# Generated by iptables-save v1.4.12 on Tue Jun 30 17:38:46 2015
*mangle
:PREROUTING ACCEPT [42853755:35842411264]
:INPUT ACCEPT [11465395:11548588783]
:FORWARD ACCEPT [31388354:24293821929]
:OUTPUT ACCEPT [6608772:1336363561]
:POSTROUTING ACCEPT [37996852:25629665722]
COMMIT
# Completed on Tue Jun 30 17:38:46 2015
# Generated by iptables-save v1.4.12 on Tue Jun 30 17:38:46 2015
*nat
:PREROUTING ACCEPT [177:15311]
:INPUT ACCEPT [10:1845]
:OUTPUT ACCEPT [4:252]
:POSTROUTING ACCEPT [178:10036]
-A PREROUTING -i eth0 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 10.30.0.43:80
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5060 -j DNAT --to-destination 10.30.0.35:5060
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5061 -j DNAT --to-destination 10.30.0.35:5061
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5062 -j DNAT --to-destination 10.30.0.35:5062
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5063 -j DNAT --to-destination 10.30.0.35:5063
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5443 -j DNAT --to-destination 10.30.0.35:443
-A PREROUTING -i eth0 -p udp -m udp --dport 3478 -j DNAT --to-destination 10.30.0.35:3478
-A PREROUTING -i eth0 -p tcp -m tcp --dport 21 -j DNAT --to-destination 10.30.0.43:21
-A PREROUTING -i eth0 -p tcp -m tcp --dport 4333 -j DNAT --to-destination 10.30.0.42:4333
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5555 -j DNAT --to-destination 10.30.0.49:5555
-A PREROUTING -i eth0 -p tcp -m tcp --dport 4433 -j DNAT --to-destination 10.30.0.43:443
-A PREROUTING -i eth0 -p tcp -m tcp --dport 2383 -j DNAT --to-destination 10.30.0.43:2383
-A PREROUTING -i eth0 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 10.30.0.43:80
-A PREROUTING -i eth0 -p tcp -m tcp --dport 4443 -j DNAT --to-destination 10.30.0.50:443
-A PREROUTING -i eth0 -p tcp -m tcp --dport 4444 -j DNAT --to-destination 10.30.0.10:443
-A PREROUTING -i tun0 -p tcp -m tcp --dport 4444 -j DNAT --to-destination 10.30.0.10:443
-A PREROUTING -i eth0 -p tcp -m tcp --dport 5544 -j DNAT --to-destination 10.30.0.49:5544
-A PREROUTING -i eth0 -p tcp -m tcp --dport 25 -j DNAT --to-destination 10.30.0.30:25
-A PREROUTING -i eth0 -p tcp -m tcp --dport 8888 -j DNAT --to-destination 10.35.0.25:8888
-A PREROUTING -i eth0 -p tcp -m tcp --dport 110 -j DNAT --to-destination 10.30.0.30:110
-A PREROUTING -i eth0 -p tcp -m tcp --dport 143 -j DNAT --to-destination 10.30.0.30:143
-A PREROUTING -i eth0 -p tcp -m tcp --dport 443 -j DNAT --to-destination 10.30.0.30:443
-A PREROUTING -i eth3 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 10.30.0.44:8080
-A PREROUTING -i eth0 -p udp -m udp --dport 9987 -j DNAT --to-destination 10.25.0.40:9987
-A POSTROUTING -s 172.16.21.0/24 -o eth0 -j MASQUERADE
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Tue Jun 30 17:38:46 2015
# Generated by iptables-save v1.4.12 on Tue Jun 30 17:38:46 2015
*filter
:INPUT DROP [1:229]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [853:187692]
:syn_flood - [0:0]
-A INPUT -i tun+ -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 0 -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 3 -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5444 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --dport 3478 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5060 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5061 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5062 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5063 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --dport 9987 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 9987 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 30033 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 30033 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 10011 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 10011 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 4443 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 4333 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 4433 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 2383 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 8081 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5544 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 5555 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 143 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 8888 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --dport 1194 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --dport 1195 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 10000 -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -i eth2 -j ACCEPT
-A INPUT -i eth3 -j ACCEPT
-A INPUT -i tun0 -j ACCEPT
-A INPUT -i tun1 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j syn_flood
-A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A FORWARD -d 10.30.0.43/32 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i tun0 -o eth1 -j ACCEPT
-A FORWARD -i tun0 -o eth2 -j ACCEPT
-A FORWARD -i tun0 -o eth3 -j ACCEPT
-A FORWARD -i tun1 -o eth1 -j ACCEPT
-A FORWARD -i eth0 -o tun1 -j ACCEPT
-A FORWARD -i lo -j ACCEPT
-A FORWARD -i eth1 -j ACCEPT
-A FORWARD -i eth2 -j ACCEPT
-A FORWARD -i eth3 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth2 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth3 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 5060 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 5061 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 5062 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 5063 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.35/32 -i eth0 -p tcp -m tcp --dport 3478 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.43/32 -i eth0 -p tcp -m tcp --dport 21 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.42/32 -i eth0 -p tcp -m tcp --dport 4333 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.49/32 -i eth0 -p tcp -m tcp --dport 5555 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.43/32 -i eth0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.43/32 -i eth0 -p tcp -m tcp --dport 2383 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.43/32 -i eth0 -p tcp -m tcp --dport 80 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.50/32 -i eth0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.10/32 -i eth0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.10/32 -i tun0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.49/32 -i eth0 -p tcp -m tcp --dport 5544 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.30/32 -i eth0 -p tcp -m tcp --dport 25 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.35.0.25/32 -i eth0 -p tcp -m tcp --dport 8888 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.30/32 -i eth0 -p tcp -m tcp --dport 110 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.30/32 -i eth0 -p tcp -m tcp --dport 143 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.30/32 -i eth0 -p tcp -m tcp --dport 443 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 10.30.0.44/32 -i eth3 -p tcp -m tcp --dport 8080 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A syn_flood -m limit --limit 1/sec -j RETURN
-A syn_flood -j DROP
COMMIT
# Completed on Tue Jun 30 17:38:46 2015