This commit is contained in:
iFargle 2023-12-06 20:50:56 +09:00
parent 1df0b67187
commit 320f405f81

View file

@ -23,76 +23,79 @@
networking.firewall.extraCommands = ''
iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -t nat -A OUTPUT -d 172.234.84.222/32 -p tcp -m tcp --dport 443 -j DNAT --to-destination 127.0.0.1:443
iptables -t nat -A POSTROUTING -o eth0 -s 110.100.0.2/32 ! -d 110.100.0.2/32 -j MASQUERADE
iptables -A FORWARD -s 10.100.0.2/32 -j ACCEPT
iptables -A FORWARD -d 10.100.0.2/32 -j ACCEPT
iptables -A FORWARD -s ! 10.100.0.2/32 -j DROP
# TCP PORTS ##################################################################################################
# PORT 80
iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 80 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 443
iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 443 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 25
iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 465
iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 587
iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 143
iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 993
iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 4190
iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 42420
iptables -t nat -A PREROUTING -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 42420 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 25565
iptables -t nat -A PREROUTING -p tcp --dport 25565 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 25565 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 25565 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 1443
iptables -t nat -A PREROUTING -p tcp --dport 1443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 1443 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 1443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 4443
iptables -t nat -A PREROUTING -p tcp --dport 4443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 4443 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 4443 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 5222
iptables -t nat -A PREROUTING -p tcp --dport 5222 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 5222 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5222 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 5347
iptables -t nat -A PREROUTING -p tcp --dport 5347 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 5347 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5347 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 5280
iptables -t nat -A PREROUTING -p tcp --dport 5280 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp --dport 5280 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p tcp --dport 5280 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p tcp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# UDP PORTS ##################################################################################################
# PORT 10000
iptables -t nat -A PREROUTING -p udp --dport 10000 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p udp --dport 10000 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p udp --dport 10000 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p udp -s 10.100.0.2 -j SNAT --to 10.100.0.2
# PORT 3478
iptables -t nat -A PREROUTING -p udp --dport 3478 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p udp --dport 3478 -j MASQUERADE
iptables -t nat -A PREROUTING -d 172.234.84.222 -p udp --dport 3478 -j DNAT --to-destination 10.100.0.2
iptables -t nat -A POSTROUTING -p udp -s 10.100.0.2 -j SNAT --to 10.100.0.2
'';
}