-
- Compiling using Shorewall 5.2.1.4...
- IN===> 5.2.1.4
- Processing /etc/shorewall/params ...
- Params:
- export COLORTERM="truecolor"
- export CONFIG_PROTECT="/var/bind /usr/share/gnupg/qualified.txt"
- export CONFIG_PROTECT_MASK="/etc/sandbox.d /etc/php/cli-php5.6/ext-active/ /etc/php/cgi-php5.6/ext-active/ /etc/php/apache2-php5.6/ext-active/ /etc/php/cli-php7.2/ext-active/ /etc/php/cgi-php7.2/ext-active/ /etc/php/apache2-php7.2/ext-active/ /etc/fonts/fonts.conf /etc/gentoo-release /etc/terminfo /etc/ca-certificates.conf /etc/revdep-rebuild"
- export EDITOR="/bin/nano"
- export FW_NET="220.233.164.62/32"
- export GCC_SPECS=""
- export HOME="/root"
- export INFOPATH="/usr/share/gcc-data/x86_64-pc-linux-gnu/7.3.0/info:/usr/share/binutils-data/x86_64-pc-linux-gnu/2.30/info:/usr/share/info"
- export LANG="en_US.utf8"
- export LESS="-R -M --shift 5"
- export LESSOPEN="|lesspipe %s"
- export LOC_NET="192.168.1.0/24"
- export LOGNAME="root"
- export LS_COLORS="rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=01;05;37;41:mi=01;05;37;41:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.zst=01;31:*.tzst=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.wim=01;31:*.swm=01;31:*.dwm=01;31:*.esd=01;31:*.jpg=01;35:*.jpeg=01;35:*.mjpg=01;35:*.mjpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.cfg=00;32:*.conf=00;32:*.diff=00;32:*.doc=00;32:*.ini=00;32:*.log=00;32:*.patch=00;32:*.pdf=00;32:*.ps=00;32:*.tex=00;32:*.txt=00;32:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:"
- export MAIL="/var/mail/root"
- export MANPAGER="manpager"
- export MANPATH="/usr/share/gcc-data/x86_64-pc-linux-gnu/7.3.0/man:/usr/share/binutils-data/x86_64-pc-linux-gnu/2.30/man:/usr/lib64/php5.6/man/:/usr/lib64/php7.2/man/:/usr/local/share/man:/usr/share/man"
- export OLDPWD="/root"
- export OPENGL_PROFILE="xorg-x11"
- export PAGER="/usr/bin/less"
- export PATH="/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin"
- export PERL_HASH_SEED="0"
- export PERL_PERTURB_KEYS="0"
- export PWD="/etc/shorewall"
- export SHELL="/bin/bash"
- export SHLVL="3"
- export SSH_CLIENT="192.168.1.26 60618 22"
- export SSH_CONNECTION="192.168.1.26 60618 192.168.1.1 22"
- export SSH_TTY="/dev/pts/0"
- export SW_CONFDIR="/etc/shorewall"
- export TERM="xterm-256color"
- export USER="root"
- PARAMS:
- FW_NET='220.233.164.62/32'
- MANPAGER='manpager'
- SHELL='/bin/bash'
- CONFIG_PROTECT_MASK='/etc/sandbox.d /etc/php/cli-php5.6/ext-active/ /etc/php/cgi-php5.6/ext-active/ /etc/php/apache2-php5.6/ext-active/ /etc/php/cli-php7.2/ext-active/ /etc/php/cgi-php7.2/ext-active/ /etc/php/apache2-php7.2/ext-active/ /etc/fonts/fonts.conf /etc/gentoo-release /etc/terminfo /etc/ca-certificates.conf /etc/revdep-rebuild'
- PERL_HASH_SEED='0'
- OPENGL_PROFILE='xorg-x11'
- SSH_CONNECTION='192.168.1.26 60618 192.168.1.1 22'
- GCC_SPECS=''
- LESSOPEN='|lesspipe %s'
- LOGNAME='root'
- LANG='en_US.utf8'
- MAIL='/var/mail/root'
- LS_COLORS='rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=01;05;37;41:mi=01;05;37;41:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arc=01;31:*.arj=01;31:*.taz=01;31:*.lha=01;31:*.lz4=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.tzo=01;31:*.t7z=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lrz=01;31:*.lz=01;31:*.lzo=01;31:*.xz=01;31:*.zst=01;31:*.tzst=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.alz=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.cab=01;31:*.wim=01;31:*.swm=01;31:*.dwm=01;31:*.esd=01;31:*.jpg=01;35:*.jpeg=01;35:*.mjpg=01;35:*.mjpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.ogv=01;35:*.ogx=01;35:*.cfg=00;32:*.conf=00;32:*.diff=00;32:*.doc=00;32:*.ini=00;32:*.log=00;32:*.patch=00;32:*.pdf=00;32:*.ps=00;32:*.tex=00;32:*.txt=00;32:*.aac=00;36:*.au=00;36:*.flac=00;36:*.m4a=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.oga=00;36:*.opus=00;36:*.spx=00;36:*.xspf=00;36:'
- PERL_PERTURB_KEYS='0'
- USER='root'
- PWD='/etc/shorewall'
- HOME='/root'
- SSH_CLIENT='192.168.1.26 60618 22'
- PAGER='/usr/bin/less'
- LESS='-R -M --shift 5'
- COLORTERM='truecolor'
- EDITOR='/bin/nano'
- TERM='xterm-256color'
- PATH='/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin'
- CONFIG_PROTECT='/var/bind /usr/share/gnupg/qualified.txt'
- SSH_TTY='/dev/pts/0'
- LOC_NET='192.168.1.0/24'
- SW_CONFDIR='/etc/shorewall'
- INFOPATH='/usr/share/gcc-data/x86_64-pc-linux-gnu/7.3.0/info:/usr/share/binutils-data/x86_64-pc-linux-gnu/2.30/info:/usr/share/info'
- MANPATH='/usr/share/gcc-data/x86_64-pc-linux-gnu/7.3.0/man:/usr/share/binutils-data/x86_64-pc-linux-gnu/2.30/man:/usr/lib64/php5.6/man/:/usr/lib64/php7.2/man/:/usr/local/share/man:/usr/share/man'
- Processing /etc/shorewall/shorewall.conf...
- IN===> STARTUP_ENABLED=Yes
- IN===> VERBOSITY=1
- IN===> PAGER=
- IN===> FIREWALL=
- IN===> LOG_LEVEL="info"
- IN===> BLACKLIST_LOG_LEVEL=
- IN===> INVALID_LOG_LEVEL=
- IN===> LOG_BACKEND=
- IN===> LOG_MARTIANS=Yes
- IN===> LOG_VERBOSITY=2
- IN===> LOG_ZONE=Both
- IN===> LOGALLNEW=
- IN===> LOGFILE=/var/log/messages
- IN===> LOGFORMAT="%s %s "
- IN===> LOGTAGONLY=No
- IN===> LOGLIMIT="s:1/sec:10"
- IN===> MACLIST_LOG_LEVEL="$LOG_LEVEL"
- IN===> RELATED_LOG_LEVEL=
- IN===> RPFILTER_LOG_LEVEL="$LOG_LEVEL"
- IN===> SFILTER_LOG_LEVEL="$LOG_LEVEL"
- IN===> SMURF_LOG_LEVEL="$LOG_LEVEL"
- IN===> STARTUP_LOG=/var/log/shorewall-init.log
- IN===> TCP_FLAGS_LOG_LEVEL="$LOG_LEVEL"
- IN===> UNTRACKED_LOG_LEVEL=
- IN===> ARPTABLES=
- IN===> CONFIG_PATH=":${CONFDIR}/shorewall:${SHAREDIR}/shorewall"
- IN===> GEOIPDIR=/usr/share/xt_geoip/LE
- IN===> IPTABLES=
- IN===> IP=
- IN===> IPSET=
- IN===> LOCKFILE=
- IN===> MODULESDIR=
- IN===> NFACCT=
- IN===> PATH="/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin:/usr/local/sbin"
- IN===> PERL=/usr/bin/perl
- IN===> RESTOREFILE=restore
- IN===> SHOREWALL_SHELL=/bin/sh
- IN===> SUBSYSLOCK=/run/lock/shorewall
- IN===> TC=
- IN===> ACCEPT_DEFAULT="none"
- IN===> BLACKLIST_DEFAULT="Broadcast(DROP),Multicast(DROP),dropNotSyn:$LOG_LEVEL,dropInvalid:$LOG_LEVEL,DropDNSrep:$LOG_LEVEL"
- IN===> DROP_DEFAULT="Broadcast(DROP),Multicast(DROP)"
- IN===> NFQUEUE_DEFAULT="none"
- IN===> QUEUE_DEFAULT="none"
- IN===> REJECT_DEFAULT="Broadcast(DROP),Multicast(DROP)"
- IN===> RCP_COMMAND='scp ${files} ${root}@${system}:${destination}'
- IN===> RSH_COMMAND='ssh ${root}@${system} ${command}'
- IN===> ACCOUNTING=Yes
- IN===> ACCOUNTING_TABLE=filter
- IN===> ADD_IP_ALIASES=No
- IN===> ADD_SNAT_ALIASES=No
- IN===> ADMINISABSENTMINDED=Yes
- IN===> AUTOCOMMENT=Yes
- IN===> AUTOHELPERS=No
- IN===> AUTOMAKE=Yes
- IN===> BALANCE_PROVIDERS=No
- IN===> BASIC_FILTERS=No
- IN===> BLACKLIST="NEW,INVALID,UNTRACKED"
- IN===> CLAMPMSS=Yes
- IN===> CLEAR_TC=Yes
- IN===> COMPLETE=No
- IN===> DEFER_DNS_RESOLUTION=Yes
- IN===> DELETE_THEN_ADD=Yes
- IN===> DETECT_DNAT_IPADDRS=No
- IN===> DISABLE_IPV6=Yes
- IN===> DOCKER=No
- IN===> DONT_LOAD=
- IN===> DYNAMIC_BLACKLIST=Yes
- IN===> EXPAND_POLICIES=Yes
- IN===> EXPORTMODULES=Yes
- IN===> FASTACCEPT=No
- IN===> FORWARD_CLEAR_MARK=
- IN===> HELPERS=
- IN===> IGNOREUNKNOWNVARIABLES=No
- IN===> IMPLICIT_CONTINUE=No
- IN===> IPSET_WARNINGS=Yes
- IN===> IP_FORWARDING=On
- IN===> KEEP_RT_TABLES=No
- IN===> LOAD_HELPERS_ONLY=Yes
- IN===> MACLIST_TABLE=filter
- IN===> MACLIST_TTL=
- IN===> MANGLE_ENABLED=Yes
- IN===> MARK_IN_FORWARD_CHAIN=No
- IN===> MINIUPNPD=No
- IN===> MULTICAST=No
- IN===> MUTEX_TIMEOUT=60
- IN===> NULL_ROUTE_RFC1918=No
- IN===> OPTIMIZE=All
- IN===> OPTIMIZE_ACCOUNTING=No
- IN===> PERL_HASH_SEED=0
- IN===> REJECT_ACTION=
- IN===> RENAME_COMBINED=Yes
- IN===> REQUIRE_INTERFACE=No
- IN===> RESTART=restart
- IN===> RESTORE_DEFAULT_ROUTE=Yes
- IN===> RESTORE_ROUTEMARKS=Yes
- IN===> RETAIN_ALIASES=No
- IN===> ROUTE_FILTER=No
- IN===> SAVE_ARPTABLES=No
- IN===> SAVE_IPSETS=No
- IN===> TC_ENABLED=No
- IN===> TC_EXPERT=Yes
- IN===> TC_PRIOMAP="2 3 3 3 2 3 1 1 2 2 2 2 2 2 2 2"
- IN===> TRACK_PROVIDERS=Yes
- IN===> TRACK_RULES=No
- IN===> USE_DEFAULT_RT=Yes
- IN===> USE_NFLOG_SIZE=No
- IN===> USE_PHYSICAL_NAMES=No
- IN===> USE_RT_NAMES=No
- IN===> VERBOSE_MESSAGES=Yes
- IN===> WARNOLDCAPVERSION=Yes
- IN===> WORKAROUNDS=No
- IN===> ZERO_MARKS=No
- IN===> ZONE2ZONE=-
- IN===> BLACKLIST_DISPOSITION=DROP
- IN===> INVALID_DISPOSITION=CONTINUE
- IN===> MACLIST_DISPOSITION=REJECT
- IN===> RELATED_DISPOSITION=ACCEPT
- IN===> RPFILTER_DISPOSITION=DROP
- IN===> SMURF_DISPOSITION=DROP
- IN===> SFILTER_DISPOSITION=DROP
- IN===> TCP_FLAGS_DISPOSITION=DROP
- IN===> UNTRACKED_DISPOSITION=CONTINUE
- IN===> TC_BITS=
- IN===> PROVIDER_BITS=
- IN===> PROVIDER_OFFSET=
- IN===> MASK_BITS=
- IN===> ZONE_BITS=0
- SYS----> /sbin/iptables -w -L -n
- Chain INPUT (policy DROP)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:67:68
-
- Chain FORWARD (policy DROP)
- target prot opt source destination
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
- ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpts:67:68
-
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- Loading Modules...
- IN===> loadmodule ip_conntrack_amanda
- IN===> loadmodule ip_conntrack_ftp
- IN===> loadmodule ip_conntrack_h323
- IN===> loadmodule ip_conntrack_irc
- IN===> loadmodule ip_conntrack_netbios_ns
- IN===> loadmodule ip_conntrack_pptp
- IN===> loadmodule ip_conntrack_sip
- IN===> loadmodule ip_conntrack_tftp
- IN===> loadmodule ip_nat_amanda
- IN===> loadmodule ip_nat_ftp
- IN===> loadmodule ip_nat_h323
- IN===> loadmodule ip_nat_irc
- IN===> loadmodule ip_nat_pptp
- IN===> loadmodule ip_nat_sip
- IN===> loadmodule ip_nat_snmp_basic
- IN===> loadmodule ip_nat_tftp
- IN===> loadmodule nf_conntrack_ftp
- IN===> loadmodule nf_conntrack_h323
- IN===> loadmodule nf_conntrack_irc
- IN===> loadmodule nf_conntrack_netbios_ns
- IN===> loadmodule nf_conntrack_netlink
- IN===> loadmodule nf_conntrack_pptp
- IN===> loadmodule nf_conntrack_proto_gre
- IN===> loadmodule nf_conntrack_proto_sctp
- IN===> loadmodule nf_conntrack_proto_udplite
- IN===> loadmodule nf_conntrack_sip sip_direct_media=0
- IN===> loadmodule nf_conntrack_tftp
- IN===> loadmodule nf_conntrack_sane
- IN===> loadmodule nf_nat_amanda
- IN===> loadmodule nf_nat_ftp
- IN===> loadmodule nf_nat_h323
- IN===> loadmodule nf_nat_irc
- IN===> loadmodule nf_nat
- IN===> loadmodule nf_nat_pptp
- IN===> loadmodule nf_nat_proto_gre
- IN===> loadmodule nf_nat_sip
- IN===> loadmodule nf_nat_snmp_basic
- IN===> loadmodule nf_nat_tftp
- IN===> loadmodule ipt_LOG
- IN===> loadmodule nf_log_ipv4
- IN===> loadmodule xt_LOG
- IN===> loadmodule xt_NFLOG
- IN===> loadmodule nfnetlink_log
- SYS----> /sbin/iptables -w -N fooX14663
- SYS----> /sbin/iptables -w -N foo1X14663
- SYS----> /sbin/iptables -w -A fooX14663 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
- SYS----> /sbin/iptables -w -A fooX14663 -p tcp -m multiport --dports 21,22 -j ACCEPT
- SYS----> /sbin/iptables -w -A fooX14663 -p tcp -m multiport --sports 60 -m multiport --dports 99 -j ACCEPT
- SYS----> /sbin/iptables -w -t raw -L -n
- Chain PREROUTING (policy ACCEPT)
- target prot opt source destination
-
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- SYS----> /sbin/iptables -w -t raw -N fooX14663
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -j CT --notrack
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 137 -j CT --helper netbios-ns
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 1729 -j CT --helper pptp
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 5060 -j CT --helper sip
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 6667 -j CT --helper irc
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 6667 -j CT --helper irc-0
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 69 -j CT --helper tftp
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 69 -j CT --helper tftp-0
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 161 -j CT --helper snmp
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 10080 -j CT --helper amanda
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p udp --dport 1719 -j CT --helper RAS
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 21 -j CT --helper ftp
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 6566 -j CT --helper sane
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -A fooX14663 -p tcp --dport 6566 -j CT --helper sane-0
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -A fooX14663 -m conntrack --ctorigdst 192.168.1.1 -j ACCEPT
- SYS----> /sbin/iptables -w -A fooX14663 -m hashlimit --hashlimit-upto 3/min --hashlimit-burst 3 --hashlimit-name fooX14663 --hashlimit-mode srcip -j ACCEPT
- SYS----> /sbin/iptables -w -A fooX14663 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
- SYS----> /sbin/iptables -w -t mangle -L -n
- Chain PREROUTING (policy ACCEPT)
- target prot opt source destination
-
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
-
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
-
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
-
- Chain POSTROUTING (policy ACCEPT)
- target prot opt source destination
- SYS----> /sbin/iptables -w -t mangle -A fooX14663 -j MARK --set-mark 1
- SYS----> /sbin/iptables -w -A fooX14663 -j LOG
- SYS----> /sbin/iptables -w -A fooX14663 -p tcp -m multiport --dports 21:22 -j ACCEPT
- NF-(N)-> raw:OUTPUT
- NF-(N)-> raw:PREROUTING
- NF-(N)-> filter:INPUT
- NF-(N)-> filter:OUTPUT
- NF-(N)-> filter:FORWARD
- NF-(N)-> nat:PREROUTING
- NF-(N)-> nat:POSTROUTING
- NF-(N)-> nat:OUTPUT
- SYS----> /sbin/iptables -w -t nat -L -n
- Chain PREROUTING (policy ACCEPT)
- target prot opt source destination
-
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
-
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
-
- Chain POSTROUTING (policy ACCEPT)
- target prot opt source destination
- SYS----> /sbin/iptables -w -t nat -L INPUT -n
- Chain INPUT (policy ACCEPT)
- target prot opt source destination
- NF-(N)-> nat:INPUT
- NF-(N)-> mangle:PREROUTING
- NF-(N)-> mangle:INPUT
- NF-(N)-> mangle:OUTPUT
- SYS----> /sbin/iptables -w -t mangle -L FORWARD -n
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- NF-(N)-> mangle:FORWARD
- NF-(N)-> mangle:POSTROUTING
- NF-(N)-> filter:reject
- Compiling /etc/shorewall/zones...
- IN===> fw firewall
- IN===> net ipv4
- IN===> loc ipv4
- IN===> vpn ipv4
- CD===> ?FORMAT 2
- Compiling /etc/shorewall/interfaces...
- IN===> loc net1 tcpflags,nosmurfs,routefilter,logmartians,dhcp
- IN===> net ppp0 tcpflags,nosmurfs,routefilter,logmartians,sourceroute=0,optional,wait=200
- SYS----> /sbin/iptables -w -F fooX14663
- SYS----> /sbin/iptables -w -X fooX14663
- SYS----> /sbin/iptables -w -F foo1X14663
- SYS----> /sbin/iptables -w -X foo1X14663
- SYS----> /sbin/iptables -w -t mangle -F fooX14663
- SYS----> /sbin/iptables -w -t mangle -X fooX14663
- SYS----> /sbin/iptables -w -t nat -F fooX14663
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t nat -X fooX14663
- iptables: No chain/target/match by that name.
- SYS----> /sbin/iptables -w -t raw -F fooX14663
- SYS----> /sbin/iptables -w -t raw -X fooX14663
- ERROR: Invalid value (200) for option wait /etc/shorewall/interfaces (line 14) at /usr/share/shorewall/Shorewall/Config.pm line 1565.
- Shorewall::Config::fatal_error("Invalid value (200) for option wait") called at /usr/share/shorewall/Shorewall/Zones.pm line 1334
- Shorewall::Zones::process_interface(2, 0) called at /usr/share/shorewall/Shorewall/Zones.pm line 1541
- Shorewall::Zones::validate_interfaces_file(0) called at /usr/share/shorewall/Shorewall/Compiler.pm line 690
- Shorewall::Compiler::compiler("script", "/var/lib/shorewall/.start", "directory", "", "verbosity", 1, "timestamp", 0, ...) called at /usr/share/shorewall/compiler.pl line 135
- eval() called 0 times
-