options-ipv4.rules 2.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152
  1. # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011
  2. *mangle
  3. :PREROUTING ACCEPT [2461:977932]
  4. :INPUT ACCEPT [2461:977932]
  5. :FORWARD ACCEPT [0:0]
  6. :OUTPUT ACCEPT [1740:367048]
  7. :POSTROUTING ACCEPT [1740:367048]
  8. # libipt_
  9. -A INPUT -p ah -m ah --ahspi 1
  10. -A INPUT -p ah -m ah --ahspi :2
  11. -A INPUT -p ah -m ah --ahspi 0:3
  12. -A INPUT -p ah -m ah --ahspi 4:
  13. -A INPUT -p ah -m ah --ahspi 5:4294967295
  14. -A FORWARD -p tcp -j ECN --ecn-tcp-remove
  15. -A FORWARD -j LOG --log-prefix "hi" --log-tcp-sequence --log-tcp-options --log-ip-options --log-uid --log-macdecode
  16. -A FORWARD -j TTL --ttl-inc 1
  17. -A FORWARD -j TTL --ttl-dec 1
  18. -A FORWARD -j TTL --ttl-set 1
  19. -A FORWARD -j ULOG --ulog-prefix "abc" --ulog-cprange 2 --ulog-qthreshold 2
  20. COMMIT
  21. # Completed on Mon Jan 31 03:03:38 2011
  22. # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011
  23. *nat
  24. :PREROUTING ACCEPT [0:0]
  25. :INPUT ACCEPT [0:0]
  26. :OUTPUT ACCEPT [0:0]
  27. :POSTROUTING ACCEPT [0:0]
  28. -A PREROUTING -d 1.2.3.4/32 -i lo -j CLUSTERIP --new --hashmode sourceip --clustermac 01:02:03:04:05:06 --total-nodes 9 --local-node 2 --hash-init 123456789
  29. -A PREROUTING -i dummy0 -j DNAT --to-destination 1.2.3.4 --random --persistent
  30. -A PREROUTING -i dummy0 -p tcp -j REDIRECT --to-ports 1-2 --random
  31. -A POSTROUTING -o dummy0 -p tcp -j MASQUERADE --to-ports 1-2 --random
  32. -A POSTROUTING -o dummy0 -p tcp -j NETMAP --to 1.0.0.0/8
  33. -A POSTROUTING -o dummy0 -p tcp -j SNAT --to-source 1.2.3.4-1.2.3.5 --random --persistent
  34. COMMIT
  35. # Completed on Mon Jan 31 03:03:38 2011
  36. # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011
  37. *filter
  38. :INPUT ACCEPT [76:13548]
  39. :FORWARD ACCEPT [0:0]
  40. :OUTPUT ACCEPT [59:11240]
  41. #-A INPUT -m addrtype --src-type UNICAST --dst-type UNICAST --limit-iface-in
  42. -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 0
  43. -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 1
  44. -A INPUT -p icmp -m icmp --icmp-type 5/0
  45. -A INPUT -p icmp -m icmp --icmp-type 5/1
  46. -A INPUT -p icmp -m icmp --icmp-type 5
  47. -A INPUT -m realm --realm 0x1 -m ttl --ttl-eq 64 -m ttl --ttl-lt 64 -m ttl --ttl-gt 64
  48. -A FORWARD -p tcp -j REJECT --reject-with tcp-reset
  49. COMMIT
  50. # Completed on Mon Jan 31 03:03:39 2011