Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.8.7 on Sat May 24 19:20:40 2025
- *mangle
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- :LIBVIRT_PRT - [0:0]
- -A POSTROUTING -j LIBVIRT_PRT
- -A LIBVIRT_PRT -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
- COMMIT
- # Completed on Sat May 24 19:20:40 2025
- # Generated by iptables-save v1.8.7 on Sat May 24 19:20:40 2025
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :LIBVIRT_FWI - [0:0]
- :LIBVIRT_FWO - [0:0]
- :LIBVIRT_FWX - [0:0]
- :LIBVIRT_INP - [0:0]
- :LIBVIRT_OUT - [0:0]
- -A INPUT -j LIBVIRT_INP
- -A FORWARD -j LIBVIRT_FWX
- -A FORWARD -j LIBVIRT_FWI
- -A FORWARD -j LIBVIRT_FWO
- -A OUTPUT -j LIBVIRT_OUT
- -A LIBVIRT_FWI -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
- -A LIBVIRT_FWI -o virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A LIBVIRT_FWO -s 192.168.122.0/24 -i virbr0 -j ACCEPT
- -A LIBVIRT_FWO -i virbr0 -j REJECT --reject-with icmp-port-unreachable
- -A LIBVIRT_FWX -i virbr0 -o virbr0 -j ACCEPT
- -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
- -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
- -A LIBVIRT_OUT -o virbr0 -p udp -m udp --dport 53 -j ACCEPT
- -A LIBVIRT_OUT -o virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
- -A LIBVIRT_OUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT
- -A LIBVIRT_OUT -o virbr0 -p tcp -m tcp --dport 68 -j ACCEPT
- COMMIT
- # Completed on Sat May 24 19:20:40 2025
- # Generated by iptables-save v1.8.7 on Sat May 24 19:20:40 2025
- *nat
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- :LIBVIRT_PRT - [0:0]
- -A POSTROUTING -j LIBVIRT_PRT
- -A LIBVIRT_PRT -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
- -A LIBVIRT_PRT -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
- -A LIBVIRT_PRT -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
- -A LIBVIRT_PRT -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
- -A LIBVIRT_PRT -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
- COMMIT
- # Completed on Sat May 24 19:20:40 2025
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement