Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.6.0 on Tue Mar 6 04:10:26 2018
- *mangle
- :PREROUTING ACCEPT [354382:26406678]
- :INPUT ACCEPT [326650:16548377]
- :FORWARD ACCEPT [27636:9850472]
- :OUTPUT ACCEPT [6055:441892]
- :POSTROUTING ACCEPT [32989:10272123]
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- COMMIT
- # Completed on Tue Mar 6 04:10:26 2018
- # Generated by iptables-save v1.6.0 on Tue Mar 6 04:10:26 2018
- *nat
- :PREROUTING ACCEPT [35828:5371260]
- :INPUT ACCEPT [744:113337]
- :OUTPUT ACCEPT [1290:95977]
- :POSTROUTING ACCEPT [3830:264182]
- -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- -A POSTROUTING ! -d 10.1.0.0/16 -o enp0s9 -j SNAT --to-source 10.0.4.15
- -A POSTROUTING ! -d 10.1.0.0/16 -o enp0s9 -j SNAT --to-source 10.0.4.15
- -A POSTROUTING ! -d 10.0.0.0/16 -o enp0s3 -j SNAT --to-source 10.8.15.157
- -A POSTROUTING ! -d 10.1.0.0/16 -o enp0s3 -j SNAT --to-source 10.8.15.157
- COMMIT
- # Completed on Tue Mar 6 04:10:26 2018
- # Generated by iptables-save v1.6.0 on Tue Mar 6 04:10:26 2018
- *filter
- :INPUT DROP [1711:91384]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [20:1663]
- :dmznet - [0:0]
- :ufw-after-forward - [0:0]
- :ufw-after-input - [0:0]
- :ufw-after-logging-forward - [0:0]
- :ufw-after-logging-input - [0:0]
- :ufw-after-logging-output - [0:0]
- :ufw-after-output - [0:0]
- :ufw-before-forward - [0:0]
- :ufw-before-input - [0:0]
- :ufw-before-logging-forward - [0:0]
- :ufw-before-logging-input - [0:0]
- :ufw-before-logging-output - [0:0]
- :ufw-before-output - [0:0]
- :ufw-reject-forward - [0:0]
- :ufw-reject-input - [0:0]
- :ufw-reject-output - [0:0]
- :ufw-track-forward - [0:0]
- :ufw-track-input - [0:0]
- :ufw-track-output - [0:0]
- -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
- -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
- -A FORWARD -s 10.0.0.1/32 -d 10.1.0.0/16 -p tcp -m tcp --dport 22 -j ACCEPT
- -A FORWARD -s 10.0.0.0/16 -d 10.1.0.0/16 -p tcp -m tcp --dport 22 -j DROP
- -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
- -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A FORWARD -s 10.0.0.0/16 -p tcp -j ACCEPT
- -A FORWARD -d 10.0.0.0/16 -p tcp -j ACCEPT
- -A FORWARD -d 10.0.0.0/16 -p udp -j ACCEPT
- -A FORWARD -s 10.0.0.0/16 -p udp -j ACCEPT
- -A FORWARD -s 10.1.0.1/32 -p tcp -m tcp --sport 80 -j ACCEPT
- -A FORWARD -d 10.1.0.1/32 -p tcp -m tcp --dport 80 -j ACCEPT
- -A FORWARD -d 10.1.0.3/32 -p tcp -m tcp --dport 53 -j ACCEPT
- -A FORWARD -s 10.1.0.3/32 -p tcp -m tcp --sport 53 -j ACCEPT
- -A FORWARD -s 10.1.0.3/32 -p udp -m udp --sport 53 -j ACCEPT
- -A FORWARD -d 10.1.0.3/32 -p udp -m udp --dport 53 -j ACCEPT
- -A FORWARD -d 10.8.0.0/16 -p udp -j ACCEPT
- -A FORWARD -d 10.8.0.0/16 -p tcp -j ACCEPT
- -A FORWARD -s 10.8.0.0/16 -p tcp -j ACCEPT
- -A FORWARD -s 10.8.0.0/16 -p udp -j ACCEPT
- -A FORWARD -j dmznet
- -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
- -A dmznet -d 10.1.0.0/16 -p tcp -j ACCEPT
- -A dmznet -d 10.1.0.0/16 -p udp -j ACCEPT
- -A dmznet -s 10.1.0.0/16 -p udp -j ACCEPT
- -A dmznet -s 10.1.0.0/16 -p tcp -j ACCEPT
- COMMIT
- # Completed on Tue Mar 6 04:10:26 2018
Add Comment
Please, Sign In to add comment