Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- BusyBox v1.31.1 () built-in shell (ash)
- ___ __ __ ___ _____ ___ ___ _
- / _ \ _ __ ___ _ _ | \/ | _ \_ _/ __| _ \_ _ ___ _ _| |_ ___ _ _
- | (_) | '_ \/ -_) ' \| |\/| | _/ | || (__| _/ '_/ _ \ || | _/ -_) '_|
- \___/| .__/\___|_||_|_| |_|_| |_| \___|_| |_| \___/\_,_|\__\___|_|
- |_|
- ------------------------------------------------------------------------------
- (r0+14653-a439f1bb47)
- ------------------------------------------------------------------------------
- -----------------------------------------------------
- PACKAGE: openmptcprouter
- VERSION: v0.56.4
- BUILD REPO: https://github.com/ysurac/openmptcprouter
- BUILD DATE: Thu Nov 5 21:12:40 UTC 2020
- -----------------------------------------------------
- root@OpenMPTCProuter:~# ubus call system board; \
- > uci export network; uci export wireless; \
- > uci export dhcp; uci export firewall; \
- > head -n -0 /etc/firewall.user; \
- > iptables-save -c; \
- > ip -4 addr ; ip -4 ro li tab all ; ip -4 ru
- {
- "kernel": "5.4.69",
- "hostname": "OpenMPTCProuter",
- "system": "ARMv7 Processor rev 3 (v7l)",
- "model": "Raspberry Pi 4 Model B Rev 1.2",
- "board_name": "raspberrypi,4-model-b",
- "release": {
- "distribution": "openmptcprouter",
- "version": "v0.56.4",
- "revision": "r0+14653-a439f1bb47",
- "target": "bcm27xx/bcm2709",
- "description": "openmptcprouter v0.56.4 r0+14653-a439f1bb47"
- }
- }
- package network
- config interface 'loopback'
- option ifname 'lo'
- option proto 'static'
- option ipaddr '127.0.0.1'
- option netmask '255.0.0.0'
- option multipath 'off'
- option macaddr '00:00:00:00:00:00'
- option metric '7'
- config globals 'globals'
- option ula_prefix 'fd87:d1cd:a5a9::/48'
- option multipath 'enable'
- option mptcp_path_manager 'fullmesh'
- option mptcp_scheduler 'blest'
- option congestion 'cubic'
- option mptcp_checksum '0'
- option mptcp_debug '0'
- option mptcp_syn_retries '2'
- option mptcp_fullmesh_num_subflows '1'
- option mptcp_fullmesh_create_on_err '1'
- option mptcp_ndiffports_num_subflows '1'
- config interface 'lan'
- option ifname 'eth0'
- option proto 'static'
- option ipaddr '192.168.100.1'
- option netmask '255.255.255.0'
- option ip6assign '60'
- option delegate '0'
- option multipath 'off'
- option ip4table 'lan'
- option macaddr '*****************'
- option modalias 'of:NethernetT(null)Cbrcm,bcm2711-genet-v5Cbrcm,genet-v5'
- option metric '8'
- option label 'lan'
- option defaultroute '0'
- option peerdns '0'
- config rule 'lan_rule'
- option lookup 'lan'
- option priority '100'
- config interface 'omrvpn'
- option ifname 'tun0'
- option ip4table 'vpn'
- option multipath 'off'
- option leasetime '12h'
- option type 'tunnel'
- option txqueuelen '100'
- option ipv6 '0'
- option metric '11'
- option proto 'none'
- config interface 'omr6in4'
- option proto '6in4'
- option ip4table 'vpn'
- option multipath 'off'
- option gateway 'fe80::a00:1'
- option ip6addr 'fe80::a00:2/128'
- option auto '0'
- option metric '12'
- option ipaddr '10.255.255.2'
- option peeraddr '10.255.255.1'
- config interface 'VZW'
- option ifname 'usb0'
- option addlatency '0'
- option macaddr '*************'
- option metric '16'
- option label 'verizon'
- option defaultroute '0'
- option peerdns '0'
- option ipv6 '0'
- option proto 'dhcp'
- option multipath 'on'
- option modalias 'usb:v04E8p6864d0C00dc00dsc00dp00icE0isc01ip03in00'
- option product '4e8/6864/c00'
- config interface 'TMB'
- option addlatency '0'
- option macaddr '**************'
- option metric '18'
- option label 'tmobile'
- option defaultroute '0'
- option peerdns '0'
- option ipv6 '0'
- option proto 'dhcp'
- option multipath 'on'
- option ifname 'usb1'
- option modalias 'usb:v04E8p6863d0C00dc00dsc00dp00icE0isc01ip03in00'
- option product '4e8/6863/c00'
- config route
- option interface 'lan'
- option netmask '255.255.255.0'
- option gateway '192.168.100.2'
- option target '192.168.1.0/24'
- package wireless
- config wifi-device 'radio0'
- option type 'mac80211'
- option channel '36'
- option hwmode '11a'
- option path 'platform/soc/fe300000.mmcnr/mmc_host/mmc1/mmc1:0001/mmc1:0001:1'
- option htmode 'VHT80'
- option country '00'
- config wifi-iface 'default_radio0'
- option device 'radio0'
- option mode 'ap'
- option ssid 'OpenWrt'
- option encryption 'none'
- option skip_inactivity_poll '1'
- option network 'wifi'
- option disabled '1'
- package dhcp
- config dnsmasq
- option domainneeded '1'
- option boguspriv '1'
- option filterwin2k '0'
- option localise_queries '1'
- option rebind_protection '1'
- option rebind_localhost '1'
- option local '/lan/'
- option domain 'lan'
- option expandhosts '1'
- option authoritative '1'
- option readethers '1'
- option leasefile '/tmp/dhcp.leases'
- option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
- option nonwildcard '1'
- option localservice '1'
- list server '127.0.0.1#5353'
- list server '/lan/'
- list server '/use-application-dns.net/'
- option noresolv '1'
- option nonegcache '1'
- list rebind_domain 'plex.direct'
- list ipset '/googlevideo.com/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/nflxvideo.net/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/s3.ll.dash.row.aiv-cdn.net/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/d25xi40x97liuc.cloudfront.net/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/aiv-delivery.net/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/vevo.com/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/audio-fa.scdn.com/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/deezer.com/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/sndcdn.com/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/last.fm/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/v.redd.it/omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/ttvnw.net/omr_dscp-cs4,omr_dscp6-cs4,omr_dscp-cs4,omr_dscp6-cs4'
- list ipset '/googletagmanager.com/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/googleusercontent.com/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/google.com/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/fbcdn.net/omr_dscp-cs4,omr_dscp6-cs4,omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/akamaihd.net/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/whatsapp.net/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/whatsapp.com/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/googleapis.com/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/1e100.net/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/hwcdn.net/omr_dscp-cs2,omr_dscp6-cs2'
- list ipset '/download.qq.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/steamcontent.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/gs2.ww.prod.dl.playstation.net/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/dropbox.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/dropboxstatic.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/dropbox-dns.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/log.getdropbox.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/drive.google.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/drive-thirdparty.googleusercontent.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/docs.google.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/docs.googleusercontent.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/gvt1.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/mmg-fna.whatsapp.net/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/upload.youtube.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/upload.video.google.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/windowsupdate.com/omr_dscp-cs1,omr_dscp6-cs1'
- list ipset '/update.microsoft.com/omr_dscp-cs1,omr_dscp6-cs1'
- config dhcp 'lan'
- option interface 'lan'
- option start '100'
- option limit '150'
- option leasetime '12h'
- option ra_slaac '1'
- option force '1'
- list ra_flags 'managed-config'
- list ra_flags 'other-config'
- config dhcp 'wan'
- option interface 'wan'
- option ignore '1'
- config odhcpd 'odhcpd'
- option maindhcp '0'
- option leasefile '/tmp/hosts/odhcpd'
- option leasetrigger '/usr/sbin/odhcpd-update'
- option loglevel '4'
- package firewall
- config defaults
- option syn_flood '1'
- option input 'REJECT'
- option output 'REJECT'
- option forward 'REJECT'
- option disable_ipv6 '1'
- config zone
- option name 'lan'
- option input 'ACCEPT'
- option output 'ACCEPT'
- option forward 'ACCEPT'
- option auto_helper '0'
- option mtu_fix '1'
- option network 'lan'
- config zone
- option name 'wan'
- option input 'REJECT'
- option output 'ACCEPT'
- option forward 'REJECT'
- option masq '1'
- option mtu_fix '1'
- option network 'wan wan6 wan2 VZW TMB'
- config forwarding
- option src 'lan'
- option dest 'wan'
- config rule
- option name 'Allow-DHCP-Renew'
- option src 'wan'
- option proto 'udp'
- option dest_port '68'
- option target 'ACCEPT'
- option family 'ipv4'
- config rule
- option name 'Allow-Ping'
- option src 'wan'
- option proto 'icmp'
- option icmp_type 'echo-request'
- option family 'ipv4'
- option target 'ACCEPT'
- config rule
- option name 'Allow-IGMP'
- option src 'wan'
- option proto 'igmp'
- option family 'ipv4'
- option target 'ACCEPT'
- config rule
- option name 'Allow-DHCPv6'
- option src 'wan'
- option proto 'udp'
- option src_ip 'fc00::/6'
- option dest_ip 'fc00::/6'
- option dest_port '546'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-MLD'
- option src 'wan'
- option proto 'icmp'
- option src_ip 'fe80::/10'
- list icmp_type '130/0'
- list icmp_type '131/0'
- list icmp_type '132/0'
- list icmp_type '143/0'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-ICMPv6-Forward'
- option src 'wan'
- option dest '*'
- option proto 'icmp'
- list icmp_type 'echo-request'
- list icmp_type 'echo-reply'
- list icmp_type 'destination-unreachable'
- list icmp_type 'packet-too-big'
- list icmp_type 'time-exceeded'
- list icmp_type 'bad-header'
- list icmp_type 'unknown-header-type'
- option limit '1000/sec'
- option family 'ipv6'
- option target 'ACCEPT'
- config rule
- option name 'Allow-IPSec-ESP'
- option src 'wan'
- option dest 'lan'
- option proto 'esp'
- option target 'ACCEPT'
- config rule
- option name 'Allow-ISAKMP'
- option src 'wan'
- option dest 'lan'
- option dest_port '500'
- option proto 'udp'
- option target 'ACCEPT'
- config rule
- option name 'Support-UDP-Traceroute'
- option src 'wan'
- option dest_port '33434:33689'
- option proto 'udp'
- option family 'ipv4'
- option target 'REJECT'
- option enabled 'false'
- config include
- option path '/etc/firewall.user'
- config rule
- option enabled '1'
- option target 'ACCEPT'
- option name 'Allow-All-LAN-to-VPN'
- option dest 'vpn'
- option src 'lan'
- config zone 'zone_vpn'
- option name 'vpn'
- option masq '1'
- option input 'REJECT'
- option forward 'ACCEPT'
- option output 'ACCEPT'
- option mtu_fix '1'
- option network 'glorytun omrvpn omr6in4'
- config rule
- option enabled '1'
- option target 'ACCEPT'
- option name 'Allow-All-Ping'
- option proto 'icmp'
- option dest '*'
- option src '*'
- option icmp_type 'echo-request'
- config rule
- option enabled '1'
- option target 'ACCEPT'
- option name 'Allow-VPN-ICMP'
- option proto 'icmp'
- option src 'vpn'
- config rule
- option enabled '1'
- option target 'ACCEPT'
- option name 'Allow-Lan-to-Wan'
- option dest 'wan'
- option src 'lan'
- config rule
- option enabled '1'
- option target 'ACCEPT'
- option name 'ICMPv6-Lan-to-OMR'
- option src 'lan'
- option family 'ipv6'
- option proto 'icmp'
- option limit '1000/sec'
- option icmp_type 'echo-reply destination-unreachable echo-request router-advertisement router-solicitation time-exceeded'
- config include 'omr_server'
- option path '/etc/firewall.omr-server'
- option reload '1'
- config include 'gre_tunnel'
- option path '/etc/firewall.gre-tunnel'
- option reload '1'
- config forwarding 'fwlantovpn'
- option src 'lan'
- option dest 'vpn'
- config rule 'blockquicproxy'
- option name 'Block QUIC Proxy'
- option proto 'udp'
- option dest_port '443'
- option target 'DROP'
- option src 'lan'
- config rule 'blockquicall'
- option name 'Block QUIC All'
- option proto 'udp'
- option src '*'
- option dest '*'
- option dest_port '443'
- option target 'DROP'
- config rule 'allow_dhcp_request_vpn'
- option name 'Allow-DHCP-Request-VPN'
- option src 'vpn'
- option proto 'udp'
- option dest_port '67'
- option target 'ACCEPT'
- option family 'ipv4'
- config include 'v2ray'
- option path '/etc/firewall.v2ray-rules'
- option reload '1'
- config include 'omr_bypass'
- option path '/etc/firewall.omr-bypass'
- option reload '1'
- config include 'miniupnpd'
- option type 'script'
- option path '/usr/share/miniupnpd/firewall.include'
- option family 'any'
- option reload '1'
- config include 'ss_rules'
- option path '/etc/firewall.ss-rules'
- option reload '1'
- # This file is interpreted as shell script.
- # Put your custom iptables rules here, they will
- # be executed with each firewall (re-)start.
- # Internal uci firewall chains are flushed and recreated on reload, so
- # put custom rules into the root chains e.g. INPUT or FORWARD or into the
- # special user chains, e.g. input_wan_rule or postrouting_lan_rule.
- # Generated by iptables-save v1.8.4 on Wed Nov 11 15:56:13 2020
- *raw
- :PREROUTING ACCEPT [19483:11530442]
- :OUTPUT ACCEPT [20208:10770120]
- COMMIT
- # Completed on Wed Nov 11 15:56:13 2020
- # Generated by iptables-save v1.8.4 on Wed Nov 11 15:56:13 2020
- *nat
- :PREROUTING ACCEPT [173:138219]
- :INPUT ACCEPT [98:5946]
- :OUTPUT ACCEPT [588:48978]
- :POSTROUTING ACCEPT [71:4566]
- :MINIUPNPD - [0:0]
- :MINIUPNPD-POSTROUTING - [0:0]
- :postrouting_lan_rule - [0:0]
- :postrouting_rule - [0:0]
- :postrouting_vpn_rule - [0:0]
- :postrouting_wan_rule - [0:0]
- :prerouting_lan_rule - [0:0]
- :prerouting_rule - [0:0]
- :prerouting_vpn_rule - [0:0]
- :prerouting_wan_rule - [0:0]
- :ssr_def_dst - [0:0]
- :ssr_def_forward - [0:0]
- :ssr_def_local_out - [0:0]
- :ssr_def_pre_src - [0:0]
- :ssr_def_src - [0:0]
- :zone_lan_postrouting - [0:0]
- :zone_lan_prerouting - [0:0]
- :zone_vpn_postrouting - [0:0]
- :zone_vpn_prerouting - [0:0]
- :zone_wan_postrouting - [0:0]
- :zone_wan_prerouting - [0:0]
- [53:2756] -A PREROUTING -p tcp -j ssr_def_pre_src
- [58:3281] -A PREROUTING -p tcp -j ssr_def_pre_src
- [242:187839] -A PREROUTING -m comment --comment "!fw3: Custom prerouting rule chain" -j prerouting_rule
- [233:187083] -A PREROUTING -i eth0 -m comment --comment "!fw3" -j zone_lan_prerouting
- [0:0] -A PREROUTING -i usb0 -m comment --comment "!fw3" -j zone_wan_prerouting
- [0:0] -A PREROUTING -i usb1 -m comment --comment "!fw3" -j zone_wan_prerouting
- [9:756] -A PREROUTING -i tun0 -m comment --comment "!fw3" -j zone_vpn_prerouting
- [231:16200] -A OUTPUT -p tcp -j ssr_def_local_out
- [449:41452] -A OUTPUT -p tcp -j ssr_def_local_out
- [865:71947] -A POSTROUTING -m comment --comment "!fw3: Custom postrouting rule chain" -j postrouting_rule
- [0:0] -A POSTROUTING -o eth0 -m comment --comment "!fw3" -j zone_lan_postrouting
- [150:16235] -A POSTROUTING -o usb0 -m comment --comment "!fw3" -j zone_wan_postrouting
- [198:16404] -A POSTROUTING -o usb1 -m comment --comment "!fw3" -j zone_wan_postrouting
- [399:31637] -A POSTROUTING -o tun0 -m comment --comment "!fw3" -j zone_vpn_postrouting
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_usb1 dst -j MARK --set-xmark 0x53918/0xffffffff
- [0:0] -A ssr_def_dst -m mark --mark 0x53918 -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_usb0 dst -j MARK --set-xmark 0x53916/0xffffffff
- [0:0] -A ssr_def_dst -m mark --mark 0x53916 -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_tun0 dst -j MARK --set-xmark 0x53911/0xffffffff
- [0:0] -A ssr_def_dst -m mark --mark 0x53911 -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_eth0 dst -j MARK --set-xmark 0x5398/0xffffffff
- [0:0] -A ssr_def_dst -m mark --mark 0x5398 -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_lo dst -j MARK --set-xmark 0x5397/0xffffffff
- [0:0] -A ssr_def_dst -m mark --mark 0x5397 -j RETURN
- [0:0] -A ssr_def_dst -m mark --mark 0x539 -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set omr_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [0:0] -A ssr_def_dst -m set --match-set ss_rules_dst_bypass_all dst -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set ss_rules_dst_bypass dst -j RETURN
- [0:0] -A ssr_def_dst -m set --match-set ss_rules_dst_forward dst -j ssr_def_forward
- [0:0] -A ssr_def_dst -m comment --comment "dst_default: forward" -j ssr_def_forward
- [57:2996] -A ssr_def_forward -p tcp -j REDIRECT --to-ports 1100-1101
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_usb1 dst -j MARK --set-xmark 0x53918/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x53918 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_usb0 dst -j MARK --set-xmark 0x53916/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x53916 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_tun0 dst -j MARK --set-xmark 0x53911/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x53911 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_eth0 dst -j MARK --set-xmark 0x5398/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x5398 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_lo dst -j MARK --set-xmark 0x5397/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x5397 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set omr_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [0:0] -A ssr_def_local_out -m mark --mark 0x539 -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set ss_rules_dst_bypass dst -j RETURN
- [0:0] -A ssr_def_local_out -m set --match-set ss_rules_dst_bypass_all dst -j RETURN
- [454:31920] -A ssr_def_local_out -m set --match-set ss_rules_dst_bypass_ dst -j RETURN
- [0:0] -A ssr_def_local_out -m mark --mark 0x539 -j RETURN
- [4:240] -A ssr_def_local_out -p tcp -m comment --comment "local_default: forward" -j ssr_def_forward
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_usb1 dst -j MARK --set-xmark 0x53918/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x53918 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_usb0 dst -j MARK --set-xmark 0x53916/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x53916 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_tun0 dst -j MARK --set-xmark 0x53911/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x53911 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_eth0 dst -j MARK --set-xmark 0x5398/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x5398 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_lo dst -j MARK --set-xmark 0x5397/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x5397 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set omr_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [0:0] -A ssr_def_pre_src -m mark --mark 0x539 -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set ss_rules_dst_bypass_ dst -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set ss_rules_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [0:0] -A ssr_def_pre_src -m set --match-set ss_rules_dst_bypass_all dst -j RETURN
- [0:0] -A ssr_def_pre_src -m set --match-set ss_rules_dst_bypass dst -j RETURN
- [0:0] -A ssr_def_pre_src -m mark --mark 0x539 -j RETURN
- [53:2756] -A ssr_def_pre_src -p tcp -j ssr_def_src
- [0:0] -A ssr_def_src -m set --match-set ss_rules_src_bypass src -j RETURN
- [0:0] -A ssr_def_src -m set --match-set ss_rules_src_forward src -j ssr_def_forward
- [0:0] -A ssr_def_src -m set --match-set ss_rules_src_checkdst src -j ssr_def_dst
- [53:2756] -A ssr_def_src -m comment --comment "src_default: forward" -j ssr_def_forward
- [0:0] -A zone_lan_postrouting -m comment --comment "!fw3: Custom lan postrouting rule chain" -j postrouting_lan_rule
- [233:187083] -A zone_lan_prerouting -m comment --comment "!fw3: Custom lan prerouting rule chain" -j prerouting_lan_rule
- [399:31637] -A zone_vpn_postrouting -m comment --comment "!fw3: Custom vpn postrouting rule chain" -j postrouting_vpn_rule
- [399:31637] -A zone_vpn_postrouting -m comment --comment "!fw3" -j MASQUERADE
- [9:756] -A zone_vpn_prerouting -m comment --comment "!fw3: Custom vpn prerouting rule chain" -j prerouting_vpn_rule
- [348:32639] -A zone_wan_postrouting -m comment --comment "!fw3: Custom wan postrouting rule chain" -j postrouting_wan_rule
- [348:32639] -A zone_wan_postrouting -m comment --comment "!fw3" -j MASQUERADE
- [0:0] -A zone_wan_prerouting -m comment --comment "!fw3: Custom wan prerouting rule chain" -j prerouting_wan_rule
- COMMIT
- # Completed on Wed Nov 11 15:56:13 2020
- # Generated by iptables-save v1.8.4 on Wed Nov 11 15:56:13 2020
- *mangle
- :PREROUTING ACCEPT [14971:9971419]
- :INPUT ACCEPT [14822:9849836]
- :FORWARD ACCEPT [149:121583]
- :OUTPUT ACCEPT [15698:9770510]
- :POSTROUTING ACCEPT [15705:9771362]
- :QOS_MARK_usb0 - [0:0]
- :QOS_MARK_usb1 - [0:0]
- :dscp_mark - [0:0]
- :dscp_output - [0:0]
- :dscp_postrouting - [0:0]
- :dscp_prerouting - [0:0]
- :omr-bypass - [0:0]
- :omr-bypass-dpi - [0:0]
- :omr-bypass-local - [0:0]
- :omr-gre-tunnel - [0:0]
- [3267:634163] -A PREROUTING -m addrtype ! --dst-type LOCAL -j omr-bypass
- [0:0] -A PREROUTING -i vtun+ -p tcp -j MARK --set-xmark 0x2/0xff
- [5398:2638627] -A PREROUTING -i usb0 -m dscp ! --dscp 0x00 -j DSCP --set-dscp 0x00
- [7271:7442119] -A PREROUTING -i usb1 -m dscp ! --dscp 0x00 -j DSCP --set-dscp 0x00
- [4435:942358] -A PREROUTING -i eth0 -j dscp_prerouting
- [3996:901636] -A PREROUTING -m addrtype ! --dst-type LOCAL -j omr-gre-tunnel
- [0:0] -A PREROUTING -m set --match-set ss_rules_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [4435:942358] -A PREROUTING -i eth0 -j dscp_mark
- [3160:593349] -A PREROUTING -m addrtype ! --dst-type LOCAL -j omr-bypass-dpi
- [0:0] -A FORWARD -o eth0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone lan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i eth0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone lan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -o usb0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i usb0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -o usb1 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i usb1 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone wan MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -o tun0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [0:0] -A FORWARD -i tun0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m comment --comment "!fw3: Zone vpn MTU fixing" -j TCPMSS --clamp-mss-to-pmtu
- [15489:9818506] -A OUTPUT -m addrtype ! --dst-type LOCAL -j omr-bypass-local
- [20160:10760121] -A OUTPUT -j dscp_output
- [694:63332] -A OUTPUT -p udp -m multiport --ports 123,53 -j DSCP --set-dscp 0x24
- [15077:9709297] -A OUTPUT -m addrtype ! --dst-type LOCAL -j omr-bypass-dpi
- [20213:10772240] -A POSTROUTING -j dscp_postrouting
- [20058:10753197] -A POSTROUTING -j dscp_mark
- [4922:356412] -A POSTROUTING -o usb1 -m mark --mark 0x0/0xff -g QOS_MARK_usb1
- [5160:919371] -A POSTROUTING -o usb0 -m mark --mark 0x0/0xff -g QOS_MARK_usb0
- [660:64583] -A POSTROUTING -m addrtype --dst-type LOCAL -j omr-bypass-dpi
- [5160:919371] -A QOS_MARK_usb0 -j MARK --set-xmark 0x2/0xff
- [0:0] -A QOS_MARK_usb0 -m dscp --dscp 0x08 -j MARK --set-xmark 0x3/0xff
- [0:0] -A QOS_MARK_usb0 -m dscp --dscp 0x30 -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb0 -m dscp --dscp 0x2e -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb0 -m dscp --dscp 0x24 -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb0 -m tos --tos 0x10/0x3f -j MARK --set-xmark 0x1/0xff
- [4922:356412] -A QOS_MARK_usb1 -j MARK --set-xmark 0x2/0xff
- [0:0] -A QOS_MARK_usb1 -m dscp --dscp 0x08 -j MARK --set-xmark 0x3/0xff
- [0:0] -A QOS_MARK_usb1 -m dscp --dscp 0x30 -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb1 -m dscp --dscp 0x2e -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb1 -m dscp --dscp 0x24 -j MARK --set-xmark 0x1/0xff
- [0:0] -A QOS_MARK_usb1 -m tos --tos 0x10/0x3f -j MARK --set-xmark 0x1/0xff
- [0:0] -A dscp_mark -m comment --comment cs4 -m dscp --dscp 0x20 -j MARK --set-xmark 0x7874756e/0xffffffff
- [608:84674] -A dscp_mark -m comment --comment cs5 -m dscp --dscp 0x28 -j MARK --set-xmark 0x7874756e/0xffffffff
- [1276:176792] -A dscp_mark -m comment --comment cs6 -m dscp --dscp 0x30 -j MARK --set-xmark 0x7874756e/0xffffffff
- [0:0] -A dscp_mark -m comment --comment cs7 -m dscp --dscp 0x38 -j MARK --set-xmark 0x7874756e/0xffffffff
- [898:74690] -A dscp_output -o tun0 -j DSCP --set-dscp 0x30
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs0 src,dst -m comment --comment cs0 -j DSCP --set-dscp 0x00
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs0 src,dst -m comment --comment cs0 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs1 src,dst -m comment --comment cs1 -j DSCP --set-dscp 0x08
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs1 src,dst -m comment --comment cs1 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs2 src,dst -m comment --comment cs2 -j DSCP --set-dscp 0x10
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs2 src,dst -m comment --comment cs2 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs3 src,dst -m comment --comment cs3 -j DSCP --set-dscp 0x18
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs3 src,dst -m comment --comment cs3 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs4 src,dst -m comment --comment cs4 -j DSCP --set-dscp 0x20
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs4 src,dst -m comment --comment cs4 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs5 src,dst -m comment --comment cs5 -j DSCP --set-dscp 0x28
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs5 src,dst -m comment --comment cs5 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs6 src,dst -m comment --comment cs6 -j DSCP --set-dscp 0x30
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs6 src,dst -m comment --comment cs6 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs7 src,dst -m comment --comment cs7 -j DSCP --set-dscp 0x38
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-cs7 src,dst -m comment --comment cs7 -j RETURN
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-ef src,dst -m comment --comment ef -j DSCP --set-dscp 0x2e
- [0:0] -A dscp_postrouting -m set --match-set omr_dscp-ef src,dst -m comment --comment ef -j RETURN
- [280:31425] -A dscp_postrouting -p icmp -m comment --comment ICMP -j DSCP --set-dscp 0x28
- [280:31425] -A dscp_postrouting -p icmp -m comment --comment ICMP -j RETURN
- [335:53837] -A dscp_postrouting -p udp -m multiport --sports 53,123,5353 -m multiport --dports 0:65535 -m comment --comment "DNS udp and NTP" -j DSCP --set-dscp 0x28
- [335:53837] -A dscp_postrouting -p udp -m multiport --sports 53,123,5353 -m multiport --dports 0:65535 -m comment --comment "DNS udp and NTP" -j RETURN
- [0:0] -A dscp_postrouting -p tcp -m multiport --sports 53,5353 -m multiport --dports 0:65535 -m comment --comment "DNS tcp" -j DSCP --set-dscp 0x28
- [0:0] -A dscp_postrouting -p tcp -m multiport --sports 53,5353 -m multiport --dports 0:65535 -m comment --comment "DNS tcp" -j RETURN
- [1163:165305] -A dscp_postrouting -p tcp -m multiport --sports 0:65535 -m multiport --dports 65001,65301,65011 -m comment --comment "OMR vpn" -j DSCP --set-dscp 0x30
- [1163:165305] -A dscp_postrouting -p tcp -m multiport --sports 0:65535 -m multiport --dports 65001,65301,65011 -m comment --comment "OMR vpn" -j RETURN
- [0:0] -A dscp_postrouting -p udp -m multiport --sports 0:65535 -m multiport --dports 65001,65301 -m comment --comment "OMR vpn" -j DSCP --set-dscp 0x30
- [0:0] -A dscp_postrouting -p udp -m multiport --sports 0:65535 -m multiport --dports 65001,65301 -m comment --comment "OMR vpn" -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs0 src,dst -m comment --comment cs0 -j DSCP --set-dscp 0x00
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs0 src,dst -m comment --comment cs0 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs1 src,dst -m comment --comment cs1 -j DSCP --set-dscp 0x08
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs1 src,dst -m comment --comment cs1 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs2 src,dst -m comment --comment cs2 -j DSCP --set-dscp 0x10
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs2 src,dst -m comment --comment cs2 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs3 src,dst -m comment --comment cs3 -j DSCP --set-dscp 0x18
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs3 src,dst -m comment --comment cs3 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs4 src,dst -m comment --comment cs4 -j DSCP --set-dscp 0x20
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs4 src,dst -m comment --comment cs4 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs5 src,dst -m comment --comment cs5 -j DSCP --set-dscp 0x28
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs5 src,dst -m comment --comment cs5 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs6 src,dst -m comment --comment cs6 -j DSCP --set-dscp 0x30
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs6 src,dst -m comment --comment cs6 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs7 src,dst -m comment --comment cs7 -j DSCP --set-dscp 0x38
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-cs7 src,dst -m comment --comment cs7 -j RETURN
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-ef src,dst -m comment --comment ef -j DSCP --set-dscp 0x2e
- [0:0] -A dscp_prerouting -m set --match-set omr_dscp-ef src,dst -m comment --comment ef -j RETURN
- [0:0] -A dscp_prerouting -p icmp -m comment --comment ICMP -j DSCP --set-dscp 0x28
- [0:0] -A dscp_prerouting -p icmp -m comment --comment ICMP -j RETURN
- [0:0] -A dscp_prerouting -p udp -m multiport --sports 53,123,5353 -m multiport --dports 0:65535 -m comment --comment "DNS udp and NTP" -j DSCP --set-dscp 0x28
- [0:0] -A dscp_prerouting -p udp -m multiport --sports 53,123,5353 -m multiport --dports 0:65535 -m comment --comment "DNS udp and NTP" -j RETURN
- [0:0] -A dscp_prerouting -p tcp -m multiport --sports 53,5353 -m multiport --dports 0:65535 -m comment --comment "DNS tcp" -j DSCP --set-dscp 0x28
- [0:0] -A dscp_prerouting -p tcp -m multiport --sports 53,5353 -m multiport --dports 0:65535 -m comment --comment "DNS tcp" -j RETURN
- [0:0] -A dscp_prerouting -p tcp -m multiport --sports 0:65535 -m multiport --dports 65001,65301,65011 -m comment --comment "OMR vpn" -j DSCP --set-dscp 0x30
- [0:0] -A dscp_prerouting -p tcp -m multiport --sports 0:65535 -m multiport --dports 65001,65301,65011 -m comment --comment "OMR vpn" -j RETURN
- [0:0] -A dscp_prerouting -p udp -m multiport --sports 0:65535 -m multiport --dports 65001,65301 -m comment --comment "OMR vpn" -j DSCP --set-dscp 0x30
- [0:0] -A dscp_prerouting -p udp -m multiport --sports 0:65535 -m multiport --dports 65001,65301 -m comment --comment "OMR vpn" -j RETURN
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_usb1 dst -j MARK --set-xmark 0x53918/0xffffffff
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_usb0 dst -j MARK --set-xmark 0x53916/0xffffffff
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_tun0 dst -j MARK --set-xmark 0x53911/0xffffffff
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_eth0 dst -j MARK --set-xmark 0x5398/0xffffffff
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_lo dst -j MARK --set-xmark 0x5397/0xffffffff
- [0:0] -A omr-bypass -m set --match-set omr_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- [0:0] -A omr-bypass-local -m set --match-set omr_dst_bypass_all dst -j MARK --set-xmark 0x539/0xffffffff
- COMMIT
- # Completed on Wed Nov 11 15:56:13 2020
- # Generated by iptables-save v1.8.4 on Wed Nov 11 15:56:13 2020
- *filter
- :INPUT DROP [0:0]
- :FORWARD DROP [0:0]
- :OUTPUT DROP [0:0]
- :MINIUPNPD - [0:0]
- :forwarding_lan_rule - [0:0]
- :forwarding_rule - [0:0]
- :forwarding_vpn_rule - [0:0]
- :forwarding_wan_rule - [0:0]
- :input_lan_rule - [0:0]
- :input_rule - [0:0]
- :input_vpn_rule - [0:0]
- :input_wan_rule - [0:0]
- :output_lan_rule - [0:0]
- :output_rule - [0:0]
- :output_vpn_rule - [0:0]
- :output_wan_rule - [0:0]
- :reject - [0:0]
- :syn_flood - [0:0]
- :zone_lan_dest_ACCEPT - [0:0]
- :zone_lan_forward - [0:0]
- :zone_lan_input - [0:0]
- :zone_lan_output - [0:0]
- :zone_lan_src_ACCEPT - [0:0]
- :zone_vpn_dest_ACCEPT - [0:0]
- :zone_vpn_forward - [0:0]
- :zone_vpn_input - [0:0]
- :zone_vpn_output - [0:0]
- :zone_vpn_src_REJECT - [0:0]
- :zone_wan_dest_ACCEPT - [0:0]
- :zone_wan_dest_REJECT - [0:0]
- :zone_wan_forward - [0:0]
- :zone_wan_input - [0:0]
- :zone_wan_output - [0:0]
- :zone_wan_src_REJECT - [0:0]
- [932:88354] -A INPUT -i lo -m comment --comment "!fw3" -j ACCEPT
- [16196:10506628] -A INPUT -m comment --comment "!fw3: Custom input rule chain" -j input_rule
- [15894:10486520] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [87:4524] -A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m comment --comment "!fw3" -j syn_flood
- [293:19352] -A INPUT -i eth0 -m comment --comment "!fw3" -j zone_lan_input
- [0:0] -A INPUT -i usb0 -m comment --comment "!fw3" -j zone_wan_input
- [0:0] -A INPUT -i usb1 -m comment --comment "!fw3" -j zone_wan_input
- [9:756] -A INPUT -i tun0 -m comment --comment "!fw3" -j zone_vpn_input
- [0:0] -A INPUT -m comment --comment "!fw3" -j reject
- [206:185851] -A FORWARD -m comment --comment "!fw3: Custom forwarding rule chain" -j forwarding_rule
- [37:3064] -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A FORWARD -p icmp -m icmp --icmp-type 8 -m comment --comment "!fw3: Allow-All-Ping" -j ACCEPT
- [157:182109] -A FORWARD -p udp -m udp --dport 443 -m comment --comment "!fw3: Block QUIC All" -j DROP
- [12:678] -A FORWARD -i eth0 -m comment --comment "!fw3" -j zone_lan_forward
- [0:0] -A FORWARD -i usb0 -m comment --comment "!fw3" -j zone_wan_forward
- [0:0] -A FORWARD -i usb1 -m comment --comment "!fw3" -j zone_wan_forward
- [0:0] -A FORWARD -i tun0 -m comment --comment "!fw3" -j zone_vpn_forward
- [0:0] -A FORWARD -m comment --comment "!fw3" -j reject
- [893:84984] -A OUTPUT -o lo -m comment --comment "!fw3" -j ACCEPT
- [17163:10276546] -A OUTPUT -m comment --comment "!fw3: Custom output rule chain" -j output_rule
- [16331:10207491] -A OUTPUT -m conntrack --ctstate RELATED,ESTABLISHED -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A OUTPUT -o eth0 -m comment --comment "!fw3" -j zone_lan_output
- [231:20774] -A OUTPUT -o usb0 -m comment --comment "!fw3" -j zone_wan_output
- [198:16404] -A OUTPUT -o usb1 -m comment --comment "!fw3" -j zone_wan_output
- [403:31877] -A OUTPUT -o tun0 -m comment --comment "!fw3" -j zone_vpn_output
- [0:0] -A OUTPUT -m comment --comment "!fw3" -j reject
- [0:0] -A reject -p tcp -m comment --comment "!fw3" -j REJECT --reject-with tcp-reset
- [0:0] -A reject -m comment --comment "!fw3" -j REJECT --reject-with icmp-port-unreachable
- [87:4524] -A syn_flood -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 25/sec --limit-burst 50 -m comment --comment "!fw3" -j RETURN
- [0:0] -A syn_flood -m comment --comment "!fw3" -j DROP
- [0:0] -A zone_lan_dest_ACCEPT -o eth0 -m comment --comment "!fw3" -j ACCEPT
- [12:678] -A zone_lan_forward -m comment --comment "!fw3: Custom lan forwarding rule chain" -j forwarding_lan_rule
- [12:678] -A zone_lan_forward -p tcp -m comment --comment "!fw3: Allow-All-LAN-to-VPN" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_lan_forward -p udp -m comment --comment "!fw3: Allow-All-LAN-to-VPN" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_lan_forward -p tcp -m comment --comment "!fw3: Allow-Lan-to-Wan" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_lan_forward -p udp -m comment --comment "!fw3: Allow-Lan-to-Wan" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_lan_forward -m comment --comment "!fw3: Zone lan to wan forwarding policy" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_lan_forward -m comment --comment "!fw3: Zone lan to vpn forwarding policy" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_lan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [0:0] -A zone_lan_forward -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [293:19352] -A zone_lan_input -m comment --comment "!fw3: Custom lan input rule chain" -j input_lan_rule
- [0:0] -A zone_lan_input -p udp -m udp --dport 443 -m comment --comment "!fw3: Block QUIC Proxy" -j DROP
- [87:4524] -A zone_lan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [206:14828] -A zone_lan_input -m comment --comment "!fw3" -j zone_lan_src_ACCEPT
- [0:0] -A zone_lan_output -m comment --comment "!fw3: Custom lan output rule chain" -j output_lan_rule
- [0:0] -A zone_lan_output -m comment --comment "!fw3" -j zone_lan_dest_ACCEPT
- [206:14828] -A zone_lan_src_ACCEPT -i eth0 -m conntrack --ctstate NEW,UNTRACKED -m comment --comment "!fw3" -j ACCEPT
- [12:678] -A zone_vpn_dest_ACCEPT -o tun0 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [403:31877] -A zone_vpn_dest_ACCEPT -o tun0 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_vpn_forward -m comment --comment "!fw3: Custom vpn forwarding rule chain" -j forwarding_vpn_rule
- [0:0] -A zone_vpn_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [0:0] -A zone_vpn_forward -m comment --comment "!fw3" -j zone_vpn_dest_ACCEPT
- [9:756] -A zone_vpn_input -m comment --comment "!fw3: Custom vpn input rule chain" -j input_vpn_rule
- [9:756] -A zone_vpn_input -p icmp -m comment --comment "!fw3: Allow-VPN-ICMP" -j ACCEPT
- [0:0] -A zone_vpn_input -p udp -m udp --dport 67 -m comment --comment "!fw3: Allow-DHCP-Request-VPN" -j ACCEPT
- [0:0] -A zone_vpn_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [0:0] -A zone_vpn_input -m comment --comment "!fw3" -j zone_vpn_src_REJECT
- [403:31877] -A zone_vpn_output -m comment --comment "!fw3: Custom vpn output rule chain" -j output_vpn_rule
- [403:31877] -A zone_vpn_output -m comment --comment "!fw3" -j zone_vpn_dest_ACCEPT
- [0:0] -A zone_vpn_src_REJECT -i tun0 -m comment --comment "!fw3" -j reject
- [23:1380] -A zone_wan_dest_ACCEPT -o usb0 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [208:19394] -A zone_wan_dest_ACCEPT -o usb0 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_ACCEPT -o usb1 -m conntrack --ctstate INVALID -m comment --comment "!fw3: Prevent NAT leakage" -j DROP
- [198:16404] -A zone_wan_dest_ACCEPT -o usb1 -m comment --comment "!fw3" -j ACCEPT
- [0:0] -A zone_wan_dest_REJECT -o usb0 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_dest_REJECT -o usb1 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_forward -m comment --comment "!fw3: Custom wan forwarding rule chain" -j forwarding_wan_rule
- [0:0] -A zone_wan_forward -p esp -m comment --comment "!fw3: Allow-IPSec-ESP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -p udp -m udp --dport 500 -m comment --comment "!fw3: Allow-ISAKMP" -j zone_lan_dest_ACCEPT
- [0:0] -A zone_wan_forward -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port forwards" -j ACCEPT
- [0:0] -A zone_wan_forward -m comment --comment "!fw3" -j zone_wan_dest_REJECT
- [0:0] -A zone_wan_input -m comment --comment "!fw3: Custom wan input rule chain" -j input_wan_rule
- [0:0] -A zone_wan_input -p udp -m udp --dport 68 -m comment --comment "!fw3: Allow-DHCP-Renew" -j ACCEPT
- [0:0] -A zone_wan_input -p icmp -m icmp --icmp-type 8 -m comment --comment "!fw3: Allow-Ping" -j ACCEPT
- [0:0] -A zone_wan_input -p igmp -m comment --comment "!fw3: Allow-IGMP" -j ACCEPT
- [0:0] -A zone_wan_input -m conntrack --ctstate DNAT -m comment --comment "!fw3: Accept port redirections" -j ACCEPT
- [0:0] -A zone_wan_input -m comment --comment "!fw3" -j zone_wan_src_REJECT
- [429:37178] -A zone_wan_output -m comment --comment "!fw3: Custom wan output rule chain" -j output_wan_rule
- [429:37178] -A zone_wan_output -m comment --comment "!fw3" -j zone_wan_dest_ACCEPT
- [0:0] -A zone_wan_src_REJECT -i usb0 -m comment --comment "!fw3" -j reject
- [0:0] -A zone_wan_src_REJECT -i usb1 -m comment --comment "!fw3" -j reject
- COMMIT
- # Completed on Wed Nov 11 15:56:13 2020
- 1: lo: <LOOPBACK,UP,LOWER_UP,80000> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
- inet 127.0.0.1/8 scope host lo
- valid_lft forever preferred_lft forever
- 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP,80000> mtu 1500 qdisc mq state UP group default qlen 1000
- inet 192.168.100.1/24 brd 192.168.100.255 scope global eth0
- valid_lft forever preferred_lft forever
- 10: usb0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1440 qdisc fq_codel state UNKNOWN group default qlen 100
- inet 192.168.42.169/24 brd 192.168.42.255 scope global usb0
- valid_lft forever preferred_lft forever
- 11: usb1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 100
- inet 192.168.42.149/24 brd 192.168.42.255 scope global usb1
- valid_lft forever preferred_lft forever
- 24: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP,80000> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 100
- inet 10.255.255.2 peer 10.255.255.1/32 scope global tun0
- valid_lft forever preferred_lft forever
- default via 10.255.255.1 dev tun0 table 11
- 10.255.255.2 dev tun0 table 11 scope link
- default via 192.168.42.129 dev usb0 table 16
- 192.168.42.0/24 dev usb0 table 16 scope link
- default via 192.168.42.129 dev usb1 table 18
- 192.168.42.0/24 dev usb1 table 18 scope link
- 192.168.1.0/24 via 192.168.100.2 dev eth0 table lan proto static metric 8
- 192.168.100.0/24 dev eth0 table lan proto static scope link metric 8
- default via 10.255.255.1 dev tun0
- default via 10.255.255.1 dev tun0 metric 11
- default via 192.168.42.129 dev usb0 metric 16
- default via 192.168.42.129 dev usb1 metric 18
- 10.255.255.1 dev tun0 proto kernel scope link src 10.255.255.2
- 10.255.255.2 dev tun0 scope link metric 11
- 23.237.137.xxx
- nexthop via 192.168.42.129 dev usb0 weight 1
- nexthop via 192.168.42.129 dev usb1 weight 1
- 127.0.0.0/8 dev lo proto static scope link metric 7
- 192.168.1.0/24 via 192.168.100.2 dev eth0
- 192.168.42.0/24 dev usb0 scope link metric 16
- 192.168.42.0/24 dev usb1 scope link metric 18
- local 10.255.255.2 dev tun0 table local proto kernel scope host src 10.255.255.2
- broadcast 127.0.0.0 dev lo table local proto kernel scope link src 127.0.0.1
- local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
- local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
- broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
- broadcast 192.168.42.0 dev usb1 table local proto kernel scope link src 192.168.42.149
- broadcast 192.168.42.0 dev usb0 table local proto kernel scope link src 192.168.42.169
- local 192.168.42.149 dev usb1 table local proto kernel scope host src 192.168.42.149
- local 192.168.42.169 dev usb0 table local proto kernel scope host src 192.168.42.169
- broadcast 192.168.42.255 dev usb1 table local proto kernel scope link src 192.168.42.149
- broadcast 192.168.42.255 dev usb0 table local proto kernel scope link src 192.168.42.169
- broadcast 192.168.100.0 dev eth0 table local proto kernel scope link src 192.168.100.1
- local 192.168.100.1 dev eth0 table local proto kernel scope host src 192.168.100.1
- broadcast 192.168.100.255 dev eth0 table local proto kernel scope link src 192.168.100.1
- 0: from all lookup local
- 0: from 10.255.255.2 lookup 11
- 0: from 192.168.42.149 lookup 18
- 0: from 192.168.42.169 lookup 16
- 1: from all fwmark 0x5397 lookup 7
- 1: from all fwmark 0x5398 lookup 8
- 1: from all fwmark 0x53911 lookup 11
- 1: from all fwmark 0x53916 lookup 16
- 1: from all fwmark 0x53918 lookup 18
- 1: from all fwmark 0x539 lookup 991337
- 100: from all lookup lan
- 10000: from 192.168.100.1 lookup lan
- 20000: from all to 192.168.100.1/24 lookup lan
- 32766: from all lookup main
- 32767: from all lookup default
- 90002: from all iif lo lookup lan
- root@OpenMPTCProuter:~#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement