Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [root@vpnsquid ~]# iptables-save -c
- # Generated by iptables-save v1.4.7 on Sat Jul 22 09:40:14 2017
- *nat
- :PREROUTING ACCEPT [14693:797845]
- :POSTROUTING ACCEPT [0:0]
- :OUTPUT ACCEPT [652:46213]
- [274:16440] -A PREROUTING -s 172.8.0.0/24 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
- [0:0] -A PREROUTING -s 172.8.0.0/24 -i tun1 -p tcp -m tcp --sport 80 -j REDIRECT --to-ports 3128
- [0:0] -A PREROUTING -s 172.8.0.0/24 -i tun1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
- [0:0] -A POSTROUTING -s 172.8.0.0/24 -o eth0 -j MASQUERADE
- [0:0] -A POSTROUTING -s 172.8.0.0/24 -o tun1 -j MASQUERADE
- [2:1585] -A POSTROUTING -o eth0 -j MASQUERADE
- [1237:78880] -A POSTROUTING -o tun+ -j MASQUERADE
- COMMIT
- # Completed on Sat Jul 22 09:40:14 2017
- # Generated by iptables-save v1.4.7 on Sat Jul 22 09:40:14 2017
- *mangle
- :PREROUTING ACCEPT [206641:109928248]
- :INPUT ACCEPT [154093:72116719]
- :FORWARD ACCEPT [52548:37811529]
- :OUTPUT ACCEPT [135844:105364471]
- :POSTROUTING ACCEPT [187666:143145592]
- COMMIT
- # Completed on Sat Jul 22 09:40:14 2017
- # Generated by iptables-save v1.4.7 on Sat Jul 22 09:40:14 2017
- *filter
- :INPUT DROP [9146:481863]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [726:30408]
- [130821:70870423] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- [259:15620] -A INPUT -i eth0 -p tcp -m tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
- [13:740] -A INPUT -i eth0 -p tcp -m tcp -m multiport --dports 53,80,443,10000 -m state --state NEW,ESTABLISHED -j ACCEPT
- [13575:731310] -A INPUT -i eth0 -p tcp -m tcp --dport 3128 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A INPUT -i tun1 -p tcp -m tcp --sport 3128 -m state --state NEW,ESTABLISHED -j ACCEPT
- [1:67] -A INPUT -i eth0 -p udp -m udp --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT
- [0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 443 -m state --state ESTABLISHED -j ACCEPT
- [0:0] -A INPUT -i eth0 -p tcp -m tcp --sport 80 -m state --state ESTABLISHED -j ACCEPT
- [0:0] -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- [0:0] -A INPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT
- [0:0] -A INPUT -i lo -j ACCEPT
- [1:40] -A INPUT -p tcp -m tcp --dport 80 -m limit --limit 25/min --limit-burst 100 -j ACCEPT
- [0:0] -A INPUT -i eth0 -p udp -m state --state NEW -m udp --dport 1194 -j ACCEPT
- [1:70] -A INPUT -i eth0 -p udp -m state --state NEW -m udp --dport 1195 -j ACCEPT
- [276:16586] -A INPUT -i tun+ -j ACCEPT
- [51950:37775569] -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
- [598:35960] -A FORWARD -i tun+ -j ACCEPT
- [0:0] -A FORWARD -i tun+ -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A FORWARD -i eth0 -o tun+ -m state --state RELATED,ESTABLISHED -j ACCEPT
- [134463:105287258] -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p tcp -m tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p tcp -m tcp -m multiport --sports 53,80,443,10000 -m state --state ESTABLISHED -j ACCEPT
- [2:2880] -A OUTPUT -p tcp -m tcp --sport 3128 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -p tcp -m tcp --dport 3128 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p udp -m udp --sport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p udp -m udp --dport 53 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p tcp -m tcp --dport 443 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p tcp -m tcp --dport 80 -m state --state NEW,ESTABLISHED -j ACCEPT
- [0:0] -A OUTPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT
- [0:0] -A OUTPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
- [0:0] -A OUTPUT -o lo -j ACCEPT
- [652:43780] -A OUTPUT -o tun+ -j ACCEPT
- [1:145] -A OUTPUT -o eth0 -p udp -m state --state NEW -m udp --dport 1194 -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -p udp -m state --state NEW -m udp --dport 1195 -j ACCEPT
- COMMIT
- # Completed on Sat Jul 22 09:40:14 2017
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement