#Generated by nupyf on 2008-10-13 11:48:20.002919 from ./same-iface/acls_ftp_http.xml #DISPATCH and DEFAULT Rules :TUN0-TUN0 - :TUN0-NET3 - :TUN0-NET4 - :TUN0-NET5 - :TUN0-ETH0 - :NET3-TUN0 - :NET3-NET3 - :NET3-NET4 - :NET3-NET5 - :NET3-ETH0 - :NET4-TUN0 - :NET4-NET3 - :NET4-NET4 - :NET4-NET5 - :NET4-ETH0 - :NET5-TUN0 - :NET5-NET3 - :NET5-NET4 - :NET5-NET5 - :NET5-ETH0 - :ETH0-TUN0 - :ETH0-NET3 - :ETH0-NET4 - :ETH0-NET5 - :ETH0-ETH0 - :IF-TUN0 - :TUN0-IF - :IF-NET3 - :NET3-IF - :IF-NET4 - :NET4-IF - :IF-NET5 - :NET5-IF - :IF-ETH0 - :ETH0-IF - -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT -A FORWARD -m state --state INVALID -j DROP -A INPUT -m state --state INVALID -j DROP -A OUTPUT -m state --state INVALID -j DROP -A FORWARD -s 10.8.0.1 -d 10.8.0.1 -i tun0 -o tun0 -j NET3-NET3 -A FORWARD -s 10.8.0.1 -d 10.8.0.0/24 -i tun0 -o tun0 -j NET3-TUN0 -A FORWARD -s 10.8.0.1 -d 192.168.33.0/24 -i tun0 -o tun0 -j NET3-NET5 -A FORWARD -s 10.8.0.1 -d 192.168.35.0/24 -i tun0 -o tun0 -j NET3-NET4 -A FORWARD -s 10.8.0.0/24 -d 10.8.0.1 -i tun0 -o tun0 -j TUN0-NET3 -A FORWARD -s 192.168.33.0/24 -d 10.8.0.1 -i tun0 -o tun0 -j NET5-NET3 -A FORWARD -s 192.168.35.0/24 -d 10.8.0.1 -i tun0 -o tun0 -j NET4-NET3 -A FORWARD -s 10.8.0.0/24 -d 10.8.0.0/24 -i tun0 -o tun0 -j TUN0-TUN0 -A FORWARD -s 10.8.0.0/24 -d 192.168.33.0/24 -i tun0 -o tun0 -j TUN0-NET5 -A FORWARD -s 10.8.0.0/24 -d 192.168.35.0/24 -i tun0 -o tun0 -j TUN0-NET4 -A FORWARD -s 192.168.33.0/24 -d 10.8.0.0/24 -i tun0 -o tun0 -j NET5-TUN0 -A FORWARD -s 192.168.33.0/24 -d 192.168.33.0/24 -i tun0 -o tun0 -j NET5-NET5 -A FORWARD -s 192.168.33.0/24 -d 192.168.35.0/24 -i tun0 -o tun0 -j NET5-NET4 -A FORWARD -s 192.168.35.0/24 -d 10.8.0.0/24 -i tun0 -o tun0 -j NET4-TUN0 -A FORWARD -s 192.168.35.0/24 -d 192.168.33.0/24 -i tun0 -o tun0 -j NET4-NET5 -A FORWARD -s 192.168.35.0/24 -d 192.168.35.0/24 -i tun0 -o tun0 -j NET4-NET4 -A INPUT -s 10.8.0.1 -i tun0 -j NET3-IF -A INPUT -s 10.8.0.0/24 -i tun0 -j TUN0-IF -A INPUT -s 192.168.33.0/24 -i tun0 -j NET5-IF -A INPUT -s 192.168.35.0/24 -i tun0 -j NET4-IF -A OUTPUT -d 10.8.0.0/24 -o tun0 -j IF-TUN0 -A OUTPUT -d 10.8.0.1 -o tun0 -j IF-NET3 -A OUTPUT -d 192.168.35.0/24 -o tun0 -j IF-NET4 -A OUTPUT -d 192.168.33.0/24 -o tun0 -j IF-NET5 -A INPUT -i eth0 -j ETH0-IF -A OUTPUT -o eth0 -j IF-ETH0 -A FORWARD -s 10.8.0.1 -i tun0 -o eth0 -j NET3-ETH0 -A FORWARD -d 10.8.0.1 -i eth0 -o tun0 -j ETH0-NET3 -A FORWARD -s 10.8.0.0/24 -i tun0 -o eth0 -j TUN0-ETH0 -A FORWARD -s 192.168.33.0/24 -i tun0 -o eth0 -j NET5-ETH0 -A FORWARD -s 192.168.35.0/24 -i tun0 -o eth0 -j NET4-ETH0 -A FORWARD -d 10.8.0.0/24 -i eth0 -o tun0 -j ETH0-TUN0 -A FORWARD -d 192.168.33.0/24 -i eth0 -o tun0 -j ETH0-NET5 -A FORWARD -d 192.168.35.0/24 -i eth0 -o tun0 -j ETH0-NET4 -A FORWARD -i eth0 -o eth0 -j ETH0-ETH0 -A INPUT -i lo -j ACCEPT -A OUTPUT -o lo -j ACCEPT -A FORWARD -j ULOG --ulog-prefix "DFT_FORWARD_DROP" -A FORWARD -j DROP -A INPUT -j ULOG --ulog-prefix "DFT_INPUT_DROP" -A INPUT -j DROP -A OUTPUT -j ULOG --ulog-prefix "DFT_OUTPUT_DROP" -A OUTPUT -j DROP