Advertisement
Guest User

iptables

a guest
Jan 24th, 2020
424
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.28 KB | None | 0 0
  1. Chain INPUT (policy ACCEPT)
  2. target prot opt source destination
  3. nm_mdmprxy_doze_mode_skip all -- anywhere anywhere
  4. bw_INPUT all -- anywhere anywhere
  5. fw_INPUT all -- anywhere anywhere
  6.  
  7. Chain FORWARD (policy ACCEPT)
  8. target prot opt source destination
  9. nm_mdmprxy_iface_pkt_fwder all -- anywhere anywhere
  10. oem_fwd all -- anywhere anywhere
  11. fw_FORWARD all -- anywhere anywhere
  12. bw_FORWARD all -- anywhere anywhere
  13. tetherctrl_FORWARD all -- anywhere anywhere
  14.  
  15. Chain OUTPUT (policy ACCEPT)
  16. target prot opt source destination
  17. nm_mdmprxy_doze_mode_skip all -- anywhere anywhere
  18. oem_out all -- anywhere anywhere
  19. fw_OUTPUT all -- anywhere anywhere
  20. st_OUTPUT all -- anywhere anywhere
  21. bw_OUTPUT all -- anywhere anywhere
  22.  
  23. Chain bw_FORWARD (1 references)
  24. target prot opt source destination
  25. bw_costly_rmnet_data2 all -- anywhere anywhere
  26. bw_costly_rmnet_data2 all -- anywhere anywhere
  27.  
  28. Chain bw_INPUT (1 references)
  29. target prot opt source destination
  30. bw_global_alert all -- anywhere anywhere
  31. bw_costly_rmnet_data2 all -- anywhere anywhere
  32. RETURN esp -- anywhere anywhere
  33. RETURN all -- anywhere anywhere mark match 0x100000/0x100000
  34. MARK all -- anywhere anywhere MARK or 0x100000
  35.  
  36. Chain bw_OUTPUT (1 references)
  37. target prot opt source destination
  38. bw_global_alert all -- anywhere anywhere
  39. bw_costly_rmnet_data2 all -- anywhere anywhere
  40. RETURN all -- anywhere anywhere
  41. RETURN all -- anywhere anywhere policy match dir out pol ipsec
  42.  
  43. Chain bw_costly_rmnet_data2 (4 references)
  44. target prot opt source destination
  45. bw_penalty_box all -- anywhere anywhere
  46. REJECT all -- anywhere anywhere ! quota rmnet_data2: 9223372036854775807 bytes reject-with icmp-port-unreachable
  47.  
  48. Chain bw_costly_shared (0 references)
  49. target prot opt source destination
  50. bw_penalty_box all -- anywhere anywhere
  51.  
  52. Chain bw_data_saver (1 references)
  53. target prot opt source destination
  54. RETURN all -- anywhere anywhere
  55.  
  56. Chain bw_global_alert (2 references)
  57. target prot opt source destination
  58. all -- anywhere anywhere ! quota globalAlert: 2097152 bytes
  59.  
  60. Chain bw_happy_box (1 references)
  61. target prot opt source destination
  62. RETURN all -- anywhere anywhere match bpf pinned /sys/fs/bpf/prog_netd_skfilter_whitelist_xtbpf
  63. bw_data_saver all -- anywhere anywhere
  64.  
  65. Chain bw_penalty_box (2 references)
  66. target prot opt source destination
  67. REJECT all -- anywhere anywhere match bpf pinned /sys/fs/bpf/prog_netd_skfilter_blacklist_xtbpf reject-with icmp-port-unreachable
  68. bw_happy_box all -- anywhere anywhere
  69.  
  70. Chain fw_FORWARD (1 references)
  71. target prot opt source destination
  72.  
  73. Chain fw_INPUT (1 references)
  74. target prot opt source destination
  75.  
  76. Chain fw_OUTPUT (1 references)
  77. target prot opt source destination
  78. DROP all -- anywhere anywhere owner UID match u0_a318
  79. DROP all -- anywhere anywhere owner UID match u999_a318
  80. DROP all -- anywhere anywhere owner UID match u0_a320
  81. DROP all -- anywhere anywhere owner UID match u999_a320
  82. DROP all -- anywhere anywhere owner UID match u0_a323
  83. DROP all -- anywhere anywhere owner UID match u999_a323
  84. DROP all -- anywhere anywhere owner UID match u0_a324
  85. DROP all -- anywhere anywhere owner UID match u999_a324
  86.  
  87. Chain nm_mdmprxy_doze_mode_skip (2 references)
  88. target prot opt source destination
  89. ACCEPT all -- anywhere anywhere mark match 0x8
  90. ACCEPT all -- anywhere anywhere mark match 0x8
  91. ACCEPT all -- anywhere anywhere mark match 0x8
  92. ACCEPT all -- anywhere anywhere mark match 0x8
  93. ACCEPT all -- anywhere anywhere mark match 0x8
  94. ACCEPT all -- anywhere anywhere mark match 0x8
  95. ACCEPT all -- anywhere anywhere mark match 0x8
  96. ACCEPT all -- anywhere anywhere mark match 0x8
  97. ACCEPT all -- anywhere anywhere mark match 0x8
  98. ACCEPT all -- anywhere anywhere mark match 0x8
  99. ACCEPT all -- anywhere anywhere mark match 0x8
  100. ACCEPT all -- anywhere anywhere mark match 0x8
  101. ACCEPT all -- anywhere anywhere mark match 0x8
  102. ACCEPT all -- anywhere anywhere mark match 0x8
  103.  
  104. Chain nm_mdmprxy_iface_pkt_fwder (1 references)
  105. target prot opt source destination
  106. ACCEPT all -- anywhere anywhere
  107. ACCEPT all -- anywhere anywhere
  108.  
  109. Chain oem_fwd (1 references)
  110. target prot opt source destination
  111.  
  112. Chain oem_out (1 references)
  113. target prot opt source destination
  114.  
  115. Chain st_OUTPUT (1 references)
  116. target prot opt source destination
  117.  
  118. Chain st_clear_caught (2 references)
  119. target prot opt source destination
  120.  
  121. Chain st_clear_detect (0 references)
  122. target prot opt source destination
  123. REJECT all -- anywhere anywhere connmark match 0x2000000/0x2000000 reject-with icmp-port-unreachable
  124. RETURN all -- anywhere anywhere connmark match 0x1000000/0x1000000
  125. CONNMARK tcp -- anywhere anywhere u32 "0x0>>0x16&0x3c@0xc>>0x1a&0x3c@0x0&0xffff0000=0x16030000&&0x0>>0x16&0x3c@0xc>>0x1a&0x3c@0x4&0xff0000=0x10000" CONNMARK or 0x1000000
  126. CONNMARK udp -- anywhere anywhere u32 "0x0>>0x16&0x3c@0x8&0xffff0000=0x16fe0000&&0x0>>0x16&0x3c@0x14&0xff0000=0x10000" CONNMARK or 0x1000000
  127. RETURN all -- anywhere anywhere connmark match 0x1000000/0x1000000
  128. st_clear_caught tcp -- anywhere anywhere state ESTABLISHED u32 "0x0>>0x16&0x3c@0xc>>0x1a&0x3c@0x0&0x0=0x0"
  129. st_clear_caught udp -- anywhere anywhere
  130.  
  131. Chain st_penalty_log (0 references)
  132. target prot opt source destination
  133. CONNMARK all -- anywhere anywhere CONNMARK or 0x1000000
  134. NFLOG all -- anywhere anywhere
  135.  
  136. Chain st_penalty_reject (0 references)
  137. target prot opt source destination
  138. CONNMARK all -- anywhere anywhere CONNMARK or 0x2000000
  139. NFLOG all -- anywhere anywhere
  140. REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
  141.  
  142. Chain tetherctrl_FORWARD (1 references)
  143. target prot opt source destination
  144. DROP all -- anywhere anywhere
  145.  
  146. Chain tetherctrl_counters (0 references)
  147. target prot opt source destination
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement