Skip to content

Instantly share code, notes, and snippets.

@BtbN
Created January 29, 2016 10:24
Show Gist options
  • Select an option

  • Save BtbN/eec2f3c834cbecd83c3c to your computer and use it in GitHub Desktop.

Select an option

Save BtbN/eec2f3c834cbecd83c3c to your computer and use it in GitHub Desktop.
stdin
# Generated by iptables-save v1.4.21 on Fri Jan 29 11:24:18 2016
*nat
:PREROUTING ACCEPT [220:13184]
:INPUT ACCEPT [220:13184]
:OUTPUT ACCEPT [381:25359]
:POSTROUTING ACCEPT [381:25359]
-A POSTROUTING -s 10.19.250.0/24 -o eth0 -j SNAT --to-source 5.9.118.179
-A POSTROUTING -s 10.19.249.0/24 -o eth0 -j SNAT --to-source 5.9.118.179
-A POSTROUTING -s 10.0.10.0/24 -o eth0 -j SNAT --to-source 5.9.118.179
COMMIT
# Completed on Fri Jan 29 11:24:18 2016
# Generated by iptables-save v1.4.21 on Fri Jan 29 11:24:18 2016
*mangle
:PREROUTING ACCEPT [5263:5294067]
:INPUT ACCEPT [5261:5293987]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [6376:4611246]
:POSTROUTING ACCEPT [6446:4625562]
COMMIT
# Completed on Fri Jan 29 11:24:18 2016
# Generated by iptables-save v1.4.21 on Fri Jan 29 11:24:18 2016
*filter
:INPUT ACCEPT [5261:5293987]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [6376:4611246]
-A INPUT -i eth0 -p tcp -m tcp --dport 3306 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -i eth0 -p tcp -m tcp --dport 9090 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -i eth0 -p tcp -m tcp --dport 9091 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -i eth0 -p tcp -m tcp --dport 15900 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -i eth0 -p tcp -m tcp --dport 15901 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr0 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ovpn -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o ovpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ovpntcp -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o ovpntcp -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ovpntcp -o virbr0 -j ACCEPT
-A FORWARD -i ovpn -o virbr0 -j ACCEPT
-A FORWARD -i ovpnhome -o virbr0 -j ACCEPT
-A FORWARD -i virbr0 -o ovpntcp -j ACCEPT
-A FORWARD -i virbr0 -o ovpn -j ACCEPT
-A FORWARD -i virbr0 -o ovpnhome -j ACCEPT
COMMIT
# Completed on Fri Jan 29 11:24:18 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment