On 21/08/2011 17:44, Tom Eastep wrote:
> Ed -- I specifically asked that the dump be forwarded as an attachment. 
> Placing it inline has caused your mailer to fold it until it is unreadable.

Apologies you did indeed.  Mailing lists are a tricky fine line to
tread.  I have recently been posting to the kernel mailing list using
using my mailer (thunderbird on osx) and as a result it defaults to
plain text, no attachments...  (I wish we could just all agree that html
email is ok...)

Correctly attached this time I believe...  Note, I have recreated the
dump - I have scanned it by eye and I believe it shows the same
representative dump as before - obviously the previous dump still
available for correlation

Apologies - thanks for looking into this

Ed W
Shorewall 4.4.22.3 Dump at localhost - Sun Aug 21 22:30:21 UTC 2011

Counters reset Sun Aug 21 16:28:28 UTC 2011

Chain INPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
 1127 89120 accountin  all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
 1127 89120 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
  954 83584 net2fw     all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 net2fw     all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
        
  173  5536 loc2fw     all  --  br0    *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:INPUT:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain FORWARD (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 accountfwd  all  --  *      *       0.0.0.0/0            0.0.0.0/0  
         
    0     0 net_frwd   all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 net_frwd   all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 loc_frwd   all  --  br0    *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:FORWARD:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
  373 28476 accountout  all  --  *      *       0.0.0.0/0            0.0.0.0/0  
         
  373 28476 fw2net     all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
    0     0 fw2net     all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        
    0     0 fw2loc     all  --  *      br0     0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:OUTPUT:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain Broadcast (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ADDRTYPE match dst-type BROADCAST
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ADDRTYPE match dst-type MULTICAST
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ADDRTYPE match dst-type ANYCAST
    0     0 DROP       all  --  *      *       0.0.0.0/0            224.0.0.0/4 
        

Chain Drop (3 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         tcp dpt:113 /* Auth */
    0     0 Broadcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0   
         icmptype 3 code 4 /* Needed ICMP types */
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0   
         icmptype 11 /* Needed ICMP types */
    0     0 Invalid    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         multiport dports 135,445 /* SMB */
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp dpts:137:139 /* SMB */
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp spt:137 dpts:1024:65535 /* SMB */
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         multiport dports 135,139,445 /* SMB */
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp dpt:1900 /* UPnP */
    0     0 NotSyn     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp spt:53 /* Late DNS Replies */

Chain Invalid (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID

Chain NotSyn (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         tcpflags:! 0x17/0x02

Chain Reject (6 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0            all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         tcp dpt:113 /* Auth */
    0     0 Broadcast  all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0   
         icmptype 3 code 4 /* Needed ICMP types */
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0   
         icmptype 11 /* Needed ICMP types */
    0     0 Invalid    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         multiport dports 135,445 /* SMB */
    0     0 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp dpts:137:139 /* SMB */
    0     0 reject     udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp spt:137 dpts:1024:65535 /* SMB */
    0     0 reject     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         multiport dports 135,139,445 /* SMB */
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp dpt:1900 /* UPnP */
    0     0 NotSyn     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         udp spt:53 /* Late DNS Replies */

Chain accountfwd (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 ACCOUNT    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ACCOUNT addr 192.168.111.0/24 tname net-loc
    0     0            all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0            all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        
    0     0            all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0            all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
    0     0            udp  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0            udp  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
    0     0            icmp --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        
    0     0            icmp --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        

Chain accountin (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0            all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
        
  954 83584            all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
        

Chain accountout (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  373 28476 ACCOUNT    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ACCOUNT addr 192.168.111.0/24 tname net-loc
    0     0            all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        
  373 28476            all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        

Chain dynamic (7 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain fw2loc (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2loc:LOG:"
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2loc:LOG:"
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2loc:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain fw2net (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
  373 28476 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2net:LOG:"
  373 28476 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2net:LOG:"
  373 28476 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:fw2net:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain loc2fw (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  173  5536 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
  173  5536 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
  173  5536 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:loc2fw:LOG:"
  173  5536 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:loc2fw:LOG:"
  173  5536 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:loc2fw:REJECT:"
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto] 

Chain loc2net (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:loc2net:LOG:"
    0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:loc2net:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain loc_frwd (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 smurfs     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 tcpflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 loc2net    all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
    0     0 loc2net    all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     all  --  *      br0     0.0.0.0/0            0.0.0.0/0   
        

Chain logdrop (0 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain logflags (5 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 4 level 6 prefix "Shorewall:logflags:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain logreject (0 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 reject     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain net2fw (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  954 83584 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
  954 83584 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
  954 83584 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:net2fw:LOG:"
  954 83584 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:net2fw:LOG:"
  954 83584 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:net2fw:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain net2loc (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate RELATED,ESTABLISHED
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:net2loc:LOG:"
    0     0 Drop       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:net2loc:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain net_frwd (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 sfilter    all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        [goto] 
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 sfilter    all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        [goto] 
    0     0 dynamic    all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ctstate INVALID,NEW
    0     0 ACCEPT     all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
    0     0 ACCEPT     all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        
    0     0 net2loc    all  --  *      br0     0.0.0.0/0            0.0.0.0/0   
        

Chain reject (13 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         ADDRTYPE match src-type BROADCAST
    0     0 DROP       all  --  *      *       224.0.0.0/4          0.0.0.0/0   
        
    0     0 DROP       2    --  *      *       0.0.0.0/0            0.0.0.0/0   
        
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         reject-with tcp-reset
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0   
         reject-with icmp-port-unreachable
    0     0 REJECT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0   
         reject-with icmp-host-unreachable
    0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         reject-with icmp-host-prohibited

Chain sfilter (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:sfilter:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain shorewall (0 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain smurflog (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 LOG        all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         LOG flags 0 level 6 prefix "Shorewall:smurfs:DROP:"
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain smurfs (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  173  5536 RETURN     all  --  *      *       0.0.0.0              0.0.0.0/0   
        
    0     0 smurflog   all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  ADDRTYPE match src-type BROADCAST
    0     0 smurflog   all  --  *      *       224.0.0.0/4          0.0.0.0/0   
        [goto] 

Chain tcpflags (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  tcpflags: 0x3F/0x29
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  tcpflags: 0x3F/0x00
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  tcpflags: 0x06/0x06
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  tcpflags: 0x03/0x03
    0     0 logflags   tcp  --  *      *       0.0.0.0/0            0.0.0.0/0   
        [goto]  tcp spt:0flags: 0x17/0x02

Log (/var/log/messages)

Aug 21 22:29:35 localhost kern.info Shorewall:net2fw:LOG:IN=eth0 OUT= 
SRC=192.168.105.7 DST=255.255.255.255 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=UDP SPT=3483 DPT=3483 LEN=24 MARK=0x10000 
Aug 21 22:29:35 localhost kern.info Shorewall:net2fw:LOG:IN=eth0 OUT= 
SRC=192.168.105.7 DST=255.255.255.255 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=UDP SPT=3483 DPT=3483 LEN=24 MARK=0x10000 
Aug 21 22:29:58 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.240 LEN=76 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=UDP SPT=123 DPT=123 LEN=56 MARK=0xc0000 
Aug 21 22:29:58 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.240 LEN=76 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=UDP SPT=123 DPT=123 LEN=56 MARK=0xc0000 
Aug 21 22:30:08 localhost kern.info Shorewall:loc2fw:LOG:IN=br0 OUT= 
SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2 
MARK=0x10000 
Aug 21 22:30:08 localhost kern.info Shorewall:loc2fw:LOG:IN=br0 OUT= 
SRC=0.0.0.0 DST=224.0.0.1 LEN=32 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2 
MARK=0x10000 
Aug 21 22:30:15 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=0 MARK=0xc0000 
Aug 21 22:30:15 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=0 MARK=0xc0000 
Aug 21 22:30:16 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=1 MARK=0xc0000 
Aug 21 22:30:16 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=1 MARK=0xc0000 
Aug 21 22:30:17 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=2 MARK=0xc0000 
Aug 21 22:30:17 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=2 MARK=0xc0000 
Aug 21 22:30:18 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=3 MARK=0xc0000 
Aug 21 22:30:18 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=3 MARK=0xc0000 
Aug 21 22:30:19 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=4 MARK=0xc0000 
Aug 21 22:30:19 localhost kern.info Shorewall:fw2net:LOG:IN= OUT=eth0 
SRC=192.168.105.70 DST=91.220.24.20 LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF 
PROTO=ICMP TYPE=8 CODE=0 ID=46691 SEQ=4 MARK=0xc0000 

NAT Table

Chain PREROUTING (policy ACCEPT 1 packets, 44 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain INPUT (policy ACCEPT 1 packets, 44 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain OUTPUT (policy ACCEPT 2 packets, 160 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain POSTROUTING (policy ACCEPT 2 packets, 160 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 eth0_masq  all  --  *      eth0    0.0.0.0/0            0.0.0.0/0   
        
  359 27300 ppp1_masq  all  --  *      ppp1    0.0.0.0/0            0.0.0.0/0   
        

Chain eth0_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 MASQUERADE  all  --  *      *       192.168.111.0/24     0.0.0.0/0  
         

Chain ppp1_masq (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 MASQUERADE  all  --  *      *       192.168.111.0/24     0.0.0.0/0  
         

Mangle Table

Chain PREROUTING (policy ACCEPT 2 packets, 76 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
  353 27726 CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         connmark match ! 0x0/0xff0000 CONNMARK restore mask 0xff0000
  774 61394 routemark  all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
         mark match 0x0/0xff0000
    0     0 routemark  all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
         mark match 0x0/0xff0000
 1127 89120 tcpre      all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain INPUT (policy ACCEPT 2 packets, 76 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
 1127 89120 tcin       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 tcfor      all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain OUTPUT (policy ACCEPT 6 packets, 496 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
    0     0 CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         connmark match ! 0x0/0xff0000 CONNMARK restore mask 0xff0000
  373 28476 tcout      all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain POSTROUTING (policy ACCEPT 6 packets, 496 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        
  373 28476 tcpost     all  --  *      *       0.0.0.0/0            0.0.0.0/0   
        

Chain routemark (2 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  774 61394 MARK       all  --  eth0   *       0.0.0.0/0            0.0.0.0/0   
         MARK set 0x10000
    0     0 MARK       all  --  ppp1   *       0.0.0.0/0            0.0.0.0/0   
         MARK set 0xc0000
  774 61394 CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         mark match ! 0x0/0xff0000 CONNMARK save mask 0xff0000

Chain tcfor (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain tcin (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain tcout (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        
  373 28476 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0   
         MARK set 0xc0000

Chain tcpost (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain tcpre (1 references)
 pkts bytes target     prot opt in     out     source               destination 
        

Raw Table

Chain PREROUTING (policy ACCEPT 1127 packets, 89120 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        

Chain OUTPUT (policy ACCEPT 373 packets, 28476 bytes)
 pkts bytes target     prot opt in     out     source               destination 
        

Conntrack Table (3 out of 14864)

icmp     1 27 src=192.168.105.70 dst=91.220.24.20 type=8 code=0 id=46691 
packets=5 bytes=420 [UNREPLIED] src=91.220.24.20 dst=192.168.105.70 type=0 
code=0 id=46691 packets=0 bytes=0 mark=0 use=2
unknown  2 586 src=0.0.0.0 dst=224.0.0.1 packets=1316 bytes=42112 [UNREPLIED] 
src=224.0.0.1 dst=0.0.0.0 packets=0 bytes=0 mark=65536 use=2
udp      17 7 src=192.168.105.70 dst=91.220.24.240 sport=123 dport=123 
packets=1 bytes=76 [UNREPLIED] src=91.220.24.240 dst=192.168.105.70 sport=123 
dport=123 packets=0 bytes=0 mark=0 use=2

IP Configuration

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN 
    inet 127.0.0.1/8 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state 
UNKNOWN qlen 1000
    inet 192.168.105.70/24 brd 192.168.105.255 scope global eth0
12: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN 
    inet 192.168.111.254/24 brd 192.168.111.255 scope global br0
15: ppp1: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast 
state UNKNOWN qlen 3
    inet 10.49.134.86 peer 10.64.64.65/32 scope global ppp1

IP Stats

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN 
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    RX: bytes  packets  errors  dropped overrun mcast   
    196068     2108     0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    196068     2108     0       0       0       0      
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state 
UNKNOWN qlen 1000
    link/ether 00:0d:b9:13:49:b4 brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    2204475    33778    0       1650    0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    84944      831      0       0       0       0      
3: eth1: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast state 
DOWN qlen 1000
    link/ether 00:0d:b9:13:49:b5 brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
4: eth2: <NO-CARRIER,BROADCAST,MULTICAST,PROMISC,UP> mtu 1500 qdisc pfifo_fast 
state DOWN qlen 1000
    link/ether 00:0d:b9:13:49:b6 brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
5: dummy0: <BROADCAST,NOARP> mtu 1500 qdisc noop state DOWN 
    link/ether 3e:cf:69:a4:61:dc brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
6: teql0: <NOARP> mtu 1500 qdisc noop state DOWN qlen 100
    link/void 
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
7: tunl0: <NOARP> mtu 1480 qdisc noop state DOWN 
    link/ipip 0.0.0.0 brd 0.0.0.0
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
8: sit0: <NOARP> mtu 1480 qdisc noop state DOWN 
    link/sit 0.0.0.0 brd 0.0.0.0
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
9: ip6tnl0: <NOARP> mtu 1452 qdisc noop state DOWN 
    link/tunnel6 :: brd ::
    RX: bytes  packets  errors  dropped overrun mcast   
    0          0        0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    0          0        0       0       0       0      
10: wlan0: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN qlen 1000
    link/ether 00:80:48:54:c0:ac brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    1499       11       0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    95504      1136     0       0       0       0      
11: wlan1: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN qlen 1000
    link/ether 00:1f:1f:cb:d0:e2 brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    2392650    7401     0       219     0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    259353     2773     0       0       0       0      
12: br0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN 
    link/ether 00:0d:b9:13:49:b6 brd ff:ff:ff:ff:ff:ff
    RX: bytes  packets  errors  dropped overrun mcast   
    1363       14       0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    65054      757      0       0       0       0      
15: ppp1: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast 
state UNKNOWN qlen 3
    link/ppp 
    RX: bytes  packets  errors  dropped overrun mcast   
    4760       65       0       0       0       0      
    TX: bytes  packets  errors  dropped carrier collsns 
    61173      792      0       0       0       0      

Bridges

bridge name     bridge id               STP enabled     interfaces
br0             8000.000db91349b6       no              eth2

Per-IP Counters

Showing table: net-loc


/proc

   /proc/version = Linux version 2.6.38.4-aufs-grsec-ipset (root@quad) (gcc 
version 4.4.5 (Gentoo Hardened 4.4.5 p1.2, pie-0.4.5) ) #11 Mon Aug 15 21:40:28 
BST 2011
   /proc/sys/net/ipv4/ip_forward = 1
   /proc/sys/net/ipv4/icmp_echo_ignore_all = 0
   /proc/sys/net/ipv4/conf/all/proxy_arp = 0
   /proc/sys/net/ipv4/conf/all/arp_filter = 0
   /proc/sys/net/ipv4/conf/all/arp_ignore = 0
   /proc/sys/net/ipv4/conf/all/rp_filter = 0
   /proc/sys/net/ipv4/conf/all/log_martians = 0
   /proc/sys/net/ipv4/conf/br0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/br0/arp_filter = 0
   /proc/sys/net/ipv4/conf/br0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/br0/rp_filter = 0
   /proc/sys/net/ipv4/conf/br0/log_martians = 1
   /proc/sys/net/ipv4/conf/default/proxy_arp = 0
   /proc/sys/net/ipv4/conf/default/arp_filter = 0
   /proc/sys/net/ipv4/conf/default/arp_ignore = 0
   /proc/sys/net/ipv4/conf/default/rp_filter = 0
   /proc/sys/net/ipv4/conf/default/log_martians = 1
   /proc/sys/net/ipv4/conf/dummy0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/dummy0/arp_filter = 0
   /proc/sys/net/ipv4/conf/dummy0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/dummy0/rp_filter = 0
   /proc/sys/net/ipv4/conf/dummy0/log_martians = 1
   /proc/sys/net/ipv4/conf/eth0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/eth0/arp_filter = 0
   /proc/sys/net/ipv4/conf/eth0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/eth0/rp_filter = 0
   /proc/sys/net/ipv4/conf/eth0/log_martians = 1
   /proc/sys/net/ipv4/conf/eth1/proxy_arp = 0
   /proc/sys/net/ipv4/conf/eth1/arp_filter = 0
   /proc/sys/net/ipv4/conf/eth1/arp_ignore = 0
   /proc/sys/net/ipv4/conf/eth1/rp_filter = 0
   /proc/sys/net/ipv4/conf/eth1/log_martians = 1
   /proc/sys/net/ipv4/conf/eth2/proxy_arp = 0
   /proc/sys/net/ipv4/conf/eth2/arp_filter = 0
   /proc/sys/net/ipv4/conf/eth2/arp_ignore = 0
   /proc/sys/net/ipv4/conf/eth2/rp_filter = 0
   /proc/sys/net/ipv4/conf/eth2/log_martians = 1
   /proc/sys/net/ipv4/conf/ip6tnl0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/ip6tnl0/arp_filter = 0
   /proc/sys/net/ipv4/conf/ip6tnl0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/ip6tnl0/rp_filter = 0
   /proc/sys/net/ipv4/conf/ip6tnl0/log_martians = 1
   /proc/sys/net/ipv4/conf/lo/proxy_arp = 0
   /proc/sys/net/ipv4/conf/lo/arp_filter = 0
   /proc/sys/net/ipv4/conf/lo/arp_ignore = 0
   /proc/sys/net/ipv4/conf/lo/rp_filter = 0
   /proc/sys/net/ipv4/conf/lo/log_martians = 1
   /proc/sys/net/ipv4/conf/ppp1/proxy_arp = 0
   /proc/sys/net/ipv4/conf/ppp1/arp_filter = 0
   /proc/sys/net/ipv4/conf/ppp1/arp_ignore = 0
   /proc/sys/net/ipv4/conf/ppp1/rp_filter = 0
   /proc/sys/net/ipv4/conf/ppp1/log_martians = 1
   /proc/sys/net/ipv4/conf/sit0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/sit0/arp_filter = 0
   /proc/sys/net/ipv4/conf/sit0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/sit0/rp_filter = 0
   /proc/sys/net/ipv4/conf/sit0/log_martians = 1
   /proc/sys/net/ipv4/conf/teql0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/teql0/arp_filter = 0
   /proc/sys/net/ipv4/conf/teql0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/teql0/rp_filter = 0
   /proc/sys/net/ipv4/conf/teql0/log_martians = 1
   /proc/sys/net/ipv4/conf/tunl0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/tunl0/arp_filter = 0
   /proc/sys/net/ipv4/conf/tunl0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/tunl0/rp_filter = 0
   /proc/sys/net/ipv4/conf/tunl0/log_martians = 1
   /proc/sys/net/ipv4/conf/wlan0/proxy_arp = 0
   /proc/sys/net/ipv4/conf/wlan0/arp_filter = 0
   /proc/sys/net/ipv4/conf/wlan0/arp_ignore = 0
   /proc/sys/net/ipv4/conf/wlan0/rp_filter = 0
   /proc/sys/net/ipv4/conf/wlan0/log_martians = 1
   /proc/sys/net/ipv4/conf/wlan1/proxy_arp = 0
   /proc/sys/net/ipv4/conf/wlan1/arp_filter = 0
   /proc/sys/net/ipv4/conf/wlan1/arp_ignore = 0
   /proc/sys/net/ipv4/conf/wlan1/rp_filter = 0
   /proc/sys/net/ipv4/conf/wlan1/log_martians = 1

Routing Rules

0:      from all lookup local 
10000:  from all fwmark 0x10000/0xff0000 lookup peth0 
10011:  from all fwmark 0xc0000/0xff0000 lookup pppp1 
20000:  from 192.168.105.70 lookup peth0 
22816:  from 10.49.134.86 lookup pppp1 
32766:  from all lookup main 
32767:  from all lookup default 

Table default:


Table local:

local 10.49.134.86 dev ppp1  proto kernel  scope host  src 10.49.134.86 
broadcast 127.255.255.255 dev lo  proto kernel  scope link  src 127.0.0.1 
broadcast 192.168.111.0 dev br0  proto kernel  scope link  src 192.168.111.254 
broadcast 192.168.111.255 dev br0  proto kernel  scope link  src 
192.168.111.254 
broadcast 192.168.105.0 dev eth0  proto kernel  scope link  src 192.168.105.70 
broadcast 192.168.105.255 dev eth0  proto kernel  scope link  src 
192.168.105.70 
local 192.168.111.254 dev br0  proto kernel  scope host  src 192.168.111.254 
broadcast 127.0.0.0 dev lo  proto kernel  scope link  src 127.0.0.1 
local 192.168.105.70 dev eth0  proto kernel  scope host  src 192.168.105.70 
local 127.0.0.1 dev lo  proto kernel  scope host  src 127.0.0.1 
local 127.0.0.0/8 dev lo  proto kernel  scope host  src 127.0.0.1 

Table main:

192.168.105.1 dev eth0  scope link  src 192.168.105.70 
10.64.64.65 dev ppp1  proto kernel  scope link  src 10.49.134.86 
192.168.111.0/24 dev br0  proto kernel  scope link  src 192.168.111.254 
192.168.105.0/24 dev eth0  proto kernel  scope link  src 192.168.105.70  metric 
2 
127.0.0.0/8 via 127.0.0.1 dev lo 
default via 192.168.105.1 dev eth0  metric 2 
default via 10.64.64.65 dev ppp1  metric 450 

Table peth0:

192.168.105.1 dev eth0  scope link  src 192.168.105.70 
192.168.111.0/24 dev br0  proto kernel  scope link  src 192.168.111.254 
192.168.105.0/24 dev eth0  proto kernel  scope link  src 192.168.105.70  metric 
2 
default via 192.168.105.1 dev eth0  src 192.168.105.70 

Table pppp1:

10.64.64.65 dev ppp1  proto kernel  scope link  src 10.49.134.86 
192.168.111.0/24 dev br0  proto kernel  scope link  src 192.168.111.254 
default dev ppp1  scope link 

ARP

? (192.168.105.1) at 00:1b:63:f4:15:8c [ether]  on eth0

Modules

ip_set                 14689  3 ip_set_hash_ip,xt_set,ip_set_bitmap_ipmac
ip_set_bitmap_ipmac     3872  7 
ip_set_hash_ip         12856  0 
xt_ACCOUNT              8220  2 
xt_IPMARK                695  0 
xt_LOGMARK              1352  0 
xt_set                  2707  0 

Shorewall has detected the following iptables/netfilter capabilities:
   NAT: Available
   Packet Mangling: Available
   Multi-port Match: Available
   Extended Multi-port Match: Available
   Connection Tracking Match: Available
   Extended Connection Tracking Match Support: Available
   Packet Type Match: Available
   Policy Match: Available
   Physdev Match: Available
   Physdev-is-bridged Support: Available
   Packet length Match: Available
   IP range Match: Available
   Recent Match: Available
   Owner Match: Available
   Ipset Match: Available
   CONNMARK Target: Available
   Extended CONNMARK Target: Available
   Connmark Match: Available
   Extended Connmark Match: Available
   Raw Table: Available
   IPP2P Match: Not available
   CLASSIFY Target: Available
   Extended REJECT: Available
   Repeat match: Available
   MARK Target: Available
   Extended MARK Target: Available
   Extended MARK Target 2: Available
   Mangle FORWARD Chain: Available
   Comments: Available
   Address Type Match: Available
   TCPMSS Match: Available
   Hashlimit Match: Available
   NFQUEUE Target: Available
   Realm Match: Available
   Helper Match: Available
   Connlimit Match: Available
   Time Match: Available
   Goto Support: Available
   LOGMARK Target: Available
   IPMARK Target: Available
   LOG Target: Available
   Persistent SNAT: Available
   TPROXY Target: Available
   FLOW Classifier: Available
   fwmark route mask: Available
   Mark in any table: Available
   Header Match: Not available
   ACCOUNT Target: Available
   AUDIT Target: Not available
   ipset V5: Available

Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       
PID/Program name    
tcp        0      0 0.0.0.0:53              0.0.0.0:*               LISTEN      
21262/dnsmasq
tcp        0      0 :::53                   :::*                    LISTEN      
21262/dnsmasq
tcp        0      0 :::22                   :::*                    LISTEN      
10183/dropbear
udp        0      0 0.0.0.0:53              0.0.0.0:*                           
21262/dnsmasq
udp        0      0 0.0.0.0:67              0.0.0.0:*                           
21262/dnsmasq
udp        0      0 0.0.0.0:323             0.0.0.0:*                           
3143/chronyd
udp        0      0 0.0.0.0:123             0.0.0.0:*                           
3143/chronyd
udp        0      0 :::53                   :::*                                
21262/dnsmasq
udp        0      0 :::323                  :::*                                
3143/chronyd
udp        0      0 :::123                  :::*                                
3143/chronyd

Traffic Control

Device eth0:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 
1 1
 Sent 84944 bytes 831 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 


Device eth1:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 
1 1
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 


Device eth2:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 
1 1
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 


Device wlan0:
qdisc mq 0: root 
 Sent 75056 bytes 1136 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 

class mq :1 root 
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 
class mq :2 root 
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 
class mq :3 root 
 Sent 75056 bytes 1136 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 
class mq :4 root 
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 

Device wlan1:
qdisc mq 0: root 
 Sent 203971 bytes 2774 pkt (dropped 0, overlimits 0 requeues 5) 
 backlog 0b 0p requeues 5 

class mq :1 root 
 Sent 708 bytes 3 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 
class mq :2 root 
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 
class mq :3 root 
 Sent 203263 bytes 2771 pkt (dropped 0, overlimits 0 requeues 5) 
 backlog 0b 0p requeues 5 
class mq :4 root 
 Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 

Device ppp1:
qdisc pfifo_fast 0: root refcnt 2 bands 3 priomap  1 2 2 2 1 2 0 0 1 1 1 1 1 1 
1 1
 Sent 61083 bytes 786 pkt (dropped 0, overlimits 0 requeues 0) 
 backlog 0b 0p requeues 0 



TC Filters

Device eth0:

Device eth1:

Device eth2:

Device wlan0:

Device wlan1:

Device ppp1:

------------------------------------------------------------------------------
Get a FREE DOWNLOAD! and learn more about uberSVN rich system, 
user administration capabilities and model configuration. Take 
the hassle out of deploying and managing Subversion and the 
tools developers use with it. http://p.sf.net/sfu/wandisco-d2d-2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to