1 # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 2 *mangle 3 :PREROUTING ACCEPT [2461:977932] 4 :INPUT ACCEPT [2461:977932] 5 :FORWARD ACCEPT [0:0] 6 :OUTPUT ACCEPT [1740:367048] 7 :POSTROUTING ACCEPT [1740:367048] 8 9 # libipt_ 10 -A INPUT -p ah -m ah --ahspi 1 11 -A INPUT -p ah -m ah --ahspi :2 12 -A INPUT -p ah -m ah --ahspi 0:3 13 -A INPUT -p ah -m ah --ahspi 4: 14 -A INPUT -p ah -m ah --ahspi 5:4294967295 15 16 -A FORWARD -p tcp -j ECN --ecn-tcp-remove 17 -A FORWARD -j LOG --log-prefix "hi" --log-tcp-sequence --log-tcp-options --log-ip-options --log-uid --log-macdecode 18 -A FORWARD -j TTL --ttl-inc 1 19 -A FORWARD -j TTL --ttl-dec 1 20 -A FORWARD -j TTL --ttl-set 1 21 -A FORWARD -j ULOG --ulog-prefix "abc" --ulog-cprange 2 --ulog-qthreshold 2 22 COMMIT 23 # Completed on Mon Jan 31 03:03:38 2011 24 # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 25 *nat 26 :PREROUTING ACCEPT [0:0] 27 :INPUT ACCEPT [0:0] 28 :OUTPUT ACCEPT [0:0] 29 :POSTROUTING ACCEPT [0:0] 30 -A PREROUTING -d 1.2.3.4/32 -i lo -j CLUSTERIP --new --hashmode sourceip --clustermac 01:02:03:04:05:06 --total-nodes 9 --local-node 2 --hash-init 123456789 31 -A PREROUTING -i dummy0 -j DNAT --to-destination 1.2.3.4 --random --persistent 32 -A PREROUTING -i dummy0 -p tcp -j REDIRECT --to-ports 1-2 --random 33 -A POSTROUTING -o dummy0 -p tcp -j MASQUERADE --to-ports 1-2 --random 34 -A POSTROUTING -o dummy0 -p tcp -j NETMAP --to 1.0.0.0/8 35 -A POSTROUTING -o dummy0 -p tcp -j SNAT --to-source 1.2.3.4-1.2.3.5 --random --persistent 36 COMMIT 37 # Completed on Mon Jan 31 03:03:38 2011 38 # Generated by iptables-save v1.4.10 on Mon Jan 31 03:03:38 2011 39 *filter 40 :INPUT ACCEPT [76:13548] 41 :FORWARD ACCEPT [0:0] 42 :OUTPUT ACCEPT [59:11240] 43 #-A INPUT -m addrtype --src-type UNICAST --dst-type UNICAST --limit-iface-in 44 -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 0 45 -A INPUT -p tcp -m ecn --ecn-tcp-ece --ecn-tcp-cwr --ecn-ip-ect 1 46 -A INPUT -p icmp -m icmp --icmp-type 5/0 47 -A INPUT -p icmp -m icmp --icmp-type 5/1 48 -A INPUT -p icmp -m icmp --icmp-type 5 49 -A INPUT -m realm --realm 0x1 -m ttl --ttl-eq 64 -m ttl --ttl-lt 64 -m ttl --ttl-gt 64 50 -A FORWARD -p tcp -j REJECT --reject-with tcp-reset 51 COMMIT 52 # Completed on Mon Jan 31 03:03:39 2011 53