iptables -nvL
root@OpenWrt:~# iptables -nvL
Chain INPUT (policy ACCEPT 54 packets, 3750 bytes)
pkts bytes target prot opt in out source destination
2804 360K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
119 7518 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
44 2612 syn_flood tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02
345 31284 input_rule all -- * * 0.0.0.0/0 0.0.0.0/0
344 31188 input all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 forwarding_rule all -- * * 0.0.0.0/0 0.0.0. 0/0
0 0 forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
2746 1039K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
119 7518 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
264 19104 output_rule all -- * * 0.0.0.0/0 0.0.0.0/0
264 19104 output all -- * * 0.0.0.0/0 0.0.0.0/0
Chain forward (1 references)
pkts bytes target prot opt in out source destination
0 0 zone_lan_forward all -- br-lan * 0.0.0.0/0 0.0.0 .0/0
0 0 zone_wan3g_forward all -- 3g-wan3g * 0.0.0.0/0 0 .0.0.0/0
Chain forwarding_lan (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * tun0 0.0.0.0/0 0.0.0.0/0
Chain forwarding_rule (1 references)
pkts bytes target prot opt in out source destination
Chain forwarding_tun0 (1 references)
pkts bytes target prot opt in out source destination
Chain forwarding_wan (1 references)
pkts bytes target prot opt in out source destination
Chain forwarding_wan3g (1 references)
pkts bytes target prot opt in out source destination
Chain input (1 references)
pkts bytes target prot opt in out source destination
283 25978 zone_lan all -- br-lan * 0.0.0.0/0 0.0.0.0/0
1 81 zone_wan3g all -- 3g-wan3g * 0.0.0.0/0 0.0.0.0/0
Chain input_lan (1 references)
pkts bytes target prot opt in out source destination
Chain input_rule (1 references)
pkts bytes target prot opt in out source destination
Chain input_tun0 (1 references)
pkts bytes target prot opt in out source destination
Chain input_wan (1 references)
pkts bytes target prot opt in out source destination
Chain input_wan3g (1 references)
pkts bytes target prot opt in out source destination
Chain output (1 references)
pkts bytes target prot opt in out source destination
262 18960 zone_lan_ACCEPT all -- * * 0.0.0.0/0 0.0.0. 0/0
252 16180 zone_wan_ACCEPT all -- * * 0.0.0.0/0 0.0.0. 0/0
252 16180 zone_wan3g_ACCEPT all -- * * 0.0.0.0/0 0.0. 0.0/0
0 0 zone_tun0_ACCEPT all -- * * 0.0.0.0/0 0.0.0 .0/0
Chain output_rule (1 references)
pkts bytes target prot opt in out source destination
Chain reject (5 references)
pkts bytes target prot opt in out source destination
0 0 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset
1 81 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain syn_flood (1 references)
pkts bytes target prot opt in out source destination
44 2612 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 25/sec burst 50
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan (1 references)
pkts bytes target prot opt in out source destination
283 25978 input_lan all -- * * 0.0.0.0/0 0.0.0.0/0
283 25978 zone_lan_ACCEPT all -- * * 0.0.0.0/0 0.0.0. 0/0
Chain zone_lan_ACCEPT (2 references)
pkts bytes target prot opt in out source destination
8 2636 ACCEPT all -- * br-lan 0.0.0.0/0 0.0.0.0/0
283 25978 ACCEPT all -- br-lan * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_DROP (0 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * br-lan 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- br-lan * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_REJECT (1 references)
pkts bytes target prot opt in out source destination
0 0 reject all -- * br-lan 0.0.0.0/0 0.0.0.0/0
0 0 reject all -- br-lan * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_forward (1 references)
pkts bytes target prot opt in out source destination
0 0 zone_tun0_ACCEPT all -- * * 0.0.0.0/0 0.0.0 .0/0
0 0 zone_wan3g_ACCEPT all -- * * 0.0.0.0/0 0.0. 0.0/0
0 0 zone_wan_ACCEPT all -- * * 0.0.0.0/0 0.0.0. 0/0
0 0 forwarding_lan all -- * * 0.0.0.0/0 0.0.0.0 /0
0 0 zone_lan_REJECT all -- * * 0.0.0.0/0 0.0.0. 0/0
Chain zone_tun0 (0 references)
pkts bytes target prot opt in out source destination
0 0 input_tun0 all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 zone_tun0_ACCEPT all -- * * 0.0.0.0/0 0.0.0 .0/0
Chain zone_tun0_ACCEPT (4 references)
pkts bytes target prot opt in out source destination
Chain zone_tun0_DROP (0 references)
pkts bytes target prot opt in out source destination
Chain zone_tun0_REJECT (0 references)
pkts bytes target prot opt in out source destination
Chain zone_tun0_forward (0 references)
pkts bytes target prot opt in out source destination
0 0 forwarding_tun0 all -- * * 0.0.0.0/0 0.0.0. 0/0
0 0 zone_tun0_ACCEPT all -- * * 0.0.0.0/0 0.0.0 .0/0
Chain zone_wan (0 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 8
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
0 0 input_wan all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 zone_wan_ACCEPT all -- * * 0.0.0.0/0 0.0.0. 0/0
Chain zone_wan3g (1 references)
pkts bytes target prot opt in out source destination
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68
1 81 input_wan3g all -- * * 0.0.0.0/0 0.0.0.0/0
1 81 zone_wan3g_REJECT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan3g_ACCEPT (2 references)
pkts bytes target prot opt in out source destination
252 16180 ACCEPT all -- * 3g-wan3g 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- 3g-wan3g * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan3g_DROP (0 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- * 3g-wan3g 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- 3g-wan3g * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan3g_REJECT (2 references)
pkts bytes target prot opt in out source destination
0 0 reject all -- * 3g-wan3g 0.0.0.0/0 0.0.0.0/0
1 81 reject all -- 3g-wan3g * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan3g_forward (1 references)
pkts bytes target prot opt in out source destination
0 0 forwarding_wan3g all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 zone_wan3g_REJECT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_ACCEPT (3 references)
pkts bytes target prot opt in out source destination
Chain zone_wan_DROP (0 references)
pkts bytes target prot opt in out source destination
Chain zone_wan_REJECT (1 references)
pkts bytes target prot opt in out source destination
Chain zone_wan_forward (0 references)
pkts bytes target prot opt in out source destination
0 0 forwarding_wan all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 zone_wan_REJECT all -- * * 0.0.0.0/0 0.0.0.0/0
-------------------------------------------------------
iptables -t nat -nvL
root@OpenWrt:~# iptables -t nat -nvL
Chain PREROUTING (policy ACCEPT 254 packets, 24670 bytes)
pkts bytes target prot opt in out source destination
255 24875 prerouting_rule all -- * * 0.0.0.0/0 0.0.0. 0/0
200 20943 zone_lan_prerouting all -- br-lan * 0.0.0.0/0 0. 0.0.0/0
1 81 zone_wan3g_prerouting all -- 3g-wan3g * 0.0.0.0/0 0.0.0.0/0
Chain INPUT (policy ACCEPT 146 packets, 19085 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 358 packets, 24922 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 127 packets, 10154 bytes)
pkts bytes target prot opt in out source destination
362 25210 postrouting_rule all -- * * 0.0.0.0/0 0.0.0 .0/0
8 2636 zone_lan_nat all -- * br-lan 0.0.0.0/0 0.0.0.0/0
231 14768 zone_wan3g_nat all -- * 3g-wan3g 0.0.0.0/0 0.0.0 .0/0
Chain postrouting_rule (1 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * tun0 0.0.0.0/0 0.0.0.0/0
Chain prerouting_lan (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_rule (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_tun0 (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_wan (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_wan3g (1 references)
pkts bytes target prot opt in out source destination
Chain zone_lan_nat (1 references)
pkts bytes target prot opt in out source destination
Chain zone_lan_prerouting (1 references)
pkts bytes target prot opt in out source destination
200 20943 prerouting_lan all -- * * 0.0.0.0/0 0.0.0.0 /0
Chain zone_tun0_nat (0 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_tun0_prerouting (0 references)
pkts bytes target prot opt in out source destination
0 0 prerouting_tun0 all -- * * 0.0.0.0/0 0.0.0. 0/0
Chain zone_wan3g_nat (1 references)
pkts bytes target prot opt in out source destination
231 14768 MASQUERADE all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan3g_prerouting (1 references)
pkts bytes target prot opt in out source destination
1 81 prerouting_wan3g all -- * * 0.0.0.0/0 0.0.0 .0/0
Chain zone_wan_nat (0 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_prerouting (0 references)
pkts bytes target prot opt in out source destination
0 0 prerouting_wan all -- * * 0.0.0.0/0 0.0.0.0 /0