new23d

iptables, rhn

Jan 25th, 2013
237
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. # Generated by iptables-save v1.4.7
  2. *filter
  3. :INPUT ACCEPT [0:0]
  4. :FORWARD ACCEPT [0:0]
  5. :OUTPUT ACCEPT [0:0]
  6. -A OUTPUT -m connmark --mark 255 -j LOG
  7. -A OUTPUT -m connmark --mark 255 -j REJECT
  8. COMMIT
  9. # Completed
  10. # Generated by iptables-save v1.4.7
  11. *nat
  12. :PREROUTING ACCEPT [0:0]
  13. :POSTROUTING ACCEPT [0:0]
  14. :OUTPUT ACCEPT [0:0]
  15. :_overflow_ - [0:0]
  16. :_rotator_ - [0:0]
  17. :_snat-102_ - [0:0]
  18. :_snat-242_ - [0:0]
  19. :_snat-252_ - [0:0]
  20. :_snat-check-102_ - [0:0]
  21. :_snat-check-242_ - [0:0]
  22. :_snat-check-252_ - [0:0]
  23. :_snat-determine_ - [0:0]
  24. :_snats_ - [0:0]
  25. -A POSTROUTING -d 192.168.11.101/32 -p tcp -m tcp --dport 80 -j _snats_
  26. -A OUTPUT -d 192.168.11.101/32 -p tcp -m tcp --dport 80 -j _rotator_
  27. -A _overflow_ -j CONNMARK --set-xmark 255
  28. -A _rotator_ -m conntrack --ctstate ESTABLISHED -j ACCEPT
  29. -A _rotator_ -m conntrack --ctstate NEW -j _snat-determine_
  30. -A _rotator_ -j _overflow_
  31. -A _snat-check-102_ -m connlimit --connlimit-above 1 -j RETURN
  32. -A _snat-check-102_ -j CONNMARK --set-xmark 102
  33. -A _snat-check-102_ -j ACCEPT
  34. -A _snat-check-242_ -m connlimit --connlimit-above 1 -j RETURN
  35. -A _snat-check-242_ -j CONNMARK --set-xmark 242
  36. -A _snat-check-242_ -j ACCEPT
  37. -A _snat-check-252_ -m connlimit --connlimit-above 1 -j RETURN
  38. -A _snat-check-252_ -j CONNMARK --set-xmark 252
  39. -A _snat-check-252_ -j ACCEPT
  40. -A _snat-determine_ -j _snat-check-102_
  41. -A _snat-determine_ -j _snat-check-242_
  42. -A _snat-determine_ -j _snat-check-252_
  43. -A _snats_ -m connmark --mark 102 -j SNAT --to-source 192.168.11.102
  44. -A _snats_ -m connmark --mark 242 -j SNAT --to-source 192.168.11.242
  45. -A _snats_ -m connmark --mark 252 -j SNAT --to-source 192.168.11.252
  46. COMMIT
  47. # Completed
RAW Paste Data