets, 416M bytes)
- pkts bytes target prot opt in out source destination
- 24701 1482K MARK all -- wgs1 * 0.0.0.0/0 0.0.0.0/0 MARK or 0x1
- Chain INPUT (policy ACCEPT 219K packets, 209M bytes)
- pkts bytes target prot opt in out source destination
- Chain FORWARD (policy ACCEPT 217K packets, 197M bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy ACCEPT 168K packets, 112M bytes)
- pkts bytes target prot opt in out source destination
- Chain POSTROUTING (policy ACCEPT 386K packets, 309M bytes)
- pkts bytes target prot opt in out source destination
- 75677 92M MARK all -- * wgs1 0.0.0.0/0 0.0.0.0/0 MARK or 0x1
- >>> iptables -t nat -vnL
- Chain PREROUTING (policy ACCEPT 26798 packets, 11M bytes)
- pkts bytes target prot opt in out source destination
- 3178 235K GAME_VSERVER all -- * * 0.0.0.0/0 192.168.100.2
- 3178 235K VSERVER all -- * * 0.0.0.0/0 192.168.100.2
- 416 32812 DNSFILTER udp -- br+ * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
- 1 64 DNSFILTER tcp -- br+ * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- Chain INPUT (policy ACCEPT 665 packets, 69026 bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy ACCEPT 11618 packets, 932K bytes)
- pkts bytes target prot opt in out source destination
- Chain POSTROUTING (policy ACCEPT 10945 packets, 872K bytes)
- pkts bytes target prot opt in out source destination
- 119 9050 MASQUERADE all -- * tun12 0.0.0.0/0 0.0.0.0/0
- 9842 794K PUPNP all -- * eth0 0.0.0.0/0 0.0.0.0/0
- 469 228K MASQUERADE all -- * eth0 !192.168.100.2 0.0.0.0/0
- 673 59508 MASQUERADE all -- * br0 192.168.10.0/24 192.168.10.0/24
- Chain DNSFILTER (2 references)
- pkts bytes target prot opt in out source destination
- 417 32876 DNAT all -- * * 0.0.0.0/0 0.0.0.0/0 to:192.168.10.1
- Chain GAME_VSERVER (1 references)
- pkts bytes target prot opt in out source destination
- Chain LOCALSRV (0 references)
- pkts bytes target prot opt in out source destination
- Chain MAPE (0 references)
- pkts bytes target prot opt in out source destination
- Chain PCREDIRECT (0 references)
- pkts bytes target prot opt in out source destination
- Chain PUPNP (1 references)
- pkts bytes target prot opt in out source destination
- Chain VSERVER (1 references)
- pkts bytes target prot opt in out source destination
- 3178 235K VUPNP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VUPNP (1 references)
- pkts bytes target prot opt in out source destination
- >>> iptables -vnL
- Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 31 1188 INPUT_PING icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 200K 205M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 25 2528 logdrop all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 15749 3107K PTCSRVWAN all -- !br0 * 0.0.0.0/0 0.0.0.0/0
- 2939 483K PTCSRVLAN all -- br0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 logdrop tcp -- !lo * 0.0.0.0/0 0.0.0.0/0 tcp dpt:<REMOVED>
- 2939 483K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0 state NEW
- 12360 2864K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 state NEW
- 2 80 INPUT_ICMP icmp -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT 47 -- * * 0.0.0.0/0 0.0.0.0/0
- 3389 243K WGSI all -- * * 0.0.0.0/0 0.0.0.0/0
- 3346 240K WGCI all -- * * 0.0.0.0/0 0.0.0.0/0
- 3346 240K OVPNSI all -- * * 0.0.0.0/0 0.0.0.0/0
- 3346 240K OVPNCI all -- * * 0.0.0.0/0 0.0.0.0/0
- 3346 240K logdrop all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
- pkts bytes target prot opt in out source destination
- 0 0 DROP ah -- br0 eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP esp -- br0 eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP udp -- br0 eth0 0.0.0.0/0 0.0.0.0/0 udp dpt:<REMOVED>
- 0 0 DROP udp -- br0 eth0 0.0.0.0/0 0.0.0.0/0 udp dpt:<REMOVED>
- 0 0 DROP udp -- br0 eth0 0.0.0.0/0 0.0.0.0/0 udp dpt:<REMOVED>
- 0 0 DROP 47 -- br0 eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP tcp -- br0 eth0 0.0.0.0/0 0.0.0.0/0 tcp dpt:<REMOVED>
- 217K 197M IPSEC_DROP_SUBNET_ICMP all -- * * 0.0.0.0/0 0.0.0.0/0
- 217K 197M IPSEC_STRONGSWAN all -- * * 0.0.0.0/0 0.0.0.0/0
- 217K 197M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 609 239K WGSF all -- * * 0.0.0.0/0 0.0.0.0/0
- 540 233K OVPNSF all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 logdrop all -- !br0 eth0 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- br0 br0 0.0.0.0/0 0.0.0.0/0
- 1 52 logdrop all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 0 0 SECURITY all -- eth0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT
- 0 0 DNSFILTER_DOT tcp -- br+ * 0.0.0.0/0 0.0.0.0/0 tcp dpt:853
- 539 233K WGCF all -- * * 0.0.0.0/0 0.0.0.0/0
- 539 233K OVPNCF all -- * * 0.0.0.0/0 0.0.0.0/0
- 476 229K VPNCF all -- * * 0.0.0.0/0 0.0.0.0/0
- 476 229K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0
- 0 0 logdrop all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain OUTPUT (policy ACCEPT 166K packets, 111M bytes)
- pkts bytes target prot opt in out source destination
- 1207 83701 OUTPUT_DNS udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:53 u32 "<REMOVED>"
- 68 6949 OUTPUT_DNS tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 u32 "<REMOVED>"
- 168K 112M OUTPUT_IP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain ACCESS_RESTRICTION (0 references)
- pkts bytes target prot opt in out source destination
- Chain DNSFILTER_DOT (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 REJECT all -- * * 0.0.0.0/0 !192.168.10.1 reject-with icmp-port-unreachable
- Chain FUPNP (0 references)
- pkts bytes target prot opt in out source destination
- Chain IControls (0 references)
- pkts bytes target prot opt in out source destination
- Chain INPUT_ICMP (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 2 80 RETURN icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 13
- 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
- Chain INPUT_PING (1 references)
- pkts bytes target prot opt in out source destination
- 30 1128 logdrop icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0
- Chain IPSEC_DROP_SUBNET_ICMP (1 references)
- pkts bytes target prot opt in out source destination
- Chain IPSEC_STRONGSWAN (1 references)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT_DNS (2 references)
- pkts bytes target prot opt in out source destination
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- 0 0 logdrop_dns all -- * * 0.0.0.0/0 0.0.0.0/0 STRING match "<REMOVED>" ALGO name bm TO 65535 ICASE
- Chain OUTPUT_IP (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- 0 0 logdrop_ip all -- * * 0.0.0.0/0 <SOMEREMOTEIP>
- Chain OVPNCF (1 references)
- pkts bytes target prot opt in out source destination
- 63 4794 ACCEPT all -- * tun12 0.0.0.0/0 0.0.0.0/0
- 0 0 DROP all -- tun12 * 0.0.0.0/0 0.0.0.0/0
- Chain OVPNCI (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- tun12 * 0.0.0.0/0 0.0.0.0/0
- Chain OVPNSF (1 references)
- pkts bytes target prot opt in out source destination
- Chain OVPNSI (1 references)
- pkts bytes target prot opt in out source destination
- Chain PControls (0 references)
- pkts bytes target prot opt in out source destination
- Chain PTCSRVLAN (1 references)
- pkts bytes target prot opt in out source destination
- Chain PTCSRVWAN (1 references)
- pkts bytes target prot opt in out source destination
- Chain SECURITY (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcpflags: 0x17/0x02 limit: avg 1/sec burst 5
- 0 0 logdrop tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcpflags: 0x17/0x02
- 0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcpflags: 0x17/0x04 limit: avg 1/sec burst 5
- 0 0 logdrop tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcpflags: 0x17/0x04
- 0 0 RETURN icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8 limit: avg 1/sec burst 5
- 0 0 logdrop icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8
- 0 0 RETURN all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain VPNCF (1 references)
- pkts bytes target prot opt in out source destination
- Chain VPNCI (0 references)
- pkts bytes target prot opt in out source destination
- Chain WGCF (1 references)
- pkts bytes target prot opt in out source destination
- Chain WGCI (1 references)
- pkts bytes target prot opt in out source destination
- Chain WGNPControls (0 references)
- pkts bytes target prot opt in out source destination
- Chain WGSF (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 ACCEPT all -- * wgs1 0.0.0.0/0 0.0.0.0/0
- 69 5052 ACCEPT all -- wgs1 * 0.0.0.0/0 0.0.0.0/0
- Chain WGSI (1 references)
- pkts bytes target prot opt in out source destination
- 6 924 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:<REMOVED>
- 37 2385 ACCEPT all -- wgs1 * 0.0.0.0/0 0.0.0.0/0
- Chain default_block (0 references)
- pkts bytes target prot opt in out source destination
- Chain logaccept (0 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 7 level 4 prefix "ACCEPT "
- 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain logdrop (10 references)
- pkts bytes target prot opt in out source destination
- 3402 243K DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain logdrop_dns (21 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 7 level 4 prefix "DROP_DNS "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain logdrop_ip (6 references)
- pkts bytes target prot opt in out source destination
- 0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 LOG flags 7 level 4 prefix "DROP_IP "
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- >>> cat /tmp/etc/openvpn/client1/config.ovpn
- cat: can't open '/tmp/etc/openvpn/client1/config.ovpn': No such file or directory
- >>> cat /tmp/etc/openvpn/client2/config.ovpn
- daemon ovpn-client2
- client
- dev tun12
- txqueuelen 1000
- proto udp
- fast-io
- remote <WANVPNIP2> 1194
- connect-retry-max 15
- nobind
- persist-key
- persist-tun
- compress
- data-ciphers AES-256-GCM:AES-128-GCM:AES-256-CBC:AES-128-CBC:CHACHA20-POLY1305
- auth SHA512
- route-noexec
- reneg-sec 0
- tls-auth static.key 1
- ca ca.crt
- auth-user-pass auth
- up 'ovpn-up 2 client'
- down 'ovpn-down 2 client'
- route-up 'ovpn-route-up'
- route-pre-down 'ovpn-route-pre-down'
- script-security 2
- route-delay 2
- verb 3
- status-version 2
- status status 5
- # Custom Configuration
- resolv-retry infinite
- remote-random
- tun-mtu 1500
- tun-mtu-extra 32
- mssfix 1450
- ping 15
- ping-restart 0
- ping-timer-rem
- verify-x509-name CN=<REMOVED>
- remote-cert-tls server
- pull
- fast-io
- cipher AES-256-CBC
- pull-filter ignore "ifconfig-ipv6"
- pull-filter ignore "route-ipv6"
- auth-nocache
- mute-replay-warnings
- disable-occ
- nobind
- persist-key
- persist-tun
- reneg-sec 0
- #log /tmp/vpn.log
- >>> cat /jffs/openvpn/vpndirector_rulelist
- <1>LAN to LAN>192.168.10.0/24>192.168.10.0/24>WAN<1>WG02 to LAN>192.168.10.0/24>192.168.11.3>WAN<1>PC to WAN>192.168.10.10>>WAN<1>RTR to WAN>192.168.10.1>>WAN<1>NAS to OVPN>192.168.10.2>>OVPN1<1>WG to OVPN>192.168.11.0/24>>OVPN2<1>LAN to OVPN>192.168.10.0/24>>OVPN2
- >>> cat /tmp/etc/dnsmasq.conf
- pid-file=/var/run/dnsmasq.pid
- user=nobody
- bind-dynamic
- interface=br0
- interface=pptp*
- no-dhcp-interface=pptp*
- no-resolv
- servers-file=/tmp/resolv.dnsmasq
- no-poll
- no-negcache
- cache-size=1500
- min-port=4096
- dns-forward-max=1500
- domain=home
- expand-hosts
- bogus-priv
- domain-needed
- local=/home/
- dhcp-range=lan,192.168.10.21,192.168.10.50,255.255.255.0,86400s
- dhcp-option=lan,3,192.168.10.1
- dhcp-option=lan,15,home
- dhcp-authoritative
- interface=br1
- dhcp-range=br1,192.168.101.2,192.168.101.254,255.255.255.0,86400s
- dhcp-option=br1,3,192.168.101.1
- interface=br2
- dhcp-range=br2,192.168.102.2,192.168.102.254,255.255.255.0,86400s
- dhcp-option=br2,3,192.168.102.1
- interface=wgs1
- no-dhcp-interface=wgs1
- dhcp-host=<MAC>,set:<MAC>,192.168.10.2
- dhcp-host=<MAC>,set:<MAC>,192.168.10.10
- dhcp-host=<MAC>,set:<MAC>,192.168.10.3
- dhcp-host=<MAC>,set:<MAC>,192.168.10.4
- dhcp-host=<MAC>,set:<MAC>,192.168.10.9
- quiet-dhcp
- quiet-dhcp6
- trust-anchor=.,20326,8,2,<REMOVED>
- dnssec
- stop-dns-rebind
- rebind-domain-ok=dns.msftncsi.com
- address=/use-application-dns.net/
- address=/_dns.resolver.arpa/
- address=/mask.icloud.com/mask-h2.icloud.com/
- dhcp-name-match=set:wpad-ignore,wpad
- dhcp-ignore-names=tag:wpad-ignore
- dhcp-script=/sbin/dhcpc_lease
- script-arp
- edns-packet-max=1232
- ipset=/1drv.ms/asuswrt-merlin.net/asuswrt.lostrealm.ca/big.oisd.nl/bin.entware.net/cdn.jsdelivr.net/codeload.github.com/diversion.ch/entware.diversion.ch/entware.net/fwupdate.asuswrt-merlin.net/gist.githubusercontent.com/localhost.localdomain/maurerr.github.io/mirrors.bfsu.edu.cn/oisd.nl/onedrive.live.com/pgl.yoyo.org/pkg.entware.net/raw.githubusercontent.com/Skynet-WhitelistDomains # Skynet
- ipset=/small.oisd.nl/snbforums.com/someonewhocares.org/sourceforge.net/urlhaus.abuse.ch/iplists.firehol.org/ipdeny.com/ipapi.co/api.db-ip.com/api.bgpview.io/asn.ipinfo.app/speedguide.net/otx.alienvault.com/github.com/astrill.com/strongpath.net/nwsrv-ns1.asus.com/0.pool.ntp.org/1.pool.ntp.org/Skynet-WhitelistDomains # Skynet
- # start of Diversion directives #
- conf-file=/opt/share/diversion/list/allowlist.conf
- conf-file=/opt/share/diversion/list/blockinglist.conf
- conf-file=/opt/share/diversion/list/denylist.conf
- log-async
- log-queries
- log-facility=/opt/var/log/dnsmasq.log
- # end of Diversion directives #
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement