Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Generated by iptables-save v1.8.3 on Fri Mar 5 10:54:34 2021
- *nat
- :PREROUTING ACCEPT [427260:55859722]
- :INPUT ACCEPT [5701:564729]
- :OUTPUT ACCEPT [5645:415955]
- :POSTROUTING ACCEPT [6781:356640]
- :postrouting_VPN_FW_rule - [0:0]
- :postrouting_WGZONE_rule - [0:0]
- :postrouting_lan_rule - [0:0]
- :postrouting_rule - [0:0]
- :postrouting_wan_rule - [0:0]
- :prerouting_VPN_FW_rule - [0:0]
- :prerouting_WGZONE_rule - [0:0]
- :prerouting_lan_rule - [0:0]
- :prerouting_rule - [0:0]
- :prerouting_wan_rule - [0:0]
- :zone_VPN_FW_postrouting - [0:0]
- :zone_VPN_FW_prerouting - [0:0]
- :zone_WGZONE_postrouting - [0:0]
- :zone_WGZONE_prerouting - [0:0]
- :zone_lan_postrouting - [0:0]
- :zone_lan_prerouting - [0:0]
- :zone_wan_postrouting - [0:0]
- :zone_wan_prerouting - [0:0]
- -A PREROUTING -m comment --comment "!fw3: Custom prerouting rule chain" -j prerouting_rule
- -A PREROUTING -i br-lan -m comment --comment "!fw3" -j zone_lan_prerouting
- -A PREROUTING -i eth2 -m comment --comment "!fw3" -j zone_wan_prerouting
- -A PREROUTING -i WGINTERFACE -m comment --comment "!fw3" -j zone_WGZONE_prerouting
- -A POSTROUTING -m comment --comment "!fw3: Custom postrouting rule chain" -j postrouting_rule
- -A POSTROUTING -o br-lan -m comment --comment "!fw3" -j zone_lan_postrouting
- -A POSTROUTING -o eth2 -m comment --comment "!fw3" -j zone_wan_postrouting
- -A POSTROUTING -o WGINTERFACE -m comment --comment "!fw3" -j zone_WGZONE_postrouting
- -A zone_VPN_FW_postrouting -m comment --comment "!fw3: Custom VPN_FW postrouting rule chain" -j postrouting_VPN_FW_rule
- -A zone_VPN_FW_postrouting -m comment --comment "!fw3" -j MASQUERADE
- -A zone_VPN_FW_prerouting -m comment --comment "!fw3: Custom VPN_FW prerouting rule chain" -j prerouting_VPN_FW_rule
- -A zone_WGZONE_postrouting -m comment --comment "!fw3: Custom WGZONE postrouting rule chain" -j postrouting_WGZONE_rule
- -A zone_WGZONE_postrouting -m comment --comment "!fw3" -j MASQUERADE
- -A zone_WGZONE_prerouting -m comment --comment "!fw3: Custom WGZONE prerouting rule chain" -j prerouting_WGZONE_rule
- -A zone_lan_postrouting -m comment --comment "!fw3: Custom lan postrouting rule chain" -j postrouting_lan_rule
- -A zone_lan_postrouting -s 192.168.x.x/24 -d 192.168.x.xxx/32 -p tcp -m tcp --dport 80 -m comment --comment "!fw3: gateway80 (reflection)" -j SNAT --to-source 192.168.x.x
- -A zone_lan_prerouting -m comment --comment "!fw3: Custom lan prerouting rule chain" -j prerouting_lan_rule
- -A zone_lan_prerouting -s 192.168.x.x/24 -d 135.xx.xxx.xxx/32 -p tcp -m tcp --dport 80 -m comment --comment "!fw3: gateway80 (reflection)" -j DNAT --to-destination 192.168.x.x:80
- -A zone_wan_postrouting -m comment --comment "!fw3: Custom wan postrouting rule chain" -j postrouting_wan_rule
- -A zone_wan_postrouting -m comment --comment "!fw3" -j MASQUERADE
- -A zone_wan_prerouting -m comment --comment "!fw3: Custom wan prerouting rule chain" -j prerouting_wan_rule
- -A zone_wan_prerouting -p tcp -m tcp --dport 80 -m comment --comment "!fw3: gateway80" -j DNAT --to-destination 192.168.x.x:80
- COMMIT
- # Completed on Fri Mar 5 10:54:34 2021
- # Generated by iptables-save v1.8.3 on Fri Mar 5 10:54:34 2021
- *mangle
- :PREROUTING ACCEPT [389184048:503094061578]
- :INPUT ACCEPT [174867785:246058333212]
- :FORWARD ACCEPT [214197634:257011675229]
- :OUTPUT ACCEPT [71797096:16990771154]
- :POSTROUTING ACCEPT [285991920:274002071853]
- :VPR_MARK0x010000 - [0:0]
- :VPR_MARK0x020000 - [0:0]
- :VPR_PREROUTING - [0:0]
- -A PREROUTING -m mark --mark 0x0/0xff0000 -j VPR_PREROUTING
- -A FORWARD -o eth2 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- -A FORWARD -o WGINTERFACE -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone WGZONE MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- -A VPR_MARK0x010000 -j MARK --set-xmark 0x10000/0xff0000
- -A VPR_MARK0x010000 -j RETURN
- -A VPR_MARK0x020000 -j MARK --set-xmark 0x20000/0xff0000
- -A VPR_MARK0x020000 -j RETURN
- -A VPR_PREROUTING -s 192.168.x.x/32 ! -d 192.168.x.x/24 -p tcp -m multiport --sports 80,443 -m comment --comment gateway -g VPR_MARK0x010000
- -A VPR_PREROUTING -s 192.168.x.x/32 ! -d 192.168.x.x/24 -p udp -m multiport --sports 80,443 -m comment --comment gateway -g VPR_MARK0x010000
- -A VPR_PREROUTING -s 192.168.x.x/32 -m comment --comment teksavvytv -g VPR_MARK0x010000
- -A VPR_PREROUTING -s 192.168.x.x/32 -m comment --comment sonytv -g VPR_MARK0x010000
- COMMIT
- # Completed on Fri Mar 5 10:54:34 2021
- # Generated by iptables-save v1.8.3 on Fri Mar 5 10:54:34 2021
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT ACCEPT [0:0]
- :forwarding_VPN_FW_rule - [0:0]
- :forwarding_WGZONE_rule - [0:0]
- :forwarding_lan_rule - [0:0]
- :forwarding_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- :input_VPN_FW_rule - [0:0]
- :input_WGZONE_rule - [0:0]
- :input_lan_rule - [0:0]
- :input_rule - [0:0]
- :input_wan_rule - [0:0]
- :output_VPN_FW_rule - [0:0]
- :output_WGZONE_rule - [0:0]
- :output_lan_rule - [0:0]
- :output_rule - [0:0]
- :output_wan_rule - [0:0]
- :reject - [0:0]
- :syn_flood - [0:0]
- :zone_VPN_FW_dest_ACCEPT - [0:0]
- :zone_VPN_FW_dest_REJECT - [0:0]
- :zone_VPN_FW_forward - [0:0]
- :zone_VPN_FW_input - [0:0]
- :zone_VPN_FW_output - [0:0]
- :zone_VPN_FW_src_REJECT - [0:0]
- :zone_WGZONE_dest_ACCEPT - [0:0]
- :zone_WGZONE_dest_REJECT - [0:0]
- :zone_WGZONE_forward - [0:0]
- :zone_WGZONE_input - [0:0]
- :zone_WGZONE_output - [0:0]
- :zone_WGZONE_src_REJECT - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_src_REJECT - [0:0]
- -A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
- -A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
- -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m comment --comment "!fw3" -j syn_flood
- -A INPUT -i br-lan -m comment --comment "!fw3" -j zone_lan_input
- -A INPUT -i eth2 -m comment --comment "!fw3" -j zone_wan_input
- -A INPUT -i WGINTERFACE -m comment --comment "!fw3" -j zone_WGZONE_input
- -A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
- -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- -A FORWARD -i br-lan -m comment --comment "!fw3" -j zone_lan_forward
- -A FORWARD -i eth2 -m comment --comment "!fw3" -j zone_wan_forward
- -A FORWARD -i WGINTERFACE -m comment --comment "!fw3" -j zone_WGZONE_forward
- -A FORWARD -m comment --comment "!fw3" -j reject
- -A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
- -A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
- -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- -A OUTPUT -o br-lan -m comment --comment "!fw3" -j zone_lan_output
- -A OUTPUT -o eth2 -m comment --comment "!fw3" -j zone_wan_output
- -A OUTPUT -o WGINTERFACE -m comment --comment "!fw3" -j zone_WGZONE_output
- -A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
- -A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp-port-unreachable
- -A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -m comment --comment "!fw3" -j RETURN
- -A syn_flood -m comment --comment "!fw3" -j DROP
- -A zone_VPN_FW_forward -m comment --comment "!fw3: Custom VPN_FW forwarding rule chain" -j forwarding_VPN_FW_rule
- -A zone_VPN_FW_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- -A zone_VPN_FW_forward -m comment --comment "!fw3" -j zone_VPN_FW_dest_REJECT
- -A zone_VPN_FW_input -m comment --comment "!fw3: Custom VPN_FW input rule chain" -j input_VPN_FW_rule
- -A zone_VPN_FW_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- -A zone_VPN_FW_input -m comment --comment "!fw3" -j zone_VPN_FW_src_REJECT
- -A zone_VPN_FW_output -m comment --comment "!fw3: Custom VPN_FW output rule chain" -j output_VPN_FW_rule
- -A zone_VPN_FW_output -m comment --comment "!fw3" -j zone_VPN_FW_dest_ACCEPT
- -A zone_WGZONE_dest_ACCEPT -o WGINTERFACE -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- -A zone_WGZONE_dest_ACCEPT -o WGINTERFACE -m comment --comment "!fw3" -j ACCEPT
- -A zone_WGZONE_dest_REJECT -o WGINTERFACE -m comment --comment "!fw3" -j reject
- -A zone_WGZONE_forward -m comment --comment "!fw3: Custom WGZONE forwarding rule chain" -j forwarding_WGZONE_rule
- -A zone_WGZONE_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- -A zone_WGZONE_forward -m comment --comment "!fw3" -j zone_WGZONE_dest_REJECT
- -A zone_WGZONE_input -m comment --comment "!fw3: Custom WGZONE input rule chain" -j input_WGZONE_rule
- -A zone_WGZONE_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- -A zone_WGZONE_input -m comment --comment "!fw3" -j zone_WGZONE_src_REJECT
- -A zone_WGZONE_output -m comment --comment "!fw3: Custom WGZONE output rule chain" -j output_WGZONE_rule
- -A zone_WGZONE_output -m comment --comment "!fw3" -j zone_WGZONE_dest_ACCEPT
- -A zone_WGZONE_src_REJECT -i WGINTERFACE -m comment --comment "!fw3" -j reject
- -A zone_lan_dest_ACCEPT -o br-lan -m comment --comment "!fw3" -j ACCEPT
- -A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
- -A zone_lan_forward -m comment --comment "!fw3: Zone lan to WGZONE forwarding policy" -j zone_WGZONE_dest_ACCEPT
- -A zone_lan_forward -m comment --comment "!fw3: Zone lan to wan forwarding policy" -j zone_wan_dest_ACCEPT
- -A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- -A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- -A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
- -A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- -A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
- -A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
- -A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- -A zone_lan_src_ACCEPT -i br-lan -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- -A zone_wan_dest_ACCEPT -o eth2 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- -A zone_wan_dest_ACCEPT -o eth2 -m comment --comment "!fw3" -j ACCEPT
- -A zone_wan_dest_REJECT -o eth2 -m comment --comment "!fw3" -j reject
- -A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
- -A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
- -A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
- -A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- -A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
- -A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
- -A zone_wan_input -p udp -m udp --dport 68 -m comment --comment "!fw3: Allow-DHCP-Renew" -j ACCEPT
- -A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment "!fw3: Allow-Ping" -j ACCEPT
- -A zone_wan_input -p igmp -m comment --comment "!fw3: Allow-IGMP" -j ACCEPT
- -A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- -A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_REJECT
- -A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
- -A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
- -A zone_wan_src_REJECT -i eth2 -m comment --comment "!fw3" -j reject
- COMMIT
- # Completed on Fri Mar 5 10:54:34 2021
Add Comment
Please, Sign In to add comment