Project

General

Profile

ip6tables-save.firewalld.txt

Dump without default route over v6 - nicksinger, 2020-11-04 15:00

 
1
# Generated by ip6tables-save v1.6.2 on Wed Nov  4 15:40:03 2020
2
*nat
3
:PREROUTING ACCEPT [0:0]
4
:INPUT ACCEPT [0:0]
5
:OUTPUT ACCEPT [0:0]
6
:POSTROUTING ACCEPT [0:0]
7
:OUTPUT_direct - [0:0]
8
:POSTROUTING_ZONES - [0:0]
9
:POSTROUTING_ZONES_SOURCE - [0:0]
10
:POSTROUTING_direct - [0:0]
11
:POST_trusted - [0:0]
12
:POST_trusted_allow - [0:0]
13
:POST_trusted_deny - [0:0]
14
:POST_trusted_log - [0:0]
15
:PREROUTING_ZONES - [0:0]
16
:PREROUTING_ZONES_SOURCE - [0:0]
17
:PREROUTING_direct - [0:0]
18
:PRE_trusted - [0:0]
19
:PRE_trusted_allow - [0:0]
20
:PRE_trusted_deny - [0:0]
21
:PRE_trusted_log - [0:0]
22
-A PREROUTING -j PREROUTING_direct
23
-A PREROUTING -j PREROUTING_ZONES_SOURCE
24
-A PREROUTING -j PREROUTING_ZONES
25
-A OUTPUT -j OUTPUT_direct
26
-A POSTROUTING -j POSTROUTING_direct
27
-A POSTROUTING -j POSTROUTING_ZONES_SOURCE
28
-A POSTROUTING -j POSTROUTING_ZONES
29
-A POSTROUTING_ZONES -o eth4 -j POST_trusted
30
-A POSTROUTING_ZONES -o ovs-system -j POST_trusted
31
-A POSTROUTING_ZONES -o br1 -j POST_trusted
32
-A POSTROUTING_ZONES -j POST_trusted
33
-A POST_trusted -j POST_trusted_log
34
-A POST_trusted -j POST_trusted_deny
35
-A POST_trusted -j POST_trusted_allow
36
-A POST_trusted_allow ! -o lo -j MASQUERADE
37
-A PREROUTING_ZONES -i eth4 -j PRE_trusted
38
-A PREROUTING_ZONES -i ovs-system -j PRE_trusted
39
-A PREROUTING_ZONES -i br1 -j PRE_trusted
40
-A PREROUTING_ZONES -j PRE_trusted
41
-A PRE_trusted -j PRE_trusted_log
42
-A PRE_trusted -j PRE_trusted_deny
43
-A PRE_trusted -j PRE_trusted_allow
44
COMMIT
45
# Completed on Wed Nov  4 15:40:03 2020
46
# Generated by ip6tables-save v1.6.2 on Wed Nov  4 15:40:03 2020
47
*raw
48
:PREROUTING ACCEPT [0:0]
49
:OUTPUT ACCEPT [54:5264]
50
:OUTPUT_direct - [0:0]
51
:PREROUTING_ZONES - [0:0]
52
:PREROUTING_ZONES_SOURCE - [0:0]
53
:PREROUTING_direct - [0:0]
54
:PRE_trusted - [0:0]
55
:PRE_trusted_allow - [0:0]
56
:PRE_trusted_deny - [0:0]
57
:PRE_trusted_log - [0:0]
58
-A PREROUTING -p ipv6-icmp -m icmp6 --icmpv6-type 135 -j ACCEPT
59
-A PREROUTING -p ipv6-icmp -m icmp6 --icmpv6-type 134 -j ACCEPT
60
-A PREROUTING -m rpfilter --invert -j DROP
61
-A PREROUTING -j PREROUTING_direct
62
-A PREROUTING -j PREROUTING_ZONES_SOURCE
63
-A PREROUTING -j PREROUTING_ZONES
64
-A OUTPUT -j OUTPUT_direct
65
-A PREROUTING_ZONES -i eth4 -j PRE_trusted
66
-A PREROUTING_ZONES -i ovs-system -j PRE_trusted
67
-A PREROUTING_ZONES -i br1 -j PRE_trusted
68
-A PREROUTING_ZONES -j PRE_trusted
69
-A PRE_trusted -j PRE_trusted_log
70
-A PRE_trusted -j PRE_trusted_deny
71
-A PRE_trusted -j PRE_trusted_allow
72
COMMIT
73
# Completed on Wed Nov  4 15:40:03 2020
74
# Generated by ip6tables-save v1.6.2 on Wed Nov  4 15:40:03 2020
75
*security
76
:INPUT ACCEPT [0:0]
77
:FORWARD ACCEPT [0:0]
78
:OUTPUT ACCEPT [54:5264]
79
:FORWARD_direct - [0:0]
80
:INPUT_direct - [0:0]
81
:OUTPUT_direct - [0:0]
82
-A INPUT -j INPUT_direct
83
-A FORWARD -j FORWARD_direct
84
-A OUTPUT -j OUTPUT_direct
85
COMMIT
86
# Completed on Wed Nov  4 15:40:03 2020
87
# Generated by ip6tables-save v1.6.2 on Wed Nov  4 15:40:03 2020
88
*mangle
89
:PREROUTING ACCEPT [1:72]
90
:INPUT ACCEPT [0:0]
91
:FORWARD ACCEPT [0:0]
92
:OUTPUT ACCEPT [54:5264]
93
:POSTROUTING ACCEPT [4:464]
94
:FORWARD_direct - [0:0]
95
:INPUT_direct - [0:0]
96
:OUTPUT_direct - [0:0]
97
:POSTROUTING_direct - [0:0]
98
:PREROUTING_ZONES - [0:0]
99
:PREROUTING_ZONES_SOURCE - [0:0]
100
:PREROUTING_direct - [0:0]
101
:PRE_trusted - [0:0]
102
:PRE_trusted_allow - [0:0]
103
:PRE_trusted_deny - [0:0]
104
:PRE_trusted_log - [0:0]
105
-A PREROUTING -j PREROUTING_direct
106
-A PREROUTING -j PREROUTING_ZONES_SOURCE
107
-A PREROUTING -j PREROUTING_ZONES
108
-A INPUT -j INPUT_direct
109
-A FORWARD -j FORWARD_direct
110
-A OUTPUT -j OUTPUT_direct
111
-A POSTROUTING -j POSTROUTING_direct
112
-A PREROUTING_ZONES -i eth4 -j PRE_trusted
113
-A PREROUTING_ZONES -i ovs-system -j PRE_trusted
114
-A PREROUTING_ZONES -i br1 -j PRE_trusted
115
-A PREROUTING_ZONES -j PRE_trusted
116
-A PRE_trusted -j PRE_trusted_log
117
-A PRE_trusted -j PRE_trusted_deny
118
-A PRE_trusted -j PRE_trusted_allow
119
COMMIT
120
# Completed on Wed Nov  4 15:40:03 2020
121
# Generated by ip6tables-save v1.6.2 on Wed Nov  4 15:40:03 2020
122
*filter
123
:INPUT ACCEPT [0:0]
124
:FORWARD ACCEPT [0:0]
125
:OUTPUT ACCEPT [54:5264]
126
:FORWARD_IN_ZONES - [0:0]
127
:FORWARD_IN_ZONES_SOURCE - [0:0]
128
:FORWARD_OUT_ZONES - [0:0]
129
:FORWARD_OUT_ZONES_SOURCE - [0:0]
130
:FORWARD_direct - [0:0]
131
:FWDI_trusted - [0:0]
132
:FWDI_trusted_allow - [0:0]
133
:FWDI_trusted_deny - [0:0]
134
:FWDI_trusted_log - [0:0]
135
:FWDO_trusted - [0:0]
136
:FWDO_trusted_allow - [0:0]
137
:FWDO_trusted_deny - [0:0]
138
:FWDO_trusted_log - [0:0]
139
:INPUT_ZONES - [0:0]
140
:INPUT_ZONES_SOURCE - [0:0]
141
:INPUT_direct - [0:0]
142
:IN_trusted - [0:0]
143
:IN_trusted_allow - [0:0]
144
:IN_trusted_deny - [0:0]
145
:IN_trusted_log - [0:0]
146
:OUTPUT_direct - [0:0]
147
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
148
-A INPUT -i lo -j ACCEPT
149
-A INPUT -j INPUT_direct
150
-A INPUT -j INPUT_ZONES_SOURCE
151
-A INPUT -j INPUT_ZONES
152
-A INPUT -m conntrack --ctstate INVALID -j DROP
153
-A INPUT -j REJECT --reject-with icmp6-adm-prohibited
154
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
155
-A FORWARD -i lo -j ACCEPT
156
-A FORWARD -j FORWARD_direct
157
-A FORWARD -j FORWARD_IN_ZONES_SOURCE
158
-A FORWARD -j FORWARD_IN_ZONES
159
-A FORWARD -j FORWARD_OUT_ZONES_SOURCE
160
-A FORWARD -j FORWARD_OUT_ZONES
161
-A FORWARD -m conntrack --ctstate INVALID -j DROP
162
-A FORWARD -j REJECT --reject-with icmp6-adm-prohibited
163
-A OUTPUT -j OUTPUT_direct
164
-A FORWARD_IN_ZONES -i eth4 -j FWDI_trusted
165
-A FORWARD_IN_ZONES -i ovs-system -j FWDI_trusted
166
-A FORWARD_IN_ZONES -i br1 -j FWDI_trusted
167
-A FORWARD_IN_ZONES -j FWDI_trusted
168
-A FORWARD_OUT_ZONES -o eth4 -j FWDO_trusted
169
-A FORWARD_OUT_ZONES -o ovs-system -j FWDO_trusted
170
-A FORWARD_OUT_ZONES -o br1 -j FWDO_trusted
171
-A FORWARD_OUT_ZONES -j FWDO_trusted
172
-A FWDI_trusted -j FWDI_trusted_log
173
-A FWDI_trusted -j FWDI_trusted_deny
174
-A FWDI_trusted -j FWDI_trusted_allow
175
-A FWDI_trusted -j ACCEPT
176
-A FWDO_trusted -j FWDO_trusted_log
177
-A FWDO_trusted -j FWDO_trusted_deny
178
-A FWDO_trusted -j FWDO_trusted_allow
179
-A FWDO_trusted -j ACCEPT
180
-A FWDO_trusted_allow -m conntrack --ctstate NEW -j ACCEPT
181
-A INPUT_ZONES -i eth4 -j IN_trusted
182
-A INPUT_ZONES -i ovs-system -j IN_trusted
183
-A INPUT_ZONES -i br1 -j IN_trusted
184
-A INPUT_ZONES -j IN_trusted
185
-A IN_trusted -j IN_trusted_log
186
-A IN_trusted -j IN_trusted_deny
187
-A IN_trusted -j IN_trusted_allow
188
-A IN_trusted -j ACCEPT
189
COMMIT
190
# Completed on Wed Nov  4 15:40:03 2020