| 54 | |
| 55 | == iptables == |
| 56 | * sudo iptables-save |
| 57 | {{{ |
| 58 | # Generated by iptables-save v1.4.8 on Thu Feb 16 10:31:29 2012 |
| 59 | *nat |
| 60 | :PREROUTING ACCEPT [743892:129452770] |
| 61 | :POSTROUTING ACCEPT [1179:112796] |
| 62 | :OUTPUT ACCEPT [1215:115607] |
| 63 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535 |
| 64 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535 |
| 65 | -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE |
| 66 | COMMIT |
| 67 | # Completed on Thu Feb 16 10:31:29 2012 |
| 68 | # Generated by iptables-save v1.4.8 on Thu Feb 16 10:31:29 2012 |
| 69 | *filter |
| 70 | :INPUT ACCEPT [4957020:3457557240] |
| 71 | :FORWARD ACCEPT [0:0] |
| 72 | :OUTPUT ACCEPT [3323525:4327643495] |
| 73 | -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT |
| 74 | -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT |
| 75 | -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT |
| 76 | -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT |
| 77 | -A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT |
| 78 | -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT |
| 79 | -A FORWARD -i virbr0 -o virbr0 -j ACCEPT |
| 80 | -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable |
| 81 | -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable |
| 82 | COMMIT |
| 83 | # Completed on Thu Feb 16 10:31:29 2012 |
| 84 | }}} |
| 85 | * lease file => /var/lib/misc/dnsmasq.leases |