aboutsummaryrefslogtreecommitdiffstats
path: root/test/output/tproxy/rules-save
diff options
context:
space:
mode:
Diffstat (limited to 'test/output/tproxy/rules-save')
-rw-r--r--test/output/tproxy/rules-save18
1 files changed, 18 insertions, 0 deletions
diff --git a/test/output/tproxy/rules-save b/test/output/tproxy/rules-save
index a61faa4..b948e2b 100644
--- a/test/output/tproxy/rules-save
+++ b/test/output/tproxy/rules-save
@@ -5,9 +5,12 @@
:OUTPUT DROP [0:0]
:icmp-routing - [0:0]
:logaccept-0 - [0:0]
+:logaccept-1 - [0:0]
:logdrop-0 - [0:0]
:logdrop-1 - [0:0]
+:logdrop-2 - [0:0]
:logpass-0 - [0:0]
+:logpass-1 - [0:0]
-A FORWARD -m conntrack --ctstate ESTABLISHED -j ACCEPT
-A FORWARD -j ACCEPT
-A FORWARD -j logdrop-0
@@ -21,6 +24,9 @@
-A FORWARD -j ACCEPT
-A FORWARD -j DROP
-A FORWARD
+-A FORWARD -j logaccept-1
+-A FORWARD -j logdrop-2
+-A FORWARD -j logpass-1
-A FORWARD -i eth0 -j ACCEPT
-A FORWARD -i eth1 -s 10.0.0.0/12 -o eth2 -d 10.1.0.0/12 -j ACCEPT
-A FORWARD -i eth1 -s 10.0.0.0/12 -o eth3 -d 10.1.0.0/12 -j ACCEPT
@@ -85,6 +91,9 @@
-A INPUT -j ACCEPT
-A INPUT -j DROP
-A INPUT
+-A INPUT -j logaccept-1
+-A INPUT -j logdrop-2
+-A INPUT -j logpass-1
-A INPUT -i eth0 -j ACCEPT
-A INPUT -j ACCEPT
-A INPUT -p icmp -j icmp-routing
@@ -102,6 +111,10 @@
-A OUTPUT -j ACCEPT
-A OUTPUT -j DROP
-A OUTPUT
+-A OUTPUT -j logaccept-1
+-A OUTPUT -j logdrop-2
+-A OUTPUT -j logpass-1
+-A OUTPUT -m limit --limit 12/minute -j ULOG
-A OUTPUT -j ACCEPT
-A OUTPUT -o eth1 -d 10.0.0.0/12 -j ACCEPT
-A OUTPUT -p icmp -j icmp-routing
@@ -110,11 +123,16 @@
-A icmp-routing -p icmp --icmp-type 12 -j ACCEPT
-A logaccept-0 -m limit --limit 1/second -j LOG
-A logaccept-0 -j ACCEPT
+-A logaccept-1 -m limit --limit 12/minute -j ULOG
+-A logaccept-1 -j ACCEPT
-A logdrop-0 -m limit --limit 1/second -j LOG
-A logdrop-0 -j DROP
-A logdrop-1 -m limit --limit 1/second -j LOG
-A logdrop-1 -j DROP
+-A logdrop-2 -m limit --limit 12/minute -j ULOG
+-A logdrop-2 -j DROP
-A logpass-0 -m limit --limit 1/second -j LOG
+-A logpass-1 -m limit --limit 12/minute -j ULOG
COMMIT
*mangle
:FORWARD ACCEPT [0:0]