Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- network.loopback=interface
- network.loopback.ifname='lo'
- network.loopback.proto='static'
- network.loopback.ipaddr='127.0.0.1'
- network.loopback.netmask='255.0.0.0'
- network.globals=globals
- network.globals.ula_prefix='fd46:e7ae:7619::/48'
- network.lan=interface
- network.lan.type='bridge'
- network.lan.proto='static'
- network.lan.ipaddr='192.168.1.1'
- network.lan.netmask='255.255.255.0'
- network.lan.ip6assign='60'
- network.lan.ifname='eth0'
- network.wan=interface
- network.wan.type='bridge'
- network.wan.netmask='255.255.255.0'
- network.wan.gateway='192.168.0.1'
- network.wan.ipv6='auto'
- network.wan.proto='dhcp'
- network.wan.ifname='eth1'
- network.wwan=interface
- network.wwan.type='bridge'
- network.wwan.ipaddr='192.168.2.1'
- network.wwan.netmask='255.255.255.0'
- network.wwan.proto='static'
- network.@device[0]=device
- network.@device[0].name='radio0.network1'
- network.vpn=interface
- network.vpn.proto='none'
- network.vpn.ifname='tun0'
- wireless.radio0=wifi-device
- wireless.radio0.type='mac80211'
- wireless.radio0.path='platform/soc/fe300000.mmcnr/mmc_host/mmc1/mmc1:0001/mmc1:0001:1'
- wireless.radio0.hwmode='11g'
- wireless.radio0.channel='11'
- wireless.radio0.country='BR'
- wireless.radio0.cell_density='0'
- wireless.default_radio0=wifi-iface
- wireless.default_radio0.device='radio0'
- wireless.default_radio0.mode='ap'
- wireless.default_radio0.ssid='normalssid'
- wireless.default_radio0.encryption='psk2+ccmp'
- wireless.default_radio0.key='secretkey'
- wireless.default_radio0.network='wwan'
- firewall.@defaults[0]=defaults
- firewall.@defaults[0].input='ACCEPT'
- firewall.@defaults[0].output='ACCEPT'
- firewall.@defaults[0].forward='REJECT'
- firewall.@defaults[0].synflood_protect='1'
- firewall.lan=zone
- firewall.lan.name='lan'
- firewall.lan.input='ACCEPT'
- firewall.lan.output='ACCEPT'
- firewall.lan.forward='ACCEPT'
- firewall.lan.network='lan'
- firewall.wan=zone
- firewall.wan.name='wan'
- firewall.wan.output='ACCEPT'
- firewall.wan.forward='REJECT'
- firewall.wan.masq='1'
- firewall.wan.mtu_fix='1'
- firewall.wan.network='wan'
- firewall.wan.input='ACCEPT'
- firewall.wwan=zone
- firewall.wwan.name='wwan'
- firewall.wwan.network='wwan'
- firewall.wwan.input='ACCEPT'
- firewall.wwan.forward='REJECT'
- firewall.wwan.output='ACCEPT'
- firewall.wwan.device='wlan0'
- firewall.@rule[0]=rule
- firewall.@rule[0].name='Allow-DHCP-Renew'
- firewall.@rule[0].src='wan'
- firewall.@rule[0].proto='udp'
- firewall.@rule[0].dest_port='68'
- firewall.@rule[0].target='ACCEPT'
- firewall.@rule[0].family='ipv4'
- firewall.@rule[1]=rule
- firewall.@rule[1].name='Allow-Ping'
- firewall.@rule[1].src='wan'
- firewall.@rule[1].proto='icmp'
- firewall.@rule[1].icmp_type='echo-request'
- firewall.@rule[1].family='ipv4'
- firewall.@rule[1].target='ACCEPT'
- firewall.@rule[2]=rule
- firewall.@rule[2].name='Allow-IGMP'
- firewall.@rule[2].src='wan'
- firewall.@rule[2].proto='igmp'
- firewall.@rule[2].family='ipv4'
- firewall.@rule[2].target='ACCEPT'
- firewall.@rule[3]=rule
- firewall.@rule[3].name='Allow-DHCPv6'
- firewall.@rule[3].src='wan'
- firewall.@rule[3].proto='udp'
- firewall.@rule[3].src_ip='fc00::/6'
- firewall.@rule[3].dest_ip='fc00::/6'
- firewall.@rule[3].dest_port='546'
- firewall.@rule[3].family='ipv6'
- firewall.@rule[3].target='ACCEPT'
- firewall.@rule[4]=rule
- firewall.@rule[4].name='Allow-MLD'
- firewall.@rule[4].src='wan'
- firewall.@rule[4].proto='icmp'
- firewall.@rule[4].src_ip='fe80::/10'
- firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
- firewall.@rule[4].family='ipv6'
- firewall.@rule[4].target='ACCEPT'
- firewall.@rule[5]=rule
- firewall.@rule[5].name='Allow-ICMPv6-Input'
- firewall.@rule[5].src='wan'
- firewall.@rule[5].proto='icmp'
- firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
- firewall.@rule[5].limit='1000/sec'
- firewall.@rule[5].family='ipv6'
- firewall.@rule[5].target='ACCEPT'
- firewall.@rule[6]=rule
- firewall.@rule[6].name='Allow-ICMPv6-Forward'
- firewall.@rule[6].src='wan'
- firewall.@rule[6].dest='*'
- firewall.@rule[6].proto='icmp'
- firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
- firewall.@rule[6].limit='1000/sec'
- firewall.@rule[6].family='ipv6'
- firewall.@rule[6].target='ACCEPT'
- firewall.@rule[7]=rule
- firewall.@rule[7].name='Allow-IPSec-ESP'
- firewall.@rule[7].src='wan'
- firewall.@rule[7].dest='lan'
- firewall.@rule[7].proto='esp'
- firewall.@rule[7].target='ACCEPT'
- firewall.@rule[8]=rule
- firewall.@rule[8].name='Allow-ISAKMP'
- firewall.@rule[8].src='wan'
- firewall.@rule[8].dest='lan'
- firewall.@rule[8].dest_port='500'
- firewall.@rule[8].proto='udp'
- firewall.@rule[8].target='ACCEPT'
- firewall.@rule[9]=rule
- firewall.@rule[9].name='Support-UDP-Traceroute'
- firewall.@rule[9].src='wan'
- firewall.@rule[9].dest_port='33434:33689'
- firewall.@rule[9].proto='udp'
- firewall.@rule[9].family='ipv4'
- firewall.@rule[9].target='REJECT'
- firewall.@rule[9].enabled='false'
- firewall.@include[0]=include
- firewall.@include[0].path='/etc/firewall.user'
- firewall.@forwarding[0]=forwarding
- firewall.@forwarding[0].src='wwan'
- firewall.@forwarding[0].dest='wan'
- firewall.vpn=zone
- firewall.vpn.name='vpn'
- firewall.vpn.output='ACCEPT'
- firewall.vpn.forward='REJECT'
- firewall.vpn.masq='1'
- firewall.vpn.mtu_fix='1'
- firewall.vpn.device='tun+'
- firewall.vpn.input='REJECT'
- firewall.vpn.network='vpn'
- firewall.@forwarding[1]=forwarding
- firewall.@forwarding[1].src='lan'
- firewall.@forwarding[1].dest='vpn'
- firewall.@forwarding[2]=forwarding
- firewall.@forwarding[2].src='vpn'
- firewall.@forwarding[2].dest='wan'
- dhcp.@dnsmasq[0]=dnsmasq
- dhcp.@dnsmasq[0].domainneeded='1'
- dhcp.@dnsmasq[0].localise_queries='1'
- dhcp.@dnsmasq[0].rebind_localhost='1'
- dhcp.@dnsmasq[0].local='/lan/'
- dhcp.@dnsmasq[0].domain='lan'
- dhcp.@dnsmasq[0].expandhosts='1'
- dhcp.@dnsmasq[0].readethers='1'
- dhcp.@dnsmasq[0].leasefile='/tmp/dhcp.leases'
- dhcp.@dnsmasq[0].ednspacket_max='1232'
- dhcp.@dnsmasq[0].logqueries='1'
- dhcp.@dnsmasq[0].authoritative='1'
- dhcp.@dnsmasq[0].confdir='/tmp/dnsmasq.d'
- dhcp.@dnsmasq[0].rebind_protection='1'
- dhcp.@dnsmasq[0].localservice='0'
- dhcp.@dnsmasq[0].noresolv='1'
- dhcp.@dnsmasq[0].server='208.67.222.222' '208.67.220.220'
- dhcp.lan=dhcp
- dhcp.lan.interface='lan'
- dhcp.lan.start='100'
- dhcp.lan.limit='150'
- dhcp.lan.leasetime='12h'
- dhcp.lan.dhcpv4='server'
- dhcp.lan.dhcpv6='server'
- dhcp.lan.ra='server'
- dhcp.lan.ra_slaac='1'
- dhcp.lan.ra_flags='managed-config' 'other-config'
- dhcp.lan.ra_management='1'
- dhcp.wan=dhcp
- dhcp.wan.interface='wan'
- dhcp.wan.ignore='1'
- dhcp.odhcpd=odhcpd
- dhcp.odhcpd.maindhcp='0'
- dhcp.odhcpd.leasefile='/tmp/hosts/odhcpd'
- dhcp.odhcpd.leasetrigger='/usr/sbin/odhcpd-update'
- dhcp.odhcpd.loglevel='4'
- dhcp.wwan=dhcp
- dhcp.wwan.interface='wwan'
- dhcp.wwan.start='100'
- dhcp.wwan.limit='150'
- dhcp.wwan.leasetime='12h'
- dhcp.wwan.dhcpv4='server'
- dhcp.wwan.dhcpv6='server'
- dhcp.wwan.ra_management='1'
- 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
- link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
- inet 127.0.0.1/8 scope host lo
- valid_lft forever preferred_lft forever
- inet6 ::1/128 scope host
- valid_lft forever preferred_lft forever
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq master br-lan state UP group default qlen 1000
- link/ether dc:a6:32:56:b3:22 brd ff:ff:ff:ff:ff:ff
- 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel master br-wan state UP group default qlen 1000
- link/ether 00:0e:c8:9e:8c:6e brd ff:ff:ff:ff:ff:ff
- 4: wlan0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel master br-wwan state UP group default qlen 1000
- link/ether dc:a6:32:56:b3:23 brd ff:ff:ff:ff:ff:ff
- inet6 fe80::dea6:32ff:fe56:b323/64 scope link
- valid_lft forever preferred_lft forever
- 5: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether dc:a6:32:56:b3:22 brd ff:ff:ff:ff:ff:ff
- inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan
- valid_lft forever preferred_lft forever
- inet6 fd46:e7ae:7619::1/60 scope global noprefixroute
- valid_lft forever preferred_lft forever
- inet6 fe80::dea6:32ff:fe56:b322/64 scope link
- valid_lft forever preferred_lft forever
- 6: br-wan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether 00:0e:c8:9e:8c:6e brd ff:ff:ff:ff:ff:ff
- inet 192.168.0.108/24 brd 192.168.0.255 scope global br-wan
- valid_lft forever preferred_lft forever
- inet6 fe80::20e:c8ff:fe9e:8c6e/64 scope link
- valid_lft forever preferred_lft forever
- 7: br-wwan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
- link/ether dc:a6:32:56:b3:23 brd ff:ff:ff:ff:ff:ff
- inet 192.168.2.1/24 brd 192.168.2.255 scope global br-wwan
- valid_lft forever preferred_lft forever
- inet6 fe80::dea6:32ff:fe56:b323/64 scope link
- valid_lft forever preferred_lft forever
- 8: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 500
- link/none
- inet 10.172.0.122 peer 10.172.0.121/32 scope global tun0
- valid_lft forever preferred_lft forever
- inet6 fe80::1728:b972:7984:e31e/64 scope link stable-privacy
- valid_lft forever preferred_lft forever
- default via 192.168.0.1 dev br-wan table wan
- 192.168.0.0/24 dev br-wan table wan proto kernel scope link src 192.168.0.108
- 192.168.1.0/24 dev br-lan table wan proto kernel scope link src 192.168.1.1
- 192.168.2.0/24 dev br-wwan table wan proto kernel scope link src 192.168.2.1
- default via 192.168.2.1 dev br-wwan table wwan
- 192.168.0.0/24 dev br-wan table wwan proto kernel scope link src 192.168.0.108
- 192.168.1.0/24 dev br-lan table wwan proto kernel scope link src 192.168.1.1
- 192.168.2.0/24 dev br-wwan table wwan proto kernel scope link src 192.168.2.1
- default via 10.172.0.122 dev tun0 table vpn
- 45.56.156.8 via 192.168.0.1 dev br-wan table vpn
- 192.168.0.0/24 dev br-wan table vpn proto kernel scope link src 192.168.0.108
- 192.168.1.0/24 dev br-lan table vpn proto kernel scope link src 192.168.1.1
- 192.168.2.0/24 dev br-wwan table vpn proto kernel scope link src 192.168.2.1
- 0.0.0.0/1 via 10.172.0.121 dev tun0
- default via 192.168.0.1 dev br-wan proto static src 192.168.0.108
- 10.172.0.1 via 10.172.0.121 dev tun0
- 10.172.0.121 dev tun0 proto kernel scope link src 10.172.0.122
- 45.56.156.8 via 192.168.0.1 dev br-wan
- 128.0.0.0/1 via 10.172.0.121 dev tun0
- 192.168.0.0/24 dev br-wan proto kernel scope link src 192.168.0.108
- 192.168.1.0/24 dev br-lan proto kernel scope link src 192.168.1.1
- 192.168.2.0/24 dev br-wwan proto kernel scope link src 192.168.2.1
- local 10.172.0.122 dev tun0 table local proto kernel scope host src 10.172.0.122
- broadcast 127.0.0.0 dev lo table local proto kernel scope link src 127.0.0.1
- local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
- local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
- broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
- broadcast 192.168.0.0 dev br-wan table local proto kernel scope link src 192.168.0.108
- local 192.168.0.108 dev br-wan table local proto kernel scope host src 192.168.0.108
- broadcast 192.168.0.255 dev br-wan table local proto kernel scope link src 192.168.0.108
- broadcast 192.168.1.0 dev br-lan table local proto kernel scope link src 192.168.1.1
- local 192.168.1.1 dev br-lan table local proto kernel scope host src 192.168.1.1
- broadcast 192.168.1.255 dev br-lan table local proto kernel scope link src 192.168.1.1
- broadcast 192.168.2.0 dev br-wwan table local proto kernel scope link src 192.168.2.1
- local 192.168.2.1 dev br-wwan table local proto kernel scope host src 192.168.2.1
- broadcast 192.168.2.255 dev br-wwan table local proto kernel scope link src 192.168.2.1
- fe80::/64 dev br-wan table wan proto kernel metric 256 pref medium
- fe80::/64 dev br-wwan table wwan proto kernel metric 256 pref medium
- fe80::/64 dev tun0 table vpn proto kernel metric 256 pref medium
- fd46:e7ae:7619::/64 dev br-lan proto static metric 1024 pref medium
- unreachable fd46:e7ae:7619::/48 dev lo proto static metric 2147483647 pref medium
- fe80::/64 dev br-lan proto kernel metric 256 pref medium
- fe80::/64 dev wlan0 proto kernel metric 256 pref medium
- fe80::/64 dev br-wwan proto kernel metric 256 pref medium
- fe80::/64 dev br-wan proto kernel metric 256 pref medium
- fe80::/64 dev tun0 proto kernel metric 256 pref medium
- local ::1 dev lo table local proto kernel metric 0 pref medium
- anycast fd46:e7ae:7619:: dev br-lan table local proto kernel metric 0 pref medium
- local fd46:e7ae:7619::1 dev br-lan table local proto kernel metric 0 pref medium
- anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
- anycast fe80:: dev br-wwan table local proto kernel metric 0 pref medium
- anycast fe80:: dev wlan0 table local proto kernel metric 0 pref medium
- anycast fe80:: dev br-wan table local proto kernel metric 0 pref medium
- anycast fe80:: dev tun0 table local proto kernel metric 0 pref medium
- local fe80::20e:c8ff:fe9e:8c6e dev br-wan table local proto kernel metric 0 pref medium
- local fe80::1728:b972:7984:e31e dev tun0 table local proto kernel metric 0 pref medium
- local fe80::dea6:32ff:fe56:b322 dev br-lan table local proto kernel metric 0 pref medium
- local fe80::dea6:32ff:fe56:b323 dev br-wwan table local proto kernel metric 0 pref medium
- local fe80::dea6:32ff:fe56:b323 dev wlan0 table local proto kernel metric 0 pref medium
- multicast ff00::/8 dev br-lan table local proto kernel metric 256 pref medium
- multicast ff00::/8 dev wlan0 table local proto kernel metric 256 pref medium
- multicast ff00::/8 dev br-wwan table local proto kernel metric 256 pref medium
- multicast ff00::/8 dev br-wan table local proto kernel metric 256 pref medium
- multicast ff00::/8 dev tun0 table local proto kernel metric 256 pref medium
- 0: from all lookup local
- 32760: from all fwmark 0x30000/0xff0000 lookup vpn
- 32761: from all fwmark 0x20000/0xff0000 lookup wwan
- 32762: from all fwmark 0x10000/0xff0000 lookup wan
- 32766: from all lookup main
- 32767: from all lookup default
- # Generated by iptables-save v1.8.7 on Sun Apr 11 04:42:49 2021
- *nat
- :PREROUTING ACCEPT [282:37471]
- :INPUT ACCEPT [25:2498]
- :OUTPUT ACCEPT [67:5242]
- :POSTROUTING ACCEPT [136:5728]
- :postrouting_lan_rule - [0:0]
- :postrouting_rule - [0:0]
- :postrouting_vpn_rule - [0:0]
- :postrouting_wan_rule - [0:0]
- :postrouting_wwan_rule - [0:0]
- :prerouting_lan_rule - [0:0]
- :prerouting_rule - [0:0]
- :prerouting_vpn_rule - [0:0]
- :prerouting_wan_rule - [0:0]
- :prerouting_wwan_rule - [0:0]
- :zone_lan_postrouting - [0:0]
- :zone_lan_prerouting - [0:0]
- :zone_vpn_postrouting - [0:0]
- :zone_vpn_prerouting - [0:0]
- :zone_wan_postrouting - [0:0]
- :zone_wan_prerouting - [0:0]
- :zone_wwan_postrouting - [0:0]
- :zone_wwan_prerouting - [0:0]
- [282:37471] -A PREROUTING -m comment --comment "!fw3: Custom prerouting rule chain" -j prerouting_rule
- [100:20927] -A PREROUTING -i br-lan -m comment --comment "!fw3" -j zone_lan_prerouting
- [36:7475] -A PREROUTING -i br-wan -m comment --comment "!fw3" -j zone_wan_prerouting
- [0:0] -A PREROUTING -i wlan0 -m comment --comment "!fw3" -j zone_wwan_prerouting
- [146:9069] -A PREROUTING -i br-wwan -m comment --comment "!fw3" -j zone_wwan_prerouting
- [0:0] -A PREROUTING -i tun+ -m comment --comment "!fw3" -j zone_vpn_prerouting
- [0:0] -A PREROUTING -i tun0 -m comment --comment "!fw3" -j zone_vpn_prerouting
- [279:28215] -A POSTROUTING -m comment --comment "!fw3: Custom postrouting rule chain" -j postrouting_rule
- [1:40] -A POSTROUTING -o br-lan -m comment --comment "!fw3" -j zone_lan_postrouting
- [5:333] -A POSTROUTING -o br-wan -m comment --comment "!fw3" -j zone_wan_postrouting
- [0:0] -A POSTROUTING -o wlan0 -m comment --comment "!fw3" -j zone_wwan_postrouting
- [135:5688] -A POSTROUTING -o br-wwan -m comment --comment "!fw3" -j zone_wwan_postrouting
- [138:22154] -A POSTROUTING -o tun+ -m comment --comment "!fw3" -j zone_vpn_postrouting
- [0:0] -A POSTROUTING -o tun0 -m comment --comment "!fw3" -j zone_vpn_postrouting
- [1:40] -A zone_lan_postrouting -m comment --comment "!fw3: Custom lan postrouting rule chain" -j postrouting_lan_rule
- [100:20927] -A zone_lan_prerouting -m comment --comment "!fw3: Custom lan prerouting rule chain" -j prerouting_lan_rule
- [138:22154] -A zone_vpn_postrouting -m comment --comment "!fw3: Custom vpn postrouting rule chain" -j postrouting_vpn_rule
- [138:22154] -A zone_vpn_postrouting -m comment --comment "!fw3" -j MASQUERADE
- [0:0] -A zone_vpn_prerouting -m comment --comment "!fw3: Custom vpn prerouting rule chain" -j prerouting_vpn_rule
- [5:333] -A zone_wan_postrouting -m comment --comment "!fw3: Custom wan postrouting rule chain" -j postrouting_wan_rule
- [5:333] -A zone_wan_postrouting -m comment --comment "!fw3" -j MASQUERADE
- [36:7475] -A zone_wan_prerouting -m comment --comment "!fw3: Custom wan prerouting rule chain" -j prerouting_wan_rule
- [135:5688] -A zone_wwan_postrouting -m comment --comment "!fw3: Custom wwan postrouting rule chain" -j postrouting_wwan_rule
- [146:9069] -A zone_wwan_prerouting -m comment --comment "!fw3: Custom wwan prerouting rule chain" -j prerouting_wwan_rule
- COMMIT
- # Completed on Sun Apr 11 04:42:49 2021
- # Generated by iptables-save v1.8.7 on Sun Apr 11 04:42:49 2021
- *mangle
- :PREROUTING ACCEPT [3411:867714]
- :INPUT ACCEPT [1524:405888]
- :FORWARD ACCEPT [1846:453082]
- :OUTPUT ACCEPT [1614:309102]
- :POSTROUTING ACCEPT [3323:754024]
- :VPR_MARK0x010000 - [0:0]
- :VPR_MARK0x020000 - [0:0]
- :VPR_MARK0x030000 - [0:0]
- :VPR_PREROUTING - [0:0]
- [3419:868852] -A PREROUTING -m mark --mark 0x0/0xff0000 -j VPR_PREROUTING
- [1:52] -A FORWARD -o br-wan -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i br-wan -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [196:11264] -A FORWARD -o tun+ -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [62:3224] -A FORWARD -i tun+ -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [196:11264] -A FORWARD -o tun0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [62:3224] -A FORWARD -i tun0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A VPR_MARK0x010000 -j MARK --set-xmark 0x10000/0xff0000
- [0:0] -A VPR_MARK0x010000 -j RETURN
- [0:0] -A VPR_MARK0x020000 -j MARK --set-xmark 0x20000/0xff0000
- [0:0] -A VPR_MARK0x020000 -j RETURN
- [787:160104] -A VPR_MARK0x030000 -j MARK --set-xmark 0x30000/0xff0000
- [787:160104] -A VPR_MARK0x030000 -j RETURN
- [787:160104] -A VPR_PREROUTING -s 192.168.1.0/24 ! -d 192.168.1.0/24 -m comment --comment lan_vpn -g VPR_MARK0x030000
- COMMIT
- # Completed on Sun Apr 11 04:42:49 2021
- # Generated by iptables-save v1.8.7 on Sun Apr 11 04:42:49 2021
- *filter
- :INPUT ACCEPT [2:104]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- :forwarding_lan_rule - [0:0]
- :forwarding_rule - [0:0]
- :forwarding_vpn_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- :forwarding_wwan_rule - [0:0]
- :input_lan_rule - [0:0]
- :input_rule - [0:0]
- :input_vpn_rule - [0:0]
- :input_wan_rule - [0:0]
- :input_wwan_rule - [0:0]
- :output_lan_rule - [0:0]
- :output_rule - [0:0]
- :output_vpn_rule - [0:0]
- :output_wan_rule - [0:0]
- :output_wwan_rule - [0:0]
- :reject - [0:0]
- :syn_flood - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_vpn_dest_ACCEPT - [0:0]
- :zone_vpn_dest_REJECT - [0:0]
- :zone_vpn_forward - [0:0]
- :zone_vpn_input - [0:0]
- :zone_vpn_output - [0:0]
- :zone_vpn_src_REJECT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_src_ACCEPT - [0:0]
- :zone_wwan_dest_ACCEPT - [0:0]
- :zone_wwan_dest_REJECT - [0:0]
- :zone_wwan_forward - [0:0]
- :zone_wwan_input - [0:0]
- :zone_wwan_output - [0:0]
- :zone_wwan_src_ACCEPT - [0:0]
- [0:0] -A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
- [1541:408393] -A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
- [1344:376498] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [2:112] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m comment --comment "!fw3" -j syn_flood
- [11:1192] -A INPUT -i br-lan -m comment --comment "!fw3" -j zone_lan_input
- [174:29674] -A INPUT -i br-wan -m comment --comment "!fw3" -j zone_wan_input
- [0:0] -A INPUT -i wlan0 -m comment --comment "!fw3" -j zone_wwan_input
- [12:1029] -A INPUT -i br-wwan -m comment --comment "!fw3" -j zone_wwan_input
- [0:0] -A INPUT -i tun+ -m comment --comment "!fw3" -j zone_vpn_input
- [0:0] -A INPUT -i tun0 -m comment --comment "!fw3" -j zone_vpn_input
- [1849:453315] -A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
- [1636:427610] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [79:17665] -A FORWARD -i br-lan -m comment --comment "!fw3" -j zone_lan_forward
- [0:0] -A FORWARD -i br-wan -m comment --comment "!fw3" -j zone_wan_forward
- [0:0] -A FORWARD -i wlan0 -m comment --comment "!fw3" -j zone_wwan_forward
- [134:8040] -A FORWARD -i br-wwan -m comment --comment "!fw3" -j zone_wwan_forward
- [0:0] -A FORWARD -i tun+ -m comment --comment "!fw3" -j zone_vpn_forward
- [0:0] -A FORWARD -i tun0 -m comment --comment "!fw3" -j zone_vpn_forward
- [135:8092] -A FORWARD -m comment --comment "!fw3" -j reject
- [0:0] -A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
- [1645:314727] -A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
- [1575:309348] -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A OUTPUT -o br-lan -m comment --comment "!fw3" -j zone_lan_output
- [6:390] -A OUTPUT -o br-wan -m comment --comment "!fw3" -j zone_wan_output
- [0:0] -A OUTPUT -o wlan0 -m comment --comment "!fw3" -j zone_wwan_output
- [1:328] -A OUTPUT -o br-wwan -m comment --comment "!fw3" -j zone_wwan_output
- [63:4661] -A OUTPUT -o tun+ -m comment --comment "!fw3" -j zone_vpn_output
- [0:0] -A OUTPUT -o tun0 -m comment --comment "!fw3" -j zone_vpn_output
- [135:8092] -A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
- [0:0] -A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp-port-unreachable
- [2:112] -A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -m comment --comment "!fw3" -j RETURN
- [0:0] -A syn_flood -m comment --comment "!fw3" -j DROP
- [0:0] -A zone_lan_dest_ACCEPT -o br-lan -m comment --comment "!fw3" -j ACCEPT
- [79:17665] -A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
- [79:17665] -A zone_lan_forward -m comment --comment "!fw3: Zone lan to vpn forwarding policy" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [1:52] -A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [11:1192] -A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
- [0:0] -A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [11:1192] -A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
- [0:0] -A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
- [0:0] -A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [11:1192] -A zone_lan_src_ACCEPT -i br-lan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- [3:120] -A zone_vpn_dest_ACCEPT -o tun+ -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [138:22154] -A zone_vpn_dest_ACCEPT -o tun+ -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_vpn_dest_ACCEPT -o tun0 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [0:0] -A zone_vpn_dest_ACCEPT -o tun0 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_vpn_dest_REJECT -o tun+ -m comment --comment "!fw3" -j reject
- [0:0] -A zone_vpn_dest_REJECT -o tun0 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_vpn_forward -m comment --comment "!fw3: Custom vpn forwarding rule chain" -j forwarding_vpn_rule
- [0:0] -A zone_vpn_forward -m comment --comment "!fw3: Zone vpn to wan forwarding policy" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_vpn_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [0:0] -A zone_vpn_forward -m comment --comment "!fw3" -j zone_vpn_dest_REJECT
- [0:0] -A zone_vpn_input -m comment --comment "!fw3: Custom vpn input rule chain" -j input_vpn_rule
- [0:0] -A zone_vpn_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [0:0] -A zone_vpn_input -m comment --comment "!fw3" -j zone_vpn_src_REJECT
- [63:4661] -A zone_vpn_output -m comment --comment "!fw3: Custom vpn output rule chain" -j output_vpn_rule
- [63:4661] -A zone_vpn_output -m comment --comment "!fw3" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_vpn_src_REJECT -i tun+ -m comment --comment "!fw3" -j reject
- [0:0] -A zone_vpn_src_REJECT -i tun0 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_dest_ACCEPT -o br-wan -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [6:390] -A zone_wan_dest_ACCEPT -o br-wan -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_REJECT -o br-wan -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
- [0:0] -A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [0:0] -A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
- [174:29674] -A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
- [0:0] -A zone_wan_input -p udp -m udp --dport 68 -m comment --comment "!fw3: Allow-DHCP-Renew" -j ACCEPT
- [0:0] -A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment "!fw3: Allow-Ping" -j ACCEPT
- [2:64] -A zone_wan_input -p igmp -m comment --comment "!fw3: Allow-IGMP" -j ACCEPT
- [0:0] -A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [172:29610] -A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_ACCEPT
- [6:390] -A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
- [6:390] -A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
- [170:29506] -A zone_wan_src_ACCEPT -i br-wan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wwan_dest_ACCEPT -o wlan0 -m comment --comment "!fw3" -j ACCEPT
- [1:328] -A zone_wwan_dest_ACCEPT -o br-wwan -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wwan_dest_REJECT -o wlan0 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wwan_dest_REJECT -o br-wwan -m comment --comment "!fw3" -j reject
- [134:8040] -A zone_wwan_forward -m comment --comment "!fw3: Custom wwan forwarding rule chain" -j forwarding_wwan_rule
- [134:8040] -A zone_wwan_forward -m comment --comment "!fw3: Zone wwan to wan forwarding policy" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_wwan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [134:8040] -A zone_wwan_forward -m comment --comment "!fw3" -j zone_wwan_dest_REJECT
- [12:1029] -A zone_wwan_input -m comment --comment "!fw3: Custom wwan input rule chain" -j input_wwan_rule
- [0:0] -A zone_wwan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [12:1029] -A zone_wwan_input -m comment --comment "!fw3" -j zone_wwan_src_ACCEPT
- [1:328] -A zone_wwan_output -m comment --comment "!fw3: Custom wwan output rule chain" -j output_wwan_rule
- [1:328] -A zone_wwan_output -m comment --comment "!fw3" -j zone_wwan_dest_ACCEPT
- [0:0] -A zone_wwan_src_ACCEPT -i wlan0 -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- [12:1029] -A zone_wwan_src_ACCEPT -i br-wwan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- COMMIT
- # Completed on Sun Apr 11 04:42:49 2021
- ==> /etc/resolv.conf <==
- # Interface wan
- nameserver 192.168.0.1
- ==> /tmp/resolv.conf <==
- # Interface wan
- nameserver 192.168.0.1
- ==> /tmp/resolv.conf.d <==
- head: /tmp/resolv.conf.d: I/O error
- ==> /tmp/resolv.conf.d/resolv.conf.auto <==
- # Interface wan
- nameserver 192.168.0.1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement