NoPaste

ipt

von Svenny

SNIPPET_TEXT:
  1. *mangle
  2. :PREROUTING ACCEPT [0:0]
  3. :OUTPUT ACCEPT [0:0]
  4. COMMIT
  5. *nat
  6. :PREROUTING ACCEPT [0:0]
  7. :POSTROUTING ACCEPT [0:0]
  8. :OUTPUT ACCEPT [0:0]
  9. -A PREROUTING -p icmp -d ww.xx.yy.zz -j DNAT --to-destination 192.168.42.1
  10. -A PREROUTING -d ww.xx.yy.zz -j TRIGGER --trigger-type dnat
  11. -A POSTROUTING -o vlan1 -j SNAT --to-source ww.xx.yy.zz
  12. -A POSTROUTING -o br0 -m pkttype --pkt-type broadcast -j RETURN
  13. -A POSTROUTING -o br0 -s 192.168.42.0/24 -d 192.168.42.0/24 -j MASQUERADE
  14. COMMIT
  15. *filter
  16. :INPUT ACCEPT [0:0]
  17. :FORWARD ACCEPT [0:0]
  18. :OUTPUT ACCEPT [0:0]
  19. :logaccept - [0:0]
  20. :logdrop - [0:0]
  21. :logreject - [0:0]
  22. :trigger_out - [0:0]
  23. :lan2wan - [0:0]
  24. :grp_1 - [0:0]
  25. :advgrp_1 - [0:0]
  26. :grp_2 - [0:0]
  27. :advgrp_2 - [0:0]
  28. :grp_3 - [0:0]
  29. :advgrp_3 - [0:0]
  30. :grp_4 - [0:0]
  31. :advgrp_4 - [0:0]
  32. :grp_5 - [0:0]
  33. :advgrp_5 - [0:0]
  34. :grp_6 - [0:0]
  35. :advgrp_6 - [0:0]
  36. :grp_7 - [0:0]
  37. :advgrp_7 - [0:0]
  38. :grp_8 - [0:0]
  39. :advgrp_8 - [0:0]
  40. :grp_9 - [0:0]
  41. :advgrp_9 - [0:0]
  42. :grp_10 - [0:0]
  43. :advgrp_10 - [0:0]
  44. -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
  45. -A INPUT -p udp -i vlan1 --dport 520 -j DROP
  46. -A INPUT -p udp -i br0 --dport 520 -j DROP
  47. -A INPUT -p udp --dport 520 -j ACCEPT
  48. -A INPUT -i vlan1 -p icmp -j DROP
  49. -A INPUT -p igmp -j DROP
  50. -A INPUT -i lo -m state --state NEW -j ACCEPT
  51. -A INPUT -i br0 -m state --state NEW -j logaccept
  52. -A INPUT -j DROP
  53. -A FORWARD -i br0 -o br0 -j ACCEPT
  54. -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
  55. -A FORWARD -j lan2wan
  56. -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
  57. -I FORWARD -o vlan1 -s 192.168.42.1/24 -p tcp --dport 1723 -j ACCEPT
  58. -I FORWARD -o vlan1 -s 192.168.42.1/24 -p gre -j ACCEPT
  59. -A FORWARD -i vlan1 -o br0 -j TRIGGER --trigger-type in
  60. -A FORWARD -i br0 -j trigger_out
  61. -A FORWARD -i br0 -m state --state NEW -j ACCEPT
  62. -A FORWARD -j DROP
  63. -A logaccept -j ACCEPT
  64. -A logdrop -j DROP
  65. -A logreject -p tcp -m tcp -j REJECT --reject-with tcp-reset
  66. COMMIT

Quellcode

Hier kannst du den Code kopieren und ihn in deinen bevorzugten Editor einfügen. PASTEBIN_DOWNLOAD_SNIPPET_EXPLAIN