-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathiptables-tor.rules
31 lines (31 loc) · 1.09 KB
/
iptables-tor.rules
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
# Generated by iptables-save v1.6.1 on Sat Sep 16 11:21:15 2017
*mangle
:PREROUTING ACCEPT [2667:1658109]
:INPUT ACCEPT [2646:1655321]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2485:1368056]
:POSTROUTING ACCEPT [2374:1339197]
COMMIT
# Completed on Sat Sep 16 11:21:15 2017
# Generated by iptables-save v1.6.1 on Sat Sep 16 11:21:15 2017
*filter
:INPUT DROP [11:1584]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [492:42053]
-A INPUT -i lo -j ACCEPT
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
# Completed on Sat Sep 16 11:21:15 2017
# Generated by iptables-save v1.6.1 on Sat Sep 16 11:21:15 2017
*nat
:PREROUTING ACCEPT [70:10996]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [66:4427]
:POSTROUTING ACCEPT [69:4968]
-A PREROUTING -p udp -m udp --dport 53 -j REDIRECT --to-ports 9053
-A PREROUTING -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REDIRECT --to-ports 9040
-A OUTPUT -p tcp -m tcp --dport 53 -j DNAT --to-destination 127.0.0.1:9053
-A OUTPUT -p udp -m udp --dport 53 -j DNAT --to-destination 127.0.0.1:9053
COMMIT
# Completed on Sat Sep 16 11:21:15 2017