Keresés

Új hozzászólás Aktív témák

  • jerry311

    nagyúr

    válasz Zwodkassy #11432 üzenetére

                                                 Flags: X - disabled, I - invalid, D - dynamic 
     0  D ;;; special dummy rule to show fasttrack counters
          chain=forward action=passthrough 
     1    chain=input action=accept src-address=10.0.10.0/24 log=no log-prefix="" 
     2    ;;; defconf: drop invalid
          chain=input action=drop connection-state=invalid log=no log-prefix="" 
     3    ;;; defconf: drop invalid
          chain=forward action=drop connection-state=invalid log=no log-prefix="" 
     4    ;;; defconf: accept in ipsec policy
          chain=forward action=accept ipsec-policy=in,ipsec 
     5    ;;; defconf: accept out ipsec policy
          chain=forward action=accept ipsec-policy=out,ipsec 
     6    ;;; defconf: fasttrack
          chain=forward action=fasttrack-connection connection-state=established,related 
     7    ;;; defconf: accept established,related, untracked
          chain=forward action=accept connection-state=established,related,untracked 
     8    chain=forward action=accept protocol=tcp dst-address-list=dyndnslist in-interface-list=WAN dst-port=5000 log=no log-prefix="" 
     9    chain=forward action=accept protocol=tcp dst-address-list=dyndnslist in-interface-list=WAN dst-port=80 log=no log-prefix="" 
    10    chain=forward action=accept protocol=tcp dst-address-list=dyndnslist in-interface-list=WAN dst-port=5001 log=no log-prefix="" 
    11    chain=forward action=accept protocol=tcp dst-address-list=dyndnslist in-interface-list=WAN dst-port=443 log=no log-prefix="" 
    12    ;;; defconf: accept established,related,untracked
          chain=input action=accept connection-state=established,related log=no log-prefix="" 
    13    chain=input action=accept protocol=udp dst-port=500 log=no log-prefix="" 
    14    chain=input action=accept protocol=udp dst-port=4500 log=no log-prefix="" 
    15    chain=input action=accept protocol=ipsec-esp log=no log-prefix="" 
    16    ;;; defconf:  drop all from WAN not DSTNATed
          chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN 
    17    chain=output action=accept protocol=udp src-address=127.0.0.1 dst-address=127.0.0.1 port=5246,5247 
    18    chain=input action=accept protocol=udp src-address=127.0.0.1 dst-address=127.0.0.1 port=5246,5247 
    19    ;;; defconf: accept ICMP
          chain=input action=accept protocol=icmp 
    20    ;;; defconf: drop all coming from WAN
          chain=input action=drop in-interface-list=WAN log=no log-prefix="" 

Új hozzászólás Aktív témák