Actually I have modules loaded. Please check debug file copied below. The problem should be something else.<br><br>Regards,<br>Ošuz.<br>
<br>
<br>
<br>
<br>
Unable to find KLIPS messages, typically found in /var/log/messages or
equivalent. You may need to run Openswan for the first time;
alternatively, your log files have been emptied (ie, logwatch) or we do
not understand your logging configuration.<br>
Unable to find Pluto messages, typically found in /var/log/secure or
equivalent. You may need to run Openswan for the first time;
alternatively, your log files have been emptied (ie, logwatch) or we do
not understand your logging configuration.<br>
app<br>
Sat Dec 6 14:48:25 EET 2008<br>
+ _________________________ version<br>
+ ipsec --version<br>
Linux Openswan U2.6.14/K2.6.18-lbr5.std.3 (netkey)<br>
See `ipsec --copyright' for copyright information.<br>
+ _________________________ /proc/version<br>
+ cat /proc/version<br>
Linux version 2.6.18-lbr5.std.3
(<a href="mailto:developer@robin-playground.labristeknoloji.com">developer@robin-playground.labristeknoloji.com</a>) (gcc version 4.1.1
20070105 (Red Hat 4.1.1-52)) #1 SMP Fri Oct 31 11:44:34 EET 2008<br>
+ _________________________ /proc/net/ipsec_eroute<br>
+ test -r /proc/net/ipsec_eroute<br>
+ _________________________ netstat-rn<br>
+ netstat -nr<br>
+ head -n 100<br>
Kernel IP routing table<br>
Destination Gateway Genmask Flags MSS Window irtt Iface<br>
85.85.85.1 0.0.0.0 255.255.255.255 UH 0 0 0 ppp0<br>
10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth2<br>
192.168.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1<br>
169.254.1.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0<br>
169.254.0.0 0.0.0.0 255.255.0.0 U 0 0 0 eth0<br>
0.0.0.0 85.85.85.1 0.0.0.0 UG 0 0 0 ppp0<br>
+ _________________________ /proc/net/ipsec_spi<br>
+ test -r /proc/net/ipsec_spi<br>
+ _________________________ /proc/net/ipsec_spigrp<br>
+ test -r /proc/net/ipsec_spigrp<br>
+ _________________________ /proc/net/ipsec_tncfg<br>
+ test -r /proc/net/ipsec_tncfg<br>
+ _________________________ /proc/net/pfkey<br>
+ test -r /proc/net/pfkey<br>
+ cat /proc/net/pfkey<br>
sk RefCnt Rmem Wmem User Inode<br>
+ _________________________ ip-xfrm-state<br>
+ ip xfrm state<br>
+ _________________________ ip-xfrm-policy<br>
+ ip xfrm policy<br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir in priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
src <a href="http://0.0.0.0/0">0.0.0.0/0</a> dst <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
dir out priority 0 <br>
+ _________________________ /proc/crypto<br>
+ test -r /proc/crypto<br>
+ cat /proc/crypto<br>
name : deflate<br>
driver : deflate-generic<br>
module : deflate<br>
priority : 0<br>
type : compression<br>
<br>
name : tnepres<br>
driver : tnepres-generic<br>
module : serpent<br>
priority : 0<br>
type : cipher<br>
blocksize : 16<br>
min keysize : 0<br>
max keysize : 32<br>
<br>
name : serpent<br>
driver : serpent-generic<br>
module : serpent<br>
priority : 0<br>
type : cipher<br>
blocksize : 16<br>
min keysize : 0<br>
max keysize : 32<br>
<br>
name : blowfish<br>
driver : blowfish-generic<br>
module : blowfish<br>
priority : 0<br>
type : cipher<br>
blocksize : 8<br>
min keysize : 4<br>
max keysize : 56<br>
<br>
name : twofish<br>
driver : twofish-generic<br>
module : twofish<br>
priority : 0<br>
type : cipher<br>
blocksize : 16<br>
min keysize : 16<br>
max keysize : 32<br>
<br>
name : md5<br>
driver : md5-generic<br>
module : md5<br>
priority : 0<br>
type : digest<br>
blocksize : 64<br>
digestsize : 16<br>
<br>
name : sha256<br>
driver : sha256-generic<br>
module : sha256<br>
priority : 0<br>
type : digest<br>
blocksize : 64<br>
digestsize : 32<br>
<br>
name : sha512<br>
driver : sha512-generic<br>
module : sha512<br>
priority : 0<br>
type : digest<br>
blocksize : 128<br>
digestsize : 64<br>
<br>
name : sha384<br>
driver : sha384-generic<br>
module : sha512<br>
priority : 0<br>
type : digest<br>
blocksize : 96<br>
digestsize : 48<br>
<br>
name : des3_ede<br>
driver : des3_ede-generic<br>
module : des<br>
priority : 0<br>
type : cipher<br>
blocksize : 8<br>
min keysize : 24<br>
max keysize : 24<br>
<br>
name : des<br>
driver : des-generic<br>
module : des<br>
priority : 0<br>
type : cipher<br>
blocksize : 8<br>
min keysize : 8<br>
max keysize : 8<br>
<br>
name : aes<br>
driver : aes-generic<br>
module : aes_generic<br>
priority : 100<br>
type : cipher<br>
blocksize : 16<br>
min keysize : 16<br>
max keysize : 32<br>
<br>
name : aes<br>
driver : aes-i586<br>
module : aes_i586<br>
priority : 200<br>
type : cipher<br>
blocksize : 16<br>
min keysize : 16<br>
max keysize : 32<br>
<br>
name : crc32c<br>
driver : crc32c-generic<br>
module : kernel<br>
priority : 0<br>
type : digest<br>
blocksize : 32<br>
digestsize : 4<br>
<br>
name : sha1<br>
driver : sha1-generic<br>
module : kernel<br>
priority : 0<br>
type : digest<br>
blocksize : 64<br>
digestsize : 20<br>
<br>
+ __________________________/proc/sys/net/core/xfrm-star<br>
/usr/libexec/ipsec/barf: line 191: __________________________/proc/sys/net/core/xfrm-star: No such file or directory<br>
+ for i in '/proc/sys/net/core/xfrm_*'<br>
+ echo -n '/proc/sys/net/core/xfrm_acq_expires: '<br>
/proc/sys/net/core/xfrm_acq_expires: + cat /proc/sys/net/core/xfrm_acq_expires<br>
30<br>
+ for i in '/proc/sys/net/core/xfrm_*'<br>
+ echo -n '/proc/sys/net/core/xfrm_aevent_etime: '<br>
/proc/sys/net/core/xfrm_aevent_etime: + cat /proc/sys/net/core/xfrm_aevent_etime<br>
10<br>
+ for i in '/proc/sys/net/core/xfrm_*'<br>
+ echo -n '/proc/sys/net/core/xfrm_aevent_rseqth: '<br>
/proc/sys/net/core/xfrm_aevent_rseqth: + cat /proc/sys/net/core/xfrm_aevent_rseqth<br>
2<br>
+ for i in '/proc/sys/net/core/xfrm_*'<br>
+ echo -n '/proc/sys/net/core/xfrm_larval_drop: '<br>
/proc/sys/net/core/xfrm_larval_drop: + cat /proc/sys/net/core/xfrm_larval_drop<br>
0<br>
+ _________________________ /proc/sys/net/ipsec-star<br>
+ test -d /proc/sys/net/ipsec<br>
+ _________________________ ipsec/status<br>
+ ipsec auto --status<br>
000 using kernel interface: netkey<br>
000 interface lo/lo 127.0.0.1<br>
000 interface lo/lo 127.0.0.1<br>
000 interface eth0/eth0 169.254.1.1<br>
000 interface eth0/eth0 169.254.1.1<br>
000 interface eth1/eth1 192.168.0.254<br>
000 interface eth1/eth1 192.168.0.254<br>
000 interface eth2/eth2 10.0.0.254<br>
000 interface eth2/eth2 10.0.0.254<br>
000 interface ppp0/ppp0 85.85.85.85<br>
000 interface ppp0/ppp0 85.85.85.85<br>
000 %myid = (none)<br>
000 debug raw+crypt+parsing+emitting+control+lifecycle+klips+dns+oppo+controlmore+pfkey+nattraversal+x509<br>
000 <br>
000 algorithm ESP encrypt: id=2, name=ESP_DES, ivlen=8, keysizemin=64, keysizemax=64<br>
000 algorithm ESP encrypt: id=3, name=ESP_3DES, ivlen=8, keysizemin=192, keysizemax=192<br>
000 algorithm ESP encrypt: id=6, name=ESP_CAST, ivlen=8, keysizemin=40, keysizemax=128<br>
000 algorithm ESP encrypt: id=7, name=ESP_BLOWFISH, ivlen=8, keysizemin=40, keysizemax=448<br>
000 algorithm ESP encrypt: id=11, name=ESP_NULL, ivlen=0, keysizemin=0, keysizemax=0<br>
000 algorithm ESP encrypt: id=12, name=ESP_AES, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=13, name=ESP_AES_CTR, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=14, name=ESP_AES_CCM_A, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=15, name=ESP_AES_CCM_B, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=16, name=ESP_AES_CCM_C, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=18, name=ESP_AES_GCM_A, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=19, name=ESP_AES_GCM_B, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=20, name=ESP_AES_GCM_C, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=252, name=ESP_SERPENT, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP encrypt: id=253, name=ESP_TWOFISH, ivlen=8, keysizemin=128, keysizemax=256<br>
000 algorithm ESP auth attr: id=1, name=AUTH_ALGORITHM_HMAC_MD5, keysizemin=128, keysizemax=128<br>
000 algorithm ESP auth attr: id=2, name=AUTH_ALGORITHM_HMAC_SHA1, keysizemin=160, keysizemax=160<br>
000 algorithm ESP auth attr: id=5, name=AUTH_ALGORITHM_HMAC_SHA2_256, keysizemin=256, keysizemax=256<br>
000 algorithm ESP auth attr: id=8, name=AUTH_ALGORITHM_HMAC_RIPEMD, keysizemin=160, keysizemax=160<br>
000 algorithm ESP auth attr: id=9, name=AUTH_ALGORITHM_AES_CBC, keysizemin=128, keysizemax=128<br>
000 algorithm ESP auth attr: id=251, name=(null), keysizemin=0, keysizemax=0<br>
000 <br>
000 algorithm IKE encrypt: id=0, name=(null), blocksize=16, keydeflen=131<br>
000 algorithm IKE encrypt: id=3, name=OAKLEY_BLOWFISH_CBC, blocksize=8, keydeflen=128<br>
000 algorithm IKE encrypt: id=5, name=OAKLEY_3DES_CBC, blocksize=8, keydeflen=192<br>
000 algorithm IKE encrypt: id=7, name=OAKLEY_AES_CBC, blocksize=16, keydeflen=128<br>
000 algorithm IKE encrypt: id=65004, name=OAKLEY_SERPENT_CBC, blocksize=16, keydeflen=128<br>
000 algorithm IKE encrypt: id=65005, name=OAKLEY_TWOFISH_CBC, blocksize=16, keydeflen=128<br>
000 algorithm IKE encrypt: id=65289, name=OAKLEY_TWOFISH_CBC_SSH, blocksize=16, keydeflen=128<br>
000 algorithm IKE hash: id=1, name=OAKLEY_MD5, hashsize=16<br>
000 algorithm IKE hash: id=2, name=OAKLEY_SHA1, hashsize=20<br>
000 algorithm IKE hash: id=4, name=OAKLEY_SHA2_256, hashsize=32<br>
000 algorithm IKE hash: id=6, name=OAKLEY_SHA2_512, hashsize=64<br>
000 algorithm IKE dh group: id=2, name=OAKLEY_GROUP_MODP1024, bits=1024<br>
000 algorithm IKE dh group: id=5, name=OAKLEY_GROUP_MODP1536, bits=1536<br>
000 algorithm IKE dh group: id=14, name=OAKLEY_GROUP_MODP2048, bits=2048<br>
000 algorithm IKE dh group: id=15, name=OAKLEY_GROUP_MODP3072, bits=3072<br>
000 algorithm IKE dh group: id=16, name=OAKLEY_GROUP_MODP4096, bits=4096<br>
000 algorithm IKE dh group: id=17, name=OAKLEY_GROUP_MODP6144, bits=6144<br>
000 algorithm IKE dh group: id=18, name=OAKLEY_GROUP_MODP8192, bits=8192<br>
000 <br>
000 stats db_ops: {curr_cnt, total_cnt, maxsz} :context={0,2,36} trans={0,2,1080} attrs={0,2,1440} <br>
000 <br>
000 "product":
<a href="http://10.0.0.0/24===85.85.85.85">10.0.0.0/24===85.85.85.85</a><85.85.85.85>[+S=C]---85.85.85.1...85.105.105.105<85.105.105.105>[+S=C]===<a href="http://192.168.1.0/24">192.168.1.0/24</a>;
unrouted; eroute owner: #0<br>
000 "product": myip=unset; hisip=unset;<br>
000 "product": ike_life: 28800s; ipsec_life: 28800s; rekey_margin: 540s; rekey_fuzz: 100%; keyingtries: 3<br>
000 "product": policy: PSK+ENCRYPT+TUNNEL+PFS+UP+IKEv2ALLOW+lKOD+rKOD; prio: 24,24; interface: ppp0; <br>
000 "product": newest ISAKMP SA: #0; newest IPsec SA: #0; <br>
000 "product": ESP algorithms wanted: 3DES(3)_000-MD5(1); flags=-strict<br>
000 "product": ESP algorithms loaded: 3DES(3)_192-MD5(1)_096<br>
000 <br>
000 #2: "product":500 STATE_QUICK_I1 (sent QI1, expecting QR1); EVENT_CRYPTO_FAILED in 82s; nodpd; idle; import:admin initiate<br>
000 <br>
+ _________________________ ifconfig-a<br>
+ ifconfig -a<br>
eth0 Link encap:Ethernet HWaddr 00:1D:92:26:BD:C2 <br>
inet addr:169.254.1.1 Bcast:169.254.1.255 Mask:255.255.255.0<br>
UP BROADCAST MULTICAST MTU:1500 Metric:1<br>
RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:1000 <br>
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)<br>
Interrupt:233 Base address:0x2800 <br>
<br>
eth1 Link encap:Ethernet HWaddr 00:0C:42:07:48:0C <br>
inet addr:192.168.0.254 Bcast:192.168.0.255 Mask:255.255.255.0<br>
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1<br>
RX packets:727381 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:613391 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:1000 <br>
RX bytes:735101802 (701.0 MiB) TX bytes:120147368 (114.5 MiB)<br>
Interrupt:50 Base address:0x4c00 <br>
<br>
eth2 Link encap:Ethernet HWaddr 00:0C:42:07:48:0D <br>
inet addr:10.0.0.254 Bcast:10.0.0.255 Mask:255.255.255.0<br>
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1<br>
RX packets:646562 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:741828 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:1000 <br>
RX bytes:108466049 (103.4 MiB) TX bytes:728851608 (695.0 MiB)<br>
Interrupt:58 Base address:0x6800 <br>
<br>
eth3 Link encap:Ethernet HWaddr 00:0C:42:07:48:0E <br>
BROADCAST MULTICAST MTU:1500 Metric:1<br>
RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:1000 <br>
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)<br>
Interrupt:66 Base address:0x8400 <br>
<br>
eth4 Link encap:Ethernet HWaddr 00:0C:42:07:48:0F <br>
BROADCAST MULTICAST MTU:1500 Metric:1<br>
RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:1000 <br>
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)<br>
Interrupt:74 Base address:0xa000 <br>
<br>
lo Link encap:Local Loopback <br>
inet addr:127.0.0.1 Mask:255.0.0.0<br>
UP LOOPBACK RUNNING MTU:16436 Metric:1<br>
RX packets:466865 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:466865 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:0 <br>
RX bytes:65724782 (62.6 MiB) TX bytes:65724782 (62.6 MiB)<br>
<br>
ppp0 Link encap:Point-to-Point Protocol <br>
inet addr:85.85.85.85 P-t-P:85.85.85.1 Mask:255.255.255.255<br>
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1492 Metric:1<br>
RX packets:722536 errors:0 dropped:0 overruns:0 frame:0<br>
TX packets:608081 errors:0 dropped:0 overruns:0 carrier:0<br>
collisions:0 txqueuelen:3 <br>
RX bytes:718910768 (685.6 MiB) TX bytes:106548724 (101.6 MiB)<br>
<br>
+ _________________________ ip-addr-list<br>
+ ip addr list<br>
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue <br>
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00<br>
inet <a href="http://127.0.0.1/8">127.0.0.1/8</a> scope host lo<br>
2: eth0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 1000<br>
link/ether 00:1d:92:26:bd:c2 brd ff:ff:ff:ff:ff:ff<br>
inet <a href="http://169.254.1.1/24">169.254.1.1/24</a> brd 169.254.1.255 scope global eth0<br>
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast qlen 1000<br>
link/ether 00:0c:42:07:48:0c brd ff:ff:ff:ff:ff:ff<br>
inet <a href="http://192.168.0.254/24">192.168.0.254/24</a> brd 192.168.0.255 scope global eth1<br>
4: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast qlen 1000<br>
link/ether 00:0c:42:07:48:0d brd ff:ff:ff:ff:ff:ff<br>
inet <a href="http://10.0.0.254/24">10.0.0.254/24</a> brd 10.0.0.255 scope global eth2<br>
5: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc noop qlen 1000<br>
link/ether 00:0c:42:07:48:0e brd ff:ff:ff:ff:ff:ff<br>
6: eth4: <BROADCAST,MULTICAST> mtu 1500 qdisc noop qlen 1000<br>
link/ether 00:0c:42:07:48:0f brd ff:ff:ff:ff:ff:ff<br>
8: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc pfifo_fast qlen 3<br>
link/ppp <br>
inet 85.85.85.85 peer <a href="http://85.85.85.1/32">85.85.85.1/32</a> scope global ppp0<br>
+ _________________________ ip-route-list<br>
+ ip route list<br>
85.85.85.1 dev ppp0 scope link <br>
<a href="http://10.0.0.0/24">10.0.0.0/24</a> dev eth2 proto kernel scope link src 10.0.0.254 <br>
<a href="http://192.168.0.0/24">192.168.0.0/24</a> dev eth1 proto kernel scope link src 192.168.0.254 <br>
<a href="http://169.254.1.0/24">169.254.1.0/24</a> dev eth0 proto kernel scope link src 169.254.1.1 <br>
<a href="http://169.254.0.0/16">169.254.0.0/16</a> dev eth0 scope link <br>
default via 85.85.85.1 dev ppp0 <br>
+ _________________________ ip-rule-list<br>
+ ip rule list<br>
0: from all lookup 255 <br>
32766: from all lookup main <br>
32767: from all lookup default <br>
+ _________________________ ipsec_verify<br>
+ ipsec verify --nocolour<br>
Checking your system to see if IPsec got installed and started correctly:<br>
Version check and ipsec on-path [OK]<br>
Linux Openswan U2.6.14/K2.6.18-lbr5.std.3 (netkey)<br>
Checking for IPsec support in kernel [OK]<br>
NETKEY detected, testing for disabled ICMP send_redirects [FAILED]<br>
<br>
Please disable /proc/sys/net/ipv4/conf/*/send_redirects<br>
or NETKEY will cause the sending of bogus ICMP redirects!<br>
<br>
NETKEY detected, testing for disabled ICMP accept_redirects [FAILED]<br>
<br>
Please disable /proc/sys/net/ipv4/conf/*/accept_redirects<br>
or NETKEY will accept bogus ICMP redirects!<br>
<br>
Checking for RSA private key (/etc/ipsec.secrets) [OK]<br>
Checking that pluto is running [OK]<br>
Two or more interfaces found, checking IP forwarding [OK]<br>
Checking NAT and MASQUERADEing <br>
Checking for 'ip' command [OK]<br>
Checking for 'iptables' command [OK]<br>
Opportunistic Encryption Support [DISABLED]<br>
+ _________________________ mii-tool<br>
+ '[' -x /sbin/mii-tool ']'<br>
+ /sbin/mii-tool -v<br>
eth0: no link<br>
product info: vendor 00:00:20, model 32 rev 1<br>
basic mode: autonegotiation enabled<br>
basic status: no link<br>
capabilities: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
advertising: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
eth1: negotiated 100baseTx-FD, link ok<br>
product info: vendor 00:40:63, model 52 rev 5<br>
basic mode: autonegotiation enabled<br>
basic status: autonegotiation complete, link ok<br>
capabilities: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
advertising: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control<br>
link partner: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
eth2: negotiated 100baseTx-FD, link ok<br>
product info: vendor 00:40:63, model 52 rev 5<br>
basic mode: autonegotiation enabled<br>
basic status: autonegotiation complete, link ok<br>
capabilities: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
advertising: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD flow-control<br>
link partner: 100baseTx-FD 100baseTx-HD 10baseT-FD 10baseT-HD<br>
SIOCGMIIPHY on 'eth3' failed: Invalid argument<br>
SIOCGMIIPHY on 'eth4' failed: Invalid argument<br>
+ _________________________ ipsec/directory<br>
+ ipsec --directory<br>
/usr/libexec/ipsec<br>
+ _________________________ hostname/fqdn<br>
+ hostname --fqdn<br>
localhost.localdomain<br>
+ _________________________ hostname/ipaddress<br>
+ hostname --ip-address<br>
127.0.0.1<br>
+ _________________________ uptime<br>
+ uptime<br>
14:48:26 up 22:59, 2 users, load average: 1.35, 1.14, 1.08<br>
+ _________________________ ps<br>
+ ps alxwf<br>
+ egrep -i 'ppid|pluto|ipsec|klips'<br>
F UID PID PPID PRI NI VSZ RSS WCHAN STAT TTY TIME COMMAND<br>
0 0 17069 23358 25 0 4484 1128 wait S+ pts/3 0:00 | \_ /bin/sh /usr/libexec/ipsec/barf<br>
0 0 17239 17069 25 0 1832 480 stext S+ pts/3 0:00 | \_ egrep -i ppid|pluto|ipsec|klips<br>
1 0 15357 1 25 0 2444 416 wait S pts/3 0:00
/bin/sh /usr/libexec/ipsec/_plutorun --debug all raw crypt parsing
emitting control lifecycle klips dns oppo controlmore x509 pfkey
nattraversal --uniqueids yes --force_busy no --nocrsend no
--strictcrlpolicy --nat_traversal yes --keep_alive --protostack
netkey --force_keepalive --disable_port_floating --virtual_private
--crlcheckinterval 0 --ocspuri --nhelpers --dump --opts
--stderrlog --wait no --pre --post --log daemon.error
--plutorestartoncrash false --pid /var/run/pluto/pluto.pid<br>
1 0 15358 15357 25 0 2444 548 wait S pts/3 0:00
\_ /bin/sh /usr/libexec/ipsec/_plutorun --debug all raw crypt parsing
emitting control lifecycle klips dns oppo controlmore x509 pfkey
nattraversal --uniqueids yes --force_busy no --nocrsend no
--strictcrlpolicy --nat_traversal yes --keep_alive --protostack
netkey --force_keepalive --disable_port_floating --virtual_private
--crlcheckinterval 0 --ocspuri --nhelpers --dump --opts
--stderrlog --wait no --pre --post --log daemon.error
--plutorestartoncrash false --pid /var/run/pluto/pluto.pid<br>
4 0 15359 15358 17 0 3168 1508 - S pts/3 0:00
| \_ /usr/libexec/ipsec/pluto --nofork --secretsfile
/etc/ipsec.secrets --debug-all --debug-raw --debug-crypt
--debug-parsing --debug-emitting --debug-control --debug-lifecycle
--debug-klips --debug-dns --debug-oppo --debug-controlmore --debug-x509
--debug-pfkey --debug-nattraversal --use-netkey --uniqueids
--nat_traversal<br>
1 0 15369 15359 26 10 3108 748 - SN pts/3 0:00
| \_ pluto helper #
0
<br>
0 0 15383 15359 25 0 1588 288 - S pts/3 0:00 | \_ _pluto_adns -d<br>
0 0 15360 15357 25 0 2444 1036 pipe_w S pts/3 0:00 \_ /bin/sh /usr/libexec/ipsec/_plutoload --wait no --post <br>
0 0 15361 1 24 0 1652 492 pipe_w S pts/3 0:00 logger -s -p daemon.error -t ipsec__plutorun<br>
+ _________________________ ipsec/showdefaults<br>
+ ipsec showdefaults<br>
ipsec showdefaults: cannot find defaults file `/var/run/pluto/<a href="http://ipsec.info">ipsec.info</a>'<br>
+ _________________________ ipsec/conf<br>
+ ipsec _include /etc/ipsec.conf<br>
+ ipsec _keycensor<br>
<br>
#< /etc/ipsec.conf 1<br>
# Created by Labris Management Console / VPN.<br>
# Do NOT change settings in this file.<br>
# 12.06.2008 - 12:17:52 PM<br>
<br>
version 2.0<br>
<br>
config setup<br>
interfaces="ipsec0=ppp0"<br>
klipsdebug=all<br>
plutodebug=all<br>
nat_traversal=yes<br>
uniqueids=yes<br>
protostack=netkey<br>
<br>
<br>
conn %default<br>
auto=add<br>
<br>
conn product<br>
authby=secret<br>
auth=esp<br>
esp=3des-md5-96<br>
left=85.85.85.85<br>
leftsubnet=<a href="http://10.0.0.0/24">10.0.0.0/24</a><br>
right=85.105.105.105<br>
rightsubnet=<a href="http://192.168.1.0/24">192.168.1.0/24</a><br>
leftnexthop=85.85.85.1<br>
disablearrivalcheck=no<br>
pfs=yes<br>
auto=add<br>
keyexchange=ike<br>
keyingtries=3<br>
ikelifetime=28800s<br>
keylife=28800s<br>
<br>
##conn labris.l2tp<br>
<br>
<br>
#< /etc/ipsec.d/no_oe.conf 1<br>
# 'include' this file to disable Opportunistic Encryption.<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
# RCSID $Id: <a href="http://no_oe.conf.in">no_oe.conf.in</a>,v 1.2 2004/10/03 19:33:10 paul Exp $<br>
conn block<br>
auto=ignore<br>
<br>
conn private<br>
auto=ignore<br>
<br>
conn private-or-clear<br>
auto=ignore<br>
<br>
conn clear-or-private<br>
auto=ignore<br>
<br>
conn clear<br>
auto=ignore<br>
<br>
conn packetdefault<br>
auto=ignore<br>
<br>
<br>
#> /etc/ipsec.conf 39<br>
<br>
+ _________________________ ipsec/secrets<br>
+ ipsec _include /etc/ipsec.secrets<br>
+ ipsec _secretcensor<br>
<br>
#< /etc/ipsec.secrets 1<br>
85.85.85.85 85.105.105.105 : PSK "[sums to 9a70...]"<br>
<br>
#:cannot open configuration file \'/etc/ipsec.*.secrets\'<br>
<br>
#> /etc/ipsec.secrets 4<br>
+ _________________________ ipsec/listall<br>
+ ipsec auto --listall<br>
000 <br>
000 List of Public Keys:<br>
000 <br>
000 List of Pre-shared secrets (from /etc/ipsec.secrets)<br>
000 1: PSK 85.105.105.105 85.85.85.85<br>
000 <br>
000 List of X.509 CA Certificates:<br>
000 <br>
000 Dec 06 14:44:12 2008, count: 1<br>
000 subject: 'C=TR, L=Istanbul, O=Soya, OU=Bim, CN=labris, E=<a href="mailto:soya@labris.com">soya@labris.com</a>'<br>
000 issuer: 'C=TR, L=Istanbul, O=Soya, OU=Bim, CN=labris, E=<a href="mailto:soya@labris.com">soya@labris.com</a>'<br>
000 serial: 00<br>
000 pubkey: 1024 RSA Key AwEAAaJ/h<br>
000 validity: not before Aug 08 15:40:42 2005 ok<br>
000 not after Aug 08 15:40:42 2006 fatal (expired)<br>
000 subjkey: 79:2a:e1:92:9f:ee:84:40:5d:83:66:cb:8d:28:63:ec:d4:55:ab:0a<br>
000 authkey: 79:2a:e1:92:9f:ee:84:40:5d:83:66:cb:8d:28:63:ec:d4:55:ab:0a<br>
000 aserial: 00<br>
+ '[' /etc/ipsec.d/policies ']'<br>
+ for policy in '$POLICIES/*'<br>
++ basename /etc/ipsec.d/policies/block<br>
+ base=block<br>
+ _________________________ ipsec/policies/block<br>
+ cat /etc/ipsec.d/policies/block<br>
# This file defines the set of CIDRs (network/mask-length) to which<br>
# communication should never be allowed.<br>
#<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
# $Id: <a href="http://block.in">block.in</a>,v 1.4 2003/02/17 02:22:15 mcr Exp $<br>
#<br>
<br>
+ for policy in '$POLICIES/*'<br>
++ basename /etc/ipsec.d/policies/clear<br>
+ base=clear<br>
+ _________________________ ipsec/policies/clear<br>
+ cat /etc/ipsec.d/policies/clear<br>
# This file defines the set of CIDRs (network/mask-length) to which<br>
# communication should always be in the clear.<br>
#<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
<br>
# root name servers should be in the clear<br>
<a href="http://192.58.128.30/32">192.58.128.30/32</a><br>
<a href="http://198.41.0.4/32">198.41.0.4/32</a><br>
<a href="http://192.228.79.201/32">192.228.79.201/32</a><br>
<a href="http://192.33.4.12/32">192.33.4.12/32</a><br>
<a href="http://128.8.10.90/32">128.8.10.90/32</a><br>
<a href="http://192.203.230.10/32">192.203.230.10/32</a><br>
<a href="http://192.5.5.241/32">192.5.5.241/32</a><br>
<a href="http://192.112.36.4/32">192.112.36.4/32</a><br>
<a href="http://128.63.2.53/32">128.63.2.53/32</a><br>
<a href="http://192.36.148.17/32">192.36.148.17/32</a><br>
<a href="http://193.0.14.129/32">193.0.14.129/32</a><br>
<a href="http://199.7.83.42/32">199.7.83.42/32</a><br>
<a href="http://202.12.27.33/32">202.12.27.33/32</a><br>
+ for policy in '$POLICIES/*'<br>
++ basename /etc/ipsec.d/policies/clear-or-private<br>
+ base=clear-or-private<br>
+ _________________________ ipsec/policies/clear-or-private<br>
+ cat /etc/ipsec.d/policies/clear-or-private<br>
# This file defines the set of CIDRs (network/mask-length) to which<br>
# we will communicate in the clear, or, if the other side initiates IPSEC,<br>
# using encryption. This behaviour is also called "Opportunistic Responder".<br>
#<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
# $Id: <a href="http://clear-or-private.in">clear-or-private.in</a>,v 1.4 2003/02/17 02:22:15 mcr Exp $<br>
#<br>
+ for policy in '$POLICIES/*'<br>
++ basename /etc/ipsec.d/policies/private<br>
+ base=private<br>
+ _________________________ ipsec/policies/private<br>
+ cat /etc/ipsec.d/policies/private<br>
# This file defines the set of CIDRs (network/mask-length) to which<br>
# communication should always be private (i.e. encrypted).<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
# $Id: <a href="http://private.in">private.in</a>,v 1.4 2003/02/17 02:22:15 mcr Exp $<br>
#<br>
+ for policy in '$POLICIES/*'<br>
++ basename /etc/ipsec.d/policies/private-or-clear<br>
+ base=private-or-clear<br>
+ _________________________ ipsec/policies/private-or-clear<br>
+ cat /etc/ipsec.d/policies/private-or-clear<br>
# This file defines the set of CIDRs (network/mask-length) to which<br>
# communication should be private, if possible, but in the clear otherwise.<br>
#<br>
# If the target has a TXT (later IPSECKEY) record that specifies<br>
# authentication material, we will require private (i.e. encrypted)<br>
# communications. If no such record is found, communications will be<br>
# in the clear.<br>
#<br>
# See /usr/share/doc/openswan/policygroups.html for details.<br>
#<br>
# $Id: <a href="http://private-or-clear.in">private-or-clear.in</a>,v 1.5 2003/02/17 02:22:15 mcr Exp $<br>
#<br>
<br>
<a href="http://0.0.0.0/0">0.0.0.0/0</a><br>
+ _________________________ ipsec/ls-libdir<br>
+ ls -l /usr/libexec/ipsec<br>
total 2272<br>
-rwxr-xr-x 1 root root 5996 Jun 22 05:03 _copyright<br>
-rwxr-xr-x 1 root root 2379 Jun 22 05:03 _include<br>
-rwxr-xr-x 1 root root 1475 Jun 22 05:03 _keycensor<br>
-rwxr-xr-x 1 root root 10028 Jun 22 05:03 _pluto_adns<br>
-rwxr-xr-x 1 root root 2632 Jun 22 05:03 _plutoload<br>
-rwxr-xr-x 1 root root 7602 Jun 22 05:03 _plutorun<br>
-rwxr-xr-x 1 root root 13746 Jun 22 05:03 _realsetup<br>
-rwxr-xr-x 1 root root 1975 Jun 22 05:03 _secretcensor<br>
-rwxr-xr-x 1 root root 9752 Jun 22 05:03 _startklips<br>
-rwxr-xr-x 1 root root 9752 Jun 22 05:03 _startklips.old<br>
-rwxr-xr-x 1 root root 4988 Jun 22 05:03 _startnetkey<br>
-rwxr-xr-x 1 root root 4949 Jun 22 05:03 _updown<br>
-rwxr-xr-x 1 root root 14030 Jun 22 05:03 _updown.klips<br>
-rwxr-xr-x 1 root root 14030 Jun 22 05:03 _updown.klips.old<br>
-rwxr-xr-x 1 root root 13739 Jun 22 05:03 _updown.mast<br>
-rwxr-xr-x 1 root root 13739 Jun 22 05:03 _updown.mast.old<br>
-rwxr-xr-x 1 root root 8337 Jun 22 05:03 _updown.netkey<br>
-rwxr-xr-x 1 root root 183808 Jun 22 05:03 addconn<br>
-rwxr-xr-x 1 root root 6129 Jun 22 05:03 auto<br>
-rwxr-xr-x 1 root root 10758 Jun 22 05:03 barf<br>
-rwxr-xr-x 1 root root 90028 Jun 22 05:03 eroute<br>
-rwxr-xr-x 1 root root 20072 Jun 22 05:03 ikeping<br>
-rwxr-xr-x 1 root root 69744 Jun 22 05:03 klipsdebug<br>
-rwxr-xr-x 1 root root 1836 Jun 22 05:03 livetest<br>
-rwxr-xr-x 1 root root 2591 Jun 22 05:03 look<br>
-rwxr-xr-x 1 root root 1921 Jun 22 05:03 newhostkey<br>
-rwxr-xr-x 1 root root 60780 Jun 22 05:03 pf_key<br>
-rwxr-xr-x 1 root root 982244 Jun 22 05:03 pluto<br>
-rwxr-xr-x 1 root root 10176 Jun 22 05:03 ranbits<br>
-rwxr-xr-x 1 root root 20532 Jun 22 05:03 rsasigkey<br>
-rwxr-xr-x 1 root root 766 Jun 22 05:03 secrets<br>
lrwxrwxrwx 1 root root 30 Dec 6 14:31 setup -> ../../../etc/rc.d/init.d/ipsec<br>
-rwxr-xr-x 1 root root 1054 Jun 22 05:03 showdefaults<br>
-rwxr-xr-x 1 root root 219660 Jun 22 05:03 showhostkey<br>
-rwxr-xr-x 1 root root 22684 Jun 22 05:03 showpolicy<br>
-rwxr-xr-x 1 root root 148008 Jun 22 05:03 spi<br>
-rwxr-xr-x 1 root root 77276 Jun 22 05:03 spigrp<br>
-rwxr-xr-x 1 root root 69384 Jun 22 05:03 tncfg<br>
-rwxr-xr-x 1 root root 12526 Jun 22 05:03 verify<br>
-rwxr-xr-x 1 root root 50568 Jun 22 05:03 whack<br>
+ _________________________ ipsec/ls-execdir<br>
+ ls -l /usr/libexec/ipsec<br>
total 2272<br>
-rwxr-xr-x 1 root root 5996 Jun 22 05:03 _copyright<br>
-rwxr-xr-x 1 root root 2379 Jun 22 05:03 _include<br>
-rwxr-xr-x 1 root root 1475 Jun 22 05:03 _keycensor<br>
-rwxr-xr-x 1 root root 10028 Jun 22 05:03 _pluto_adns<br>
-rwxr-xr-x 1 root root 2632 Jun 22 05:03 _plutoload<br>
-rwxr-xr-x 1 root root 7602 Jun 22 05:03 _plutorun<br>
-rwxr-xr-x 1 root root 13746 Jun 22 05:03 _realsetup<br>
-rwxr-xr-x 1 root root 1975 Jun 22 05:03 _secretcensor<br>
-rwxr-xr-x 1 root root 9752 Jun 22 05:03 _startklips<br>
-rwxr-xr-x 1 root root 9752 Jun 22 05:03 _startklips.old<br>
-rwxr-xr-x 1 root root 4988 Jun 22 05:03 _startnetkey<br>
-rwxr-xr-x 1 root root 4949 Jun 22 05:03 _updown<br>
-rwxr-xr-x 1 root root 14030 Jun 22 05:03 _updown.klips<br>
-rwxr-xr-x 1 root root 14030 Jun 22 05:03 _updown.klips.old<br>
-rwxr-xr-x 1 root root 13739 Jun 22 05:03 _updown.mast<br>
-rwxr-xr-x 1 root root 13739 Jun 22 05:03 _updown.mast.old<br>
-rwxr-xr-x 1 root root 8337 Jun 22 05:03 _updown.netkey<br>
-rwxr-xr-x 1 root root 183808 Jun 22 05:03 addconn<br>
-rwxr-xr-x 1 root root 6129 Jun 22 05:03 auto<br>
-rwxr-xr-x 1 root root 10758 Jun 22 05:03 barf<br>
-rwxr-xr-x 1 root root 90028 Jun 22 05:03 eroute<br>
-rwxr-xr-x 1 root root 20072 Jun 22 05:03 ikeping<br>
-rwxr-xr-x 1 root root 69744 Jun 22 05:03 klipsdebug<br>
-rwxr-xr-x 1 root root 1836 Jun 22 05:03 livetest<br>
-rwxr-xr-x 1 root root 2591 Jun 22 05:03 look<br>
-rwxr-xr-x 1 root root 1921 Jun 22 05:03 newhostkey<br>
-rwxr-xr-x 1 root root 60780 Jun 22 05:03 pf_key<br>
-rwxr-xr-x 1 root root 982244 Jun 22 05:03 pluto<br>
-rwxr-xr-x 1 root root 10176 Jun 22 05:03 ranbits<br>
-rwxr-xr-x 1 root root 20532 Jun 22 05:03 rsasigkey<br>
-rwxr-xr-x 1 root root 766 Jun 22 05:03 secrets<br>
lrwxrwxrwx 1 root root 30 Dec 6 14:31 setup -> ../../../etc/rc.d/init.d/ipsec<br>
-rwxr-xr-x 1 root root 1054 Jun 22 05:03 showdefaults<br>
-rwxr-xr-x 1 root root 219660 Jun 22 05:03 showhostkey<br>
-rwxr-xr-x 1 root root 22684 Jun 22 05:03 showpolicy<br>
-rwxr-xr-x 1 root root 148008 Jun 22 05:03 spi<br>
-rwxr-xr-x 1 root root 77276 Jun 22 05:03 spigrp<br>
-rwxr-xr-x 1 root root 69384 Jun 22 05:03 tncfg<br>
-rwxr-xr-x 1 root root 12526 Jun 22 05:03 verify<br>
-rwxr-xr-x 1 root root 50568 Jun 22 05:03 whack<br>
+ _________________________ /proc/net/dev<br>
+ cat /proc/net/dev<br>
Inter-| Receive | Transmit<br>
face |bytes packets errs drop fifo frame compressed multicast|bytes packets errs drop fifo colls carrier compressed<br>
lo:65724782 466865 0 0 0 0 0 0 65724782 466865 0 0 0 0 0 0<br>
eth0: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0<br>
eth1:735126767 727400 0 0 0 0 0 0 120148705 613403 0 0 0 0 0 0<br>
eth2:108467344 646574 0 0 0 0 0 0 728876421 741847 0 0 0 0 0 0<br>
eth3: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0<br>
eth4: 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0<br>
ppp0:718935315 722555 0 0 0 0 0 0 106549797 608093 0 0 0 0 0 0<br>
+ _________________________ /proc/net/route<br>
+ cat /proc/net/route<br>
Iface Destination Gateway Flags RefCnt Use Metric
Mask MTU Window
IRTT <br>
ppp0 01946955 00000000 0005 0 0 0 FFFFFFFF 0
0
0
<br>
eth2 0000000A 00000000 0001 0 0 0 00FFFFFF 0
0
0
<br>
eth1 0000A8C0 00000000 0001 0 0 0 00FFFFFF 0
0
0
<br>
eth0 0001FEA9 00000000 0001 0 0 0 00FFFFFF 0
0
0
<br>
eth0 0000FEA9 00000000 0001 0 0 0 0000FFFF 0
0
0
<br>
ppp0 00000000 01946955 0003 0 0 0 00000000 0
0
0
<br>
+ _________________________ /proc/sys/net/ipv4/ip_no_pmtu_disc<br>
+ cat /proc/sys/net/ipv4/ip_no_pmtu_disc<br>
0<br>
+ _________________________ /proc/sys/net/ipv4/ip_forward<br>
+ cat /proc/sys/net/ipv4/ip_forward<br>
1<br>
+ _________________________ /proc/sys/net/ipv4/tcp_ecn<br>
+ cat /proc/sys/net/ipv4/tcp_ecn<br>
0<br>
+ _________________________ /proc/sys/net/ipv4/conf/star-rp_filter<br>
+ cd /proc/sys/net/ipv4/conf<br>
+ egrep '^' all/rp_filter default/rp_filter eth0/rp_filter eth1/rp_filter eth2/rp_filter lo/rp_filter ppp0/rp_filter<br>
all/rp_filter:0<br>
default/rp_filter:1<br>
eth0/rp_filter:1<br>
eth1/rp_filter:1<br>
eth2/rp_filter:1<br>
lo/rp_filter:0<br>
ppp0/rp_filter:1<br>
+ _________________________ /proc/sys/net/ipv4/conf/star-star-redirects<br>
+ cd /proc/sys/net/ipv4/conf<br>
+ egrep '^' all/accept_redirects all/secure_redirects
all/send_redirects default/accept_redirects default/secure_redirects
default/send_redirects eth0/accept_redirects eth0/secure_redirects
eth0/send_redirects eth1/accept_redirects eth1/secure_redirects
eth1/send_redirects eth2/accept_redirects eth2/secure_redirects
eth2/send_redirects lo/accept_redirects lo/secure_redirects
lo/send_redirects ppp0/accept_redirects ppp0/secure_redirects
ppp0/send_redirects<br>
all/accept_redirects:0<br>
all/secure_redirects:1<br>
all/send_redirects:1<br>
default/accept_redirects:1<br>
default/secure_redirects:1<br>
default/send_redirects:1<br>
eth0/accept_redirects:1<br>
eth0/secure_redirects:1<br>
eth0/send_redirects:1<br>
eth1/accept_redirects:1<br>
eth1/secure_redirects:1<br>
eth1/send_redirects:1<br>
eth2/accept_redirects:1<br>
eth2/secure_redirects:1<br>
eth2/send_redirects:1<br>
lo/accept_redirects:1<br>
lo/secure_redirects:1<br>
lo/send_redirects:1<br>
ppp0/accept_redirects:1<br>
ppp0/secure_redirects:1<br>
ppp0/send_redirects:1<br>
+ _________________________ /proc/sys/net/ipv4/tcp_window_scaling<br>
+ cat /proc/sys/net/ipv4/tcp_window_scaling<br>
1<br>
+ _________________________ /proc/sys/net/ipv4/tcp_adv_win_scale<br>
+ cat /proc/sys/net/ipv4/tcp_adv_win_scale<br>
2<br>
+ _________________________ uname-a<br>
+ uname -a<br>
Linux app 2.6.18-lbr5.std.3 #1 SMP Fri Oct 31 11:44:34 EET 2008 i686 i686 i386 GNU/Linux<br>
+ _________________________ config-built-with<br>
+ test -r /proc/config_built_with<br>
+ _________________________ distro-release<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/redhat-release<br>
+ cat /etc/redhat-release<br>
Labris release 1.5.5<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/debian-release<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/SuSE-release<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/mandrake-release<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/mandriva-release<br>
+ for distro in /etc/redhat-release /etc/debian-release
/etc/SuSE-release /etc/mandrake-release /etc/mandriva-release
/etc/gentoo-release<br>
+ test -f /etc/gentoo-release<br>
+ _________________________ /proc/net/ipsec_version<br>
+ test -r /proc/net/ipsec_version<br>
+ test -r /proc/net/pfkey<br>
++ uname -r<br>
+ echo 'NETKEY (2.6.18-lbr5.std.3) support detected '<br>
NETKEY (2.6.18-lbr5.std.3) support detected <br>
+ _________________________ iptables<br>
+ test -r /sbin/iptables<br>
+ iptables -L -v -n<br>
Chain INPUT (policy DROP 0 packets, 0 bytes)<br>
pkts bytes target prot opt in out source destination <br>
33647 6151K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
48314 6634K ACCEPT all -- lo * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
108 5171 console_input_custom_chain icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
10094 705K console_input_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:22 <br>
0 0 console_input_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:81 <br>
392 37991 console_input_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:4000 <br>
11524 1255K BADPACKETS all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- lo * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
4614 515K ACCEPT all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- lo * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
6905 739K BADPACKETS all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- lo * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- lo * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
6905 739K auto-auth all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
6905 739K Application_Rules all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
1159 159K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
19 2811 General_Rule_0 all -- * * 10.0.0.24 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
74 9852 General_Rule_0 all -- * * 10.0.0.100 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
35 3966 General_Rule_0 all -- * * 10.0.0.21 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 81.81.81.81 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 85.85.85.85 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
24 6024 General_Rule_1 all -- * * 10.0.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
24 6024 General_Rule_1 all -- * * 192.168.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:25 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:80 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:25 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:80 state NEW <br>
0 0 General_Rule_3 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:3389 state NEW <br>
2012 196K General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:80 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:443 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:25 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:465 state NEW <br>
0 0 General_Rule_5 udp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:53 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:53 state NEW <br>
0 0 General_Rule_6 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1352 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpts:1700:1702 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:4500 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:500 state NEW <br>
0 0 General_Rule_7 esp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 ah -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:4500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:1700:1702 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:3366 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:4866 state NEW <br>
0 0 General_Rule_10 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:3355 state NEW <br>
0 0 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1863 state NEW <br>
0 0 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:6891:6900 state NEW <br>
3558 356K General_Rule_13 all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 6 prefix `_lfp_ Default --DENY' <br>
<br>
Chain FORWARD (policy DROP 0 packets, 0 bytes)<br>
pkts bytes target prot opt in out source destination <br>
153K 89M ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
353K 236M BADPACKETS all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
191K 213M ppp0_custom_chain all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth4_custom_chain all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth3_custom_chain all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
162K 23M eth2_custom_chain all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
191K 213M ppp0_custom_chain all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth1_custom_chain all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth0_custom_chain all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
353K 236M BADPACKETS all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
191K 213M ppp0_custom_chain all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth4_custom_chain all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth3_custom_chain all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
162K 23M eth2_custom_chain all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
191K 213M ppp0_custom_chain all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth1_custom_chain all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 eth0_custom_chain all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- lo lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
353K 236M auto-auth all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
353K 236M Application_Rules all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
342K 235M ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 General_Rule_0 all -- * * 10.0.0.24 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_0 all -- * * 10.0.0.100 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
5317 686K General_Rule_0 all -- * * 10.0.0.21 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 81.81.81.81 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 85.85.85.85 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 10.0.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 192.168.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
25 1260 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:25 state NEW <br>
2 96 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:80 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:25 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:80 state NEW <br>
0 0 General_Rule_3 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:3389 state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
2 96 General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
2905 143K General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:80 state NEW <br>
177 8968 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:443 state NEW <br>
3 144 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:25 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:465 state NEW <br>
991 67954 General_Rule_5 udp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:53 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:53 state NEW <br>
21 1028 General_Rule_6 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1352 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpts:1700:1702 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:4500 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:500 state NEW <br>
0 0 General_Rule_7 esp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 ah -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:4500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:1700:1702 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:3366 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:4866 state NEW <br>
0 0 General_Rule_10 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:3355 state NEW <br>
2 96 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1863 state NEW <br>
0 0 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:6891:6900 state NEW <br>
1159 85029 General_Rule_13 all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 6 prefix `_lfp_ Default --DENY' <br>
<br>
Chain OUTPUT (policy DROP 0 packets, 0 bytes)<br>
pkts bytes target prot opt in out source destination <br>
28714 4658K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
3057 398K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
48314 6634K ACCEPT all -- * lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
1400 129K console_output_custom_chain icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
7502 1190K console_output_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp spt:22 <br>
0 0 console_output_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp spt:81 <br>
433 69397 console_output_custom_chain tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp spt:4000 <br>
0 0 ACCEPT all -- * lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * eth1 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
4431 421K ACCEPT all -- * eth2 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth3 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth4 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth0 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * eth1 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth2 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth3 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth4 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * eth0 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 ACCEPT all -- * lo <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
1609 354K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state RELATED,ESTABLISHED <br>
0 0 General_Rule_0 all -- * * 10.0.0.24 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_0 all -- * * 10.0.0.100 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_0 all -- * * 10.0.0.21 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_1 all -- * * 81.81.81.81 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
2129 144K General_Rule_1 all -- * * 85.85.85.85 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
600 40584 General_Rule_1 all -- * * 10.0.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
24 6024 General_Rule_1 all -- * * 192.168.0.254 <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:25 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:80 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:25 state NEW <br>
0 0 General_Rule_2 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:80 state NEW <br>
0 0 General_Rule_3 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:3389 state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> state NEW <br>
0 0 General_Rule_4 all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:80 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:443 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:25 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:465 state NEW <br>
0 0 General_Rule_5 udp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:53 state NEW <br>
0 0 General_Rule_5 tcp -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:53 state NEW <br>
0 0 General_Rule_6 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1352 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpts:1700:1702 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:4500 state NEW <br>
0 0 General_Rule_7 udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> udp dpt:500 state NEW <br>
0 0 General_Rule_7 esp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 ah -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:4500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:500 state NEW <br>
0 0 General_Rule_7 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:1700:1702 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:3366 state NEW <br>
0 0 General_Rule_8 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.111 tcp dpt:4866 state NEW <br>
0 0 General_Rule_10 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.200 tcp dpt:3355 state NEW <br>
0 0 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpt:1863 state NEW <br>
0 0 General_Rule_12 tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp dpts:6891:6900 state NEW <br>
24 6024 General_Rule_13 all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state NEW <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 6 prefix `_lfp_ --DENY' <br>
<br>
Chain Application_Rules (2 references)<br>
pkts bytes target prot opt in out source destination <br>
<br>
Chain BADPACKETS (4 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x29 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x37 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x00 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x3F <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x01 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x06/0x06 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x03/0x03 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp option=64 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp option=128 <br>
0 0 DOS all -f * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
29 1591 DOS all -- !eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state INVALID <br>
0 0 SMALL udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:27 <br>
0 0 SMALL tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:39 <br>
0 0 SMALL icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:27 <br>
10 11016 NEWNOTSYN tcp -- !eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:!0x17/0x02 state NEW <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x29 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x37 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x00 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x3F <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x3F/0x01 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x06/0x06 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:0x03/0x03 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp option=64 <br>
0 0 PSCAN tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp option=128 <br>
0 0 DOS all -f * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 DOS all -- !eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> state INVALID <br>
0 0 SMALL udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:27 <br>
0 0 SMALL tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:39 <br>
0 0 SMALL icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> length 0:27 <br>
0 0 NEWNOTSYN tcp -- !eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> tcp flags:!0x17/0x02 state NEW <br>
<br>
Chain DOS (4 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ ICMP DoS DENY ' <br>
29 1591 LOG tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ TCP DoS DENY ' <br>
0 0 LOG udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ UDP DoS DENY ' <br>
29 1591 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ ICMP DoS DENY ' <br>
0 0 LOG tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ TCP DoS DENY ' <br>
0 0 LOG udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ UDP DoS DENY ' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_0 (9 references)<br>
pkts bytes target prot opt in out source destination <br>
5445 703K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_1 (12 references)<br>
pkts bytes target prot opt in out source destination <br>
2801 203K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_10 (3 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_12 (6 references)<br>
pkts bytes target prot opt in out source destination <br>
2 96 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 6 prefix `_lfp_ Rule 12 -- DENY' <br>
2 96 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_13 (3 references)<br>
pkts bytes target prot opt in out source destination <br>
4741 447K DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_2 (12 references)<br>
pkts bytes target prot opt in out source destination <br>
27 1356 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_3 (3 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_4 (12 references)<br>
pkts bytes target prot opt in out source destination <br>
2014 196K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_5 (18 references)<br>
pkts bytes target prot opt in out source destination <br>
4076 220K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_6 (3 references)<br>
pkts bytes target prot opt in out source destination <br>
21 1028 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_7 (24 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain General_Rule_8 (6 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain NEWNOTSYN (2 references)<br>
pkts bytes target prot opt in out source destination <br>
10 11016 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ NEW not SYN DENY
' <br>
10 11016 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ NEW not SYN DENY
' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain PSCAN (18 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ TCP Scan DENY ' <br>
0 0 LOG udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ UDP Scan DENY ' <br>
0 0 LOG icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ ICMP Scan DENY ' <br>
0 0 LOG all -f * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ FRAG Scan DENY ' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ TCP Scan DENY ' <br>
0 0 LOG udp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ UDP Scan DENY ' <br>
0 0 LOG icmp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ ICMP Scan DENY ' <br>
0 0 LOG all -f * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ FRAG Scan DENY ' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain SMALL (6 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ Too small DENY ' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_ Too small DENY ' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain auto-auth (2 references)<br>
pkts bytes target prot opt in out source destination <br>
<br>
Chain console_input_custom_chain (4 references)<br>
pkts bytes target prot opt in out source destination <br>
10486 743K ACCEPT all -- * * 81.81.81.81 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * * 10.0.0.100 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
108 5171 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * * 169.254.1.11 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain console_output_custom_chain (4 references)<br>
pkts bytes target prot opt in out source destination <br>
7935 1260K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 81.81.81.81 <br>
0 0 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 10.0.0.100 <br>
1400 129K ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 ACCEPT all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 169.254.1.11 <br>
0 0 LOG all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain eth0_custom_chain (2 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- eth0 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth0 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- eth0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
0 0 RETURN all -- eth0 * <a href="http://169.254.1.0/24">169.254.1.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain eth1_custom_chain (2 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- eth1 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth1 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- eth1 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
0 0 RETURN all -- eth1 * <a href="http://192.168.0.0/24">192.168.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain eth2_custom_chain (2 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- eth2 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth2 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- eth2 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
324K 47M RETURN all -- eth2 * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain eth3_custom_chain (2 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- eth3 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth3 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- eth3 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
<br>
Chain eth4_custom_chain (2 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- eth4 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth4 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- eth4 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
<br>
Chain ppp0_custom_chain (4 references)<br>
pkts bytes target prot opt in out source destination <br>
0 0 LOG all -- ppp0 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> LOG flags 0 level 4 prefix `_lfp_DROP' <br>
0 0 DROP all -- ppp0 * <a href="http://127.0.0.0/8">127.0.0.0/8</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
0 0 LOG all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST LOG flags 0 level
4 prefix `_lfp_DROP' <br>
0 0 DROP all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> ADDRTYPE match src-type BROADCAST <br>
0 0 LOG all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a>
<a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast LOG flags 0 level 4 prefix
`_lfp_DROP' <br>
0 0 DROP all -- ppp0 * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> PKTTYPE = broadcast <br>
0 0 RETURN all -- ppp0 * 85.85.85.85 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
+ _________________________ iptables-nat<br>
+ iptables -t nat -L -v -n<br>
Chain PREROUTING (policy ACCEPT 20128 packets, 1956K bytes)<br>
pkts bytes target prot opt in out source destination <br>
2922 280K ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
141 6768 ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
76 3736 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf3 to:10.0.0.200 <br>
0 0 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf3 to:10.0.0.200 <br>
0 0 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf3 to:10.0.0.200 <br>
0 0 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf4 to:10.0.0.200 <br>
0 0 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf5 to:10.0.0.111 <br>
0 0 DNAT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf6 to:10.0.0.222 <br>
<br>
Chain POSTROUTING (policy ACCEPT 1996 packets, 128K bytes)<br>
pkts bytes target prot opt in out source destination <br>
829 53242 ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
3 144 ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://192.168.1.0/24">192.168.1.0/24</a> <a href="http://192.168.1.0/24">192.168.1.0/24</a> <br>
0 0 ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://10.0.0.0/24">10.0.0.0/24</a> <br>
0 0 SNAT all -- * eth0 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
0 0 SNAT all -- * eth1 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
13795 1301K SNAT all -- * ppp0 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
0 0 SNAT all -- * eth2 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
0 0 SNAT all -- * eth3 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
0 0 SNAT all -- * eth4 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
0 0 SNAT all -- * ppp0 <a href="http://0.0.0.0/0">0.0.0.0/0</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK match 0xf7 to:85.85.85.85 <br>
<br>
Chain OUTPUT (policy ACCEPT 2773 packets, 184K bytes)<br>
pkts bytes target prot opt in out source destination <br>
+ _________________________ iptables-mangle<br>
+ iptables -t mangle -L -v -n<br>
Chain PREROUTING (policy ACCEPT 352K packets, 292M bytes)<br>
pkts bytes target prot opt in out source destination <br>
5860 7279K MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:25 MARK set 0xf3 <br>
5860 7279K ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:25 <br>
50 5566 MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:80 MARK set 0xf3 <br>
50 5566 ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:80 <br>
5028 1369K MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:1352 MARK set 0xf3 <br>
5028 1369K ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:1352 <br>
3659 5275K MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3355 MARK set 0xf4 <br>
3659 5275K ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3355 <br>
0 0 MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3366 MARK set 0xf5 <br>
0 0 ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3366 <br>
0 0 MARK tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3389 MARK set 0xf6 <br>
0 0 ACCEPT tcp -- * * <a href="http://0.0.0.0/0">0.0.0.0/0</a> 85.85.85.85 tcp dpt:3389 <br>
243K 33M MARK all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> MARK set 0xf7 <br>
243K 33M ACCEPT all -- * * <a href="http://10.0.0.0/24">10.0.0.0/24</a> <a href="http://0.0.0.0/0">0.0.0.0/0</a> <br>
<br>
Chain INPUT (policy ACCEPT 104K packets, 15M bytes)<br>
pkts bytes target prot opt in out source destination <br>
<br>
Chain FORWARD (policy ACCEPT 506K packets, 325M bytes)<br>
pkts bytes target prot opt in out source destination <br>
<br>
Chain OUTPUT (policy ACCEPT 98245 packets, 14M bytes)<br>
pkts bytes target prot opt in out source destination <br>
<br>
Chain POSTROUTING (policy ACCEPT 603K packets, 339M bytes)<br>
pkts bytes target prot opt in out source destination <br>
+ _________________________ /proc/modules<br>
+ test -f /proc/modules<br>
+ cat /proc/modules<br>
ipcomp 11528 0 - Live 0xdcb6e000 (U)<br>
ah4 10368 0 - Live 0xdcb6a000 (U)<br>
esp4 12416 0 - Live 0xdcb65000 (U)<br>
xfrm4_tunnel 6656 0 - Live 0xdcb2f000 (U)<br>
xfrm4_mode_tunnel 6912 0 - Live 0xdcb29000 (U)<br>
xfrm4_mode_transport 6272 0 - Live 0xdcb23000 (U)<br>
af_key 39568 0 - Live 0xdcb49000 (U)<br>
ip_nat_ftp 7424 0 - Live 0xdcb32000 (U)<br>
ip_conntrack_ftp 11248 1 ip_nat_ftp, Live 0xdcba6000 (U)<br>
deflate 7936 0 - Live 0xdcb35000 (U)<br>
zlib_deflate 22040 1 deflate, Live 0xdcbc2000 (U)<br>
zlib_inflate 18944 1 deflate, Live 0xdcbbc000 (U)<br>
serpent 29440 0 - Live 0xdcbb3000 (U)<br>
blowfish 12672 0 - Live 0xdcbd2000 (U)<br>
twofish 46080 0 - Live 0xdcbda000 (U)<br>
md5 8320 0 - Live 0xdcba2000 (U)<br>
sha256 15360 0 - Live 0xdcb9d000 (U)<br>
sha512 13184 0 - Live 0xdcb88000 (U)<br>
des 21632 0 - Live 0xdcb7d000 (U)<br>
aes_generic 31808 0 - Live 0xdcb94000 (U)<br>
aes_i586 37120 0 - Live 0xdcb72000 (U)<br>
xfrm4_esp 9728 1 esp4, Live 0xdcb61000 (U)<br>
aead 11904 1 esp4, Live 0xdcb84000 (U)<br>
crypto_algapi 21376 1 aead, Live 0xdcb5a000 (U)<br>
xfrm_nalgo 13828 3 ah4,esp4,xfrm4_esp, Live 0xdcb8f000 (U)<br>
crypto_api 12160 5 ah4,esp4,aead,crypto_algapi,xfrm_nalgo, Live 0xdcb41000 (U)<br>
tunnel4 7428 1 xfrm4_tunnel, Live 0xdcb2c000 (U)<br>
iptable_mangle 6912 1 - Live 0xdcb26000 (U)<br>
xt_state 6400 138 - Live 0xdcb1d000 (U)<br>
iptable_nat 11524 1 - Live 0xdc986000 (U)<br>
ip_nat 26412 2 ip_nat_ftp,iptable_nat, Live 0xdc97e000 (U)<br>
ipt_layer7 14980 0 - Live 0xdc979000 (U)<br>
ip_conntrack 50912 6 ip_nat_ftp,ip_conntrack_ftp,xt_state,iptable_nat,ip_nat,ipt_layer7, Live 0xdc96b000 (U)<br>
iptable_filter 7168 1 - Live 0xdc8c1000 (U)<br>
ip_tables 17092 3 iptable_mangle,iptable_nat,iptable_filter, Live 0xdc939000 (U)<br>
xt_pkttype 6144 12 - Live 0xdcb46000 (U)<br>
ipt_addrtype 6016 12 - Live 0xdcb3e000 (U)<br>
xt_length 6144 6 - Live 0xdcb38000 (U)<br>
xt_mark 6144 13 - Live 0xdcb20000 (U)<br>
xt_tcpudp 7296 107 - Live 0xdcb1a000 (U)<br>
xt_MARK 6528 7 - Live 0xdcb3b000 (U)<br>
nfnetlink 10776 4 ip_nat,ip_conntrack, Live 0xdc960000 (U)<br>
ipt_LOG 10112 42 - Live 0xdc95c000 (U)<br>
ppp_synctty 13824 0 - Live 0xdc951000 (U)<br>
ppp_async 15360 1 - Live 0xdc94c000 (U)<br>
crc_ccitt 6400 1 ppp_async, Live 0xdc922000 (U)<br>
ppp_generic 30228 6 ppp_synctty,ppp_async, Live 0xdc943000 (U)<br>
slhc 10624 1 ppp_generic, Live 0xdc93f000 (U)<br>
x_tables 17540 11
xt_state,iptable_nat,ipt_layer7,ip_tables,xt_pkttype,ipt_addrtype,xt_length,xt_mark,xt_tcpudp,xt_MARK,ipt_LOG,
Live 0xdc965000 (U)<br>
dm_mirror 29316 0 - Live 0xdc98a000 (U)<br>
dm_multipath 22024 0 - Live 0xdc91b000 (U)<br>
dm_mod 59032 2 dm_mirror,dm_multipath, Live 0xdc90b000 (U)<br>
video 21384 0 - Live 0xdc904000 (U)<br>
backlight 10112 1 video, Live 0xdc92e000 (U)<br>
button 10768 0 - Live 0xdc925000 (U)<br>
battery 13700 0 - Live 0xdc929000 (U)<br>
asus_acpi 19480 0 - Live 0xdc933000 (U)<br>
ac 9220 0 - Live 0xdc8db000 (U)<br>
sg 36252 0 - Live 0xdc8cc000 (U)<br>
via_rhine 27276 0 - Live 0xdc8b9000 (U)<br>
pata_via 16004 0 - Live 0xdc8b4000 (U)<br>
mii 9472 1 via_rhine, Live 0xdc8d7000 (U)<br>
serio_raw 10884 0 - Live 0xdc85e000 (U)<br>
sata_via 15236 5 - Live 0xdc851000 (U)<br>
pata_acpi 11264 0 - Live 0xdc85a000 (U)<br>
ata_generic 11396 0 - Live 0xdc856000 (U)<br>
libata 143676 4 pata_via,sata_via,pata_acpi,ata_generic, Live 0xdc8df000 (U)<br>
sd_mod 24832 6 - Live 0xdc82b000 (U)<br>
scsi_mod 134540 3 sg,libata,sd_mod, Live 0xdc873000 (U)<br>
ext3 115592 4 - Live 0xdc896000 (U)<br>
jbd 56488 1 ext3, Live 0xdc864000 (U)<br>
uhci_hcd 25356 0 - Live 0xdc812000 (U)<br>
ohci_hcd 23196 0 - Live 0xdc824000 (U)<br>
ehci_hcd 33292 0 - Live 0xdc81a000 (U)<br>
usbcore 116484 4 uhci_hcd,ohci_hcd,ehci_hcd, Live 0xdc833000 (U)<br>
+ _________________________ /proc/meminfo<br>
+ cat /proc/meminfo<br>
MemTotal: 450000 kB<br>
MemFree: 35568 kB<br>
Buffers: 11052 kB<br>
Cached: 97948 kB<br>
SwapCached: 52404 kB<br>
Active: 359040 kB<br>
Inactive: 29264 kB<br>
HighTotal: 0 kB<br>
HighFree: 0 kB<br>
LowTotal: 450000 kB<br>
LowFree: 35568 kB<br>
SwapTotal: 3068372 kB<br>
SwapFree: 2865944 kB<br>
Dirty: 1120 kB<br>
Writeback: 0 kB<br>
AnonPages: 257368 kB<br>
Mapped: 36076 kB<br>
Slab: 15856 kB<br>
PageTables: 5440 kB<br>
NFS_Unstable: 0 kB<br>
Bounce: 0 kB<br>
CommitLimit: 3293372 kB<br>
Committed_AS: 1206240 kB<br>
VmallocTotal: 573432 kB<br>
VmallocUsed: 3940 kB<br>
VmallocChunk: 569224 kB<br>
HugePages_Total: 0<br>
HugePages_Free: 0<br>
HugePages_Rsvd: 0<br>
Hugepagesize: 4096 kB<br>
+ _________________________ /proc/net/ipsec-ls<br>
+ test -f /proc/net/ipsec_version<br>
+ _________________________ usr/src/linux/.config<br>
+ test -f /proc/config.gz<br>
++ uname -r<br>
+ test -f /lib/modules/2.6.18-lbr5.std.3/build/.config<br>
+ echo 'no .config file found, cannot list kernel properties'<br>
no .config file found, cannot list kernel properties<br>
+ _________________________ etc/resolv.conf<br>
+ cat /etc/resolv.conf<br>
# Created by Labris Management Console on 05/11/108 11:37:18<br>
# WARNING: Comments on this file will be lost on next update<br>
<br>
nameserver 192.168.2.1<br>
nameserver 195.175.39.39<br>
+ _________________________ lib/modules-ls<br>
+ ls -ltr /lib/modules<br>
total 4<br>
drwxr-xr-x 3 root root 4096 Dec 2 09:31 2.6.18-lbr5.std.3<br>
+ _________________________ /proc/ksyms-netif_rx<br>
+ test -r /proc/ksyms<br>
+ test -r /proc/kallsyms<br>
+ egrep netif_rx /proc/kallsyms<br>
c05493b9 T __netif_rx_schedule<br>
c054a0a8 T netif_rx<br>
c054b300 T netif_rx_ni<br>
c054a0a8 U netif_rx [xfrm4_esp]<br>
c054a0a8 U netif_rx [ppp_generic]<br>
c05493b9 U __netif_rx_schedule [via_rhine]<br>
+ _________________________ lib/modules-netif_rx<br>
+ modulegoo kernel/net/ipv4/ipip.o netif_rx<br>
+ set +x<br>
2.6.18-lbr5.std.3: <br>
+ _________________________ kern.debug<br>
+ test -f /var/log/kern.debug<br>
+ _________________________ klog<br>
+ sed -n '1,$p' /dev/null<br>
+ egrep -i 'ipsec|klips|pluto'<br>
+ case "$1" in<br>
+ cat<br>
+ _________________________ plog<br>
+ sed -n '1,$p' /dev/null<br>
+ egrep -i pluto<br>
+ case "$1" in<br>
+ cat<br>
+ _________________________ date<br>
+ date<br>
Sat Dec 6 14:48:26 EET 2008<br>
<br>
<br>
<br><br><div class="gmail_quote">On Mon, Dec 8, 2008 at 9:08 PM, Paul Wouters <span dir="ltr"><<a href="mailto:paul@xelerance.com">paul@xelerance.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div class="Ih2E3d">On Sat, 6 Dec 2008, Oguz Yilmaz wrote:<br>
<br>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
cipher=oakley_3des_cbc_192 prf=oakley_md5 group=modp1024}<br>
117 "product" #2: STATE_QUICK_I1: initiate<br>
003 "product" #2: ERROR: netlink response for Add SA <a href="mailto:esp.b6ff9135@85.105.105.105" target="_blank">esp.b6ff9135@85.105.105.105</a> included errno 2: No<br>
such file or directory<br>
</blockquote>
<br></div>
Looks like you don't have all the NETKEY related modules loaded. eg esp4, xfrm_*<br><font color="#888888">
<br>
Paul<br>
</font></blockquote></div><br>