From b33be7b1e6bcc7368d02a75f9c9152791e78c59b Mon Sep 17 00:00:00 2001 From: iFargle Date: Wed, 6 Dec 2023 19:35:58 +0900 Subject: [PATCH] no masquerade --- nixos/hosts/osaka-linode-01/firewall.nix | 34 ++++++++++++------------ 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/nixos/hosts/osaka-linode-01/firewall.nix b/nixos/hosts/osaka-linode-01/firewall.nix index 67f09f10..52aaca28 100644 --- a/nixos/hosts/osaka-linode-01/firewall.nix +++ b/nixos/hosts/osaka-linode-01/firewall.nix @@ -28,71 +28,71 @@ # TCP PORTS ################################################################################################## # PORT 80 iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 80 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 80 # PORT 443 iptables -t nat -A PREROUTING -p tcp --dport 443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 443 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 443 # PORT 25 iptables -t nat -A PREROUTING -p tcp --dport 25 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 25 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 25 # PORT 465 iptables -t nat -A PREROUTING -p tcp --dport 465 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 465 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 465 # PORT 587 iptables -t nat -A PREROUTING -p tcp --dport 587 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 587 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 587 # PORT 143 iptables -t nat -A PREROUTING -p tcp --dport 143 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 143 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 143 # PORT 993 iptables -t nat -A PREROUTING -p tcp --dport 993 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 993 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 993 # PORT 4190 iptables -t nat -A PREROUTING -p tcp --dport 4190 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 4190 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 4190 # PORT 42420 iptables -t nat -A PREROUTING -p tcp --dport 42420 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 42420 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 42420 # PORT 25565 iptables -t nat -A PREROUTING -p tcp --dport 25565 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 25565 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 25565 # PORT 1443 iptables -t nat -A PREROUTING -p tcp --dport 1443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 1443 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 1443 # PORT 4443 iptables -t nat -A PREROUTING -p tcp --dport 4443 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 4443 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 4443 # PORT 5222 iptables -t nat -A PREROUTING -p tcp --dport 5222 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 5222 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 5222 # PORT 5347 iptables -t nat -A PREROUTING -p tcp --dport 5347 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 5347 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 5347 # PORT 5280 iptables -t nat -A PREROUTING -p tcp --dport 5280 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p tcp --dport 5280 -j MASQUERADE + iptables -t nat -A POSTROUTING -p tcp --dport 5280 # UDP PORTS ################################################################################################## # PORT 10000 iptables -t nat -A PREROUTING -p udp --dport 10000 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p udp --dport 10000 -j MASQUERADE + iptables -t nat -A POSTROUTING -p udp --dport 10000 # PORT 3478 iptables -t nat -A PREROUTING -p udp --dport 3478 -j DNAT --to-destination 10.100.0.2 - iptables -t nat -A POSTROUTING -p udp --dport 3478 -j MASQUERADE + iptables -t nat -A POSTROUTING -p udp --dport 3478 ''; } \ No newline at end of file