Shorewall 4.4.20.1 Dump at cyber3 - mié jun  8 18:13:12 ART 2011

Counters reset mié jun  8 13:02:10 ART 2011

Chain INPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
 725K   61M dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
7383K 1181M lan2fw     all  --  eth6   *       0.0.0.0/0            0.0.0.0/0           
26567 3731K lan22fw    all  --  eth5   *       0.0.0.0/0            0.0.0.0/0           
3425K 3882M dsl0_in    all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           
2329K 2599M dsl1_in    all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           
2713K 3241M dsl2_in    all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           
2436K 2823M dsl3_in    all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           
1056K 1251M inet22fw   all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0           
 1845 51660 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:INPUT:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain FORWARD (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
5223K  823M lan_frwd   all  --  eth6   *       0.0.0.0/0            0.0.0.0/0           
21768 2076K lan2_frwd  all  --  eth5   *       0.0.0.0/0            0.0.0.0/0           
 772K  599M dsl0_fwd   all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           
 583K  496M dsl1_fwd   all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           
1192K  935M dsl2_fwd   all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           
 869K  519M dsl3_fwd   all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           
1564K 1082M inet2_frwd  all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           
    1    93 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    1    93 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:FORWARD:REJECT:' 
    1    93 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
7516K   13G fw2lan     all  --  *      eth6    0.0.0.0/0            0.0.0.0/0           
60680   33M fw2lan2    all  --  *      eth5    0.0.0.0/0            0.0.0.0/0           
2360K  402M fw2inet    all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
1573K  269M fw2inet    all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
1741K  270M fw2inet    all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
1651K  289M fw2inet    all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
 722K  103M fw2inet2   all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain %Limit (1 references)
 pkts bytes target     prot opt in     out     source               destination         
   10   576            all  --  *      *       0.0.0.0/0            0.0.0.0/0           recent: SET name: SSHA side: source 
    3   180 %Limit%    all  --  *      *       0.0.0.0/0            0.0.0.0/0           recent: UPDATE seconds: 60 hit_count: 3 name: SSHA side: source 
    7   396 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain %Limit% (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    3   180 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:SSHA:DROP:' 
    3   180 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain Drop (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:113 /* Auth */ 
    0     0 dropBcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 4 /* Needed ICMP types */ 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 /* Needed ICMP types */ 
    0     0 dropInvalid  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 135,445 /* SMB */ 
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:137:139 /* SMB */ 
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:137 dpts:1024:65535 /* SMB */ 
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 135,139,445 /* SMB */ 
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1900 /* UPnP */ 
    0     0 dropNotSyn  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:53 /* Late DNS Replies */ 

Chain Reject (16 references)
 pkts bytes target     prot opt in     out     source               destination         
 527K   49M            all  --  *      *       0.0.0.0/0            0.0.0.0/0           
  496 26516 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:113 /* Auth */ 
 526K   49M dropBcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 code 4 /* Needed ICMP types */ 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 /* Needed ICMP types */ 
 524K   49M dropInvalid  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 135,445 /* SMB */ 
   57  4446 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:137:139 /* SMB */ 
    0     0 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:137 dpts:1024:65535 /* SMB */ 
 1213 59464 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 135,139,445 /* SMB */ 
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1900 /* UPnP */ 
 108K 5735K dropNotSyn  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
  166 16536 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:53 /* Late DNS Replies */ 

Chain dropBcast (2 references)
 pkts bytes target     prot opt in     out     source               destination         
  933 97032 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           ADDRTYPE match dst-type BROADCAST 
 1845 51660 DROP       all  --  *      *       0.0.0.0/0            224.0.0.0/4         

Chain dropInvalid (2 references)
 pkts bytes target     prot opt in     out     source               destination         
11700  675K DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID 

Chain dropNotSyn (2 references)
 pkts bytes target     prot opt in     out     source               destination         
  743  364K DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:!0x17/0x02 

Chain dsl0_fwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
 408K  343M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
 772K  599M inet_frwd  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl0_in (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 139K   13M smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
3289K 3867M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
3425K 3882M inet2fw    all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl1_fwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
 287K  254M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
 583K  496M inet_frwd  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl1_in (1 references)
 pkts bytes target     prot opt in     out     source               destination         
97921 9407K smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
2226K 2586M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
2329K 2599M inet2fw    all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl2_fwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
 651K  605M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
1192K  935M inet_frwd  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl2_in (1 references)
 pkts bytes target     prot opt in     out     source               destination         
97123 9261K smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
2609K 3229M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
2713K 3241M inet2fw    all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl3_fwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
 403K  364M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
 869K  519M inet_frwd  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dsl3_in (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 105K   11M smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
2347K 2813M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
2436K 2823M inet2fw    all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain dynamic (8 references)
 pkts bytes target     prot opt in     out     source               destination         

Chain fw2inet (4 references)
 pkts bytes target     prot opt in     out     source               destination         
7128K 1217M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
 197K   13M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain fw2inet2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 706K  102M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
15399  927K ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain fw2lan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
7516K   13G ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain fw2lan2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
60678   33M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    2   104 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain inet22fw (1 references)
 pkts bytes target     prot opt in     out     source               destination         
72493 5685K smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
 994K 1246M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
 984K 1245M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
   68  3724 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 80,10003 
   10   576 %Limit     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:22 
 1615 57618 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 limit: avg 2/sec burst 3 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 0 limit: avg 2/sec burst 3 
    1    56 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 limit: avg 2/sec burst 3 
   40  3850 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 limit: avg 2/sec burst 3 
70757 5620K Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
66645 5327K LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet22fw:REJECT:' 
66645 5327K reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet22inet (4 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet22inet:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet22lan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
1564K 1082M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:9055 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:9022 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:4899 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3339 ctorigdst 200.51.46.51 
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            192.168.150.99      udp dpt:1194 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3390 ctorigdst 200.51.46.51 
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            192.168.150.99      udp dpt:3390 ctorigdst 200.51.46.51 
    4   192 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3060 ctorigdst 200.51.46.51 
    1    48 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3061 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3070 ctorigdst 200.51.46.51 
  193 10024 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1500 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:8085 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:8065 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:6022 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3306 ctorigdst 200.51.46.51 
    2    80 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:8080 ctorigdst 200.51.46.51 
    1    48 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:5900 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3180 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:60443 ctorigdst 200.51.46.51 
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            192.168.150.99      udp dpt:60443 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1433 ctorigdst 200.51.46.51 
    1    48 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3389 ctorigdst 200.51.46.51 
    3   144 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1080 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1081 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:8481 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:5905 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:5906 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:5907 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1030 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1031 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:10025 ctorigdst 200.51.46.51 
   21  1260 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:10026 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1035 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1036 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1040 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2130 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2131 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2132 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2133 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2134 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2135 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1037 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1038 ctorigdst 200.51.46.51 
    2   103 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1041 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1042 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1043 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1044 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1045 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:1046 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:2106 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:7777 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:5901 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:47323 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3390 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:3388 ctorigdst 200.51.46.51 
    2   169 ACCEPT     udp  --  *      *       0.0.0.0/0            192.168.150.99      udp dpt:47323 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:34567 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:7010 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:7011 ctorigdst 200.51.46.51 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:7012 ctorigdst 200.51.46.51 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet22lan:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet22lan2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
   57 31848 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet22lan2:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet2_frwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
  230 12116 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
  230 12116 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
1430K  997M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
1564K 1082M inet22lan  all  --  *      eth6    0.0.0.0/0            0.0.0.0/0           
   57 31848 inet22lan2  all  --  *      eth5    0.0.0.0/0            0.0.0.0/0           
    0     0 inet22inet  all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
    0     0 inet22inet  all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
    0     0 inet22inet  all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
    0     0 inet22inet  all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           

Chain inet2fw (4 references)
 pkts bytes target     prot opt in     out     source               destination         
  10M   13G ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
 5507  213K ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 limit: avg 2/sec burst 3 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 0 limit: avg 2/sec burst 3 
   28  5836 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 limit: avg 2/sec burst 3 
  822 76624 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 limit: avg 2/sec burst 3 
 433K   43M Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 423K   42M LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet2fw:REJECT:' 
 423K   42M reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet2inet (4 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain inet2inet2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet2inet2:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet2lan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
3414K 2547M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            192.168.150.99      tcp dpt:47323 
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            192.168.150.99      udp dpt:47323 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet2lan:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet2lan2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 2822 1705K ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:inet2lan2:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain inet_frwd (4 references)
 pkts bytes target     prot opt in     out     source               destination         
3414K 2547M inet2lan   all  --  *      eth6    0.0.0.0/0            0.0.0.0/0           
 2822 1705K inet2lan2  all  --  *      eth5    0.0.0.0/0            0.0.0.0/0           
    0     0 inet2inet  all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
    0     0 inet2inet  all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
    0     0 inet2inet  all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
    0     0 inet2inet  all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
    0     0 inet2inet2  all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           

Chain lan22fw (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 1584 88487 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
25155 3641K tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
24983 3643K ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
 1565 87312 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 22,53,80,10003,3128 
   19  1175 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 53,123,4827,3130 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:3128 ctorigdstport 80 ! ctorigdst 10.10.50.0/24 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan22fw:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan22inet (4 references)
 pkts bytes target     prot opt in     out     source               destination         
 3169 1136K ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
  169  9328 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 80,8080,443,1863,53,110,21,5050,995,143,465,1723 
    3   134 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 53,123,1723 
17115  854K Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
17115  854K LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan22inet:REJECT:' 
17115  854K reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan22inet2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
   73 13720 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    7   388 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 80,8080,443,1863,53,110,21,5050,995,143,465,1723 
    2    58 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 53,123,1723 
 1230 62082 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 1230 62082 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan22inet2:REJECT:' 
 1230 62082 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan22lan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan22lan:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan2_frwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
18526  926K dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
18526  926K smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
19511 2002K tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 lan22lan   all  --  *      eth6    0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  *      eth5    0.0.0.0/0            0.0.0.0/0           
 6078  393K lan22inet  all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
 4693  691K lan22inet  all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
 4786  298K lan22inet  all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
 4899  617K lan22inet  all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
 1312 76248 lan22inet2  all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           

Chain lan2fw (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 209K   13M smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
7381K 1180M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
7173K 1168M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           
 207K   12M ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 20,21,22,53,80,10003,3128,10140 
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 53,123,4827,3130 
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:3128 ctorigdstport 80 ! ctorigdst 192.168.150.0/24 
 2563  190K Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
 1630 93247 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan2fw:REJECT:' 
 1630 93247 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan2inet (4 references)
 pkts bytes target     prot opt in     out     source               destination         
2145K  364M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
1600K  111M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain lan2inet2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
1302K  337M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
 176K   11M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain lan2lan2 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate RELATED,ESTABLISHED 
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:lan2lan2:REJECT:' 
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] 

Chain lan_frwd (1 references)
 pkts bytes target     prot opt in     out     source               destination         
1776K  122M dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
1776K  122M smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0           ctstate INVALID,NEW 
2881K  557M tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  *      eth6    0.0.0.0/0            0.0.0.0/0           
    0     0 lan2lan2   all  --  *      eth5    0.0.0.0/0            0.0.0.0/0           
 953K  116M lan2inet   all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
 718K   87M lan2inet   all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
1169K  171M lan2inet   all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
 907K  102M lan2inet   all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
1477K  348M lan2inet2  all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           

Chain logdrop (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain logflags (5 references)
 pkts bytes target     prot opt in     out     source               destination         
    7   416 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 4 level 6 prefix `Shorewall:logflags:DROP:' 
    7   416 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain logreject (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain reject (23 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           ADDRTYPE match src-type BROADCAST 
    0     0 DROP       all  --  *      *       224.0.0.0/4          0.0.0.0/0           
    0     0 DROP       2    --  *      *       0.0.0.0/0            0.0.0.0/0           
 109K 5457K REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with tcp-reset 
 402K   43M REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with icmp-port-unreachable 
  670 27854 REJECT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with icmp-host-unreachable 
    0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with icmp-host-prohibited 

Chain shorewall (0 references)
 pkts bytes target     prot opt in     out     source               destination         

Chain smurflog (2 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0           LOG flags 0 level 6 prefix `Shorewall:smurfs:DROP:' 
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain smurfs (14 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 RETURN     all  --  *      *       0.0.0.0              0.0.0.0/0           
    0     0 smurflog   all  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] ADDRTYPE match src-type BROADCAST 
    0     0 smurflog   all  --  *      *       224.0.0.0/4          0.0.0.0/0           [goto] 

Chain tcpflags (14 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] tcp flags:0x3F/0x29 
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] tcp flags:0x3F/0x00 
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] tcp flags:0x06/0x06 
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] tcp flags:0x03/0x03 
    7   416 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           [goto] tcp spt:0 flags:0x17/0x02 

Log (/var/log/messages)


NAT Table

Chain PREROUTING (policy ACCEPT 17353 packets, 1283K bytes)
 pkts bytes target     prot opt in     out     source               destination         
2238K  165M dnat       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain OUTPUT (policy ACCEPT 1794 packets, 109K bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain POSTROUTING (policy ACCEPT 2786 packets, 154K bytes)
 pkts bytes target     prot opt in     out     source               destination         
 500K   33M dsl0_masq  all  --  *      dsl0    0.0.0.0/0            0.0.0.0/0           
 371K   25M dsl1_masq  all  --  *      dsl1    0.0.0.0/0            0.0.0.0/0           
 373K   25M dsl2_masq  all  --  *      dsl2    0.0.0.0/0            0.0.0.0/0           
 374K   25M dsl3_masq  all  --  *      dsl3    0.0.0.0/0            0.0.0.0/0           
 182K   11M eth7_masq  all  --  *      eth7    0.0.0.0/0            0.0.0.0/0           

Chain dnat (1 references)
 pkts bytes target     prot opt in     out     source               destination         
1718K  116M lan_dnat   all  --  eth6   *       0.0.0.0/0            0.0.0.0/0           
20105 1015K lan2_dnat  all  --  eth5   *       0.0.0.0/0            0.0.0.0/0           
 136K   13M inet_dnat  all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           
96100 9275K inet_dnat  all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           
95099 9159K inet_dnat  all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           
 103K   11M inet_dnat  all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           
69603 5521K inet2_dnat  all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           

Chain dsl0_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 415K   29M MASQUERADE  all  --  *      *       192.168.150.0/24     0.0.0.0/0           
   43  2428 MASQUERADE  all  --  *      *       10.10.50.0/24        0.0.0.0/0           

Chain dsl1_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 310K   21M MASQUERADE  all  --  *      *       192.168.150.0/24     0.0.0.0/0           
   33  1817 MASQUERADE  all  --  *      *       10.10.50.0/24        0.0.0.0/0           

Chain dsl2_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 314K   22M MASQUERADE  all  --  *      *       192.168.150.0/24     0.0.0.0/0           
   53  2944 MASQUERADE  all  --  *      *       10.10.50.0/24        0.0.0.0/0           

Chain dsl3_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 314K   22M MASQUERADE  all  --  *      *       192.168.150.0/24     0.0.0.0/0           
   32  1796 MASQUERADE  all  --  *      *       10.10.50.0/24        0.0.0.0/0           

Chain eth7_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 155K 9794K SNAT       all  --  *      *       192.168.150.0/24     0.0.0.0/0           to:200.51.46.51 
    8   417 SNAT       all  --  *      *       10.10.50.0/24        0.0.0.0/0           to:200.51.46.51 

Chain inet2_dnat (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:9055 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:9022 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:4899 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3339 to:192.168.150.99 
    0     0 DNAT       udp  --  *      *       0.0.0.0/0            200.51.46.51        udp dpt:1194 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3390 to:192.168.150.99 
    0     0 DNAT       udp  --  *      *       0.0.0.0/0            200.51.46.51        udp dpt:3390 to:192.168.150.99 
    4   192 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3060 to:192.168.150.99 
    1    48 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3061 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3070 to:192.168.150.99 
  191  9932 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1500 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:8085 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:8065 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:6022 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3306 to:192.168.150.99 
    2    80 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:8080 to:192.168.150.99 
    1    48 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:5900 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3180 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:60443 to:192.168.150.99 
    0     0 DNAT       udp  --  *      *       0.0.0.0/0            200.51.46.51        udp dpt:60443 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1433 to:192.168.150.99 
    1    48 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3389 to:192.168.150.99 
    3   144 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1080 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1081 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:8481 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:5905 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:5906 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:5907 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1030 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1031 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:10025 to:192.168.150.99 
   21  1260 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:10026 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1035 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1036 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1040 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2130 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2131 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2132 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2133 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2134 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2135 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1037 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1038 to:192.168.150.99 
    1    63 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1041 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1042 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1043 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1044 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1045 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:1046 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:2106 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:7777 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:5901 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:47323 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3390 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:3388 to:192.168.150.99 
    1    70 DNAT       udp  --  *      *       0.0.0.0/0            200.51.46.51        udp dpt:47323 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:34567 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:7010 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:7011 to:192.168.150.99 
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            200.51.46.51        tcp dpt:7012 to:192.168.150.99 

Chain inet_dnat (4 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DNAT       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:47323 to:192.168.150.99 
    0     0 DNAT       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:47323 to:192.168.150.99 

Chain lan2_dnat (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 1565 87312 REDIRECT   tcp  --  *      *       0.0.0.0/0           !10.10.50.0/24       tcp dpt:80 redir ports 3128 

Chain lan_dnat (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 207K   12M REDIRECT   tcp  --  *      *       0.0.0.0/0           !192.168.150.0/24    tcp dpt:80 redir ports 3128 

Mangle Table

Chain PREROUTING (policy ACCEPT 279K packets, 186M bytes)
 pkts bytes target     prot opt in     out     source               destination         
  19M   18G CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           connmark match !0x0/0xff CONNMARK restore mask 0xff 
 425K   49M routemark  all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 
 314K   37M routemark  all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 
 314K   37M routemark  all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 
 321K   39M routemark  all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 
 195K   18M routemark  all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 
4198K 4481M tcpre      all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           
2912K 3095M tcpre      all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           
3906K 4176M tcpre      all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           
3305K 3343M tcpre      all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           
2621K 2333M tcpre      all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           
9192K 1307M tcpre      all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 

Chain INPUT (policy ACCEPT 172K packets, 137M bytes)
 pkts bytes target     prot opt in     out     source               destination         
  19M   15G tcin       all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain FORWARD (policy ACCEPT 108K packets, 48M bytes)
 pkts bytes target     prot opt in     out     source               destination         
  10M 4457M MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0           MARK and 0xffffff00 
  10M 4457M tcfor      all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain OUTPUT (policy ACCEPT 144K packets, 135M bytes)
 pkts bytes target     prot opt in     out     source               destination         
7834K 1319M CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           connmark match !0x0/0xff CONNMARK restore mask 0xff 
7790K   13G tcout      all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match 0x0/0xff 

Chain POSTROUTING (policy ACCEPT 251K packets, 184M bytes)
 pkts bytes target     prot opt in     out     source               destination         
  26M   19G tcpost     all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain routemark (5 references)
 pkts bytes target     prot opt in     out     source               destination         
 425K   49M MARK       all  --  dsl0   *       0.0.0.0/0            0.0.0.0/0           MARK set 0x1 
 314K   37M MARK       all  --  dsl1   *       0.0.0.0/0            0.0.0.0/0           MARK set 0x2 
 314K   37M MARK       all  --  dsl2   *       0.0.0.0/0            0.0.0.0/0           MARK set 0x3 
 321K   39M MARK       all  --  dsl3   *       0.0.0.0/0            0.0.0.0/0           MARK set 0x4 
 195K   18M MARK       all  --  eth7   *       0.0.0.0/0            0.0.0.0/0           MARK set 0x5 
1569K  180M CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0           mark match !0x0/0xff CONNMARK save mask 0xff 

Chain tcfor (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 6421  805K MARK       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            ipp2p  --edk  --gnu  --kazaa  --bit  --apple  --soul  --winmx  --ares MARK set 0x4 

Chain tcin (1 references)
 pkts bytes target     prot opt in     out     source               destination         

Chain tcout (1 references)
 pkts bytes target     prot opt in     out     source               destination         
  116  106K MARK       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 9187,25,465,995,3306,10019,10020,26000,443,1863,7001,6891:6900,1503,3389 MARK set 0x5 
    1    40 MARK       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 5061,1025,5050,5100 MARK set 0x5 
    0     0 MARK       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 9,7001,5000,5004,1025,49152 MARK set 0x5 

Chain tcpost (1 references)
 pkts bytes target     prot opt in     out     source               destination         

Chain tcpre (6 references)
 pkts bytes target     prot opt in     out     source               destination         
49593 2488K MARK       tcp  --  *      *       192.168.150.0/24     0.0.0.0/0           multiport dports 9187,25,465,995,3306,10019,10020,26000,443,1863,7001,6891:6900,1503,3389 MARK set 0x5 
  194  9628 MARK       tcp  --  *      *       192.168.150.0/24     0.0.0.0/0           multiport dports 5061,1025,5050,5100 MARK set 0x5 
 2089  106K MARK       udp  --  *      *       192.168.150.0/24     0.0.0.0/0           multiport dports 9,7001,5000,5004,1025,49152 MARK set 0x5 

Raw Table

Chain PREROUTING (policy ACCEPT 30M packets, 19G bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 16M packets, 15G bytes)
 pkts bytes target     prot opt in     out     source               destination         

Conntrack Table (12280 out of 131072)

