Skip to content

Instantly share code, notes, and snippets.

@diogenese
Created August 16, 2019 20:27
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save diogenese/1937d01241d74156d4ad018344010be4 to your computer and use it in GitHub Desktop.
Save diogenese/1937d01241d74156d4ad018344010be4 to your computer and use it in GitHub Desktop.
****************************************
/etc/resolv.conf
# Generated by NetworkManager
search master.privatedomian
nameserver 8.8.8.8
****************************************
/etc/sysconfig/network-scripts/ifcfg-enp10s0:
NAME=enp10s0
TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=none
DEFROUTE=yes
ONBOOT=yes
DEVICE=enp10s0
IPADDR=12.172.164.68
GATEWAY=12.172.164.1
DNS1=8.8.8.8
PREFIX=24
METRIC=10
UUID=7c79a251-b818-4ee8-a79c-4abc762d40ea
HWADDR=6C:B3:11:52:39:B3
IPV4_FAILURE_FATAL=no
IPV4_DNS_PRIORITY=100
IPV6INIT=no
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_PRIVACY=no
IPV6_ADDR_GEN_MODE=stable-privacy
****************************************
/etc/sysconfig/network-scripts/ifcfg-enp5s0:
NAME=enp5s0
TYPE=Ethernet
PROXY_METHOD=none
BROWSER_ONLY=no
BOOTPROTO=none
DEFROUTE=yes
ONBOOT=yes
DEVICE=enp5s0
IPADDR=192.168.10.3
GATEWAY=192.168.10.4
PREFIX=24
IPADDR1=192.168.20.3
PREFIX1=24
DNS1=8.8.8.8
METRIC=100
UUID=e3f592ea-036d-4b76-9051-7acc71af8747
HWADDR=70:85:C2:BF:E1:0B
IPV4_FAILURE_FATAL=no
IPV4_DNS_PRIORITY=100
IPV6INIT=no
IPV6_AUTOCONF=yes
IPV6_DEFROUTE=yes
IPV6_FAILURE_FATAL=no
IPV6_PRIVACY=no
IPV6_ADDR_GEN_MODE=stable-privacy
****************************************
netstat -nr:
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 12.172.164.1 0.0.0.0 UG 0 0 0 enp10s0
0.0.0.0 192.168.10.4 0.0.0.0 UG 0 0 0 enp5s0
12.172.164.0 0.0.0.0 255.255.255.0 U 0 0 0 enp10s0
192.168.10.0 0.0.0.0 255.255.255.0 U 0 0 0 enp5s0
192.168.20.0 0.0.0.0 255.255.255.0 U 0 0 0 enp5s0
****************************************
ip route list:
default via 12.172.164.1 dev enp10s0 proto static metric 20100
default via 192.168.10.4 dev enp5s0 proto static metric 20101
12.172.164.0/24 dev enp10s0 proto kernel scope link src 12.172.164.68 metric 100
192.168.10.0/24 dev enp5s0 proto kernel scope link src 192.168.10.3 metric 101
192.168.20.0/24 dev enp5s0 proto kernel scope link src 192.168.20.3 metric 101
****************************************
ip link list:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: enp5s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
link/ether 70:85:c2:bf:e1:0b brd ff:ff:ff:ff:ff:ff
3: enp10s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
link/ether 6c:b3:11:52:39:b3 brd ff:ff:ff:ff:ff:ff
4: wlp4s0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 2a:f0:e7:80:41:72 brd ff:ff:ff:ff:ff:ff
****************************************
ip address list:
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: enp5s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 70:85:c2:bf:e1:0b brd ff:ff:ff:ff:ff:ff
inet 192.168.10.3/24 brd 192.168.10.255 scope global noprefixroute enp5s0
valid_lft forever preferred_lft forever
inet 192.168.20.3/24 brd 192.168.20.255 scope global noprefixroute enp5s0
valid_lft forever preferred_lft forever
inet6 fe80::7285:c2ff:febf:e10b/64 scope link
valid_lft forever preferred_lft forever
3: enp10s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 6c:b3:11:52:39:b3 brd ff:ff:ff:ff:ff:ff
inet 12.172.164.68/24 brd 12.172.164.255 scope global noprefixroute enp10s0
valid_lft forever preferred_lft forever
inet6 fe80::6eb3:11ff:fe52:39b3/64 scope link
valid_lft forever preferred_lft forever
4: wlp4s0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 2a:f0:e7:80:41:72 brd ff:ff:ff:ff:ff:ff
****************************************
ip route show table default:
Error: ipv4: FIB table does not exist.
Dump terminated
****************************************
shorewall show net-fw
Shorewall 5.2.2 Chain net-fw at master.privatedomian - Fri 16 Aug 2019 01:24:33 PM PDT
Counters reset Fri 16 Aug 2019 01:21:55 PM PDT
Chain net-fw (1 references)
pkts bytes target prot opt in out source destination
17 4087 dynamic all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate INVALID,NEW,UNTRACKED
0 0 tcpflags tcp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 80,113,443,8999
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:8999
5 1762 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
12 2325 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix "net-fw DROP "
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
****************************************
shorewall show INPUT
Shorewall 5.2.2 Chain INPUT at master.privatedomian - Fri 16 Aug 2019 01:24:34 PM PDT
Counters reset Fri 16 Aug 2019 01:21:55 PM PDT
Chain INPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
21 4277 ~comb0 all -- enp5s0 * 0.0.0.0/0 0.0.0.0/0
0 0 ~comb0 all -- wlp4s0 * 0.0.0.0/0 0.0.0.0/0
17 4087 net-fw all -- enp10s0 * 0.0.0.0/0 0.0.0.0/0
472 28527 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix "INPUT REJECT "
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
****************************************
shorewall show OUTPUT
Shorewall 5.2.2 Chain OUTPUT at master.privatedomian - Fri 16 Aug 2019 01:24:34 PM PDT
Counters reset Fri 16 Aug 2019 01:21:55 PM PDT
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
16 2627 ACCEPT all -- * enp5s0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT all -- * wlp4s0 0.0.0.0/0 0.0.0.0/0
215 17488 ACCEPT all -- * enp10s0 0.0.0.0/0 0.0.0.0/0
472 28527 ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type BROADCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type ANYCAST
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 ADDRTYPE match dst-type MULTICAST
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 limit: up to 1/sec burst 10 mode srcip LOG flags 0 level 6 prefix "OUTPUT REJECT "
0 0 reject all -- * * 0.0.0.0/0 0.0.0.0/0 [goto]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment