| | 54 | |
| | 55 | == iptables == |
| | 56 | * sudo iptables-save |
| | 57 | {{{ |
| | 58 | # Generated by iptables-save v1.4.8 on Thu Feb 16 10:31:29 2012 |
| | 59 | *nat |
| | 60 | :PREROUTING ACCEPT [743892:129452770] |
| | 61 | :POSTROUTING ACCEPT [1179:112796] |
| | 62 | :OUTPUT ACCEPT [1215:115607] |
| | 63 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535 |
| | 64 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535 |
| | 65 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE |
| | 66 | COMMIT |
| | 67 | # Completed on Thu Feb 16 10:31:29 2012 |
| | 68 | # Generated by iptables-save v1.4.8 on Thu Feb 16 10:31:29 2012 |
| | 69 | *filter |
| | 70 | :INPUT ACCEPT [4957020:3457557240] |
| | 71 | :FORWARD ACCEPT [0:0] |
| | 72 | :OUTPUT ACCEPT [3323525:4327643495] |
| | 73 | -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT |
| | 74 | -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT |
| | 75 | -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT |
| | 76 | -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT |
| | 77 | -A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT |
| | 78 | -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT |
| | 79 | -A FORWARD -i virbr0 -o virbr0 -j ACCEPT |
| | 80 | -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable |
| | 81 | -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable |
| | 82 | COMMIT |
| | 83 | # Completed on Thu Feb 16 10:31:29 2012 |
| | 84 | }}} |
| | 85 | * lease file => /var/lib/misc/dnsmasq.leases |