Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ?SECTION INVALID
- ?SECTION UNTRACKED
- ?SECTION NEW
- # Don't allow connection pickup from the net
- #
- Invalid(DROP) net all tcp
- #
- # Accept DNS connections from the firewall to the network
- #
- DNS(ACCEPT) $FW net
- #
- # Allow Ping from/to the VPN
- #
- Ping(ACCEPT) vpn $FW
- Ping(ACCEPT) $FW vpn
- #
- # Allow Ping from the firewall to the network
- #
- Ping(ACCEPT) $FW net
- #
- # Drop Ping from the "bad" net zone.. and prevent your log from being flooded..
- #
- #Ping(DROP) net $FW
- Ping(ACCEPT) net $FW
- #
- # Accept connection from port > 65000 for shadowsocks and glorytun on the firewall
- #
- ACCEPT net $FW tcp 65000-65535
- ACCEPT net $FW udp 65000-65535
- #
- # Accept connection from SSH to the firewall
- #
- ACCEPT net $FW tcp 65222
- #
- # DHCP forward to the VPN from the firewall
- #
- DHCPfwd(ACCEPT) $FW vpn
- #
- # Redirect all port from 1 to 64999 to the VPN client from the network
- #
- DNAT net vpn:$OMR_ADDR tcp 1-64999
- DNAT net vpn:$OMR_ADDR udp 1-64999
- ACCEPT net $FW tcp 65101 # OMR openmptcprouter open shadowsocks port tcp
- ACCEPT net $FW udp 65101 # OMR openmptcprouter open shadowsocks port udp
- ACCEPT net $FW tcp 65001 # OMR openmptcprouter open glorytun port tcp
- ACCEPT net $FW udp 65001 # OMR openmptcprouter open glorytun port udp
- DNAT net vpn:$OMR_ADDR tcp 15501 # OMR openmptcprouter redirect router 15501 port tcp
- DNAT net vpn:$OMR_ADDR tcp 15500 # OMR openmptcprouter redirect router 15500 port tcp
- DNAT net vpn:$OMR_ADDR tcp 443 # OMR openmptcprouter redirect router 443 port tcp
- DNAT net vpn:$OMR_ADDR tcp 80 # OMR openmptcprouter redirect router 80 port tcp
- DNAT net vpn:$OMR_ADDR tcp 5006 # OMR openmptcprouter redirect router 5006 port tcp
- DNAT net vpn:$OMR_ADDR tcp 6690 # OMR openmptcprouter redirect router 6690 port tcp
- DNAT net vpn:$OMR_ADDR tcp 53 # OMR openmptcprouter redirect router 53 port tcp
- DNAT net vpn:$OMR_ADDR udp 500 # OMR openmptcprouter redirect router 500 port udp
- DNAT net vpn:$OMR_ADDR udp 4500 # OMR openmptcprouter redirect router 4500 port udp
Add Comment
Please, Sign In to add comment