Skip to content

Instantly share code, notes, and snippets.

@niner
Created December 22, 2017 11:20
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save niner/1634cd292d39b9fad307fc227d83a478 to your computer and use it in GitHub Desktop.
Save niner/1634cd292d39b9fad307fc227d83a478 to your computer and use it in GitHub Desktop.
ns1:/home/nine # iptables -L -v -n -t nat
Chain PREROUTING (policy ACCEPT 291K packets, 18M bytes)
pkts bytes target prot opt in out source destination
Chain INPUT (policy ACCEPT 278K packets, 17M bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 170K packets, 13M bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 170K packets, 13M bytes)
pkts bytes target prot opt in out source destination
4 662 RETURN all -- * * 192.168.122.0/24 224.0.0.0/24
0 0 RETURN all -- * * 192.168.122.0/24 255.255.255.255
4193 252K MASQUERADE tcp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
8901 676K MASQUERADE udp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
5 420 MASQUERADE all -- * * 192.168.122.0/24 !192.168.122.0/24
ns1:/home/nine # iptables -L -v -n
Chain INPUT (policy ACCEPT 4325K packets, 1118M bytes)
pkts bytes target prot opt in out source destination
11948 703K ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
756 269K ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
29616 78M ACCEPT all -- * virbr0 0.0.0.0/0 192.168.122.0/24 ctstate RELATED,ESTABLISHED
231K 18M ACCEPT all -- virbr0 * 192.168.122.0/24 0.0.0.0/0
10 3306 ACCEPT all -- virbr0 virbr0 0.0.0.0/0 0.0.0.0/0
0 0 REJECT all -- * virbr0 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
0 0 REJECT all -- virbr0 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain OUTPUT (policy ACCEPT 9492K packets, 11G bytes)
pkts bytes target prot opt in out source destination
756 250K ACCEPT udp -- * virbr0 0.0.0.0/0 0.0.0.0/0 udp dpt:68
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment