Advertisement
Guest User

Untitled

a guest
Sep 20th, 2019
119
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.92 KB | None | 0 0
  1. table ip filter {
  2. chain input {
  3. type filter hook input priority filter; policy drop;
  4. ct state { established, related } accept
  5. ct state invalid drop
  6. iifname "lo" accept
  7. iifname "intern0" accept
  8. ip protocol icmp accept
  9. tcp dport 22 accept
  10. reject
  11. }
  12.  
  13. chain forward {
  14. type filter hook forward priority filter; policy accept;
  15. }
  16.  
  17. chain output {
  18. type filter hook output priority filter; policy accept;
  19. }
  20. }
  21. table ip nat {
  22. chain prerouting {
  23. type nat hook prerouting priority filter; policy accept;
  24. iif "extern0" tcp dport 49153-49155 dnat to 192.168.1.2
  25. iif "extern0" tcp dport 2222 dnat to 192.168.1.2:22
  26. iif "extern0" tcp dport 32400 dnat to 192.168.1.2
  27. iif "extern0" tcp dport 80 dnat to 192.168.1.2
  28. iif "extern0" tcp dport 443 dnat to 192.168.1.2
  29. iif "extern0" tcp dport 8096 dnat to 192.168.1.2
  30. iif "extern0" udp dport 6881-6883 dnat to 192.168.1.2
  31. ip daddr 8.8.8.8 dnat to 192.168.1.1
  32. ip daddr 8.8.4.4 dnat to 192.168.1.1
  33. }
  34.  
  35. chain postrouting {
  36. type nat hook postrouting priority srcnat; policy accept;
  37. masquerade
  38. }
  39. }
  40. table ip6 filter {
  41. chain input {
  42. type filter hook input priority filter; policy drop;
  43. ct state { established, related } accept
  44. ct state invalid drop
  45. iifname "lo" accept
  46. iifname "intern0" accept
  47. }
  48.  
  49. chain forward {
  50. type filter hook forward priority filter; policy drop;
  51. ct state { established, related } accept
  52. ct state invalid drop
  53. iifname "lo" accept
  54. iifname "intern0" accept
  55. }
  56.  
  57. chain output {
  58. type filter hook output priority filter; policy accept;
  59. }
  60. }
  61. table ip mangle {
  62. chain prerouting {
  63. type filter hook prerouting priority raw; policy accept;
  64. ip saddr 192.168.1.2 tcp sport 6881-6883 ip dscp set cs1
  65. ip saddr 192.168.1.2 udp sport 6881-6883 ip dscp set cs1
  66. ip saddr 192.168.1.2 tcp sport 49153-49155 ip dscp set cs1
  67. ip saddr 192.168.1.2 udp sport 49153-49155 ip dscp set cs1
  68. }
  69. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement