1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 1000
link/ether 00:15:5d:01:8d:30 brd ff:ff:ff:ff:ff:ff
inet --.--.252.123/24 brd --.--.252.255 scope global eth0
inet6 fe80::215:5dff:fe01:8d30/64 scope link
valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 1000
link/ether 00:15:5d:01:8d:31 brd ff:ff:ff:ff:ff:ff
inet 192.168.7.1/24 brd 192.168.7.255 scope global eth1
inet6 fe80::215:5dff:fe01:8d31/64 scope link
valid_lft forever preferred_lft forever
4: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 10.8.0.1 peer 10.8.0.2/32 scope global tun0
5: tun1: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 10.1.0.1 peer 10.1.0.2/32 scope global tun1
6: tun2: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 10.2.0.1 peer 10.2.0.2/32 scope global tun2
7: tun3: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 10.3.0.1 peer 10.3.0.2/32 scope global tun3
8: tun4: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 10.4.0.1 peer 10.4.0.2/32 scope global tun4
# Generated by iptables-save v1.4.4 on Fri Oct 11 13:21:49 2013
*mangle
:PREROUTING ACCEPT [21156160:13738244558]
:INPUT ACCEPT [5391973:3446848684]
:FORWARD ACCEPT [15764021:10291384842]
:OUTPUT ACCEPT [5243248:4162421971]
:POSTROUTING ACCEPT [19020741:14333891595]
COMMIT
# Completed on Fri Oct 11 13:21:49 2013
# Generated by iptables-save v1.4.4 on Fri Oct 11 13:21:49 2013
*nat
:PREROUTING ACCEPT [2263785:141171717]
:POSTROUTING ACCEPT [96874:12195833]
:OUTPUT ACCEPT [94531:5762479]
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 21 -j DNAT --to-destination 192.168.7.11:21
-A PREROUTING -d --.---.252.123/32 -p tcp -m tcp --dport 20 -j DNAT --to-destination 192.168.7.11:20
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.7.16:80
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 9500 -j DNAT --to-destination 192.168.7.26:9500
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 9577 -j DNAT --to-destination 192.168.7.12:9577
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 2221 -j DNAT --to-destination 192.168.7.7:2221
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 2222 -j DNAT --to-destination 192.168.7.7:2222
-A PREROUTING -d --.--.252.123/32 -p udp -m udp --dport 8767 -j DNAT --to-destination 192.168.7.83:8767
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 8008 -j DNAT --to-destination 192.168.7.190:8008
-A PREROUTING -d --.---.252.123/32 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 192.168.7.6:8081
-A PREROUTING -d ---.--.252.123/32 -p tcp -m tcp --dport 9786 -j DNAT --to-destination 192.168.7.88:9786
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 41067 -j DNAT --to-destination 192.168.7.81:41067
-A PREROUTING -d --.--.252.123/32 -p udp -m udp --dport 41067 -j DNAT --to-destination 192.168.7.81:41067
-A PREROUTING -d --.--.252.123/32 -p tcp -m tcp --dport 1111 -j DNAT --to-destination 192.168.7.88:1111
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Fri Oct 11 13:21:49 2013
# Generated by iptables-save v1.4.4 on Fri Oct 11 13:21:49 2013
*filter
:INPUT DROP [87470:7172675]
:FORWARD DROP [1986844:119954281]
:OUTPUT ACCEPT [5243248:4162421971]
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p udp -m udp --dport 1194 -j ACCEPT
-A INPUT -i tun0 -j ACCEPT
-A INPUT -p udp -m udp --dport 1195 -j ACCEPT
-A INPUT -i tun1 -j ACCEPT
-A INPUT -p udp -m udp --dport 1197 -j ACCEPT
-A INPUT -i tun3 -j ACCEPT
-A INPUT -p udp -m udp --dport 1198 -j ACCEPT
-A INPUT -i tun4 -j ACCEPT
-A INPUT -p tcp -m multiport --dports 32122 -j ACCEPT
-A INPUT -i eth1 -p tcp -m multiport --dports 53,80,139,445,2121,3128,10000 -j ACCEPT
-A INPUT -i eth1 -p udp -m multiport --dports 53,123,137,138 -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i tun0 -j ACCEPT
-A FORWARD -o tun0 -j ACCEPT
-A FORWARD -i tun1 -j ACCEPT
-A FORWARD -o tun1 -j ACCEPT
-A FORWARD -i tun2 -j ACCEPT
-A FORWARD -o tun2 -j ACCEPT
-A FORWARD -i tun3 -j ACCEPT
-A FORWARD -o tun3 -j ACCEPT
-A FORWARD -i tun4 -j ACCEPT
-A FORWARD -o tun4 -j ACCEPT
-A FORWARD -i tun5 -j ACCEPT
-A FORWARD -o tun5 -j ACCEPT
-A FORWARD -s 192.168.7.3/32 -j ACCEPT
-A FORWARD -s 192.168.7.4/32 -j ACCEPT
-A FORWARD -s 192.168.7.5/32 -j ACCEPT
-A FORWARD -s 192.168.7.6/32 -j ACCEPT
-A FORWARD -s 192.168.7.8/32 -j ACCEPT
-A FORWARD -s 192.168.7.16/32 -j ACCEPT
-A FORWARD -s 192.168.7.19/32 -j ACCEPT
-A FORWARD -s 192.168.7.22/32 -j ACCEPT
-A FORWARD -s 192.168.7.23/32 -j ACCEPT
-A FORWARD -s 192.168.7.29/32 -j ACCEPT
-A FORWARD -s 192.168.7.31/32 -j ACCEPT
-A FORWARD -s 192.168.7.33/32 -j ACCEPT
-A FORWARD -s 192.168.7.36/32 -j ACCEPT
-A FORWARD -s 192.168.7.39/32 -j ACCEPT
-A FORWARD -s 192.168.7.56/32 -j ACCEPT
-A FORWARD -s 192.168.7.81/32 -j ACCEPT
-A FORWARD -s 192.168.7.86/32 -j ACCEPT
-A FORWARD -s 192.168.7.88/32 -j ACCEPT
-A FORWARD -s 192.168.7.55/32 -j ACCEPT
-A FORWARD -s 192.168.7.91/32 -j ACCEPT
-A FORWARD -s 192.168.7.190/32 -j ACCEPT
-A FORWARD -d 80.68.240.0/20 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -d 194.186.36.0/24 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 21,22,25,53,110,143,993,995,2121 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p udp -m multiport --dports 53,123 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 2525,465,587 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 5190 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 1194 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p udp -m multiport --dports 1194 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 3389,9911,9920,9925 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 9935,9936 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 4321 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 631 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 32122 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 30583 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 1999 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 8010,8020 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 2000,2001,2002,2003,2004,2005,2006,2007 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 3000,3001,3002,3003,3004,3005,3006,3007 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 1024 -j ACCEPT
-A FORWARD -s 192.168.7.0/24 -i eth1 -p tcp -m multiport --dports 47,1723 -j ACCEPT
-A FORWARD -s 77.244.72.5/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 77.244.72.5/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s 80.245.244.94/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 80.245.244.94/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s 46.52.130.62/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 46.52.130.62/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s 185.18.108.2/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 185.18.108.2/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s 95.170.133.74/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 95.170.133.74/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s --.--.252.128/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -d 192.168.7.6/32 -i eth0 -p tcp -m tcp --dport 8081 -j ACCEPT
-A FORWARD -d 192.168.7.190/32 -i eth0 -p tcp -m tcp --dport 8008 -j ACCEPT
-A FORWARD -d 192.168.7.88/32 -i eth0 -p tcp -m tcp --dport 9786 -j ACCEPT
-A FORWARD -s 62.141.72.26/32 -d 192.168.7.26/32 -i eth0 -p tcp -m tcp --dport 9500 -j ACCEPT
-A FORWARD -s 62.141.72.26/32 -d 192.168.7.12/32 -i eth0 -p tcp -m tcp --dport 9577 -j ACCEPT
-A FORWARD -s 83.239.24.114/32 -d 192.168.7.88/32 -i eth0 -p tcp -m tcp --dport 1111 -j ACCEPT
-A FORWARD -s 80.245.244.94/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -s 80.245.244.94/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A FORWARD -s 46.52.130.62/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -s 46.52.130.62/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A FORWARD -s 77.244.72.5/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -s 77.244.72.5/32 -d 192.168.7.11/32 -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A FORWARD -d 192.168.7.7/32 -i eth0 -p tcp -m tcp --dport 2221 -j ACCEPT
-A FORWARD -d 192.168.7.7/32 -i eth0 -p tcp -m tcp --dport 2222 -j ACCEPT
-A FORWARD -d 192.168.7.83/32 -i eth0 -p udp -m udp --dport 8767 -j ACCEPT
-A FORWARD -s 77.244.72.5/32 -d 192.168.7.16/32 -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 192.168.7.31/32 -i eth0 -p tcp -m tcp --dport 56250 -j ACCEPT
-A FORWARD -d 192.168.7.31/32 -i eth0 -p udp -m udp --dport 56250 -j ACCEPT
-A FORWARD -d 192.168.7.81/32 -i eth0 -p tcp -m tcp --dport 41067 -j ACCEPT
-A FORWARD -d 192.168.7.81/32 -i eth0 -p udp -m udp --dport 41067 -j ACCEPT
COMMIT
# Completed on Fri Oct 11 13:21:50 2013