Jan Engelhardt | 6a74dc8 | 2011-06-07 19:06:51 +0200 | [diff] [blame] | 1 | # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 |
| 2 | *mangle |
| 3 | :PREROUTING ACCEPT [2461:977932] |
| 4 | :INPUT ACCEPT [2461:977932] |
| 5 | :FORWARD ACCEPT [0:0] |
| 6 | :OUTPUT ACCEPT [1740:367048] |
| 7 | :POSTROUTING ACCEPT [1740:367048] |
| 8 | |
| 9 | # libipt_ |
| 10 | -A INPUT -p ah -m ah --ahspi 1 |
| 11 | -A INPUT -p ah -m ah --ahspi :2 |
| 12 | -A INPUT -p ah -m ah --ahspi 0:3 |
| 13 | -A INPUT -p ah -m ah --ahspi 4: |
| 14 | -A INPUT -p ah -m ah --ahspi 5:4294967295 |
| 15 | |
| 16 | -A FORWARD -p tcp -j ECN --ecn-tcp-remove |
| 17 | -A FORWARD -j LOG --log-prefix "hi" --log-tcp-sequence --log-tcp-options --log-ip-options --log-uid --log-macdecode |
| 18 | -A FORWARD -j TTL --ttl-inc 1 |
| 19 | -A FORWARD -j TTL --ttl-dec 1 |
| 20 | -A FORWARD -j TTL --ttl-set 1 |
| 21 | -A FORWARD -j ULOG --ulog-prefix "abc" --ulog-cprange 2 --ulog-qthreshold 2 |
| 22 | COMMIT |
| 23 | # Completed on Mon Jan 31 03:03:38 2011 |
| 24 | # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 |
| 25 | *nat |
| 26 | :PREROUTING ACCEPT [0:0] |
| 27 | :INPUT ACCEPT [0:0] |
| 28 | :OUTPUT ACCEPT [0:0] |
| 29 | :POSTROUTING ACCEPT [0:0] |
| 30 | -A PREROUTING -d 1.2.3.4/32 -i lo -j CLUSTERIP --new --hashmode sourceip --clustermac 01:02:03:04:05:06 --total-nodes 9 --local-node 2 --hash-init 123456789 |
| 31 | -A PREROUTING -i dummy0 -j DNAT --to-destination 1.2.3.4 --random --persistent |
| 32 | -A PREROUTING -i dummy0 -p tcp -j REDIRECT --to-ports 1-2 --random |
| 33 | -A POSTROUTING -o dummy0 -p tcp -j MASQUERADE --to-ports 1-2 --random |
| 34 | -A POSTROUTING -o dummy0 -p tcp -j NETMAP --to 1.0.0.0/8 |
| 35 | -A POSTROUTING -o dummy0 -p tcp -j SNAT --to-source 1.2.3.4-1.2.3.5 --random --persistent |
| 36 | COMMIT |
| 37 | # Completed on Mon Jan 31 03:03:38 2011 |
| 38 | # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 |
| 39 | *filter |
| 40 | :INPUT ACCEPT [76:13548] |
| 41 | :FORWARD ACCEPT [0:0] |
| 42 | :OUTPUT ACCEPT [59:11240] |
| 43 | #-A INPUT -m addrtype --src-type UNICAST --dst-type UNICAST --limit-iface-in |
| 44 | -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 0 |
| 45 | -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 1 |
| 46 | -A INPUT -p icmp -m icmp --icmp-type 5/0 |
| 47 | -A INPUT -p icmp -m icmp --icmp-type 5/1 |
| 48 | -A INPUT -p icmp -m icmp --icmp-type 5 |
| 49 | -A INPUT -m realm --realm 0x1 -m ttl --ttl-eq 64 -m ttl --ttl-lt 64 -m ttl --ttl-gt 64 |
| 50 | -A FORWARD -p tcp -j REJECT --reject-with tcp-reset |
| 51 | COMMIT |
| 52 | # Completed on Mon Jan 31 03:03:39 2011 |