1
0
mirror of https://gitlab.com/libvirt/libvirt.git synced 2025-01-09 01:18:00 +03:00

nwfilter: drop support for legacy iptables conntrack direction

Long ago we adapted to Linux kernel changes which inverted the
behaviour of the conntrack --ctdir setting:

  commit a6a04ea47a
  Author: Stefan Berger <stefanb@us.ibm.com>
  Date:   Wed May 15 21:02:11 2013 -0400

    nwfilter: check for inverted ctdir

    Linux netfilter at some point (Linux 2.6.39) inverted the meaning of the
    '--ctdir reply' and newer netfilter implementations now expect
    '--ctdir original' instead and vice-versa.
    We check for the kernel version and assume that all Linux kernels with version
    2.6.39 have the newer inverted logic.

    Any distro backporting the Linux kernel patch that inverts the --ctdir logic
    (Linux commit 96120d86f) must also backport this patch for Linux and
    adapt the kernel version being tested for.

    Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>

Given our supported platform targets, we no longer need to
consider a version of Linux before 2.6.39, so can drop
support for the old direction behaviour.

The test suite updates are triggered because that never
probed for the ctdir direction, and so the iptables syntax
generator unconditionally dropped the ctdir args.

Reviewed-by: Laine Stump <laine@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
This commit is contained in:
Daniel P. Berrangé 2022-02-25 16:28:32 +00:00
parent 02b8045517
commit 2a95dbd03c
27 changed files with 764 additions and 53 deletions

View File

@ -64,17 +64,6 @@ VIR_LOG_INIT("nwfilter.nwfilter_ebiptables_driver");
#define BRIDGE_NF_CALL_ALERT_INTERVAL 10 /* seconds */
/*
* --ctdir original vs. --ctdir reply's meaning was inverted in netfilter
* at some point (Linux 2.6.39)
*/
enum ctdirStatus {
CTDIR_STATUS_UNKNOWN = 0,
CTDIR_STATUS_CORRECTED = 1,
CTDIR_STATUS_OLD = 2,
};
static enum ctdirStatus iptables_ctdir_corrected;
#define PRINT_ROOT_CHAIN(buf, prefix, ifname) \
g_snprintf(buf, sizeof(buf), "libvirt-%c-%s", prefix, ifname)
#define PRINT_CHAIN(buf, prefix, ifname, suffix) \
@ -1088,24 +1077,13 @@ iptablesEnforceDirection(virFirewall *fw,
bool directionIn,
virNWFilterRuleDef *rule)
{
switch (iptables_ctdir_corrected) {
case CTDIR_STATUS_UNKNOWN:
/* could not be determined or s.th. is seriously wrong */
return;
case CTDIR_STATUS_CORRECTED:
directionIn = !directionIn;
break;
case CTDIR_STATUS_OLD:
break;
}
if (rule->tt != VIR_NWFILTER_RULE_DIRECTION_INOUT)
virFirewallRuleAddArgList(fw, fwrule,
"-m", "conntrack",
"--ctdir",
(directionIn ?
"Original" :
"Reply"),
"Reply" :
"Original"),
NULL);
}
@ -3633,41 +3611,12 @@ virNWFilterTechDriver ebiptables_driver = {
.removeBasicRules = ebtablesRemoveBasicRules,
};
static void
ebiptablesDriverProbeCtdir(void)
{
struct utsname utsname;
unsigned long thisversion;
iptables_ctdir_corrected = CTDIR_STATUS_UNKNOWN;
if (uname(&utsname) < 0) {
VIR_ERROR(_("Call to utsname failed: %d"), errno);
return;
}
/* following Linux lxr, the logic was inverted in 2.6.39 */
if (virStringParseVersion(&thisversion, utsname.release, true) < 0) {
VIR_ERROR(_("Could not determine kernel version from string %s"),
utsname.release);
return;
}
if (thisversion >= 2 * 1000000 + 6 * 1000 + 39)
iptables_ctdir_corrected = CTDIR_STATUS_CORRECTED;
else
iptables_ctdir_corrected = CTDIR_STATUS_OLD;
}
static int
ebiptablesDriverInit(bool privileged)
{
if (!privileged)
return 0;
ebiptablesDriverProbeCtdir();
ebiptables_driver.flags = TECHDRV_FLAG_INITIALIZED;
return 0;

View File

@ -10,6 +10,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -21,6 +23,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -34,6 +38,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -44,6 +50,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -56,6 +64,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -66,6 +76,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -76,6 +88,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -88,6 +102,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -98,4 +114,6 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -53,6 +61,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -73,6 +85,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -95,4 +111,6 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -10,6 +10,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -21,6 +23,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -34,6 +38,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -44,6 +50,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -56,6 +64,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -66,6 +76,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -76,6 +88,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -88,6 +102,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -98,4 +114,6 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -53,6 +61,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -73,6 +85,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -95,4 +111,6 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -57,6 +57,8 @@ iptables \
--dport 564:1092 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'udp rule' \
-j RETURN
@ -71,6 +73,8 @@ iptables \
--sport 564:1092 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'udp rule' \
-j ACCEPT
@ -87,6 +91,8 @@ iptables \
--dport 564:1092 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'udp rule' \
-j RETURN
@ -101,6 +107,8 @@ ip6tables \
--sport 256:4369 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'tcp/ipv6 rule' \
-j RETURN
@ -117,6 +125,8 @@ ip6tables \
--dport 256:4369 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'tcp/ipv6 rule' \
-j ACCEPT
@ -131,6 +141,8 @@ ip6tables \
--sport 256:4369 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'tcp/ipv6 rule' \
-j RETURN
@ -140,6 +152,8 @@ ip6tables \
-p udp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment '`ls`;${COLUMNS};$(ls);"test";&'\''3 spaces'\''' \
-j RETURN
@ -149,6 +163,8 @@ ip6tables \
-p udp \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment '`ls`;${COLUMNS};$(ls);"test";&'\''3 spaces'\''' \
-j ACCEPT
@ -158,6 +174,8 @@ ip6tables \
-p udp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment '`ls`;${COLUMNS};$(ls);"test";&'\''3 spaces'\''' \
-j RETURN
@ -167,6 +185,8 @@ ip6tables \
-p sctp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'comment with lone '\'', `, ", `, \, $x, and two spaces' \
-j RETURN
@ -176,6 +196,8 @@ ip6tables \
-p sctp \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'comment with lone '\'', `, ", `, \, $x, and two spaces' \
-j ACCEPT
@ -185,6 +207,8 @@ ip6tables \
-p sctp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'comment with lone '\'', `, ", `, \, $x, and two spaces' \
-j RETURN
@ -194,6 +218,8 @@ ip6tables \
-p ah \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'tmp=`mktemp`; echo ${RANDOM} > ${tmp} ; cat < ${tmp}; rm -f ${tmp}' \
-j RETURN
@ -203,6 +229,8 @@ ip6tables \
-p ah \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'tmp=`mktemp`; echo ${RANDOM} > ${tmp} ; cat < ${tmp}; rm -f ${tmp}' \
-j ACCEPT
@ -212,6 +240,8 @@ ip6tables \
-p ah \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'tmp=`mktemp`; echo ${RANDOM} > ${tmp} ; cat < ${tmp}; rm -f ${tmp}' \
-j RETURN

View File

@ -32,6 +32,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -39,6 +41,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -46,4 +50,6 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN

View File

@ -10,6 +10,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -21,6 +23,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -34,6 +38,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -44,6 +50,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -56,6 +64,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -66,6 +76,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -76,6 +88,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -88,6 +102,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -98,4 +114,6 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -53,6 +61,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -73,6 +85,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -95,4 +111,6 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -5,6 +5,8 @@ iptables \
--sport 22 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -13,6 +15,8 @@ iptables \
--dport 22 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -21,6 +25,8 @@ iptables \
--sport 22 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -28,6 +34,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -35,6 +43,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -42,6 +52,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -49,6 +61,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -56,6 +70,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +79,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \

View File

@ -57,6 +57,8 @@ iptables \
--dport 564:1092 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -69,6 +71,8 @@ iptables \
--sport 564:1092 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -83,6 +87,8 @@ iptables \
--dport 564:1092 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -95,6 +101,8 @@ ip6tables \
--sport 256:4369 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -109,6 +117,8 @@ ip6tables \
--dport 256:4369 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -121,4 +131,6 @@ ip6tables \
--sport 256:4369 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -4,6 +4,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -11,6 +13,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -18,6 +22,8 @@ iptables \
-p icmp \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -53,6 +61,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -73,6 +85,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -95,4 +111,6 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -4,6 +4,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m set \
--match-set tck_test src,dst \
-j RETURN
@ -13,6 +15,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src \
-j ACCEPT
@ -22,6 +26,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m set \
--match-set tck_test src,dst \
-j RETURN
@ -58,6 +64,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src,dst \
-j RETURN
@ -67,6 +75,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m set \
--match-set tck_test src,dst,src \
-j ACCEPT
@ -76,6 +86,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src,dst \
-j RETURN
@ -85,6 +97,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src,dst \
-j RETURN
@ -94,6 +108,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m set \
--match-set tck_test src,dst,src \
-j ACCEPT
@ -103,6 +119,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src,dst \
-j RETURN
@ -112,6 +130,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src \
-j RETURN
@ -121,6 +141,8 @@ iptables \
-p all \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m set \
--match-set tck_test src,dst \
-j ACCEPT
@ -130,6 +152,8 @@ iptables \
-p all \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m set \
--match-set tck_test dst,src \
-j RETURN

View File

@ -8,6 +8,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -30,6 +34,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -52,6 +60,8 @@ iptables \
--dport 90 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -74,6 +86,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -96,4 +112,6 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN

File diff suppressed because it is too large Load Diff

View File

@ -8,6 +8,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -30,6 +34,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -52,6 +60,8 @@ iptables \
--dport 90 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -74,6 +86,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -96,6 +112,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -107,6 +125,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -118,6 +138,8 @@ iptables \
--dport 90 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -129,6 +151,8 @@ iptables \
--sport 90 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -141,6 +165,8 @@ iptables \
--dport 1100 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -153,6 +179,8 @@ iptables \
--sport 1100 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -165,4 +193,6 @@ iptables \
--dport 1100 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN

View File

@ -9,6 +9,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -19,6 +21,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -31,6 +35,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -43,6 +49,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -57,6 +65,8 @@ ip6tables \
--dport 100:1111 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -69,6 +79,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -81,6 +93,8 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -95,6 +109,8 @@ ip6tables \
--dport 65535:65535 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -107,4 +123,6 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -43,6 +49,8 @@ iptables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -57,6 +65,8 @@ iptables \
--dport 100:1111 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -69,6 +79,8 @@ iptables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -81,6 +93,8 @@ iptables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -95,6 +109,8 @@ iptables \
--dport 65535:65535 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -107,4 +123,6 @@ iptables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -51,6 +51,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'accept rule -- dir out' \
-j RETURN
@ -63,6 +65,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'accept rule -- dir out' \
-j ACCEPT
@ -77,6 +81,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'accept rule -- dir out' \
-j RETURN
@ -157,6 +163,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'accept rule -- dir in' \
-j RETURN
@ -171,6 +179,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-m comment \
--comment 'accept rule -- dir in' \
-j ACCEPT
@ -183,6 +193,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-m comment \
--comment 'accept rule -- dir in' \
-j RETURN

View File

@ -23,6 +23,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -31,6 +33,8 @@ iptables \
--dport 80 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -39,6 +43,8 @@ iptables \
--sport 80 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \

View File

@ -9,6 +9,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -19,6 +21,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -31,6 +35,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -43,6 +49,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -57,6 +65,8 @@ ip6tables \
--dport 100:1111 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -69,6 +79,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -81,6 +93,8 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -95,6 +109,8 @@ ip6tables \
--dport 65535:65535 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -107,4 +123,6 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \

View File

@ -9,6 +9,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -19,6 +21,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -31,6 +35,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -43,6 +49,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -57,6 +65,8 @@ ip6tables \
--dport 100:1111 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -69,6 +79,8 @@ ip6tables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -81,6 +93,8 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -95,6 +109,8 @@ ip6tables \
--dport 65535:65535 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -107,4 +123,6 @@ ip6tables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -43,6 +49,8 @@ iptables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -57,6 +65,8 @@ iptables \
--dport 100:1111 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -69,6 +79,8 @@ iptables \
--sport 100:1111 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -81,6 +93,8 @@ iptables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -95,6 +109,8 @@ iptables \
--dport 65535:65535 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -107,4 +123,6 @@ iptables \
--sport 65535:65535 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -10,6 +10,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -21,6 +23,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
ip6tables \
-w \
@ -34,6 +38,8 @@ ip6tables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
ip6tables \
-w \
@ -44,6 +50,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -56,6 +64,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -66,6 +76,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -76,6 +88,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
ip6tables \
-w \
@ -88,6 +102,8 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
ip6tables \
-w \
@ -98,4 +114,6 @@ ip6tables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN

View File

@ -9,6 +9,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -19,6 +21,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j ACCEPT
iptables \
-w \
@ -31,6 +35,8 @@ iptables \
--dscp 2 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j RETURN
iptables \
-w \
@ -41,6 +47,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -53,6 +61,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -63,6 +73,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -73,6 +85,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN
iptables \
-w \
@ -85,6 +99,8 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate NEW,ESTABLISHED \
-m conntrack \
--ctdir Original \
-j ACCEPT
iptables \
-w \
@ -95,4 +111,6 @@ iptables \
--dscp 33 \
-m conntrack \
--ctstate ESTABLISHED \
-m conntrack \
--ctdir Reply \
-j RETURN