Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- *nat
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- -A PREROUTING -i pppoe-wan -p tcp -m multiport --dports 80,42000 -j DNAT --to-destination 192.168.1.20
- -A PREROUTING -i pppoe-wan -p udp -m udp --dport 42000 -j DNAT --to-destination 192.168.1.20
- -A PREROUTING -i pppoe-wan -p tcp -m multiport --dports 43000:43010 -j DNAT --to-destination 192.168.1.25
- -A PREROUTING -i pppoe-wan -p udp -m multiport --dports 43000:43010 -j DNAT --to-destination 192.168.1.25
- -A POSTROUTING -o pppoe-wan -j MASQUERADE
- COMMIT
- *mangle
- :PREROUTING ACCEPT [0:0]
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- :POSTROUTING ACCEPT [0:0]
- -A FORWARD -o pppoe-wan -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- COMMIT
- *filter
- :INPUT ACCEPT [0:0]
- :FORWARD ACCEPT [0:0]
- :OUTPUT ACCEPT [0:0]
- -A INPUT -i pppoe-wan -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
- -A INPUT -i pppoe-wan -m state ! --state RELATED,ESTABLISHED -j DROP
- COMMIT
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement