Advertisement
ujiajah1

iptables rc.local for tproxy + dns crypt

Jan 8th, 2016
447
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 1.04 KB | None | 0 0
  1. ## iptable ##
  2. ==============
  3. # /usr/local/sbin/dnscrypt-proxy -a 127.0.0.1:40 -d -R d0wn-sg-ns1 -e 4096 -p /run/dnscrypt-proxy.pid # autostart dnscrypt_unbound
  4. modprobe xt_TPROXY
  5. modprobe xt_socket
  6. modprobe xt_mark
  7. modprobe nf_nat
  8. modprobe nf_conntrack_ipv4
  9. modprobe nf_conntrack
  10. modprobe nf_defrag_ipv4
  11. modprobe ipt_REDIRECT
  12. modprobe iptable_nat
  13.  
  14. iptables -t mangle -F
  15. iptables -t mangle -X
  16.  
  17. iptables -t mangle -N DIVERT
  18. iptables -t mangle -A DIVERT -j MARK --set-mark 1
  19. iptables -t mangle -A DIVERT -j ACCEPT
  20. iptables -t mangle -A INPUT -j ACCEPT
  21. iptables -t mangle -A PREROUTING -p tcp -m socket -j DIVERT
  22. iptables -t mangle -A PREROUTING ! -d 172.16.0.2/24 -p tcp --dport 80 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 3129
  23. iptables -t mangle -A PREROUTING ! -d 172.16.0.2/24 -p tcp --dport 443 -j TPROXY --tproxy-mark 0x1/0x1 --on-port 3127
  24.  
  25. /sbin/ip rule add fwmark 1 lookup 100
  26. /sbin/ip route add local 0.0.0.0/0 dev lo table 100
  27.  
  28. echo 0 > /proc/sys/net/ipv4/conf/lo/rp_filter
  29. echo 1 > /proc/sys/net/ipv4/ip_forward
  30. exit 0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement