|
楼主 |
发表于 2025-3-17 21:11
|
显示全部楼层
display ip6tables filter
显示如下,
Chain INPUT (policy ACCEPT 44 packets, 4576 bytes)
num pkts bytes target prot opt in out source destina tion
1 1332 110K INPUT_USERDEV_CTRL all * * ::/0 ::/0
2 0 0 DROP tcp br+ * ::/0 ::/0 tcp dpt:53 state NEW recent: CHECK seconds: 1 hit_count: 80 name: DNS side: source mask: ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff
3 0 0 tcp br+ * ::/0 ::/0 tcp dpt:53 state NEW recent: SET name: DNS side: source mask: ffff :ffff:ffff:ffff:ffff:ffff:ffff:ffff
4 1332 110K INPUT_IPSET_TRAFFIC_CONTROL all * * ::/0 ::/0
5 1332 110K INPUT_PROTOCOL_FLT all * * ::/0 ::/0
6 1332 110K INPUT_GUEST_NETWORK all * * ::/0 ::/0
7 1332 110K INPUT_ACL_WAN_WHITELIST all * * ::/0 ::/0
8 1332 110K INPUT_ACL_WHITELIST all * * ::/0 ::/0
9 1332 110K INPUT_ACL_PORT all * * ::/0 :: /0
10 1332 110K INPUT_VXLAN all * * ::/0 ::/0
11 1332 110K INPUT_ACL_WIFI all * * ::/0 :: /0
12 1332 110K INPUT_ACL_MAINTENANCE all * * ::/0 ::/0
13 1332 110K INPUT_ACL_WAN all * * ::/0 ::/ 0
14 1332 110K INPUT_ACL all * * ::/0 ::/0
15 1332 110K INPUT_DOS all * * ::/0 ::/0
16 1332 110K INPUT_SERVICE all * * ::/0 ::/ 0
17 191 19640 INPUT_PCP_WAN all * * ::/0 ::/ 0
18 191 19640 INPUT_PORT_SCAN all * * ::/0 : :/0
19 191 19640 INPUT_FIREWALL all * * ::/0 :: /0
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
num pkts bytes target prot opt in out source destina tion
1 0 0 FWD_ETH_INVISIBLE all * * ::/0 ::/0
2 0 0 FWD_IPSET_TRAFFIC_CONTROL all * * ::/0 ::/0
3 0 0 FWD_SIP_CHECK all * * ::/0 ::/ 0
4 0 0 FWD_GUEST_NETWORK all * * ::/0 ::/0
5 0 0 FWD_PROTOCOL_FLT all * * ::/0 ::/0
6 0 0 FWD_WANUPDOWN all * * ::/0 ::/ 0
7 0 0 FWD_virtual** all * * ::/0 ::/0
8 0 0 FWD_REJECT all * * ::/0 ::/0
9 0 0 FWD_IPFLT all * * ::/0 ::/0
10 0 0 FWD_IPFLT_DEFAULT all * * ::/0 ::/0
11 0 0 FWD_SESSION_LIMIT all * * ::/0 ::/0
12 0 0 FWD_SERVICE all * * ::/0 ::/0
13 0 0 FWD_PORTMAP all * * ::/0 ::/0
14 0 0 FWD_TRAFFIC_FOWARD all * * ::/0 ::/0
15 0 0 FWD_DMZV6 all * * ::/0 ::/0
16 0 0 FWD_FIREWALL_RULE all * * ::/0 ::/0
17 0 0 FWD_FIREWALL_CUST all * * ::/0 ::/0
18 0 0 FWD_FIREWALL all * * ::/0 ::/0
Chain OUTPUT (policy ACCEPT 122 packets, 9920 bytes)
num pkts bytes target prot opt in out source destina tion
1 0 0 DROP all * ra+ ::/0 ::/0
2 0 0 DROP all * wl+ ::/0 ::/0
Chain FWD_DMZV6 (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_ETH_INVISIBLE (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_FIREWALL (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_FIREWALL_CHAIN1 (0 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_FIREWALL_CUST (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_FIREWALL_RULE (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_GUEST_NETWORK (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_IPFLT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_IPFLT_DEFAULT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_IPSET_TRAFFIC_CONTROL (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_PORTMAP (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_PROTOCOL_FLT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_REJECT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_SERVICE (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 ACCEPT all ppp+ * ::/0 ::/0 state RELATED,ESTABLISHED
2 0 0 ACCEPT all wan+ * ::/0 ::/0 state RELATED,ESTABLISHED
3 0 0 ACCEPT all br+ * ::/0 ::/0 state RELATED,ESTABLISHED
Chain FWD_SESSION_LIMIT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_SIP_CHECK (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 DROP all br+ * ::/0 ::/0
Chain FWD_TRAFFIC_FOWARD (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_virtual** (1 references)
num pkts bytes target prot opt in out source destina tion
Chain FWD_WANUPDOWN (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 DROP all * * ::/0 ::/0 rt type:0
Chain INPUT_ACL (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 ACCEPT tcp br+ * ::/0 ::/0 tcp dpt:23 mark match 0x102001/0x1fffffff
2 0 0 ACCEPT tcp br+ * ::/0 ::/0 tcp dpt:8080
3 0 0 ACCEPT tcp br+ * ::/0 ::/0 tcp dpt:443
4 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:8080
5 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:8080
6 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:443
7 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:443
8 0 0 ACCEPT tcp br+ * ::/0 ::/0 tcp dpt:23
9 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:23
10 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:23
11 0 0 DROP tcp br+ * ::/0 ::/0 tcp dpt:22
12 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:22
13 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:22
14 0 0 DROP tcp br+ * ::/0 ::/0 tcp dpt:8022
15 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:8022
16 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:8022
17 0 0 DROP tcp br+ * ::/0 ::/0 tcp dpt:21
18 0 0 DROP tcp wan+ * ::/0 ::/0 tcp dpt:21
19 0 0 DROP tcp ppp+ * ::/0 ::/0 tcp dpt:21
Chain INPUT_ACL_MAINTENANCE (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_ACL_PORT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_ACL_WAN (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_ACL_WAN_WHITELIST (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_ACL_WHITELIST (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_ACL_WIFI (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_DOS (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 128 limit: avg 100/sec burst 100
2 0 0 DROP icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 128
3 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 128 limit: avg 100/sec burst 100
4 0 0 DROP icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 128
5 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 137 limit: avg 1/sec burst 5
6 0 0 DROP icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 137
7 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 137 limit: avg 1/sec burst 5
8 0 0 DROP icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 137
Chain INPUT_FIREWALL (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 DROP all wan+ * ::/0 ::/0
2 0 0 DROP all ppp+ * ::/0 ::/0
Chain INPUT_GUEST_NETWORK (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_IPSET_TRAFFIC_CONTROL (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_PCP_WAN (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_PORT_SCAN (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_PROTOCOL_FLT (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_SERVICE (1 references)
num pkts bytes target prot opt in out source destina tion
1 0 0 ACCEPT all wan+ * ::/0 ::/0 state RELATED,ESTABLISHED
2 0 0 ACCEPT all ppp+ * ::/0 ::/0 state RELATED,ESTABLISHED
3 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 133
4 69 16896 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 134
5 214 15408 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 135
6 858 58336 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 136
7 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 141
8 0 0 ACCEPT icmpv6 * * ::/0 ::/0 ipv6-icmptype 142
9 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 1
10 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 2
11 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 3
12 0 0 ACCEPT icmpv6 wan+ * ::/0 ::/0 ipv6-icmptype 4
13 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 1
14 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 2
15 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 3
16 0 0 ACCEPT icmpv6 ppp+ * ::/0 ::/0 ipv6-icmptype 4
Chain INPUT_USERDEV_CTRL (1 references)
num pkts bytes target prot opt in out source destina tion
Chain INPUT_VXLAN (1 references)
num pkts bytes target prot opt in out source destina tion
success!
|
|