The host says what filters the machine, with owners, and keeps the found firewall retired on every converged apply (hq ADR 0168)
Every table and chain that refuses traffic is reported with whose it is: the mesh's, the found firewall's, the container runtime's own, a ban, or other — the runtime's user chain is other, which is where both predecessors kept their rules, in the legacy filter on one machine and invisible to the mesh. Adoption's threshold does not move; a converged machine's report grows by its filters and its found firewall's state. Convergence is a state the host keeps: a found firewall enabled again is retired again and said; a reconcile that finds it inactive records that it was found so, never that the mesh did it; a step skipped after a failed apply is said. A retirement the mesh began and did not finish is finished. Fixtures are rulesets captured from three machines of the first mesh.
This commit is contained in:
+588
@@ -0,0 +1,588 @@
|
||||
# Warning: table ip filter is managed by iptables-nft, do not touch!
|
||||
table ip filter {
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy accept;
|
||||
ip protocol tcp counter packets 945757787 bytes 1737008792038 jump f2b-sshd
|
||||
ip protocol tcp counter packets 945756610 bytes 1737008898620 jump f2b-recidive
|
||||
counter packets 2862213204 bytes 3144751431654 jump ufw-before-logging-input
|
||||
counter packets 2862213204 bytes 3144751431654 jump ufw-before-input
|
||||
counter packets 989333889 bytes 1776344988272 jump ufw-after-input
|
||||
counter packets 989303248 bytes 1776343408920 jump ufw-after-logging-input
|
||||
counter packets 989303248 bytes 1776343408920 jump ufw-reject-input
|
||||
counter packets 989303248 bytes 1776343408920 jump ufw-track-input
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
oifname "mesh0" counter packets 1613103 bytes 2577614868 accept
|
||||
iifname "mesh0" counter packets 995195 bytes 84526284 accept
|
||||
counter packets 20454697 bytes 11504107676 jump DOCKER-USER
|
||||
counter packets 20442192 bytes 11503368404 jump DOCKER-FORWARD
|
||||
counter packets 12438285 bytes 10907281833 jump ufw-before-logging-forward
|
||||
counter packets 12438285 bytes 10907281833 jump ufw-before-forward
|
||||
counter packets 384 bytes 39643 jump ufw-after-forward
|
||||
counter packets 384 bytes 39643 jump ufw-after-logging-forward
|
||||
counter packets 384 bytes 39643 jump ufw-reject-forward
|
||||
counter packets 384 bytes 39643 jump ufw-track-forward
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
counter packets 3195070897 bytes 3951725261199 jump ufw-before-logging-output
|
||||
counter packets 3195070897 bytes 3951725261199 jump ufw-before-output
|
||||
counter packets 945745931 bytes 1778546547406 jump ufw-after-output
|
||||
counter packets 945745931 bytes 1778546547406 jump ufw-after-logging-output
|
||||
counter packets 945745931 bytes 1778546547406 jump ufw-reject-output
|
||||
counter packets 945745931 bytes 1778546547406 jump ufw-track-output
|
||||
}
|
||||
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 20442192 bytes 11503368404 jump DOCKER-CT
|
||||
counter packets 8079126 bytes 1230017985 jump DOCKER-INTERNAL
|
||||
counter packets 8079126 bytes 1230017985 jump DOCKER-BRIDGE
|
||||
iifname "br-cadedce55fe9" counter packets 0 bytes 0 accept
|
||||
iifname "br-dd007c7e67bc" counter packets 0 bytes 0 accept
|
||||
iifname "br-a5fbc29c2c2a" counter packets 0 bytes 0 accept
|
||||
iifname "br-6eb1e7f7f847" counter packets 0 bytes 0 accept
|
||||
iifname "br-8ce143481a5b" counter packets 14700 bytes 2493600 accept
|
||||
iifname "br-84e7d0cfeada" counter packets 0 bytes 0 accept
|
||||
iifname "br-f8b083119d99" counter packets 264 bytes 57438 accept
|
||||
iifname "br-0d1490cc67c9" counter packets 732468 bytes 351624109 accept
|
||||
iifname "br-3b338a381229" counter packets 137 bytes 11876 accept
|
||||
iifname "br-3008d408e73a" counter packets 25380 bytes 1564417 accept
|
||||
iifname "br-ca07a9577a7f" counter packets 0 bytes 0 accept
|
||||
iifname "docker0" counter packets 6695791 bytes 795364128 accept
|
||||
iifname "br-a63fa64a9e18" counter packets 0 bytes 0 accept
|
||||
iifname "br-1ccb887b3344" counter packets 237174 bytes 36804979 accept
|
||||
iifname "br-9fd22324ec08" counter packets 0 bytes 0 accept
|
||||
iifname "br-73641cceafc3" counter packets 36 bytes 6614 accept
|
||||
iifname "br-77eb8a9e2ba1" counter packets 0 bytes 0 accept
|
||||
iifname "br-e99ce5248c84" counter packets 0 bytes 0 accept
|
||||
iifname "br-e5d78502832d" counter packets 0 bytes 0 accept
|
||||
iifname "br-2e4a76a7cd2e" counter packets 20339 bytes 1799711 accept
|
||||
iifname "br-72fd626a8ff7" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
ip protocol tcp counter packets 3054221 bytes 3329963005 jump f2b-sshd
|
||||
ip protocol tcp counter packets 3054221 bytes 3329963005 jump f2b-recidive
|
||||
counter packets 1421378091 bytes 2045004412819 return
|
||||
}
|
||||
|
||||
chain ufw-before-logging-input {
|
||||
}
|
||||
|
||||
chain ufw-before-logging-output {
|
||||
}
|
||||
|
||||
chain ufw-before-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw-before-input {
|
||||
}
|
||||
|
||||
chain ufw-before-output {
|
||||
}
|
||||
|
||||
chain ufw-before-forward {
|
||||
}
|
||||
|
||||
chain ufw-after-input {
|
||||
}
|
||||
|
||||
chain ufw-after-output {
|
||||
}
|
||||
|
||||
chain ufw-after-forward {
|
||||
}
|
||||
|
||||
chain ufw-after-logging-input {
|
||||
}
|
||||
|
||||
chain ufw-after-logging-output {
|
||||
}
|
||||
|
||||
chain ufw-after-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw-reject-input {
|
||||
}
|
||||
|
||||
chain ufw-reject-output {
|
||||
}
|
||||
|
||||
chain ufw-reject-forward {
|
||||
}
|
||||
|
||||
chain ufw-track-input {
|
||||
}
|
||||
|
||||
chain ufw-track-output {
|
||||
}
|
||||
|
||||
chain ufw-track-forward {
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
ip daddr 172.17.0.7 iifname != "docker0" oifname "docker0" tcp dport 5432 counter packets 8 bytes 480 accept
|
||||
ip daddr 172.19.0.2 iifname != "br-72fd626a8ff7" oifname "br-72fd626a8ff7" tcp dport 8080 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.6 iifname != "docker0" oifname "docker0" tcp dport 9443 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.6 iifname != "docker0" oifname "docker0" tcp dport 9000 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.176.2 iifname != "br-f8b083119d99" oifname "br-f8b083119d99" tcp dport 9001 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.176.2 iifname != "br-f8b083119d99" oifname "br-f8b083119d99" tcp dport 9000 counter packets 47769 bytes 2866140 accept
|
||||
ip daddr 172.20.0.2 iifname != "br-6eb1e7f7f847" oifname "br-6eb1e7f7f847" tcp dport 8080 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.27.0.2 iifname != "br-3008d408e73a" oifname "br-3008d408e73a" tcp dport 3000 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.48.5 iifname != "br-77eb8a9e2ba1" oifname "br-77eb8a9e2ba1" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.48.4 iifname != "br-77eb8a9e2ba1" oifname "br-77eb8a9e2ba1" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.48.3 iifname != "br-77eb8a9e2ba1" oifname "br-77eb8a9e2ba1" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.48.2 iifname != "br-77eb8a9e2ba1" oifname "br-77eb8a9e2ba1" tcp dport 9000 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.18.0.2 iifname != "br-2e4a76a7cd2e" oifname "br-2e4a76a7cd2e" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.5 iifname != "docker0" oifname "docker0" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.3 iifname != "docker0" oifname "docker0" tcp dport 8222 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.3 iifname != "docker0" oifname "docker0" tcp dport 4222 counter packets 97 bytes 5744 accept
|
||||
ip daddr 172.28.0.2 iifname != "br-8ce143481a5b" oifname "br-8ce143481a5b" tcp dport 1433 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.80.2 iifname != "br-e99ce5248c84" oifname "br-e99ce5248c84" tcp dport 8080 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.112.3 iifname != "br-e5d78502832d" oifname "br-e5d78502832d" tcp dport 9000 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.112.2 iifname != "br-e5d78502832d" oifname "br-e5d78502832d" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.128.2 iifname != "br-73641cceafc3" oifname "br-73641cceafc3" tcp dport 27017 counter packets 14 bytes 840 accept
|
||||
ip daddr 192.168.208.2 iifname != "br-9fd22324ec08" oifname "br-9fd22324ec08" tcp dport 35621 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.203.13 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 4243 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 995 counter packets 194 bytes 11000 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 993 counter packets 188 bytes 9394 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 587 counter packets 444 bytes 23312 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 465 counter packets 104 bytes 5852 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 443 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 143 counter packets 443 bytes 25280 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 110 counter packets 192 bytes 9561 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 80 counter packets 0 bytes 0 accept
|
||||
ip daddr 192.168.203.12 iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" tcp dport 25 counter packets 430 bytes 22919 accept
|
||||
ip daddr 172.17.0.2 iifname != "docker0" oifname "docker0" tcp dport 3000 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.17.0.2 iifname != "docker0" oifname "docker0" tcp dport 22 counter packets 1578 bytes 93884 accept
|
||||
ip daddr 172.17.0.4 iifname != "docker0" oifname "docker0" tcp dport 5000 counter packets 25 bytes 1492 accept
|
||||
iifname != "br-cadedce55fe9" oifname "br-cadedce55fe9" counter packets 0 bytes 0 drop
|
||||
iifname != "br-dd007c7e67bc" oifname "br-dd007c7e67bc" counter packets 0 bytes 0 drop
|
||||
iifname != "br-a5fbc29c2c2a" oifname "br-a5fbc29c2c2a" counter packets 0 bytes 0 drop
|
||||
iifname != "br-6eb1e7f7f847" oifname "br-6eb1e7f7f847" counter packets 0 bytes 0 drop
|
||||
iifname != "br-8ce143481a5b" oifname "br-8ce143481a5b" counter packets 0 bytes 0 drop
|
||||
iifname != "br-84e7d0cfeada" oifname "br-84e7d0cfeada" counter packets 0 bytes 0 drop
|
||||
iifname != "br-f8b083119d99" oifname "br-f8b083119d99" counter packets 0 bytes 0 drop
|
||||
iifname != "br-0d1490cc67c9" oifname "br-0d1490cc67c9" counter packets 0 bytes 0 drop
|
||||
iifname != "br-3b338a381229" oifname "br-3b338a381229" counter packets 0 bytes 0 drop
|
||||
iifname != "br-3008d408e73a" oifname "br-3008d408e73a" counter packets 0 bytes 0 drop
|
||||
iifname != "br-ca07a9577a7f" oifname "br-ca07a9577a7f" counter packets 0 bytes 0 drop
|
||||
iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop
|
||||
iifname != "br-a63fa64a9e18" oifname "br-a63fa64a9e18" counter packets 0 bytes 0 drop
|
||||
iifname != "br-1ccb887b3344" oifname "br-1ccb887b3344" counter packets 0 bytes 0 drop
|
||||
iifname != "br-9fd22324ec08" oifname "br-9fd22324ec08" counter packets 0 bytes 0 drop
|
||||
iifname != "br-73641cceafc3" oifname "br-73641cceafc3" counter packets 0 bytes 0 drop
|
||||
iifname != "br-77eb8a9e2ba1" oifname "br-77eb8a9e2ba1" counter packets 0 bytes 0 drop
|
||||
iifname != "br-e99ce5248c84" oifname "br-e99ce5248c84" counter packets 0 bytes 0 drop
|
||||
iifname != "br-e5d78502832d" oifname "br-e5d78502832d" counter packets 0 bytes 0 drop
|
||||
iifname != "br-2e4a76a7cd2e" oifname "br-2e4a76a7cd2e" counter packets 0 bytes 0 drop
|
||||
iifname != "br-72fd626a8ff7" oifname "br-72fd626a8ff7" counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
oifname "br-cadedce55fe9" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-dd007c7e67bc" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-a5fbc29c2c2a" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-6eb1e7f7f847" counter packets 799 bytes 47940 jump DOCKER
|
||||
oifname "br-8ce143481a5b" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-84e7d0cfeada" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-f8b083119d99" counter packets 98911 bytes 5934660 jump DOCKER
|
||||
oifname "br-0d1490cc67c9" counter packets 69740 bytes 4118476 jump DOCKER
|
||||
oifname "br-3b338a381229" counter packets 32 bytes 1920 jump DOCKER
|
||||
oifname "br-3008d408e73a" counter packets 458 bytes 27480 jump DOCKER
|
||||
oifname "br-ca07a9577a7f" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "docker0" counter packets 87073 bytes 5223529 jump DOCKER
|
||||
oifname "br-a63fa64a9e18" counter packets 1353 bytes 81180 jump DOCKER
|
||||
oifname "br-1ccb887b3344" counter packets 7662 bytes 419862 jump DOCKER
|
||||
oifname "br-9fd22324ec08" counter packets 173 bytes 10380 jump DOCKER
|
||||
oifname "br-73641cceafc3" counter packets 162 bytes 9720 jump DOCKER
|
||||
oifname "br-77eb8a9e2ba1" counter packets 94 bytes 5640 jump DOCKER
|
||||
oifname "br-e99ce5248c84" counter packets 8 bytes 480 jump DOCKER
|
||||
oifname "br-e5d78502832d" counter packets 26 bytes 1560 jump DOCKER
|
||||
oifname "br-2e4a76a7cd2e" counter packets 7 bytes 420 jump DOCKER
|
||||
oifname "br-72fd626a8ff7" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
oifname "br-cadedce55fe9" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-dd007c7e67bc" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-a5fbc29c2c2a" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-6eb1e7f7f847" xt match "conntrack" counter packets 38458 bytes 6234236 accept
|
||||
oifname "br-8ce143481a5b" xt match "conntrack" counter packets 60403 bytes 20478794 accept
|
||||
oifname "br-84e7d0cfeada" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-f8b083119d99" xt match "conntrack" counter packets 1008024 bytes 206364436 accept
|
||||
oifname "br-0d1490cc67c9" xt match "conntrack" counter packets 871134 bytes 1416174426 accept
|
||||
oifname "br-3b338a381229" xt match "conntrack" counter packets 4649 bytes 2311375 accept
|
||||
oifname "br-3008d408e73a" xt match "conntrack" counter packets 13415 bytes 1974731 accept
|
||||
oifname "br-ca07a9577a7f" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "docker0" xt match "conntrack" counter packets 8909862 bytes 7892163419 accept
|
||||
oifname "br-a63fa64a9e18" xt match "conntrack" counter packets 16688 bytes 6822829 accept
|
||||
oifname "br-1ccb887b3344" xt match "conntrack" counter packets 461453 bytes 141913887 accept
|
||||
oifname "br-9fd22324ec08" xt match "conntrack" counter packets 1677 bytes 427538 accept
|
||||
oifname "br-73641cceafc3" xt match "conntrack" counter packets 417619 bytes 35343624 accept
|
||||
oifname "br-77eb8a9e2ba1" xt match "conntrack" counter packets 125437 bytes 94155193 accept
|
||||
oifname "br-e99ce5248c84" xt match "conntrack" counter packets 91 bytes 19173 accept
|
||||
oifname "br-e5d78502832d" xt match "conntrack" counter packets 128653 bytes 40539569 accept
|
||||
oifname "br-2e4a76a7cd2e" xt match "conntrack" counter packets 20257 bytes 158631592 accept
|
||||
oifname "br-72fd626a8ff7" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
|
||||
chain f2b-recidive {
|
||||
ip saddr 2.57.122.209 counter packets 0 bytes 0 xt target "REJECT"
|
||||
ip saddr 2.57.122.76 counter packets 127 bytes 7600 xt target "REJECT"
|
||||
ip saddr 195.178.110.228 counter packets 17 bytes 1000 xt target "REJECT"
|
||||
ip saddr 2.57.122.74 counter packets 11 bytes 620 xt target "REJECT"
|
||||
ip saddr 195.178.110.26 counter packets 56 bytes 3360 xt target "REJECT"
|
||||
ip saddr 92.118.39.77 counter packets 2 bytes 80 xt target "REJECT"
|
||||
ip saddr 92.118.39.71 counter packets 1 bytes 40 xt target "REJECT"
|
||||
ip saddr 45.148.10.240 counter packets 0 bytes 0 xt target "REJECT"
|
||||
ip saddr 195.178.110.30 counter packets 8 bytes 320 xt target "REJECT"
|
||||
counter packets 948810608 bytes 1740338848565 return
|
||||
}
|
||||
|
||||
chain f2b-sshd {
|
||||
counter packets 948810709 bytes 1740338655735 return
|
||||
}
|
||||
}
|
||||
# Warning: table ip6 filter is managed by iptables-nft, do not touch!
|
||||
table ip6 filter {
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy accept;
|
||||
counter packets 5426360 bytes 34419159588 jump ufw6-before-logging-input
|
||||
counter packets 5426360 bytes 34419159588 jump ufw6-before-input
|
||||
counter packets 367982 bytes 3415126642 jump ufw6-after-input
|
||||
counter packets 367982 bytes 3415126642 jump ufw6-after-logging-input
|
||||
counter packets 367982 bytes 3415126642 jump ufw6-reject-input
|
||||
counter packets 367982 bytes 3415126642 jump ufw6-track-input
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
counter packets 0 bytes 0 jump DOCKER-USER
|
||||
counter packets 0 bytes 0 jump DOCKER-FORWARD
|
||||
counter packets 0 bytes 0 jump ufw6-before-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw6-before-forward
|
||||
counter packets 0 bytes 0 jump ufw6-after-forward
|
||||
counter packets 0 bytes 0 jump ufw6-after-logging-forward
|
||||
counter packets 0 bytes 0 jump ufw6-reject-forward
|
||||
counter packets 0 bytes 0 jump ufw6-track-forward
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
counter packets 6004354 bytes 1866587952 jump ufw6-before-logging-output
|
||||
counter packets 6004354 bytes 1866587952 jump ufw6-before-output
|
||||
counter packets 2241898 bytes 639173314 jump ufw6-after-output
|
||||
counter packets 2241898 bytes 639173314 jump ufw6-after-logging-output
|
||||
counter packets 2241898 bytes 639173314 jump ufw6-reject-output
|
||||
counter packets 2241898 bytes 639173314 jump ufw6-track-output
|
||||
}
|
||||
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 0 bytes 0 jump DOCKER-CT
|
||||
counter packets 0 bytes 0 jump DOCKER-INTERNAL
|
||||
counter packets 0 bytes 0 jump DOCKER-BRIDGE
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
counter packets 0 bytes 0 jump ufw6-user-forward
|
||||
xt match "conntrack" counter packets 0 bytes 0 return
|
||||
xt match "conntrack" counter packets 0 bytes 0 drop
|
||||
iifname "docker0" oifname "docker0" counter packets 0 bytes 0 accept
|
||||
ip6 saddr fd00::/8 counter packets 0 bytes 0 return
|
||||
ip6 daddr fd00::/8 xt match "conntrack" counter packets 0 bytes 0 jump ufw6-docker-logging-deny
|
||||
counter packets 0 bytes 0 return
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-input {
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-output {
|
||||
}
|
||||
|
||||
chain ufw6-before-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw6-before-input {
|
||||
}
|
||||
|
||||
chain ufw6-before-output {
|
||||
}
|
||||
|
||||
chain ufw6-before-forward {
|
||||
}
|
||||
|
||||
chain ufw6-after-input {
|
||||
}
|
||||
|
||||
chain ufw6-after-output {
|
||||
}
|
||||
|
||||
chain ufw6-after-forward {
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-input {
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-output {
|
||||
}
|
||||
|
||||
chain ufw6-after-logging-forward {
|
||||
}
|
||||
|
||||
chain ufw6-reject-input {
|
||||
}
|
||||
|
||||
chain ufw6-reject-output {
|
||||
}
|
||||
|
||||
chain ufw6-reject-forward {
|
||||
}
|
||||
|
||||
chain ufw6-track-input {
|
||||
}
|
||||
|
||||
chain ufw6-track-output {
|
||||
}
|
||||
|
||||
chain ufw6-track-forward {
|
||||
}
|
||||
|
||||
chain ufw6-user-forward {
|
||||
}
|
||||
|
||||
chain ufw6-docker-logging-deny {
|
||||
limit rate 3/minute burst 10 packets counter packets 0 bytes 0 xt target "LOG"
|
||||
counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
}
|
||||
# Warning: table ip nat is managed by iptables-nft, do not touch!
|
||||
table ip nat {
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 10757093 bytes 647829087 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 128611 bytes 7705178 jump DOCKER
|
||||
}
|
||||
|
||||
chain POSTROUTING {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
ip saddr 172.19.0.0/16 oifname != "br-72fd626a8ff7" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
ip saddr 172.18.0.0/16 oifname != "br-2e4a76a7cd2e" counter packets 825 bytes 49500 xt target "MASQUERADE"
|
||||
ip saddr 192.168.112.0/20 oifname != "br-e5d78502832d" counter packets 126 bytes 7560 xt target "MASQUERADE"
|
||||
ip saddr 192.168.80.0/20 oifname != "br-e99ce5248c84" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
ip saddr 192.168.48.0/20 oifname != "br-77eb8a9e2ba1" counter packets 99 bytes 5940 xt target "MASQUERADE"
|
||||
ip saddr 192.168.128.0/20 oifname != "br-73641cceafc3" counter packets 536 bytes 32160 xt target "MASQUERADE"
|
||||
ip saddr 192.168.208.0/20 oifname != "br-9fd22324ec08" counter packets 2 bytes 120 xt target "MASQUERADE"
|
||||
ip saddr 192.168.203.0/24 oifname != "br-1ccb887b3344" counter packets 37248 bytes 2854476 xt target "MASQUERADE"
|
||||
ip saddr 192.168.64.0/20 oifname != "br-a63fa64a9e18" counter packets 353 bytes 21180 xt target "MASQUERADE"
|
||||
ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 99933 bytes 6001436 xt target "MASQUERADE"
|
||||
ip saddr 172.21.0.0/16 oifname != "br-84e7d0cfeada" counter packets 2 bytes 128 xt target "MASQUERADE"
|
||||
ip saddr 192.168.176.0/20 oifname != "br-f8b083119d99" counter packets 209 bytes 12644 xt target "MASQUERADE"
|
||||
ip saddr 172.20.0.0/16 oifname != "br-6eb1e7f7f847" counter packets 699 bytes 42516 xt target "MASQUERADE"
|
||||
ip saddr 172.28.0.0/16 oifname != "br-8ce143481a5b" counter packets 1934 bytes 116040 xt target "MASQUERADE"
|
||||
ip saddr 172.27.0.0/16 oifname != "br-3008d408e73a" counter packets 2904 bytes 174240 xt target "MASQUERADE"
|
||||
ip saddr 172.25.0.0/16 oifname != "br-cadedce55fe9" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
ip saddr 172.24.0.0/16 oifname != "br-3b338a381229" counter packets 385 bytes 23164 xt target "MASQUERADE"
|
||||
ip saddr 192.168.224.0/20 oifname != "br-ca07a9577a7f" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
ip saddr 192.168.0.0/20 oifname != "br-a5fbc29c2c2a" counter packets 10 bytes 600 xt target "MASQUERADE"
|
||||
ip saddr 172.31.0.0/16 oifname != "br-dd007c7e67bc" counter packets 0 bytes 0 xt target "MASQUERADE"
|
||||
ip saddr 192.168.240.0/20 oifname != "br-0d1490cc67c9" counter packets 587045 bytes 35224163 xt target "MASQUERADE"
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
iifname != "docker0" tcp dport 5100 counter packets 8247 bytes 494812 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 222 counter packets 2304 bytes 137444 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 20000 counter packets 1532 bytes 91584 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 25 counter packets 433 bytes 23099 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 7080 counter packets 35 bytes 1864 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 110 counter packets 195 bytes 9741 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 143 counter packets 448 bytes 25580 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 7443 counter packets 58 bytes 2868 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 465 counter packets 107 bytes 6032 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 587 counter packets 447 bytes 23492 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 993 counter packets 201 bytes 10174 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 995 counter packets 197 bytes 11180 xt target "DNAT"
|
||||
iifname != "br-1ccb887b3344" tcp dport 20004 counter packets 5 bytes 300 xt target "DNAT"
|
||||
iifname != "br-9fd22324ec08" tcp dport 20005 counter packets 5 bytes 300 xt target "DNAT"
|
||||
iifname != "br-73641cceafc3" tcp dport 20006 counter packets 19 bytes 1140 xt target "DNAT"
|
||||
iifname != "br-e5d78502832d" tcp dport 20007 counter packets 5 bytes 284 xt target "DNAT"
|
||||
iifname != "br-e5d78502832d" tcp dport 20008 counter packets 4 bytes 240 xt target "DNAT"
|
||||
iifname != "br-e99ce5248c84" tcp dport 1842 counter packets 12 bytes 720 xt target "DNAT"
|
||||
iifname != "br-8ce143481a5b" tcp dport 4848 counter packets 40 bytes 1960 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 4222 counter packets 3846 bytes 231012 xt target "DNAT"
|
||||
ip daddr 127.0.0.1 iifname != "docker0" tcp dport 8222 counter packets 0 bytes 0 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 20003 counter packets 18942 bytes 1136512 xt target "DNAT"
|
||||
iifname != "br-2e4a76a7cd2e" tcp dport 9070 counter packets 195 bytes 11676 xt target "DNAT"
|
||||
iifname != "br-77eb8a9e2ba1" tcp dport 9102 counter packets 13 bytes 772 xt target "DNAT"
|
||||
iifname != "br-77eb8a9e2ba1" tcp dport 8102 counter packets 17 bytes 944 xt target "DNAT"
|
||||
iifname != "br-77eb8a9e2ba1" tcp dport 8104 counter packets 16 bytes 916 xt target "DNAT"
|
||||
iifname != "br-77eb8a9e2ba1" tcp dport 8103 counter packets 13 bytes 756 xt target "DNAT"
|
||||
iifname != "br-3008d408e73a" tcp dport 1212 counter packets 189 bytes 11188 xt target "DNAT"
|
||||
iifname != "br-6eb1e7f7f847" tcp dport 20009 counter packets 138 bytes 8280 xt target "DNAT"
|
||||
iifname != "br-f8b083119d99" tcp dport 20001 counter packets 47780 bytes 2866736 xt target "DNAT"
|
||||
iifname != "br-f8b083119d99" tcp dport 20002 counter packets 7 bytes 404 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 20010 counter packets 74 bytes 4424 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 20011 counter packets 4 bytes 240 xt target "DNAT"
|
||||
iifname != "br-72fd626a8ff7" tcp dport 20012 counter packets 237 bytes 14220 xt target "DNAT"
|
||||
iifname != "docker0" tcp dport 6852 counter packets 16489 bytes 989324 xt target "DNAT"
|
||||
}
|
||||
}
|
||||
# Warning: table ip6 nat is managed by iptables-nft, do not touch!
|
||||
table ip6 nat {
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 399 bytes 22104 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
}
|
||||
}
|
||||
table ip raw {
|
||||
chain PREROUTING {
|
||||
type filter hook prerouting priority raw; policy accept;
|
||||
ip daddr 127.0.0.1 iifname != "lo" tcp dport 8222 counter packets 0 bytes 0 drop
|
||||
}
|
||||
}
|
||||
table ip mangle {
|
||||
chain FORWARD {
|
||||
type filter hook forward priority mangle; policy accept;
|
||||
}
|
||||
}
|
||||
table inet mesh {
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iif "lo" accept
|
||||
iifname != { "mesh0", "enp9s0" } accept
|
||||
icmp type echo-request accept
|
||||
icmpv6 type { echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
|
||||
iifname != { "mesh0", "enp9s0" } udp dport { 53, 67 } accept
|
||||
iifname != { "mesh0", "enp9s0" } tcp dport 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 22 accept
|
||||
tcp dport 22 accept
|
||||
tcp dport 4222 accept
|
||||
tcp dport 22 accept
|
||||
tcp dport 25 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } udp dport 53 accept
|
||||
tcp dport 80 accept
|
||||
tcp dport 110 accept
|
||||
tcp dport 143 accept
|
||||
tcp dport 222 accept
|
||||
tcp dport 443 accept
|
||||
tcp dport 465 accept
|
||||
tcp dport 587 accept
|
||||
tcp dport 993 accept
|
||||
tcp dport 995 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 1212 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 1842 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 4222 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 4848 accept
|
||||
tcp dport 5100 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 6852 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 7080 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 7443 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 8102 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 8103 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 8104 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 9000 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 9070 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 9102 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20000 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20001 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20002 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20003 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20004 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20005 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20006 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20007 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20008 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20009 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20010 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20011 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 20012 accept
|
||||
udp dport 51820 accept
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iifname != { "mesh0", "enp9s0" } accept
|
||||
iifname "mesh0" oifname "mesh0" accept
|
||||
ct original proto-dst 22 accept
|
||||
ct original proto-dst 25 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept
|
||||
ct original proto-dst 80 accept
|
||||
ct original proto-dst 110 accept
|
||||
ct original proto-dst 143 accept
|
||||
ct original proto-dst 222 accept
|
||||
ct original proto-dst 443 accept
|
||||
ct original proto-dst 465 accept
|
||||
ct original proto-dst 587 accept
|
||||
ct original proto-dst 993 accept
|
||||
ct original proto-dst 995 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 1212 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 1842 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 4222 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 4848 accept
|
||||
ct original proto-dst 5100 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 6852 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 7080 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 7443 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 8102 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 8103 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 8104 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 9000 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 9070 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 9102 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20000 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20001 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20002 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20003 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20004 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20005 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20006 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20007 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20008 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20009 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20010 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20011 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 20012 accept
|
||||
ct original proto-dst 51820 accept
|
||||
ct original proto-dst 4222 accept
|
||||
}
|
||||
}
|
||||
+149
@@ -0,0 +1,149 @@
|
||||
-P INPUT ACCEPT
|
||||
-P FORWARD DROP
|
||||
-P OUTPUT ACCEPT
|
||||
-N DOCKER
|
||||
-N DOCKER-BRIDGE
|
||||
-N DOCKER-CT
|
||||
-N DOCKER-FORWARD
|
||||
-N DOCKER-INTERNAL
|
||||
-N DOCKER-USER
|
||||
-N HAL-MESH-ONLY
|
||||
-N ufw-after-forward
|
||||
-N ufw-after-input
|
||||
-N ufw-after-logging-forward
|
||||
-N ufw-after-logging-input
|
||||
-N ufw-after-logging-output
|
||||
-N ufw-after-output
|
||||
-N ufw-before-forward
|
||||
-N ufw-before-input
|
||||
-N ufw-before-logging-forward
|
||||
-N ufw-before-logging-input
|
||||
-N ufw-before-logging-output
|
||||
-N ufw-before-output
|
||||
-N ufw-reject-forward
|
||||
-N ufw-reject-input
|
||||
-N ufw-reject-output
|
||||
-N ufw-track-forward
|
||||
-N ufw-track-input
|
||||
-N ufw-track-output
|
||||
-A INPUT -j ufw-before-logging-input
|
||||
-A INPUT -j ufw-before-input
|
||||
-A INPUT -j ufw-after-input
|
||||
-A INPUT -j ufw-after-logging-input
|
||||
-A INPUT -j ufw-reject-input
|
||||
-A INPUT -j ufw-track-input
|
||||
-A FORWARD -j DOCKER-USER
|
||||
-A FORWARD -j DOCKER-FORWARD
|
||||
-A FORWARD -j ufw-before-logging-forward
|
||||
-A FORWARD -j ufw-before-forward
|
||||
-A FORWARD -j ufw-after-forward
|
||||
-A FORWARD -j ufw-after-logging-forward
|
||||
-A FORWARD -j ufw-reject-forward
|
||||
-A FORWARD -j ufw-track-forward
|
||||
-A OUTPUT -j ufw-before-logging-output
|
||||
-A OUTPUT -j ufw-before-output
|
||||
-A OUTPUT -j ufw-after-output
|
||||
-A OUTPUT -j ufw-after-logging-output
|
||||
-A OUTPUT -j ufw-reject-output
|
||||
-A OUTPUT -j ufw-track-output
|
||||
-A DOCKER -d 172.17.0.18/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8686 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.14/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8989 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.15/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 7878 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.5/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9117 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.13/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 6789 -j ACCEPT
|
||||
-A DOCKER -d 172.19.0.2/32 ! -i br-32062158f584 -o br-32062158f584 -p tcp -m tcp --dport 8080 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.2/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 5432 -j ACCEPT
|
||||
-A DOCKER -d 172.27.0.2/32 ! -i br-0910a98c6158 -o br-0910a98c6158 -p tcp -m tcp --dport 5678 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.21/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 3579 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.19/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8181 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.17/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8787 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.16/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 6767 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.12/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 3000 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.11/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 80 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.10/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9443 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.10/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 9000 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.9/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 3000 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.7/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 1880 -j ACCEPT
|
||||
-A DOCKER -d 172.28.0.2/32 ! -i br-b11461b5b028 -o br-b11461b5b028 -p tcp -m tcp --dport 80 -j ACCEPT
|
||||
-A DOCKER -d 172.23.0.14/32 ! -i br-66ffa5c1cba5 -o br-66ffa5c1cba5 -p tcp -m tcp --dport 6543 -j ACCEPT
|
||||
-A DOCKER -d 172.23.0.14/32 ! -i br-66ffa5c1cba5 -o br-66ffa5c1cba5 -p tcp -m tcp --dport 5432 -j ACCEPT
|
||||
-A DOCKER -d 172.23.0.5/32 ! -i br-66ffa5c1cba5 -o br-66ffa5c1cba5 -p tcp -m tcp --dport 8000 -j ACCEPT
|
||||
-A DOCKER -d 172.26.0.3/32 ! -i br-b0fec361ccaa -o br-b0fec361ccaa -p tcp -m tcp --dport 6167 -j ACCEPT
|
||||
-A DOCKER -d 172.26.0.2/32 ! -i br-b0fec361ccaa -o br-b0fec361ccaa -p tcp -m tcp --dport 80 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.8/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8000 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p udp -m udp --dport 10001 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8880 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8843 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8443 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8080 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 6789 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p udp -m udp --dport 5514 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p udp -m udp --dport 3478 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.6/32 ! -i docker0 -o docker0 -p udp -m udp --dport 1900 -j ACCEPT
|
||||
-A DOCKER -d 172.25.0.3/32 ! -i br-b98821f7dc38 -o br-b98821f7dc38 -p tcp -m tcp --dport 8000 -j ACCEPT
|
||||
-A DOCKER -d 172.18.0.3/32 ! -i br-442a0bfc65f8 -o br-442a0bfc65f8 -p tcp -m tcp --dport 1433 -j ACCEPT
|
||||
-A DOCKER -d 172.20.0.3/32 ! -i br-afa37ac8b33d -o br-afa37ac8b33d -p tcp -m tcp --dport 8081 -j ACCEPT
|
||||
-A DOCKER -d 172.20.0.3/32 ! -i br-afa37ac8b33d -o br-afa37ac8b33d -p tcp -m tcp --dport 1883 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.4/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 8086 -j ACCEPT
|
||||
-A DOCKER -d 172.21.0.2/32 ! -i br-df15d8e19ec7 -o br-df15d8e19ec7 -p tcp -m tcp --dport 6379 -j ACCEPT
|
||||
-A DOCKER -d 172.30.0.3/32 ! -i br-521eab9a3a5e -o br-521eab9a3a5e -p tcp -m tcp --dport 8283 -j ACCEPT
|
||||
-A DOCKER -d 172.17.0.3/32 ! -i docker0 -o docker0 -p tcp -m tcp --dport 3000 -j ACCEPT
|
||||
-A DOCKER ! -i br-32062158f584 -o br-32062158f584 -j DROP
|
||||
-A DOCKER ! -i docker0 -o docker0 -j DROP
|
||||
-A DOCKER ! -i br-521eab9a3a5e -o br-521eab9a3a5e -j DROP
|
||||
-A DOCKER ! -i br-df15d8e19ec7 -o br-df15d8e19ec7 -j DROP
|
||||
-A DOCKER ! -i br-afa37ac8b33d -o br-afa37ac8b33d -j DROP
|
||||
-A DOCKER ! -i br-442a0bfc65f8 -o br-442a0bfc65f8 -j DROP
|
||||
-A DOCKER ! -i br-b98821f7dc38 -o br-b98821f7dc38 -j DROP
|
||||
-A DOCKER ! -i br-b0fec361ccaa -o br-b0fec361ccaa -j DROP
|
||||
-A DOCKER ! -i br-66ffa5c1cba5 -o br-66ffa5c1cba5 -j DROP
|
||||
-A DOCKER ! -i br-b11461b5b028 -o br-b11461b5b028 -j DROP
|
||||
-A DOCKER ! -i br-2df4e541b877 -o br-2df4e541b877 -j DROP
|
||||
-A DOCKER ! -i br-0910a98c6158 -o br-0910a98c6158 -j DROP
|
||||
-A DOCKER-BRIDGE -o br-32062158f584 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o docker0 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-521eab9a3a5e -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-df15d8e19ec7 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-afa37ac8b33d -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-442a0bfc65f8 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-b98821f7dc38 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-b0fec361ccaa -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-66ffa5c1cba5 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-b11461b5b028 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-2df4e541b877 -j DOCKER
|
||||
-A DOCKER-BRIDGE -o br-0910a98c6158 -j DOCKER
|
||||
-A DOCKER-CT -o br-32062158f584 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-521eab9a3a5e -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-df15d8e19ec7 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-afa37ac8b33d -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-442a0bfc65f8 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-b98821f7dc38 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-b0fec361ccaa -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-66ffa5c1cba5 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-b11461b5b028 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-2df4e541b877 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-CT -o br-0910a98c6158 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
-A DOCKER-FORWARD -j DOCKER-CT
|
||||
-A DOCKER-FORWARD -j DOCKER-INTERNAL
|
||||
-A DOCKER-FORWARD -j DOCKER-BRIDGE
|
||||
-A DOCKER-FORWARD -i br-32062158f584 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i docker0 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-521eab9a3a5e -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-df15d8e19ec7 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-afa37ac8b33d -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-442a0bfc65f8 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-b98821f7dc38 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-b0fec361ccaa -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-66ffa5c1cba5 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-b11461b5b028 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-2df4e541b877 -j ACCEPT
|
||||
-A DOCKER-FORWARD -i br-0910a98c6158 -j ACCEPT
|
||||
-A DOCKER-USER -i enp6s0 -p tcp -m conntrack --ctstate NEW -j HAL-MESH-ONLY
|
||||
-A HAL-MESH-ONLY -m conntrack --ctorigdstport 6881 -j RETURN
|
||||
-A HAL-MESH-ONLY -m conntrack --ctorigdstport 80 -j RETURN
|
||||
-A HAL-MESH-ONLY -m conntrack --ctorigdstport 443 -j RETURN
|
||||
-A HAL-MESH-ONLY -s 10.0.0.0/8 -j RETURN
|
||||
-A HAL-MESH-ONLY -s 172.16.0.0/12 -j RETURN
|
||||
-A HAL-MESH-ONLY -s 192.168.0.0/16 -j RETURN
|
||||
-A HAL-MESH-ONLY -m comment --comment "HAL: not public -> mesh only" -j DROP
|
||||
+327
@@ -0,0 +1,327 @@
|
||||
table ip mangle {
|
||||
chain FORWARD {
|
||||
type filter hook forward priority mangle; policy accept;
|
||||
}
|
||||
}
|
||||
# Warning: table ip nat is managed by iptables-nft, do not touch!
|
||||
table ip nat {
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 12072 bytes 4564241 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip daddr != 127.0.0.0/8 xt match "addrtype" counter packets 1854 bytes 111240 jump DOCKER
|
||||
}
|
||||
|
||||
chain POSTROUTING {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
ip saddr 172.17.0.0/16 oifname != "docker0" counter packets 903 bytes 61577 xt target "MASQUERADE"
|
||||
ip saddr 172.21.0.0/16 oifname != "br-86a5d6b30e2b" counter packets 344 bytes 27744 xt target "MASQUERADE"
|
||||
ip saddr 172.25.0.0/16 oifname != "br-61495e14a004" counter packets 374 bytes 33016 xt target "MASQUERADE"
|
||||
ip saddr 172.30.0.0/16 oifname != "br-5107796ee9b4" counter packets 352 bytes 28224 xt target "MASQUERADE"
|
||||
ip saddr 172.18.0.0/16 oifname != "br-cfd337ac4e58" counter packets 339 bytes 27444 xt target "MASQUERADE"
|
||||
ip saddr 172.19.0.0/16 oifname != "br-8f0c6ee01425" counter packets 351 bytes 28164 xt target "MASQUERADE"
|
||||
ip saddr 172.22.0.0/16 oifname != "br-75ac3c36e87f" counter packets 333 bytes 27084 xt target "MASQUERADE"
|
||||
ip saddr 172.20.0.0/16 oifname != "br-0529801521bc" counter packets 343 bytes 27404 xt target "MASQUERADE"
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
iifname != "br-61495e14a004" tcp dport 5680 counter packets 2 bytes 120 xt target "DNAT"
|
||||
ip daddr 127.0.0.1 iifname != "br-61495e14a004" tcp dport 15673 counter packets 0 bytes 0 xt target "DNAT"
|
||||
ip daddr 127.0.0.1 iifname != "docker0" tcp dport 55432 counter packets 0 bytes 0 xt target "DNAT"
|
||||
}
|
||||
}
|
||||
# Warning: table ip filter is managed by iptables-nft, do not touch!
|
||||
table ip filter {
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 702328 bytes 1801910999 jump DOCKER-CT
|
||||
counter packets 337315 bytes 23928864 jump DOCKER-INTERNAL
|
||||
counter packets 337315 bytes 23928864 jump DOCKER-BRIDGE
|
||||
iifname "br-75ac3c36e87f" counter packets 0 bytes 0 accept
|
||||
iifname "br-86a5d6b30e2b" counter packets 0 bytes 0 accept
|
||||
iifname "br-8f0c6ee01425" counter packets 0 bytes 0 accept
|
||||
iifname "br-cfd337ac4e58" counter packets 0 bytes 0 accept
|
||||
iifname "br-0529801521bc" counter packets 0 bytes 0 accept
|
||||
iifname "br-5107796ee9b4" counter packets 0 bytes 0 accept
|
||||
iifname "br-61495e14a004" counter packets 0 bytes 0 accept
|
||||
iifname "docker0" counter packets 337315 bytes 23928864 accept
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
counter packets 702328 bytes 1801910999 jump DOCKER-USER
|
||||
counter packets 702328 bytes 1801910999 jump DOCKER-FORWARD
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
ip protocol tcp counter packets 702510 bytes 1801965868 jump f2b-sshd
|
||||
oifname "incusbr0" counter packets 0 bytes 0 accept
|
||||
iifname "incusbr0" counter packets 0 bytes 0 accept
|
||||
}
|
||||
|
||||
chain f2b-sshd {
|
||||
counter packets 10423854 bytes 13891318049 return
|
||||
}
|
||||
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy accept;
|
||||
ip protocol tcp counter packets 9721344 bytes 12089352181 jump f2b-sshd
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
ip daddr 172.17.0.2 iifname != "docker0" oifname "docker0" tcp dport 5432 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.25.0.2 iifname != "br-61495e14a004" oifname "br-61495e14a004" tcp dport 15672 counter packets 0 bytes 0 accept
|
||||
ip daddr 172.25.0.2 iifname != "br-61495e14a004" oifname "br-61495e14a004" tcp dport 5672 counter packets 0 bytes 0 accept
|
||||
iifname != "br-75ac3c36e87f" oifname "br-75ac3c36e87f" counter packets 0 bytes 0 drop
|
||||
iifname != "br-86a5d6b30e2b" oifname "br-86a5d6b30e2b" counter packets 0 bytes 0 drop
|
||||
iifname != "br-8f0c6ee01425" oifname "br-8f0c6ee01425" counter packets 0 bytes 0 drop
|
||||
iifname != "br-cfd337ac4e58" oifname "br-cfd337ac4e58" counter packets 0 bytes 0 drop
|
||||
iifname != "br-0529801521bc" oifname "br-0529801521bc" counter packets 0 bytes 0 drop
|
||||
iifname != "br-5107796ee9b4" oifname "br-5107796ee9b4" counter packets 0 bytes 0 drop
|
||||
iifname != "br-61495e14a004" oifname "br-61495e14a004" counter packets 0 bytes 0 drop
|
||||
iifname != "docker0" oifname "docker0" counter packets 0 bytes 0 drop
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
oifname "br-75ac3c36e87f" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-86a5d6b30e2b" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-8f0c6ee01425" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-cfd337ac4e58" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-0529801521bc" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-5107796ee9b4" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "br-61495e14a004" counter packets 0 bytes 0 jump DOCKER
|
||||
oifname "docker0" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
oifname "br-75ac3c36e87f" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-86a5d6b30e2b" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-8f0c6ee01425" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-cfd337ac4e58" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-0529801521bc" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-5107796ee9b4" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "br-61495e14a004" xt match "conntrack" counter packets 0 bytes 0 accept
|
||||
oifname "docker0" xt match "conntrack" counter packets 365013 bytes 1777982135 accept
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
}
|
||||
# Warning: table ip6 nat is managed by iptables-nft, do not touch!
|
||||
table ip6 nat {
|
||||
chain PREROUTING {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
xt match "addrtype" counter packets 363 bytes 67927 jump DOCKER
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
ip6 daddr != ::1 xt match "addrtype" counter packets 0 bytes 0 jump DOCKER
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
}
|
||||
}
|
||||
table ip6 filter {
|
||||
chain DOCKER-FORWARD {
|
||||
counter packets 0 bytes 0 jump DOCKER-CT
|
||||
counter packets 0 bytes 0 jump DOCKER-INTERNAL
|
||||
counter packets 0 bytes 0 jump DOCKER-BRIDGE
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
counter packets 0 bytes 0 jump DOCKER-USER
|
||||
counter packets 0 bytes 0 jump DOCKER-FORWARD
|
||||
}
|
||||
|
||||
chain DOCKER-USER {
|
||||
}
|
||||
|
||||
chain DOCKER {
|
||||
}
|
||||
|
||||
chain DOCKER-BRIDGE {
|
||||
}
|
||||
|
||||
chain DOCKER-CT {
|
||||
}
|
||||
|
||||
chain DOCKER-INTERNAL {
|
||||
}
|
||||
}
|
||||
table ip raw {
|
||||
chain PREROUTING {
|
||||
type filter hook prerouting priority raw; policy accept;
|
||||
ip daddr 172.25.0.2 iifname != "br-61495e14a004" counter packets 0 bytes 0 drop
|
||||
ip daddr 127.0.0.1 iifname != "lo" tcp dport 15673 counter packets 0 bytes 0 drop
|
||||
ip daddr 172.17.0.2 iifname != "docker0" counter packets 0 bytes 0 drop
|
||||
ip daddr 127.0.0.1 iifname != "lo" tcp dport 55432 counter packets 0 bytes 0 drop
|
||||
}
|
||||
}
|
||||
table inet incus {
|
||||
set bridges {
|
||||
type ifname
|
||||
elements = { "incusbr0" }
|
||||
}
|
||||
|
||||
chain pstrt.incusbr0 {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
ip saddr 10.7.169.0/24 oifname @bridges accept
|
||||
ip saddr 10.7.169.0/24 ip daddr != 10.7.169.0/24 masquerade
|
||||
ip6 saddr fd42:cbc4:e123:f6::/64 oifname @bridges accept
|
||||
ip6 saddr fd42:cbc4:e123:f6::/64 ip6 daddr != fd42:cbc4:e123:f6::/64 masquerade
|
||||
}
|
||||
|
||||
chain fwd.incusbr0 {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
ip version 4 oifname "incusbr0" accept
|
||||
ip version 4 iifname "incusbr0" accept
|
||||
ip6 version 6 oifname "incusbr0" accept
|
||||
ip6 version 6 iifname "incusbr0" accept
|
||||
}
|
||||
|
||||
chain in.incusbr0 {
|
||||
type filter hook input priority filter; policy accept;
|
||||
iifname "incusbr0" tcp dport 53 accept
|
||||
iifname "incusbr0" udp dport 53 accept
|
||||
iifname "incusbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept
|
||||
iifname "incusbr0" udp dport 67 accept
|
||||
iifname "incusbr0" ip protocol udp udp checksum set 0
|
||||
iifname "incusbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, nd-router-solicit, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept
|
||||
iifname "incusbr0" udp dport 547 accept
|
||||
}
|
||||
|
||||
chain out.incusbr0 {
|
||||
type filter hook output priority filter; policy accept;
|
||||
oifname "incusbr0" tcp sport 53 accept
|
||||
oifname "incusbr0" udp sport 53 accept
|
||||
oifname "incusbr0" icmp type { destination-unreachable, time-exceeded, parameter-problem } accept
|
||||
oifname "incusbr0" udp sport 67 accept
|
||||
oifname "incusbr0" ip protocol udp udp checksum set 0
|
||||
oifname "incusbr0" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, mld2-listener-report } accept
|
||||
oifname "incusbr0" udp sport 547 accept
|
||||
}
|
||||
}
|
||||
table ip fct_filter {
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-QUARANTINE-EMS {
|
||||
}
|
||||
|
||||
chain FCT-QUARANTINE-FAZ {
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-WEBFILTER-QUIC-CHAIN {
|
||||
}
|
||||
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-QUARANTINE {
|
||||
}
|
||||
|
||||
chain FCT-DNS-QUIC-FILTER {
|
||||
}
|
||||
|
||||
chain FCT-VPN-CHAIN {
|
||||
}
|
||||
}
|
||||
table ip fct_nat {
|
||||
chain OUTPUT {
|
||||
type nat hook output priority dstnat; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-DNS-UDP-CHAIN-STAGE-2 {
|
||||
}
|
||||
|
||||
chain FCT-DNS-UDP-CHAIN-STAGE-1 {
|
||||
}
|
||||
|
||||
chain FCT-TCP-CHAIN {
|
||||
}
|
||||
|
||||
chain FCT-DNS-DOH-CHAIN-STAGE-1 {
|
||||
}
|
||||
|
||||
chain FCT-WEBFILTER-CHAIN {
|
||||
}
|
||||
|
||||
chain FCT-DNS-DOH-CHAIN-STAGE-2 {
|
||||
}
|
||||
}
|
||||
table ip6 fct_filter {
|
||||
chain FCT-QUARANTINE {
|
||||
}
|
||||
|
||||
chain INPUT {
|
||||
type filter hook input priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain FORWARD {
|
||||
type filter hook forward priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type filter hook output priority filter; policy accept;
|
||||
}
|
||||
}
|
||||
table ip fct_mangle {
|
||||
chain PREROUTING {
|
||||
type filter hook prerouting priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-UDP-STAGE-1 {
|
||||
}
|
||||
|
||||
chain OUTPUT {
|
||||
type route hook output priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain FCT-UDP-STAGE-2 {
|
||||
}
|
||||
|
||||
chain FCT-UDP-OUTPUT {
|
||||
}
|
||||
}
|
||||
table inet mesh {
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iif "lo" accept
|
||||
iifname != { "mesh0", "wlp3s0" } accept
|
||||
icmp type echo-request accept
|
||||
icmpv6 type { echo-request, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } accept
|
||||
iifname != { "mesh0", "wlp3s0" } udp dport { 53, 67 } accept
|
||||
iifname != { "mesh0", "wlp3s0" } tcp dport 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 22 accept
|
||||
tcp dport 22 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } tcp dport 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } udp dport 53 accept
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority filter; policy accept;
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iifname != { "mesh0", "wlp3s0" } accept
|
||||
iifname "mesh0" oifname "mesh0" accept
|
||||
ct original proto-dst 22 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept
|
||||
ip saddr { 10.10.0.1, 10.10.0.2, 10.10.0.3, 10.10.0.4 } ct original proto-dst 53 accept
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user