mirror of
https://gitlab.com/libvirt/libvirt.git
synced 2024-12-22 17:34:18 +03:00
2a95dbd03c
Long ago we adapted to Linux kernel changes which inverted the
behaviour of the conntrack --ctdir setting:
commit a6a04ea47a
Author: Stefan Berger <stefanb@us.ibm.com>
Date: Wed May 15 21:02:11 2013 -0400
nwfilter: check for inverted ctdir
Linux netfilter at some point (Linux 2.6.39) inverted the meaning of the
'--ctdir reply' and newer netfilter implementations now expect
'--ctdir original' instead and vice-versa.
We check for the kernel version and assume that all Linux kernels with version
2.6.39 have the newer inverted logic.
Any distro backporting the Linux kernel patch that inverts the --ctdir logic
(Linux commit 96120d86f) must also backport this patch for Linux and
adapt the kernel version being tested for.
Signed-off-by: Stefan Berger <stefanb@linux.vnet.ibm.com>
Given our supported platform targets, we no longer need to
consider a version of Linux before 2.6.39, so can drop
support for the old direction behaviour.
The test suite updates are triggered because that never
probed for the ctdir direction, and so the iptables syntax
generator unconditionally dropped the ctdir args.
Reviewed-by: Laine Stump <laine@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2332 lines
32 KiB
Plaintext
2332 lines
32 KiB
Plaintext
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--dport 80 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--dport 90 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--dport 80 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 1 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 80 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 80 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 80 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 80 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 90 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 90 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--dport 90 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 2 \
|
|
--sport 90 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 3 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1080 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1080 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1090 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1090 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1100 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1100 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 80 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 80 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p tcp \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--dport 90 \
|
|
--sport 1110 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p tcp \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 4 \
|
|
--sport 90 \
|
|
--dport 1110 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 1.1.1.1 \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 2.2.2.2 \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 3.3.3.3 \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 1.1.1.1 \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 2.2.2.2 \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 3.3.3.3 \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 1.1.1.1 \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 1.1.1.1 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 2.2.2.2 \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 2.2.2.2 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p udp \
|
|
--destination 3.3.3.3 \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p udp \
|
|
--source 3.3.3.3 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 5 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 1.1.1.1 \
|
|
--source 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 1.1.1.1 \
|
|
--destination 1.1.1.1 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 2.2.2.2 \
|
|
--source 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 2.2.2.2 \
|
|
--destination 2.2.2.2 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|
|
iptables \
|
|
-w \
|
|
-A FP-vnet0 \
|
|
-p sctp \
|
|
--destination 3.3.3.3 \
|
|
--source 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Reply \
|
|
-j ACCEPT
|
|
iptables \
|
|
-w \
|
|
-A HJ-vnet0 \
|
|
-p sctp \
|
|
--source 3.3.3.3 \
|
|
--destination 3.3.3.3 \
|
|
-m dscp \
|
|
--dscp 6 \
|
|
-m conntrack \
|
|
--ctstate NEW,ESTABLISHED \
|
|
-m conntrack \
|
|
--ctdir Original \
|
|
-j RETURN
|