Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No access to my auto-hosted sites since VPS upgrade #3868

Open
KoulEl opened this issue Mar 22, 2025 · 16 comments
Open

No access to my auto-hosted sites since VPS upgrade #3868

KoulEl opened this issue Mar 22, 2025 · 16 comments
Labels

Comments

@KoulEl
Copy link

KoulEl commented Mar 22, 2025

Can't access my web servers from external.

I should be able to access my web sites (eg. https://video.amiga-ng.org). I can access them from my internal network.

Current Behavior

I try to access my websites but get stuck until timeout. Nothing revelant in the System log (except this : Mar 22 09:46:36 OpenMPTCProuter daemon.err dnsmasq[1]: nftset inet fw4 omr_dscp_cs2_6 Error: Could not resolve hostname: Name has no usable address).

It used to work correctly. I even recovered my saved configuration from the server to be sure I had not changed anything. Still the same problem. Everything ik in Firewall rules and OMR-Bypass.

Possible Solution

Maybe downgrade the VPS?

Steps to Reproduce the Problem

  1. Ask Milkywan to upgrade the VPS.
  2. Try to access auto-hosting sites.

Context (Environment)

Specifications

  • OpenMPTCProuter version: v0.61-6.6 r0+27346-c7ba5574 (not the 0.62-66 since I had troubles with network cards recognition as explained in another issue)
  • OpenMPTCProuter VPS version: v0.1032 6.12.15-c64v3-xanmod1
  • OpenMPTCProuter VPS provider: Milkywan
  • OpenMPTCProuter platform: x86_64
  • Country: France
@KoulEl KoulEl added the bug label Mar 22, 2025
@KoulEl KoulEl changed the title No access tomy webserver snce server upgrade No access to my auto-hosted sites since VPS upgrade Mar 22, 2025
@Ysurac
Copy link
Owner

Ysurac commented Mar 22, 2025

@KoulEl
Copy link
Author

KoulEl commented Mar 22, 2025

Thanks, I cannot (or don't know how to) access the VPS, I'll ask Milkywan for help and will come back to you.

@Ysurac
Copy link
Owner

Ysurac commented Mar 22, 2025

In fact just the tcpdump part on the router will tell if firewall config work or not

@KoulEl
Copy link
Author

KoulEl commented Mar 22, 2025

Here are the results:

root@OpenMPTCProuter:~# tcpdump -i tun0 port 80
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes
^C
0 packets captured
0 packets received by filter
0 packets dropped by kernel

root@OpenMPTCProuter:~# tcpdump -i tun0 port 443
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on tun0, link-type RAW (Raw IP), snapshot length 262144 bytes
^C
0 packets captured
0 packets received by filter
0 packets dropped by kernel

@Ysurac
Copy link
Owner

Ysurac commented Mar 22, 2025

When you tried to reach website ?
Can you give me result of uci show firewall ?

@KoulEl
Copy link
Author

KoulEl commented Mar 22, 2025

Here it is :

root@OpenMPTCProuter:~# uci show firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='REJECT'
firewall.@defaults[0].output='REJECT'
firewall.@defaults[0].forward='REJECT'
firewall.@defaults[0].fullcone='0'
firewall.@defaults[0].flow_offloading='0'
firewall.@defaults[0].flow_offloading_hw='0'
firewall.zone_lan=zone
firewall.zone_lan.name='lan'
firewall.zone_lan.network='lan'
firewall.zone_lan.input='ACCEPT'
firewall.zone_lan.output='ACCEPT'
firewall.zone_lan.forward='ACCEPT'
firewall.zone_lan.auto_helper='1'
firewall.zone_lan.mtu_fix='1'
firewall.zone_wan=zone
firewall.zone_wan.name='wan'
firewall.zone_wan.input='REJECT'
firewall.zone_wan.output='ACCEPT'
firewall.zone_wan.forward='REJECT'
firewall.zone_wan.fullcone4='0'
firewall.zone_wan.fullcone6='0'
firewall.zone_wan.masq='1'
firewall.zone_wan.mtu_fix='1'
firewall.zone_wan.auto_helper='1'
firewall.zone_wan.network='wan1' 'wan2'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Forward'
firewall.@rule[5].src='wan'
firewall.@rule[5].dest=''
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-IPSec-ESP'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='lan'
firewall.@rule[6].proto='esp'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-ISAKMP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].dest_port='500'
firewall.@rule[7].proto='udp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].target='ACCEPT'
firewall.@rule[8].name='Allow-All-LAN-to-VPN'
firewall.@rule[8].dest='vpn'
firewall.@rule[8].src='lan'
firewall.@rule[8].proto='all'
firewall.zone_vpn=zone
firewall.zone_vpn.name='vpn'
firewall.zone_vpn.masq='1'
firewall.zone_vpn.input='REJECT'
firewall.zone_vpn.forward='ACCEPT'
firewall.zone_vpn.output='ACCEPT'
firewall.zone_vpn.network='omrvpn' 'omr6in4'
firewall.zone_vpn.mtu_fix='1'
firewall.zone_vpn.auto_helper='1'
firewall.@rule[9]=rule
firewall.@rule[9].target='ACCEPT'
firewall.@rule[9].name='Allow-All-Ping'
firewall.@rule[9].proto='icmp'
firewall.@rule[9].dest='
'
firewall.@rule[9].src=''
firewall.@rule[9].icmp_type='echo-request'
firewall.@rule[9].limit='1000/sec'
firewall.@rule[10]=rule
firewall.@rule[10].target='ACCEPT'
firewall.@rule[10].name='Allow-VPN-ICMP'
firewall.@rule[10].proto='icmp'
firewall.@rule[10].src='vpn'
firewall.@rule[11]=rule
firewall.@rule[11].target='ACCEPT'
firewall.@rule[11].name='Allow-Lan-to-Wan'
firewall.@rule[11].dest='wan'
firewall.@rule[11].src='lan'
firewall.@rule[11].proto='all'
firewall.@rule[12]=rule
firewall.@rule[12].target='ACCEPT'
firewall.@rule[12].name='ICMPv6-Lan-to-OMR'
firewall.@rule[12].src='lan'
firewall.@rule[12].family='ipv6'
firewall.@rule[12].proto='icmp'
firewall.@rule[12].limit='1000/sec'
firewall.@rule[12].icmp_type='echo-reply destination-unreachable echo-request router-advertisement router-solicitation time-exceeded'
firewall.omr_server=include
firewall.omr_server.path='/etc/firewall.omr-server'
firewall.gre_tunnel=include
firewall.gre_tunnel.path='/etc/firewall.gre-tunnel'
firewall.ttl=include
firewall.ttl.path='/etc/firewall.ttl'
firewall.upnp=include
firewall.upnp.path='/etc/firewall.ttl'
firewall.upnp.type='script'
firewall.upnp.fw4_compatible='1'
firewall.fwlantovpn=forwarding
firewall.fwlantovpn.src='lan'
firewall.fwlantovpn.dest='vpn'
firewall.blockquicproxy=rule
firewall.blockquicproxy.name='Block QUIC Proxy'
firewall.blockquicproxy.proto='udp'
firewall.blockquicproxy.dest_port='443'
firewall.blockquicproxy.target='DROP'
firewall.blockquicproxy.src='lan'
firewall.blockquicall=rule
firewall.blockquicall.name='Block QUIC All'
firewall.blockquicall.proto='udp'
firewall.blockquicall.src='
'
firewall.blockquicall.dest=''
firewall.blockquicall.dest_port='443'
firewall.blockquicall.target='DROP'
firewall.allowicmpipv6=rule
firewall.allowicmpipv6.proto='icmp'
firewall.allowicmpipv6.target='ACCEPT'
firewall.allowicmpipv6.src='wan'
firewall.allowicmpipv6.name='Allow IPv6 ICMP'
firewall.allowicmpipv6.family='ipv6'
firewall.allowicmpipv6.limit='1000/sec'
firewall.allowicmpipv6.icmp_type='neighbour-advertisement neighbour-solicitation router-advertisement router-solicitation'
firewall.allowdhcpv6546=rule
firewall.allowdhcpv6546.target='ACCEPT'
firewall.allowdhcpv6546.src='wan'
firewall.allowdhcpv6546.proto='udp'
firewall.allowdhcpv6546.dest_port='547'
firewall.allowdhcpv6546.name='Allow DHCPv6 (546-to-547)'
firewall.allowdhcpv6546.family='ipv6'
firewall.allowdhcpv6546.src_port='546'
firewall.allowdhcpv6547=rule
firewall.allowdhcpv6547.target='ACCEPT'
firewall.allowdhcpv6547.src='wan'
firewall.allowdhcpv6547.proto='udp'
firewall.allowdhcpv6547.dest_port='546'
firewall.allowdhcpv6547.name='Allow DHCPv6 (547-to-546)'
firewall.allowdhcpv6547.family='ipv6'
firewall.allowdhcpv6547.src_port='547'
firewall.user=include
firewall.user.path='/etc/firewall.user'
firewall.user.enabled='1'
firewall.user.type='script'
firewall.user.fw4_compatible='1'
firewall.omr_bypass=include
firewall.omr_bypass.path='/etc/firewall.omr-bypass'
firewall.omr_bypass.reload='0'
firewall.omr_bypass.enabled='1'
firewall.omr_bypass.type='script'
firewall.omr_bypass.fw4_compatible='1'
firewall.@reDIrect[0]=redirect
firewall.@reDIrect[0].target='DNAT'
firewall.@reDIrect[0].name='HTTP80'
firewall.@reDIrect[0].src='vpn'
firewall.@reDIrect[0].src_dport='80'
firewall.@reDIrect[0].dest='lan'
firewall.@reDIrect[0].dest_ip='192.168.5.178'
firewall.@reDIrect[0].dest_port='80'
firewall.@reDIrect[0].proto='tcp'
firewall.@reDIrect[1]=redirect
firewall.@reDIrect[1].target='DNAT'
firewall.@reDIrect[1].name='KVMShare'
firewall.@reDIrect[1].src='lan'
firewall.@reDIrect[1].src_dport='35402'
firewall.@reDIrect[1].dest='lan'
firewall.@reDIrect[1].dest_ip='192.168.5.190'
firewall.@reDIrect[1].dest_port='35402'
firewall.@reDIrect[2]=redirect
firewall.@reDIrect[2].target='DNAT'
firewall.@reDIrect[2].name='SMTP'
firewall.@reDIrect[2].proto='tcp'
firewall.@reDIrect[2].src='vpn'
firewall.@reDIrect[2].src_dport='25'
firewall.@reDIrect[2].dest='lan'
firewall.@reDIrect[2].dest_ip='192.168.5.178'
firewall.@reDIrect[2].dest_port='25'
firewall.@reDIrect[3]=redirect
firewall.@reDIrect[3].target='DNAT'
firewall.@reDIrect[3].name='FTP'
firewall.@reDIrect[3].proto='tcp'
firewall.@reDIrect[3].src='vpn'
firewall.@reDIrect[3].src_dport='21'
firewall.@reDIrect[3].dest='lan'
firewall.@reDIrect[3].dest_ip='192.168.5.178'
firewall.@reDIrect[3].dest_port='21'
firewall.@reDIrect[4]=redirect
firewall.@reDIrect[4].target='DNAT'
firewall.@reDIrect[4].name='FTP-20'
firewall.@reDIrect[4].proto='udp'
firewall.@reDIrect[4].src='vpn'
firewall.@reDIrect[4].src_dport='20'
firewall.@reDIrect[4].dest='lan'
firewall.@reDIrect[4].dest_ip='192.168.5.178'
firewall.@reDIrect[4].dest_port='20'
firewall.@reDIrect[5]=redirect
firewall.@reDIrect[5].target='DNAT'
firewall.@reDIrect[5].name='HTTPS'
firewall.@reDIrect[5].proto='tcp'
firewall.@reDIrect[5].src='vpn'
firewall.@reDIrect[5].src_dport='443'
firewall.@reDIrect[5].dest='lan'
firewall.@reDIrect[5].dest_ip='192.168.5.178'
firewall.@reDIrect[5].dest_port='443'
firewall.@reDIrect[6]=redirect
firewall.@reDIrect[6].target='DNAT'
firewall.@reDIrect[6].name='Jitsi1'
firewall.@reDIrect[6].proto='tcp'
firewall.@reDIrect[6].src='vpn'
firewall.@reDIrect[6].src_dport='4433'
firewall.@reDIrect[6].dest='lan'
firewall.@reDIrect[6].dest_ip='192.168.5.182'
firewall.@reDIrect[6].dest_port='4433'
firewall.@reDIrect[7]=redirect
firewall.@reDIrect[7].target='DNAT'
firewall.@reDIrect[7].name='Jitsi2'
firewall.@reDIrect[7].proto='tcp'
firewall.@reDIrect[7].src='vpn'
firewall.@reDIrect[7].src_dport='4443'
firewall.@reDIrect[7].dest='lan'
firewall.@reDIrect[7].dest_ip='192.168.5.182'
firewall.@reDIrect[7].dest_port='4443'
firewall.@reDIrect[8]=redirect
firewall.@reDIrect[8].target='DNAT'
firewall.@reDIrect[8].name='Jitsis3'
firewall.@reDIrect[8].proto='udp'
firewall.@reDIrect[8].src='vpn'
firewall.@reDIrect[8].src_dport='10000'
firewall.@reDIrect[8].dest='lan'
firewall.@reDIrect[8].dest_ip='192.168.5.182'
firewall.@reDIrect[8].dest_port='10000'
firewall.@reDIrect[9]=redirect
firewall.@reDIrect[9].target='DNAT'
firewall.@reDIrect[9].name='Jitsi5'
firewall.@reDIrect[9].proto='tcp'
firewall.@reDIrect[9].src='vpn'
firewall.@reDIrect[9].src_dport='4445-4446'
firewall.@reDIrect[9].dest='lan'
firewall.@reDIrect[9].dest_ip='192.168.5.182'
firewall.@reDIrect[9].dest_port='4445-4446'
firewall.@reDIrect[10]=redirect
firewall.@reDIrect[10].target='DNAT'
firewall.@reDIrect[10].name='SSH-2222'
firewall.@reDIrect[10].proto='tcp'
firewall.@reDIrect[10].src='vpn'
firewall.@reDIrect[10].src_dport='2222'
firewall.@reDIrect[10].dest='lan'
firewall.@reDIrect[10].dest_ip='192.168.5.184'
firewall.@reDIrect[10].dest_port='2222'
firewall.@reDIrect[11]=redirect
firewall.@reDIrect[11].target='DNAT'
firewall.@reDIrect[11].name='OwnCloudSecure'
firewall.@reDIrect[11].proto='tcp'
firewall.@reDIrect[11].src='vpn'
firewall.@reDIrect[11].src_dport='4435'
firewall.@reDIrect[11].dest='lan'
firewall.@reDIrect[11].dest_ip='192.168.5.184'
firewall.@reDIrect[11].dest_port='4435'
firewall.@reDIrect[12]=redirect
firewall.@reDIrect[12].target='DNAT'
firewall.@reDIrect[12].name='OwnCloud1'
firewall.@reDIrect[12].proto='tcp'
firewall.@reDIrect[12].src='vpn'
firewall.@reDIrect[12].src_dport='4455'
firewall.@reDIrect[12].dest='lan'
firewall.@reDIrect[12].dest_ip='192.168.5.184'
firewall.@reDIrect[12].dest_port='4455'
firewall.@reDIrect[13]=redirect
firewall.@reDIrect[13].target='DNAT'
firewall.@reDIrect[13].name='TubeNunch'
firewall.@reDIrect[13].proto='tcp'
firewall.@reDIrect[13].src='vpn'
firewall.@reDIrect[13].src_dport='4466'
firewall.@reDIrect[13].dest='lan'
firewall.@reDIrect[13].dest_ip='192.168.5.185'
firewall.@reDIrect[13].dest_port='4466'
firewall.@reDIrect[14]=redirect
firewall.@reDIrect[14].target='DNAT'
firewall.@reDIrect[14].name='TubeNunchSSL'
firewall.@reDIrect[14].proto='tcp'
firewall.@reDIrect[14].src='vpn'
firewall.@reDIrect[14].src_dport='4436'
firewall.@reDIrect[14].dest='lan'
firewall.@reDIrect[14].dest_ip='192.168.5.185'
firewall.@reDIrect[14].dest_port='4436'
firewall.@reDIrect[15]=redirect
firewall.@reDIrect[15].target='DNAT'
firewall.@reDIrect[15].name='POP3'
firewall.@reDIrect[15].proto='tcp'
firewall.@reDIrect[15].src='vpn'
firewall.@reDIrect[15].src_dport='110'
firewall.@reDIrect[15].dest='lan'
firewall.@reDIrect[15].dest_ip='192.168.5.181'
firewall.@reDIrect[15].dest_port='110'
firewall.@reDIrect[16]=redirect
firewall.@reDIrect[16].target='DNAT'
firewall.@reDIrect[16].name='IMAP'
firewall.@reDIrect[16].proto='tcp'
firewall.@reDIrect[16].src='vpn'
firewall.@reDIrect[16].src_dport='143'
firewall.@reDIrect[16].dest='lan'
firewall.@reDIrect[16].dest_ip='192.168.5.181'
firewall.@reDIrect[16].dest_port='143'
firewall.@reDIrect[17]=redirect
firewall.@reDIrect[17].target='DNAT'
firewall.@reDIrect[17].name='TripleA587'
firewall.@reDIrect[17].proto='tcp'
firewall.@reDIrect[17].src='vpn'
firewall.@reDIrect[17].src_dport='587'
firewall.@reDIrect[17].dest='lan'
firewall.@reDIrect[17].dest_ip='192.168.5.181'
firewall.@reDIrect[17].dest_port='587'
firewall.@reDIrect[18]=redirect
firewall.@reDIrect[18].target='DNAT'
firewall.@reDIrect[18].name='TripleA993'
firewall.@reDIrect[18].proto='tcp'
firewall.@reDIrect[18].src='vpn'
firewall.@reDIrect[18].src_dport='993'
firewall.@reDIrect[18].dest='lan'
firewall.@reDIrect[18].dest_ip='192.168.5.181'
firewall.@reDIrect[18].dest_port='993'
firewall.@reDIrect[19]=redirect
firewall.@reDIrect[19].target='DNAT'
firewall.@reDIrect[19].name='TripleA995'
firewall.@reDIrect[19].proto='tcp'
firewall.@reDIrect[19].src='vpn'
firewall.@reDIrect[19].src_dport='995'
firewall.@reDIrect[19].dest='lan'
firewall.@reDIrect[19].dest_ip='192.168.5.181'
firewall.@reDIrect[19].dest_port='995'
firewall.@reDIrect[20]=redirect
firewall.@reDIrect[20].target='DNAT'
firewall.@reDIrect[20].name='FTP-2'
firewall.@reDIrect[20].proto='tcp'
firewall.@reDIrect[20].src='vpn'
firewall.@reDIrect[20].src_dport='20'
firewall.@reDIrect[20].dest='lan'
firewall.@reDIrect[20].dest_ip='192.168.5.178'
firewall.@reDIrect[20].dest_port='20'
firewall.@reDIrect[21]=redirect
firewall.@reDIrect[21].target='DNAT'
firewall.@reDIrect[21].name='PlageTA'
firewall.@reDIrect[21].proto='tcp'
firewall.@reDIrect[21].src='vpn'
firewall.@reDIrect[21].src_dport='10090-10100'
firewall.@reDIrect[21].dest='lan'
firewall.@reDIrect[21].dest_ip='192.168.5.181'
firewall.@reDIrect[21].dest_port='10090-10100'
firewall.@reDIrect[22]=redirect
firewall.@reDIrect[22].target='DNAT'
firewall.@reDIrect[22].name='TripleaTCP22'
firewall.@reDIrect[22].proto='tcp'
firewall.@reDIrect[22].src='vpn'
firewall.@reDIrect[22].src_dport='22'
firewall.@reDIrect[22].dest='lan'
firewall.@reDIrect[22].dest_ip='192.168.5.178'
firewall.@reDIrect[22].dest_port='22'
firewall.@reDIrect[23]=redirect
firewall.@reDIrect[23].target='DNAT'
firewall.@reDIrect[23].name='HTTP Secondaire'
firewall.@reDIrect[23].proto='tcp'
firewall.@reDIrect[23].src='vpn'
firewall.@reDIrect[23].src_dport='8080'
firewall.@reDIrect[23].dest='lan'
firewall.@reDIrect[23].dest_ip='192.168.5.178'
firewall.@reDIrect[23].dest_port='8080'
firewall.@reDIrect[24]=redirect
firewall.@reDIrect[24].target='DNAT'
firewall.@reDIrect[24].name='VNC Ext'
firewall.@reDIrect[24].proto='tcp'
firewall.@reDIrect[24].src='vpn'
firewall.@reDIrect[24].src_dport='63241'
firewall.@reDIrect[24].dest='lan'
firewall.@reDIrect[24].dest_ip='192.168.5.178'
firewall.@reDIrect[24].dest_port='5900'
firewall.@reDIrect[25]=redirect
firewall.@reDIrect[25].target='DNAT'
firewall.@reDIrect[25].name='SSH PeerTube'
firewall.@reDIrect[25].proto='tcp'
firewall.@reDIrect[25].src='vpn'
firewall.@reDIrect[25].src_dport='22027'
firewall.@reDIrect[25].dest='lan'
firewall.@reDIrect[25].dest_ip='192.168.5.183'
firewall.@reDIrect[25].dest_port='22'
firewall.@reDIrect[26]=redirect
firewall.@reDIrect[26].target='DNAT'
firewall.@reDIrect[26].name='NunchSSH'
firewall.@reDIrect[26].proto='tcp'
firewall.@reDIrect[26].src='vpn'
firewall.@reDIrect[26].src_dport='22028'
firewall.@reDIrect[26].dest='lan'
firewall.@reDIrect[26].dest_ip='192.168.5.185'
firewall.@reDIrect[26].dest_port='22'
firewall.@reDIrect[27]=redirect
firewall.@reDIrect[27].target='DNAT'
firewall.@reDIrect[27].name='SSH Mac Pro'
firewall.@reDIrect[27].proto='tcp'
firewall.@reDIrect[27].src='vpn'
firewall.@reDIrect[27].src_dport='22029'
firewall.@reDIrect[27].dest='lan'
firewall.@reDIrect[27].dest_ip='192.168.5.178'
firewall.@reDIrect[27].dest_port='22'
firewall.@rule[18]=rule
firewall.@rule[18].name='HTTP Secondary'
firewall.@rule[18].proto='tcp'
firewall.@rule[18].src='
'
firewall.@rule[18].src_port='8080'
firewall.@rule[18].dest='lan'
firewall.@rule[18].dest_ip='192.168.5.178'
firewall.@rule[18].dest_port='8080'
firewall.@rule[18].target='ACCEPT'
firewall.@rule[18].src_ip='0.0.0.0'
firewall.@rule[19]=rule
firewall.@rule[19].name='PeerTube'
firewall.@rule[19].proto='tcp'
firewall.@rule[19].src=''
firewall.@rule[19].src_port='9000'
firewall.@rule[19].dest='lan'
firewall.@rule[19].dest_ip='192.168.5.178'
firewall.@rule[19].dest_port='9000'
firewall.@rule[19].target='ACCEPT'
firewall.@rule[19].src_ip='0.0.0.0'
firewall.@rule[20]=rule
firewall.@rule[20].name='TripleA995'
firewall.@rule[20].src='
'
firewall.@rule[20].src_ip='0.0.0.0'
firewall.@rule[20].src_port='995'
firewall.@rule[20].dest='lan'
firewall.@rule[20].dest_port='995'
firewall.@rule[20].target='ACCEPT'
firewall.@rule[21]=rule
firewall.@rule[21].name='TripleA 587'
firewall.@rule[21].src=''
firewall.@rule[21].src_ip='0.0.0.0'
firewall.@rule[21].src_port='587'
firewall.@rule[21].dest='lan'
firewall.@rule[21].dest_ip='192.168.5.181'
firewall.@rule[21].dest_port='587'
firewall.@rule[21].target='ACCEPT'
firewall.@rule[22]=rule
firewall.@rule[22].name='IMAP 143'
firewall.@rule[22].src='
'
firewall.@rule[22].src_ip='0.0.0.0'
firewall.@rule[22].src_port='143'
firewall.@rule[22].dest='lan'
firewall.@rule[22].dest_port='143'
firewall.@rule[22].target='ACCEPT'
firewall.@rule[23]=rule
firewall.@rule[23].name='POP3 110'
firewall.@rule[23].src=''
firewall.@rule[23].src_ip='0.0.0.0'
firewall.@rule[23].src_port='110'
firewall.@rule[23].dest='lan'
firewall.@rule[23].dest_ip='192.168.5.181'
firewall.@rule[23].dest_port='110'
firewall.@rule[23].target='ACCEPT'
firewall.@rule[24]=rule
firewall.@rule[24].name='HTTPS 443'
firewall.@rule[24].proto='tcp'
firewall.@rule[24].src='
'
firewall.@rule[24].src_ip='0.0.0.0'
firewall.@rule[24].src_port='443'
firewall.@rule[24].dest='lan'
firewall.@rule[24].dest_ip='192.168.5.184'
firewall.@rule[24].dest_port='443'
firewall.@rule[24].target='ACCEPT'
firewall.@rule[25]=rule
firewall.@rule[25].name='JITSI 5'
firewall.@rule[25].src=''
firewall.@rule[25].src_ip='0.0.0.0'
firewall.@rule[25].src_port='4445'
firewall.@rule[25].dest='lan'
firewall.@rule[25].dest_ip='192.168.5.182'
firewall.@rule[25].dest_port='4445'
firewall.@rule[25].target='ACCEPT'
firewall.@rule[26]=rule
firewall.@rule[26].name='JITSI 3'
firewall.@rule[26].src='
'
firewall.@rule[26].src_ip='0.0.0.0'
firewall.@rule[26].src_port='10000'
firewall.@rule[26].dest='lan'
firewall.@rule[26].dest_ip='192.168.5.182'
firewall.@rule[26].dest_port='10000'
firewall.@rule[26].target='ACCEPT'
firewall.@rule[27]=rule
firewall.@rule[27].name='JITSI 2'
firewall.@rule[27].src=''
firewall.@rule[27].src_ip='0.0.0.0'
firewall.@rule[27].src_port='4443'
firewall.@rule[27].dest='lan'
firewall.@rule[27].dest_ip='192.168.5.182'
firewall.@rule[27].dest_port='4443'
firewall.@rule[27].target='ACCEPT'
firewall.@rule[28]=rule
firewall.@rule[28].name='JITSI 1'
firewall.@rule[28].src='
'
firewall.@rule[28].src_ip='0.0.0.0'
firewall.@rule[28].src_port='4433'
firewall.@rule[28].dest='lan'
firewall.@rule[28].dest_ip='192.168.5.182'
firewall.@rule[28].dest_port='4433'
firewall.@rule[28].target='ACCEPT'
firewall.@rule[29]=rule
firewall.@rule[29].name='HTTP 80'
firewall.@rule[29].src=''
firewall.@rule[29].src_ip='0.0.0.0'
firewall.@rule[29].src_port='80'
firewall.@rule[29].dest='lan'
firewall.@rule[29].dest_ip='192.168.5.178'
firewall.@rule[29].dest_port='80'
firewall.@rule[29].target='ACCEPT'
firewall.@rule[30]=rule
firewall.@rule[30].name='OwnCloud Secure'
firewall.@rule[30].src='
'
firewall.@rule[30].src_ip='0.0.0.0'
firewall.@rule[30].src_port='4435'
firewall.@rule[30].dest='lan'
firewall.@rule[30].dest_ip='192.168.5.184'
firewall.@rule[30].dest_port='4435'
firewall.@rule[30].target='ACCEPT'
firewall.@rule[31]=rule
firewall.@rule[31].name='OwnCloud 1'
firewall.@rule[31].src=''
firewall.@rule[31].src_ip='0.0.0.0'
firewall.@rule[31].src_port='4455'
firewall.@rule[31].dest='lan'
firewall.@rule[31].dest_ip='192.168.5.184'
firewall.@rule[31].dest_port='4455'
firewall.@rule[31].target='ACCEPT'
firewall.@rule[32]=rule
firewall.@rule[32].name='FTP'
firewall.@rule[32].src='
'
firewall.@rule[32].src_ip='0.0.0.0'
firewall.@rule[32].src_port='20'
firewall.@rule[32].dest='lan'
firewall.@rule[32].dest_ip='192.168.5.178'
firewall.@rule[32].dest_port='20'
firewall.@rule[32].target='ACCEPT'
firewall.@rule[32].proto='tcp' 'udp'
firewall.@rule[33]=rule
firewall.@rule[33].name='TubeNunch'
firewall.@rule[33].src=''
firewall.@rule[33].src_ip='0.0.0.0'
firewall.@rule[33].src_port='4466'
firewall.@rule[33].dest='lan'
firewall.@rule[33].dest_ip='192.168.5.185'
firewall.@rule[33].dest_port='4466'
firewall.@rule[33].target='ACCEPT'
firewall.@rule[34]=rule
firewall.@rule[34].name='TubeNunchSSL'
firewall.@rule[34].src='
'
firewall.@rule[34].src_ip='0.0.0.0'
firewall.@rule[34].src_port='4436'
firewall.@rule[34].dest='lan'
firewall.@rule[34].dest_ip='192.168.5.185'
firewall.@rule[34].dest_port='4436'
firewall.@rule[34].target='ACCEPT'
firewall.@rule[35]=rule
firewall.@rule[35].name='FTP 21'
firewall.@rule[35].proto='tcp'
firewall.@rule[35].src=''
firewall.@rule[35].src_ip='0.0.0.0'
firewall.@rule[35].src_port='21'
firewall.@rule[35].dest='lan'
firewall.@rule[35].dest_ip='192.168.5.178'
firewall.@rule[35].dest_port='21'
firewall.@rule[35].target='ACCEPT'
firewall.@rule[36]=rule
firewall.@rule[36].name='SMTP 25'
firewall.@rule[36].src='
'
firewall.@rule[36].src_ip='0.0.0.0'
firewall.@rule[36].src_port='25'
firewall.@rule[36].dest='lan'
firewall.@rule[36].dest_ip='192.168.5.184'
firewall.@rule[36].dest_port='25'
firewall.@rule[36].target='ACCEPT'
firewall.@rule[37]=rule
firewall.@rule[37].name='SSH 2222'
firewall.@rule[37].src=''
firewall.@rule[37].src_ip='0.0.0.0'
firewall.@rule[37].src_port='2222'
firewall.@rule[37].dest='lan'
firewall.@rule[37].dest_ip='192.168.5.184'
firewall.@rule[37].dest_port='2222'
firewall.@rule[37].target='ACCEPT'
firewall.@nat[0]=nat
firewall.@nat[0].name='HTTP 80'
firewall.@nat[0].proto='tcp'
firewall.@nat[0].src='lan'
firewall.@nat[0].dest_ip='192.168.5.178'
firewall.@nat[0].dest_port='80'
firewall.@nat[0].target='SNAT'
firewall.@nat[0].snat_ip='192.168.5.1'
firewall.@nat[0].enabled='0'
firewall.@nat[1]=nat
firewall.@nat[1].name='HTTP 443'
firewall.@nat[1].proto='tcp'
firewall.@nat[1].src='lan'
firewall.@nat[1].dest_ip='192.168.5.178'
firewall.@nat[1].dest_port='443'
firewall.@nat[1].target='SNAT'
firewall.@nat[1].snat_ip='192.168.5.1'
firewall.@nat[1].enabled='0'
firewall.@reDIrect[28]=redirect
firewall.@reDIrect[28].target='DNAT'
firewall.@reDIrect[28].name='SSH Jitsi'
firewall.@reDIrect[28].proto='tcp'
firewall.@reDIrect[28].src='vpn'
firewall.@reDIrect[28].src_dport='22026'
firewall.@reDIrect[28].dest='lan'
firewall.@reDIrect[28].dest_ip='192.168.5.182'
firewall.@reDIrect[28].dest_port='22'
firewall.@nat[2]=nat
firewall.@nat[2].name='Jitsi1'
firewall.@nat[2].proto='tcp'
firewall.@nat[2].src='lan'
firewall.@nat[2].src_port='4433'
firewall.@nat[2].dest_port='4433'
firewall.@nat[2].target='SNAT'
firewall.@nat[2].snat_ip='192.168.5.1'
firewall.@nat[2].dest_ip='192.168.5.182'
firewall.@nat[3]=nat
firewall.@nat[3].name='Jitsi2'
firewall.@nat[3].proto='tcp'
firewall.@nat[3].src='lan'
firewall.@nat[3].src_port='4443'
firewall.@nat[3].dest_ip='192.168.5.182'
firewall.@nat[3].dest_port='4443'
firewall.@nat[3].target='SNAT'
firewall.@nat[3].snat_ip='192.168.5.1'
firewall.@nat[4]=nat
firewall.@nat[4].name='Jitsi3'
firewall.@nat[4].proto='udp'
firewall.@nat[4].src='lan'
firewall.@nat[4].src_port='10000'
firewall.@nat[4].dest_ip='192.168.5.182'
firewall.@nat[4].dest_port='10000'
firewall.@nat[4].target='SNAT'
firewall.@nat[4].snat_ip='192.168.5.1'
firewall.@nat[5]=nat
firewall.@nat[5].name='Jitsi5'
firewall.@nat[5].proto='tcp'
firewall.@nat[5].src='lan'
firewall.@nat[5].src_port='4445-4446'
firewall.@nat[5].dest_ip='192.168.5.182'
firewall.@nat[5].dest_port='4445-4446'
firewall.@nat[5].target='SNAT'
firewall.@nat[5].snat_ip='192.168.5.1'
firewall.@reDIrect[29]=redirect
firewall.@reDIrect[29].target='DNAT'
firewall.@reDIrect[29].name='TRENT'
firewall.@reDIrect[29].src='vpn'
firewall.@reDIrect[29].src_dport='16881'
firewall.@reDIrect[29].dest='lan'
firewall.@reDIrect[29].dest_port='16881'
firewall.@reDIrect[29].dest_ip='192.168.5.205'
firewall.@rule[38]=rule
firewall.@rule[38].name='TRENT'
firewall.@rule[38].src='
'
firewall.@rule[38].src_ip='0.0.0.0'
firewall.@rule[38].src_port='16881'
firewall.@rule[38].dest='lan'
firewall.@rule[38].dest_ip='192.168.5.205'
firewall.@rule[38].dest_port='16881'
firewall.@rule[38].target='ACCEPT'
firewall.@nat[6]=nat
firewall.@nat[6].name='TRENT'
firewall.@nat[6].proto='tcp' 'udp'
firewall.@nat[6].src='lan'
firewall.@nat[6].src_port='16881'
firewall.@nat[6].dest_port='16881'
firewall.@nat[6].target='SNAT'
firewall.@nat[6].snat_ip='192.168.5.1'
firewall.@nat[6].dest_ip='192.168.5.202'
firewall.@reDIrect[30]=redirect
firewall.@reDIrect[30].target='DNAT'
firewall.@reDIrect[30].name='TRENT2'
firewall.@reDIrect[30].src='lan'
firewall.@reDIrect[30].src_dport='16881'
firewall.@reDIrect[30].dest='vpn'
firewall.@reDIrect[30].dest_port='16881'
firewall.@rule[39]=rule
firewall.@rule[39].name='TRENT2'
firewall.@rule[39].src='lan'
firewall.@rule[39].src_ip='192.168.5.205'
firewall.@rule[39].src_port='16881'
firewall.@rule[39].dest='vpn'
firewall.@rule[39].dest_ip='0.0.0.0'
firewall.@rule[39].dest_port='16881'
firewall.@rule[39].target='ACCEPT'
firewall.@nat[7]=nat
firewall.@nat[7].name='TRENT2'
firewall.@nat[7].src='lan'
firewall.@nat[7].target='SNAT'
firewall.@nat[7].snat_ip='192.168.5.1'
firewall.@nat[7].proto='tcp' 'udp'
firewall.@nat[7].src_port='16881'
firewall.@nat[7].dest_port='16881'
firewall.@nat[7].src_ip='192.168.5.205'
firewall.omr_dscp_cs0_4=ipset
firewall.omr_dscp_cs0_4.name='omr_dscp_cs0_4'
firewall.omr_dscp_cs0_4.match='dest_ip'
firewall.omr_dscp_cs0_6=ipset
firewall.omr_dscp_cs0_6.name='omr_dscp_cs0_6'
firewall.omr_dscp_cs0_6.match='dest_ip'
firewall.omr_dscp_rule_cs0_4=rule
firewall.omr_dscp_rule_cs0_4.name='omr_dscp_cs0_4'
firewall.omr_dscp_rule_cs0_4.ipset='omr_dscp_cs0_4'
firewall.omr_dscp_rule_cs0_4.set_dscp='CS0'
firewall.omr_dscp_rule_cs0_4.target='DSCP'
firewall.omr_dscp_rule_cs0_4.enabled='1'
firewall.omr_dscp_rule_cs0_4.src=''
firewall.omr_dscp_rule_cs0_4.dest='
'
firewall.omr_dscp_rule_cs0_6=rule
firewall.omr_dscp_rule_cs0_6.name='omr6_dscp_cs0_6'
firewall.omr_dscp_rule_cs0_6.ipset='omr_dscp_cs0_6'
firewall.omr_dscp_rule_cs0_6.target='DSCP'
firewall.omr_dscp_rule_cs0_6.set_dscp='CS0'
firewall.omr_dscp_rule_cs0_6.enabled='1'
firewall.omr_dscp_rule_cs0_6.src=''
firewall.omr_dscp_rule_cs0_6.dest='
'
firewall.omr_dscp_cs1_4=ipset
firewall.omr_dscp_cs1_4.name='omr_dscp_cs1_4'
firewall.omr_dscp_cs1_4.match='dest_ip'
firewall.omr_dscp_cs1_6=ipset
firewall.omr_dscp_cs1_6.name='omr_dscp_cs1_6'
firewall.omr_dscp_cs1_6.match='dest_ip'
firewall.omr_dscp_rule_cs1_4=rule
firewall.omr_dscp_rule_cs1_4.name='omr_dscp_cs1_4'
firewall.omr_dscp_rule_cs1_4.ipset='omr_dscp_cs1_4'
firewall.omr_dscp_rule_cs1_4.set_dscp='CS1'
firewall.omr_dscp_rule_cs1_4.target='DSCP'
firewall.omr_dscp_rule_cs1_4.enabled='1'
firewall.omr_dscp_rule_cs1_4.src=''
firewall.omr_dscp_rule_cs1_4.dest='
'
firewall.omr_dscp_rule_cs1_6=rule
firewall.omr_dscp_rule_cs1_6.name='omr6_dscp_cs1_6'
firewall.omr_dscp_rule_cs1_6.ipset='omr_dscp_cs1_6'
firewall.omr_dscp_rule_cs1_6.target='DSCP'
firewall.omr_dscp_rule_cs1_6.set_dscp='CS1'
firewall.omr_dscp_rule_cs1_6.enabled='1'
firewall.omr_dscp_rule_cs1_6.src=''
firewall.omr_dscp_rule_cs1_6.dest='
'
firewall.omr_dscp_cs2_4=ipset
firewall.omr_dscp_cs2_4.name='omr_dscp_cs2_4'
firewall.omr_dscp_cs2_4.match='dest_ip'
firewall.omr_dscp_cs2_6=ipset
firewall.omr_dscp_cs2_6.name='omr_dscp_cs2_6'
firewall.omr_dscp_cs2_6.match='dest_ip'
firewall.omr_dscp_rule_cs2_4=rule
firewall.omr_dscp_rule_cs2_4.name='omr_dscp_cs2_4'
firewall.omr_dscp_rule_cs2_4.ipset='omr_dscp_cs2_4'
firewall.omr_dscp_rule_cs2_4.set_dscp='CS2'
firewall.omr_dscp_rule_cs2_4.target='DSCP'
firewall.omr_dscp_rule_cs2_4.enabled='1'
firewall.omr_dscp_rule_cs2_4.src=''
firewall.omr_dscp_rule_cs2_4.dest='
'
firewall.omr_dscp_rule_cs2_6=rule
firewall.omr_dscp_rule_cs2_6.name='omr6_dscp_cs2_6'
firewall.omr_dscp_rule_cs2_6.ipset='omr_dscp_cs2_6'
firewall.omr_dscp_rule_cs2_6.target='DSCP'
firewall.omr_dscp_rule_cs2_6.set_dscp='CS2'
firewall.omr_dscp_rule_cs2_6.enabled='1'
firewall.omr_dscp_rule_cs2_6.src=''
firewall.omr_dscp_rule_cs2_6.dest='
'
firewall.omr_dscp_cs3_4=ipset
firewall.omr_dscp_cs3_4.name='omr_dscp_cs3_4'
firewall.omr_dscp_cs3_4.match='dest_ip'
firewall.omr_dscp_cs3_6=ipset
firewall.omr_dscp_cs3_6.name='omr_dscp_cs3_6'
firewall.omr_dscp_cs3_6.match='dest_ip'
firewall.omr_dscp_rule_cs3_4=rule
firewall.omr_dscp_rule_cs3_4.name='omr_dscp_cs3_4'
firewall.omr_dscp_rule_cs3_4.ipset='omr_dscp_cs3_4'
firewall.omr_dscp_rule_cs3_4.set_dscp='CS3'
firewall.omr_dscp_rule_cs3_4.target='DSCP'
firewall.omr_dscp_rule_cs3_4.enabled='1'
firewall.omr_dscp_rule_cs3_4.src=''
firewall.omr_dscp_rule_cs3_4.dest='
'
firewall.omr_dscp_rule_cs3_6=rule
firewall.omr_dscp_rule_cs3_6.name='omr6_dscp_cs3_6'
firewall.omr_dscp_rule_cs3_6.ipset='omr_dscp_cs3_6'
firewall.omr_dscp_rule_cs3_6.target='DSCP'
firewall.omr_dscp_rule_cs3_6.set_dscp='CS3'
firewall.omr_dscp_rule_cs3_6.enabled='1'
firewall.omr_dscp_rule_cs3_6.src=''
firewall.omr_dscp_rule_cs3_6.dest='
'
firewall.omr_dscp_cs4_4=ipset
firewall.omr_dscp_cs4_4.name='omr_dscp_cs4_4'
firewall.omr_dscp_cs4_4.match='dest_ip'
firewall.omr_dscp_cs4_6=ipset
firewall.omr_dscp_cs4_6.name='omr_dscp_cs4_6'
firewall.omr_dscp_cs4_6.match='dest_ip'
firewall.omr_dscp_rule_cs4_4=rule
firewall.omr_dscp_rule_cs4_4.name='omr_dscp_cs4_4'
firewall.omr_dscp_rule_cs4_4.ipset='omr_dscp_cs4_4'
firewall.omr_dscp_rule_cs4_4.set_dscp='CS4'
firewall.omr_dscp_rule_cs4_4.target='DSCP'
firewall.omr_dscp_rule_cs4_4.enabled='1'
firewall.omr_dscp_rule_cs4_4.src=''
firewall.omr_dscp_rule_cs4_4.dest='
'
firewall.omr_dscp_rule_cs4_6=rule
firewall.omr_dscp_rule_cs4_6.name='omr6_dscp_cs4_6'
firewall.omr_dscp_rule_cs4_6.ipset='omr_dscp_cs4_6'
firewall.omr_dscp_rule_cs4_6.target='DSCP'
firewall.omr_dscp_rule_cs4_6.set_dscp='CS4'
firewall.omr_dscp_rule_cs4_6.enabled='1'
firewall.omr_dscp_rule_cs4_6.src=''
firewall.omr_dscp_rule_cs4_6.dest='
'
firewall.omr_dscp_cs5_4=ipset
firewall.omr_dscp_cs5_4.name='omr_dscp_cs5_4'
firewall.omr_dscp_cs5_4.match='dest_ip'
firewall.omr_dscp_cs5_6=ipset
firewall.omr_dscp_cs5_6.name='omr_dscp_cs5_6'
firewall.omr_dscp_cs5_6.match='dest_ip'
firewall.omr_dscp_rule_cs5_4=rule
firewall.omr_dscp_rule_cs5_4.name='omr_dscp_cs5_4'
firewall.omr_dscp_rule_cs5_4.ipset='omr_dscp_cs5_4'
firewall.omr_dscp_rule_cs5_4.set_dscp='CS5'
firewall.omr_dscp_rule_cs5_4.target='DSCP'
firewall.omr_dscp_rule_cs5_4.enabled='1'
firewall.omr_dscp_rule_cs5_4.src=''
firewall.omr_dscp_rule_cs5_4.dest='
'
firewall.omr_dscp_rule_cs5_6=rule
firewall.omr_dscp_rule_cs5_6.name='omr6_dscp_cs5_6'
firewall.omr_dscp_rule_cs5_6.ipset='omr_dscp_cs5_6'
firewall.omr_dscp_rule_cs5_6.target='DSCP'
firewall.omr_dscp_rule_cs5_6.set_dscp='CS5'
firewall.omr_dscp_rule_cs5_6.enabled='1'
firewall.omr_dscp_rule_cs5_6.src=''
firewall.omr_dscp_rule_cs5_6.dest='
'
firewall.omr_dscp_cs6_4=ipset
firewall.omr_dscp_cs6_4.name='omr_dscp_cs6_4'
firewall.omr_dscp_cs6_4.match='dest_ip'
firewall.omr_dscp_cs6_6=ipset
firewall.omr_dscp_cs6_6.name='omr_dscp_cs6_6'
firewall.omr_dscp_cs6_6.match='dest_ip'
firewall.omr_dscp_rule_cs6_4=rule
firewall.omr_dscp_rule_cs6_4.name='omr_dscp_cs6_4'
firewall.omr_dscp_rule_cs6_4.ipset='omr_dscp_cs6_4'
firewall.omr_dscp_rule_cs6_4.set_dscp='CS6'
firewall.omr_dscp_rule_cs6_4.target='DSCP'
firewall.omr_dscp_rule_cs6_4.enabled='1'
firewall.omr_dscp_rule_cs6_4.src=''
firewall.omr_dscp_rule_cs6_4.dest='
'
firewall.omr_dscp_rule_cs6_6=rule
firewall.omr_dscp_rule_cs6_6.name='omr6_dscp_cs6_6'
firewall.omr_dscp_rule_cs6_6.ipset='omr_dscp_cs6_6'
firewall.omr_dscp_rule_cs6_6.target='DSCP'
firewall.omr_dscp_rule_cs6_6.set_dscp='CS6'
firewall.omr_dscp_rule_cs6_6.enabled='1'
firewall.omr_dscp_rule_cs6_6.src=''
firewall.omr_dscp_rule_cs6_6.dest='
'
firewall.omr_dscp_cs7_4=ipset
firewall.omr_dscp_cs7_4.name='omr_dscp_cs7_4'
firewall.omr_dscp_cs7_4.match='dest_ip'
firewall.omr_dscp_cs7_6=ipset
firewall.omr_dscp_cs7_6.name='omr_dscp_cs7_6'
firewall.omr_dscp_cs7_6.match='dest_ip'
firewall.omr_dscp_rule_cs7_4=rule
firewall.omr_dscp_rule_cs7_4.name='omr_dscp_cs7_4'
firewall.omr_dscp_rule_cs7_4.ipset='omr_dscp_cs7_4'
firewall.omr_dscp_rule_cs7_4.set_dscp='CS7'
firewall.omr_dscp_rule_cs7_4.target='DSCP'
firewall.omr_dscp_rule_cs7_4.enabled='1'
firewall.omr_dscp_rule_cs7_4.src=''
firewall.omr_dscp_rule_cs7_4.dest='
'
firewall.omr_dscp_rule_cs7_6=rule
firewall.omr_dscp_rule_cs7_6.name='omr6_dscp_cs7_6'
firewall.omr_dscp_rule_cs7_6.ipset='omr_dscp_cs7_6'
firewall.omr_dscp_rule_cs7_6.target='DSCP'
firewall.omr_dscp_rule_cs7_6.set_dscp='CS7'
firewall.omr_dscp_rule_cs7_6.enabled='1'
firewall.omr_dscp_rule_cs7_6.src=''
firewall.omr_dscp_rule_cs7_6.dest='
'
firewall.omr_dscp_ef_4=ipset
firewall.omr_dscp_ef_4.name='omr_dscp_ef_4'
firewall.omr_dscp_ef_4.match='dest_ip'
firewall.omr_dscp_ef_6=ipset
firewall.omr_dscp_ef_6.name='omr_dscp_ef_6'
firewall.omr_dscp_ef_6.match='dest_ip'
firewall.omr_dscp_rule_ef_4=rule
firewall.omr_dscp_rule_ef_4.name='omr_dscp_ef_4'
firewall.omr_dscp_rule_ef_4.ipset='omr_dscp_ef_4'
firewall.omr_dscp_rule_ef_4.set_dscp='EF'
firewall.omr_dscp_rule_ef_4.target='DSCP'
firewall.omr_dscp_rule_ef_4.enabled='1'
firewall.omr_dscp_rule_ef_4.src=''
firewall.omr_dscp_rule_ef_4.dest='
'
firewall.omr_dscp_rule_ef_6=rule
firewall.omr_dscp_rule_ef_6.name='omr6_dscp_ef_6'
firewall.omr_dscp_rule_ef_6.ipset='omr_dscp_ef_6'
firewall.omr_dscp_rule_ef_6.target='DSCP'
firewall.omr_dscp_rule_ef_6.set_dscp='EF'
firewall.omr_dscp_rule_ef_6.enabled='1'
firewall.omr_dscp_rule_ef_6.src=''
firewall.omr_dscp_rule_ef_6.dest='
'
firewall.omr_dscp_rule1=rule
firewall.omr_dscp_rule1.name='omr_dscp_rule1'
firewall.omr_dscp_rule1.target='DSCP'
firewall.omr_dscp_rule1.set_dscp='CS7'
firewall.omr_dscp_rule1.src=''
firewall.omr_dscp_rule1.dest='
'
firewall.omr_dscp_rule1.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule1.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule1.proto='icmp'
firewall.omr_dscp_rule1.enabled='1'
firewall.omr_dscp_rule1.src_port='0-65535'
firewall.omr_dscp_rule1.dest_port='0-65535'
firewall.omr_dscp_rule2=rule
firewall.omr_dscp_rule2.name='omr_dscp_rule2'
firewall.omr_dscp_rule2.target='DSCP'
firewall.omr_dscp_rule2.set_dscp='CS4'
firewall.omr_dscp_rule2.src=''
firewall.omr_dscp_rule2.dest='
'
firewall.omr_dscp_rule2.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule2.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule2.proto='udp'
firewall.omr_dscp_rule2.enabled='1'
firewall.omr_dscp_rule2.src_port='53' '123' '5353'
firewall.omr_dscp_rule2.dest_port='0-65535'
firewall.omr_dscp_rule3=rule
firewall.omr_dscp_rule3.name='omr_dscp_rule3'
firewall.omr_dscp_rule3.target='DSCP'
firewall.omr_dscp_rule3.set_dscp='CS4'
firewall.omr_dscp_rule3.src=''
firewall.omr_dscp_rule3.dest='
'
firewall.omr_dscp_rule3.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule3.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule3.proto='tcp'
firewall.omr_dscp_rule3.enabled='1'
firewall.omr_dscp_rule3.src_port='53' '5353'
firewall.omr_dscp_rule3.dest_port='0-65535'
firewall.omr_dscp_rule4=rule
firewall.omr_dscp_rule4.name='omr_dscp_rule4'
firewall.omr_dscp_rule4.target='DSCP'
firewall.omr_dscp_rule4.set_dscp='CS4'
firewall.omr_dscp_rule4.src=''
firewall.omr_dscp_rule4.dest='
'
firewall.omr_dscp_rule4.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule4.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule4.proto='tcp'
firewall.omr_dscp_rule4.enabled='1'
firewall.omr_dscp_rule4.src_port='0-65535'
firewall.omr_dscp_rule4.dest_port='65500'
firewall.omr_dscp_rule5=rule
firewall.omr_dscp_rule5.name='omr_dscp_rule5'
firewall.omr_dscp_rule5.target='DSCP'
firewall.omr_dscp_rule5.set_dscp='CS7'
firewall.omr_dscp_rule5.src=''
firewall.omr_dscp_rule5.dest='
'
firewall.omr_dscp_rule5.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule5.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule5.proto='tcp'
firewall.omr_dscp_rule5.enabled='1'
firewall.omr_dscp_rule5.src_port='0-65535'
firewall.omr_dscp_rule5.dest_port='65001' '65301' '65401' '65011'
firewall.omr_dscp_rule6=rule
firewall.omr_dscp_rule6.name='omr_dscp_rule6'
firewall.omr_dscp_rule6.target='DSCP'
firewall.omr_dscp_rule6.set_dscp='CS7'
firewall.omr_dscp_rule6.src=''
firewall.omr_dscp_rule6.dest='
'
firewall.omr_dscp_rule6.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule6.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule6.proto='udp'
firewall.omr_dscp_rule6.enabled='1'
firewall.omr_dscp_rule6.src_port='0-65535'
firewall.omr_dscp_rule6.dest_port='65001' '65301'
firewall.omr_dscp_rule7=rule
firewall.omr_dscp_rule7.name='omr_dscp_rule7'
firewall.omr_dscp_rule7.target='DSCP'
firewall.omr_dscp_rule7.set_dscp='CS6'
firewall.omr_dscp_rule7.src=''
firewall.omr_dscp_rule7.dest='
'
firewall.omr_dscp_rule7.src_ip='0.0.0.0/0'
firewall.omr_dscp_rule7.dest_ip='0.0.0.0/0'
firewall.omr_dscp_rule7.proto='tcp'
firewall.omr_dscp_rule7.enabled='1'
firewall.omr_dscp_rule7.src_port='0-65535'
firewall.omr_dscp_rule7.dest_port='65101' '65228'
firewall.omr_dst_bypass_eth0_4=ipset
firewall.omr_dst_bypass_eth0_4.name='omr_dst_bypass_eth0_4'
firewall.omr_dst_bypass_eth0_4.match='dest_ip'
firewall.omr_dst_bypass_eth0_4.family='ipv4'
firewall.omr_dst_bypass_eth0_4.enabled='1'
firewall.omr_dst_bypass_eth0_6=ipset
firewall.omr_dst_bypass_eth0_6.name='omr_dst_bypass_eth0_6'
firewall.omr_dst_bypass_eth0_6.match='dest_ip'
firewall.omr_dst_bypass_eth0_6.family='ipv6'
firewall.omr_dst_bypass_eth0_6.enabled='1'
firewall.omr_dst_bypass_eth0_dstip_4=rule
firewall.omr_dst_bypass_eth0_dstip_4.name='omr_dst_bypass_eth0_rule'
firewall.omr_dst_bypass_eth0_dstip_4.ipset='omr_dst_bypass_eth0_4'
firewall.omr_dst_bypass_eth0_dstip_4.target='MARK'
firewall.omr_dst_bypass_eth0_dstip_4.src='lan'
firewall.omr_dst_bypass_eth0_dstip_4.dest=''
firewall.omr_dst_bypass_eth0_dstip_4.family='ipv4'
firewall.omr_dst_bypass_eth0_dstip_4.enabled='0'
firewall.omr_dst_bypass_eth0_dstip_4.proto='all'
firewall.omr_dst_bypass_eth0_dstip_4.set_mark='0x45399999'
firewall.omr_dst_bypass_eth0_dstip_4_accept=rule
firewall.omr_dst_bypass_eth0_dstip_4_accept.name='omr_dst_bypass_eth0_rule_accept'
firewall.omr_dst_bypass_eth0_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth0_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_eth0_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_eth0_dstip_4_accept.enabled='0'
firewall.omr_dst_bypass_eth0_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_eth0_dstip_4_accept.mark='0x45399999'
firewall.omr_dst_bypass_eth0_srcip_4=rule
firewall.omr_dst_bypass_eth0_srcip_4.name='omr_dst_bypass_eth0_srcip'
firewall.omr_dst_bypass_eth0_srcip_4.src='lan'
firewall.omr_dst_bypass_eth0_srcip_4.dest=''
firewall.omr_dst_bypass_eth0_srcip_4.family='ipv4'
firewall.omr_dst_bypass_eth0_srcip_4.target='MARK'
firewall.omr_dst_bypass_eth0_srcip_4.enabled='0'
firewall.omr_dst_bypass_eth0_srcip_4.proto='all'
firewall.omr_dst_bypass_eth0_srcip_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_mac_4=rule
firewall.omr_dst_bypass_eth0_mac_4.name='omr_dst_bypass_eth0_mac'
firewall.omr_dst_bypass_eth0_mac_4.src='lan'
firewall.omr_dst_bypass_eth0_mac_4.dest='
'
firewall.omr_dst_bypass_eth0_mac_4.target='MARK'
firewall.omr_dst_bypass_eth0_mac_4.enabled='0'
firewall.omr_dst_bypass_eth0_mac_4.proto='all'
firewall.omr_dst_bypass_eth0_mac_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_srcport_tcp_4=rule
firewall.omr_dst_bypass_eth0_srcport_tcp_4.name='omr_dst_bypass_eth0_srcport_tcp'
firewall.omr_dst_bypass_eth0_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth0_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth0_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_eth0_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth0_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth0_srcport_tcp_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_srcport_udp_4=rule
firewall.omr_dst_bypass_eth0_srcport_udp_4.name='omr_dst_bypass_eth0_srcport_udp'
firewall.omr_dst_bypass_eth0_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth0_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_eth0_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_eth0_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth0_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth0_srcport_udp_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_dstport_tcp_4=rule
firewall.omr_dst_bypass_eth0_dstport_tcp_4.name='omr_dst_bypass_eth0_dstport_tcp'
firewall.omr_dst_bypass_eth0_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth0_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_eth0_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth0_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth0_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth0_dstport_tcp_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_dstport_udp_4=rule
firewall.omr_dst_bypass_eth0_dstport_udp_4.name='omr_dst_bypass_eth0_dstport_udp'
firewall.omr_dst_bypass_eth0_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_eth0_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_eth0_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth0_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth0_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth0_dstport_udp_4.set_xmark='0x45399999'
firewall.omr_dst_bypass_eth0_dstip_6=rule
firewall.omr_dst_bypass_eth0_dstip_6.name='omr_dst_bypass_eth0_rule'
firewall.omr_dst_bypass_eth0_dstip_6.ipset='omr_dst_bypass_eth0_6'
firewall.omr_dst_bypass_eth0_dstip_6.target='MARK'
firewall.omr_dst_bypass_eth0_dstip_6.src='lan'
firewall.omr_dst_bypass_eth0_dstip_6.dest=''
firewall.omr_dst_bypass_eth0_dstip_6.family='ipv6'
firewall.omr_dst_bypass_eth0_dstip_6.enabled='0'
firewall.omr_dst_bypass_eth0_dstip_6.proto='all'
firewall.omr_dst_bypass_eth0_dstip_6.set_mark='0x65399999'
firewall.omr_dst_bypass_eth0_dstip_6_accept=rule
firewall.omr_dst_bypass_eth0_dstip_6_accept.name='omr_dst_bypass_eth0_rule_accept'
firewall.omr_dst_bypass_eth0_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth0_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_eth0_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_eth0_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_eth0_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_eth0_dstip_6_accept.mark='0x65399999'
firewall.omr_dst_bypass_eth0_srcip_6=rule
firewall.omr_dst_bypass_eth0_srcip_6.name='omr_dst_bypass_eth0_srcip'
firewall.omr_dst_bypass_eth0_srcip_6.src='lan'
firewall.omr_dst_bypass_eth0_srcip_6.dest=''
firewall.omr_dst_bypass_eth0_srcip_6.family='ipv6'
firewall.omr_dst_bypass_eth0_srcip_6.target='MARK'
firewall.omr_dst_bypass_eth0_srcip_6.enabled='0'
firewall.omr_dst_bypass_eth0_srcip_6.proto='all'
firewall.omr_dst_bypass_eth0_srcip_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth0_mac_6=rule
firewall.omr_dst_bypass_eth0_mac_6.name='omr_dst_bypass_eth0_mac'
firewall.omr_dst_bypass_eth0_mac_6.src='lan'
firewall.omr_dst_bypass_eth0_mac_6.dest='
'
firewall.omr_dst_bypass_eth0_mac_6.target='MARK'
firewall.omr_dst_bypass_eth0_mac_6.enabled='0'
firewall.omr_dst_bypass_eth0_mac_6.proto='all'
firewall.omr_dst_bypass_eth0_mac_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth0_srcport_tcp_6=rule
firewall.omr_dst_bypass_eth0_srcport_tcp_6.name='omr_dst_bypass_eth0_srcport_tcp'
firewall.omr_dst_bypass_eth0_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth0_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth0_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_eth0_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth0_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth0_srcport_tcp_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth0_srcport_udp_6=rule
firewall.omr_dst_bypass_eth0_srcport_udp_6.name='omr_dst_bypass_eth0_srcport_udp'
firewall.omr_dst_bypass_eth0_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth0_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_eth0_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_eth0_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth0_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth0_srcport_udp_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth0_dstport_tcp_6=rule
firewall.omr_dst_bypass_eth0_dstport_tcp_6.name='omr_dst_bypass_eth0_dstport_tcp'
firewall.omr_dst_bypass_eth0_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth0_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_eth0_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth0_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth0_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth0_dstport_tcp_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth0_dstport_udp_6=rule
firewall.omr_dst_bypass_eth0_dstport_udp_6.name='omr_dst_bypass_eth0_dstport_udp'
firewall.omr_dst_bypass_eth0_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_eth0_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_eth0_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth0_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth0_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth0_dstport_udp_6.set_xmark='0x65399999'
firewall.omr_dst_bypass_eth1_4=ipset
firewall.omr_dst_bypass_eth1_4.name='omr_dst_bypass_eth1_4'
firewall.omr_dst_bypass_eth1_4.match='dest_ip'
firewall.omr_dst_bypass_eth1_4.family='ipv4'
firewall.omr_dst_bypass_eth1_4.enabled='1'
firewall.omr_dst_bypass_eth1_6=ipset
firewall.omr_dst_bypass_eth1_6.name='omr_dst_bypass_eth1_6'
firewall.omr_dst_bypass_eth1_6.match='dest_ip'
firewall.omr_dst_bypass_eth1_6.family='ipv6'
firewall.omr_dst_bypass_eth1_6.enabled='1'
firewall.omr_dst_bypass_eth1_dstip_4=rule
firewall.omr_dst_bypass_eth1_dstip_4.name='omr_dst_bypass_eth1_rule'
firewall.omr_dst_bypass_eth1_dstip_4.ipset='omr_dst_bypass_eth1_4'
firewall.omr_dst_bypass_eth1_dstip_4.target='MARK'
firewall.omr_dst_bypass_eth1_dstip_4.src='lan'
firewall.omr_dst_bypass_eth1_dstip_4.dest=''
firewall.omr_dst_bypass_eth1_dstip_4.family='ipv4'
firewall.omr_dst_bypass_eth1_dstip_4.enabled='0'
firewall.omr_dst_bypass_eth1_dstip_4.proto='all'
firewall.omr_dst_bypass_eth1_dstip_4.set_mark='0x45396'
firewall.omr_dst_bypass_eth1_dstip_4_accept=rule
firewall.omr_dst_bypass_eth1_dstip_4_accept.name='omr_dst_bypass_eth1_rule_accept'
firewall.omr_dst_bypass_eth1_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth1_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_eth1_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_eth1_dstip_4_accept.enabled='0'
firewall.omr_dst_bypass_eth1_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_eth1_dstip_4_accept.mark='0x45396'
firewall.omr_dst_bypass_eth1_srcip_4=rule
firewall.omr_dst_bypass_eth1_srcip_4.name='omr_dst_bypass_eth1_srcip'
firewall.omr_dst_bypass_eth1_srcip_4.src='lan'
firewall.omr_dst_bypass_eth1_srcip_4.dest=''
firewall.omr_dst_bypass_eth1_srcip_4.family='ipv4'
firewall.omr_dst_bypass_eth1_srcip_4.target='MARK'
firewall.omr_dst_bypass_eth1_srcip_4.enabled='0'
firewall.omr_dst_bypass_eth1_srcip_4.proto='all'
firewall.omr_dst_bypass_eth1_srcip_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_mac_4=rule
firewall.omr_dst_bypass_eth1_mac_4.name='omr_dst_bypass_eth1_mac'
firewall.omr_dst_bypass_eth1_mac_4.src='lan'
firewall.omr_dst_bypass_eth1_mac_4.dest='
'
firewall.omr_dst_bypass_eth1_mac_4.target='MARK'
firewall.omr_dst_bypass_eth1_mac_4.enabled='0'
firewall.omr_dst_bypass_eth1_mac_4.proto='all'
firewall.omr_dst_bypass_eth1_mac_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_srcport_tcp_4=rule
firewall.omr_dst_bypass_eth1_srcport_tcp_4.name='omr_dst_bypass_eth1_srcport_tcp'
firewall.omr_dst_bypass_eth1_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth1_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth1_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_eth1_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth1_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth1_srcport_tcp_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_srcport_udp_4=rule
firewall.omr_dst_bypass_eth1_srcport_udp_4.name='omr_dst_bypass_eth1_srcport_udp'
firewall.omr_dst_bypass_eth1_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth1_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_eth1_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_eth1_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth1_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth1_srcport_udp_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_dstport_tcp_4=rule
firewall.omr_dst_bypass_eth1_dstport_tcp_4.name='omr_dst_bypass_eth1_dstport_tcp'
firewall.omr_dst_bypass_eth1_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth1_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_eth1_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth1_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth1_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth1_dstport_tcp_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_dstport_udp_4=rule
firewall.omr_dst_bypass_eth1_dstport_udp_4.name='omr_dst_bypass_eth1_dstport_udp'
firewall.omr_dst_bypass_eth1_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_eth1_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_eth1_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth1_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth1_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth1_dstport_udp_4.set_xmark='0x45396'
firewall.omr_dst_bypass_eth1_dstip_6=rule
firewall.omr_dst_bypass_eth1_dstip_6.name='omr_dst_bypass_eth1_rule'
firewall.omr_dst_bypass_eth1_dstip_6.ipset='omr_dst_bypass_eth1_6'
firewall.omr_dst_bypass_eth1_dstip_6.target='MARK'
firewall.omr_dst_bypass_eth1_dstip_6.src='lan'
firewall.omr_dst_bypass_eth1_dstip_6.dest=''
firewall.omr_dst_bypass_eth1_dstip_6.family='ipv6'
firewall.omr_dst_bypass_eth1_dstip_6.enabled='0'
firewall.omr_dst_bypass_eth1_dstip_6.proto='all'
firewall.omr_dst_bypass_eth1_dstip_6.set_mark='0x65396'
firewall.omr_dst_bypass_eth1_dstip_6_accept=rule
firewall.omr_dst_bypass_eth1_dstip_6_accept.name='omr_dst_bypass_eth1_rule_accept'
firewall.omr_dst_bypass_eth1_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth1_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_eth1_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_eth1_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_eth1_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_eth1_dstip_6_accept.mark='0x65396'
firewall.omr_dst_bypass_eth1_srcip_6=rule
firewall.omr_dst_bypass_eth1_srcip_6.name='omr_dst_bypass_eth1_srcip'
firewall.omr_dst_bypass_eth1_srcip_6.src='lan'
firewall.omr_dst_bypass_eth1_srcip_6.dest=''
firewall.omr_dst_bypass_eth1_srcip_6.family='ipv6'
firewall.omr_dst_bypass_eth1_srcip_6.target='MARK'
firewall.omr_dst_bypass_eth1_srcip_6.enabled='0'
firewall.omr_dst_bypass_eth1_srcip_6.proto='all'
firewall.omr_dst_bypass_eth1_srcip_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth1_mac_6=rule
firewall.omr_dst_bypass_eth1_mac_6.name='omr_dst_bypass_eth1_mac'
firewall.omr_dst_bypass_eth1_mac_6.src='lan'
firewall.omr_dst_bypass_eth1_mac_6.dest='
'
firewall.omr_dst_bypass_eth1_mac_6.target='MARK'
firewall.omr_dst_bypass_eth1_mac_6.enabled='0'
firewall.omr_dst_bypass_eth1_mac_6.proto='all'
firewall.omr_dst_bypass_eth1_mac_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth1_srcport_tcp_6=rule
firewall.omr_dst_bypass_eth1_srcport_tcp_6.name='omr_dst_bypass_eth1_srcport_tcp'
firewall.omr_dst_bypass_eth1_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth1_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth1_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_eth1_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth1_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth1_srcport_tcp_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth1_srcport_udp_6=rule
firewall.omr_dst_bypass_eth1_srcport_udp_6.name='omr_dst_bypass_eth1_srcport_udp'
firewall.omr_dst_bypass_eth1_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth1_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_eth1_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_eth1_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth1_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth1_srcport_udp_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth1_dstport_tcp_6=rule
firewall.omr_dst_bypass_eth1_dstport_tcp_6.name='omr_dst_bypass_eth1_dstport_tcp'
firewall.omr_dst_bypass_eth1_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth1_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_eth1_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth1_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth1_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth1_dstport_tcp_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth1_dstport_udp_6=rule
firewall.omr_dst_bypass_eth1_dstport_udp_6.name='omr_dst_bypass_eth1_dstport_udp'
firewall.omr_dst_bypass_eth1_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_eth1_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_eth1_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth1_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth1_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth1_dstport_udp_6.set_xmark='0x65396'
firewall.omr_dst_bypass_eth2_4=ipset
firewall.omr_dst_bypass_eth2_4.name='omr_dst_bypass_eth2_4'
firewall.omr_dst_bypass_eth2_4.match='dest_ip'
firewall.omr_dst_bypass_eth2_4.family='ipv4'
firewall.omr_dst_bypass_eth2_4.enabled='1'
firewall.omr_dst_bypass_eth2_4.entry='45.13.104.49'
firewall.omr_dst_bypass_eth2_6=ipset
firewall.omr_dst_bypass_eth2_6.name='omr_dst_bypass_eth2_6'
firewall.omr_dst_bypass_eth2_6.match='dest_ip'
firewall.omr_dst_bypass_eth2_6.family='ipv6'
firewall.omr_dst_bypass_eth2_6.enabled='1'
firewall.omr_dst_bypass_eth2_dstip_4=rule
firewall.omr_dst_bypass_eth2_dstip_4.name='omr_dst_bypass_eth2_rule'
firewall.omr_dst_bypass_eth2_dstip_4.ipset='omr_dst_bypass_eth2_4'
firewall.omr_dst_bypass_eth2_dstip_4.target='MARK'
firewall.omr_dst_bypass_eth2_dstip_4.src='lan'
firewall.omr_dst_bypass_eth2_dstip_4.dest=''
firewall.omr_dst_bypass_eth2_dstip_4.family='ipv4'
firewall.omr_dst_bypass_eth2_dstip_4.enabled='1'
firewall.omr_dst_bypass_eth2_dstip_4.proto='all'
firewall.omr_dst_bypass_eth2_dstip_4.set_mark='0x45397'
firewall.omr_dst_bypass_eth2_dstip_4_accept=rule
firewall.omr_dst_bypass_eth2_dstip_4_accept.name='omr_dst_bypass_eth2_rule_accept'
firewall.omr_dst_bypass_eth2_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth2_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_eth2_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_eth2_dstip_4_accept.enabled='1'
firewall.omr_dst_bypass_eth2_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_eth2_dstip_4_accept.mark='0x45397'
firewall.omr_dst_bypass_eth2_srcip_4=rule
firewall.omr_dst_bypass_eth2_srcip_4.name='omr_dst_bypass_eth2_srcip'
firewall.omr_dst_bypass_eth2_srcip_4.src='lan'
firewall.omr_dst_bypass_eth2_srcip_4.dest=''
firewall.omr_dst_bypass_eth2_srcip_4.family='ipv4'
firewall.omr_dst_bypass_eth2_srcip_4.target='MARK'
firewall.omr_dst_bypass_eth2_srcip_4.enabled='0'
firewall.omr_dst_bypass_eth2_srcip_4.proto='all'
firewall.omr_dst_bypass_eth2_srcip_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_mac_4=rule
firewall.omr_dst_bypass_eth2_mac_4.name='omr_dst_bypass_eth2_mac'
firewall.omr_dst_bypass_eth2_mac_4.src='lan'
firewall.omr_dst_bypass_eth2_mac_4.dest='
'
firewall.omr_dst_bypass_eth2_mac_4.target='MARK'
firewall.omr_dst_bypass_eth2_mac_4.enabled='0'
firewall.omr_dst_bypass_eth2_mac_4.proto='all'
firewall.omr_dst_bypass_eth2_mac_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_srcport_tcp_4=rule
firewall.omr_dst_bypass_eth2_srcport_tcp_4.name='omr_dst_bypass_eth2_srcport_tcp'
firewall.omr_dst_bypass_eth2_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth2_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth2_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_eth2_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth2_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth2_srcport_tcp_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_srcport_udp_4=rule
firewall.omr_dst_bypass_eth2_srcport_udp_4.name='omr_dst_bypass_eth2_srcport_udp'
firewall.omr_dst_bypass_eth2_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth2_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_eth2_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_eth2_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth2_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth2_srcport_udp_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_dstport_tcp_4=rule
firewall.omr_dst_bypass_eth2_dstport_tcp_4.name='omr_dst_bypass_eth2_dstport_tcp'
firewall.omr_dst_bypass_eth2_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_eth2_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_eth2_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_eth2_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_eth2_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_eth2_dstport_tcp_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_dstport_udp_4=rule
firewall.omr_dst_bypass_eth2_dstport_udp_4.name='omr_dst_bypass_eth2_dstport_udp'
firewall.omr_dst_bypass_eth2_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_eth2_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_eth2_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_eth2_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_eth2_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_eth2_dstport_udp_4.set_xmark='0x45397'
firewall.omr_dst_bypass_eth2_dstip_6=rule
firewall.omr_dst_bypass_eth2_dstip_6.name='omr_dst_bypass_eth2_rule'
firewall.omr_dst_bypass_eth2_dstip_6.ipset='omr_dst_bypass_eth2_6'
firewall.omr_dst_bypass_eth2_dstip_6.target='MARK'
firewall.omr_dst_bypass_eth2_dstip_6.src='lan'
firewall.omr_dst_bypass_eth2_dstip_6.dest=''
firewall.omr_dst_bypass_eth2_dstip_6.family='ipv6'
firewall.omr_dst_bypass_eth2_dstip_6.enabled='0'
firewall.omr_dst_bypass_eth2_dstip_6.proto='all'
firewall.omr_dst_bypass_eth2_dstip_6.set_mark='0x65397'
firewall.omr_dst_bypass_eth2_dstip_6_accept=rule
firewall.omr_dst_bypass_eth2_dstip_6_accept.name='omr_dst_bypass_eth2_rule_accept'
firewall.omr_dst_bypass_eth2_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_eth2_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_eth2_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_eth2_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_eth2_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_eth2_dstip_6_accept.mark='0x65397'
firewall.omr_dst_bypass_eth2_srcip_6=rule
firewall.omr_dst_bypass_eth2_srcip_6.name='omr_dst_bypass_eth2_srcip'
firewall.omr_dst_bypass_eth2_srcip_6.src='lan'
firewall.omr_dst_bypass_eth2_srcip_6.dest=''
firewall.omr_dst_bypass_eth2_srcip_6.family='ipv6'
firewall.omr_dst_bypass_eth2_srcip_6.target='MARK'
firewall.omr_dst_bypass_eth2_srcip_6.enabled='0'
firewall.omr_dst_bypass_eth2_srcip_6.proto='all'
firewall.omr_dst_bypass_eth2_srcip_6.set_xmark='0x65397'
firewall.omr_dst_bypass_eth2_mac_6=rule
firewall.omr_dst_bypass_eth2_mac_6.name='omr_dst_bypass_eth2_mac'
firewall.omr_dst_bypass_eth2_mac_6.src='lan'
firewall.omr_dst_bypass_eth2_mac_6.dest='
'
firewall.omr_dst_bypass_eth2_mac_6.target='MARK'
firewall.omr_dst_bypass_eth2_mac_6.enabled='0'
firewall.omr_dst_bypass_eth2_mac_6.proto='all'
firewall.omr_dst_bypass_eth2_mac_6.set_xmark='0x65397'
firewall.omr_dst_bypass_eth2_srcport_tcp_6=rule
firewall.omr_dst_bypass_eth2_srcport_tcp_6.name='omr_dst_bypass_eth2_srcport_tcp'
firewall.omr_dst_bypass_eth2_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth2_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth2_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_eth2_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth2_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth2_srcport_tcp_6.set_xmark='0x65397'
firewall.omr_dst_bypass_eth2_srcport_udp_6=rule
firewall.omr_dst_bypass_eth2_srcport_udp_6.name='omr_dst_bypass_eth2_srcport_udp'
firewall.omr_dst_bypass_eth2_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth2_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_eth2_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_eth2_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth2_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth2_srcport_udp_6.set_xmark='0x65397'
firewall.omr_dst_bypass_eth2_dstport_tcp_6=rule
firewall.omr_dst_bypass_eth2_dstport_tcp_6.name='omr_dst_bypass_eth2_dstport_tcp'
firewall.omr_dst_bypass_eth2_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_eth2_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_eth2_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_eth2_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_eth2_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_eth2_dstport_tcp_6.set_xmark='0x65397'
firewall.omr_dst_bypass_eth2_dstport_udp_6=rule
firewall.omr_dst_bypass_eth2_dstport_udp_6.name='omr_dst_bypass_eth2_dstport_udp'
firewall.omr_dst_bypass_eth2_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_eth2_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_eth2_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_eth2_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_eth2_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_eth2_dstport_udp_6.set_xmark='0x65397'
firewall.omr_dst_bypass_tun0_4=ipset
firewall.omr_dst_bypass_tun0_4.name='omr_dst_bypass_tun0_4'
firewall.omr_dst_bypass_tun0_4.match='dest_ip'
firewall.omr_dst_bypass_tun0_4.family='ipv4'
firewall.omr_dst_bypass_tun0_4.enabled='1'
firewall.omr_dst_bypass_tun0_6=ipset
firewall.omr_dst_bypass_tun0_6.name='omr_dst_bypass_tun0_6'
firewall.omr_dst_bypass_tun0_6.match='dest_ip'
firewall.omr_dst_bypass_tun0_6.family='ipv6'
firewall.omr_dst_bypass_tun0_6.enabled='1'
firewall.omr_dst_bypass_tun0_dstip_4=rule
firewall.omr_dst_bypass_tun0_dstip_4.name='omr_dst_bypass_tun0_rule'
firewall.omr_dst_bypass_tun0_dstip_4.ipset='omr_dst_bypass_tun0_4'
firewall.omr_dst_bypass_tun0_dstip_4.target='MARK'
firewall.omr_dst_bypass_tun0_dstip_4.src='lan'
firewall.omr_dst_bypass_tun0_dstip_4.dest=''
firewall.omr_dst_bypass_tun0_dstip_4.family='ipv4'
firewall.omr_dst_bypass_tun0_dstip_4.enabled='0'
firewall.omr_dst_bypass_tun0_dstip_4.proto='all'
firewall.omr_dst_bypass_tun0_dstip_4.set_mark='0x45391500'
firewall.omr_dst_bypass_tun0_dstip_4_accept=rule
firewall.omr_dst_bypass_tun0_dstip_4_accept.name='omr_dst_bypass_tun0_rule_accept'
firewall.omr_dst_bypass_tun0_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_tun0_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_tun0_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_tun0_dstip_4_accept.enabled='0'
firewall.omr_dst_bypass_tun0_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_tun0_dstip_4_accept.mark='0x45391500'
firewall.omr_dst_bypass_tun0_srcip_4=rule
firewall.omr_dst_bypass_tun0_srcip_4.name='omr_dst_bypass_tun0_srcip'
firewall.omr_dst_bypass_tun0_srcip_4.src='lan'
firewall.omr_dst_bypass_tun0_srcip_4.dest=''
firewall.omr_dst_bypass_tun0_srcip_4.family='ipv4'
firewall.omr_dst_bypass_tun0_srcip_4.target='MARK'
firewall.omr_dst_bypass_tun0_srcip_4.enabled='0'
firewall.omr_dst_bypass_tun0_srcip_4.proto='all'
firewall.omr_dst_bypass_tun0_srcip_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_mac_4=rule
firewall.omr_dst_bypass_tun0_mac_4.name='omr_dst_bypass_tun0_mac'
firewall.omr_dst_bypass_tun0_mac_4.src='lan'
firewall.omr_dst_bypass_tun0_mac_4.dest='
'
firewall.omr_dst_bypass_tun0_mac_4.target='MARK'
firewall.omr_dst_bypass_tun0_mac_4.enabled='0'
firewall.omr_dst_bypass_tun0_mac_4.proto='all'
firewall.omr_dst_bypass_tun0_mac_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_srcport_tcp_4=rule
firewall.omr_dst_bypass_tun0_srcport_tcp_4.name='omr_dst_bypass_tun0_srcport_tcp'
firewall.omr_dst_bypass_tun0_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_tun0_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_tun0_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_tun0_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_tun0_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_tun0_srcport_tcp_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_srcport_udp_4=rule
firewall.omr_dst_bypass_tun0_srcport_udp_4.name='omr_dst_bypass_tun0_srcport_udp'
firewall.omr_dst_bypass_tun0_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_tun0_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_tun0_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_tun0_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_tun0_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_tun0_srcport_udp_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_dstport_tcp_4=rule
firewall.omr_dst_bypass_tun0_dstport_tcp_4.name='omr_dst_bypass_tun0_dstport_tcp'
firewall.omr_dst_bypass_tun0_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_tun0_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_tun0_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_tun0_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_tun0_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_tun0_dstport_tcp_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_dstport_udp_4=rule
firewall.omr_dst_bypass_tun0_dstport_udp_4.name='omr_dst_bypass_tun0_dstport_udp'
firewall.omr_dst_bypass_tun0_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_tun0_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_tun0_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_tun0_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_tun0_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_tun0_dstport_udp_4.set_xmark='0x45391500'
firewall.omr_dst_bypass_tun0_dstip_6=rule
firewall.omr_dst_bypass_tun0_dstip_6.name='omr_dst_bypass_tun0_rule'
firewall.omr_dst_bypass_tun0_dstip_6.ipset='omr_dst_bypass_tun0_6'
firewall.omr_dst_bypass_tun0_dstip_6.target='MARK'
firewall.omr_dst_bypass_tun0_dstip_6.src='lan'
firewall.omr_dst_bypass_tun0_dstip_6.dest=''
firewall.omr_dst_bypass_tun0_dstip_6.family='ipv6'
firewall.omr_dst_bypass_tun0_dstip_6.enabled='0'
firewall.omr_dst_bypass_tun0_dstip_6.proto='all'
firewall.omr_dst_bypass_tun0_dstip_6.set_mark='0x65391500'
firewall.omr_dst_bypass_tun0_dstip_6_accept=rule
firewall.omr_dst_bypass_tun0_dstip_6_accept.name='omr_dst_bypass_tun0_rule_accept'
firewall.omr_dst_bypass_tun0_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_tun0_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_tun0_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_tun0_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_tun0_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_tun0_dstip_6_accept.mark='0x65391500'
firewall.omr_dst_bypass_tun0_srcip_6=rule
firewall.omr_dst_bypass_tun0_srcip_6.name='omr_dst_bypass_tun0_srcip'
firewall.omr_dst_bypass_tun0_srcip_6.src='lan'
firewall.omr_dst_bypass_tun0_srcip_6.dest=''
firewall.omr_dst_bypass_tun0_srcip_6.family='ipv6'
firewall.omr_dst_bypass_tun0_srcip_6.target='MARK'
firewall.omr_dst_bypass_tun0_srcip_6.enabled='0'
firewall.omr_dst_bypass_tun0_srcip_6.proto='all'
firewall.omr_dst_bypass_tun0_srcip_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_tun0_mac_6=rule
firewall.omr_dst_bypass_tun0_mac_6.name='omr_dst_bypass_tun0_mac'
firewall.omr_dst_bypass_tun0_mac_6.src='lan'
firewall.omr_dst_bypass_tun0_mac_6.dest='
'
firewall.omr_dst_bypass_tun0_mac_6.target='MARK'
firewall.omr_dst_bypass_tun0_mac_6.enabled='0'
firewall.omr_dst_bypass_tun0_mac_6.proto='all'
firewall.omr_dst_bypass_tun0_mac_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_tun0_srcport_tcp_6=rule
firewall.omr_dst_bypass_tun0_srcport_tcp_6.name='omr_dst_bypass_tun0_srcport_tcp'
firewall.omr_dst_bypass_tun0_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_tun0_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_tun0_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_tun0_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_tun0_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_tun0_srcport_tcp_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_tun0_srcport_udp_6=rule
firewall.omr_dst_bypass_tun0_srcport_udp_6.name='omr_dst_bypass_tun0_srcport_udp'
firewall.omr_dst_bypass_tun0_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_tun0_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_tun0_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_tun0_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_tun0_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_tun0_srcport_udp_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_tun0_dstport_tcp_6=rule
firewall.omr_dst_bypass_tun0_dstport_tcp_6.name='omr_dst_bypass_tun0_dstport_tcp'
firewall.omr_dst_bypass_tun0_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_tun0_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_tun0_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_tun0_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_tun0_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_tun0_dstport_tcp_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_tun0_dstport_udp_6=rule
firewall.omr_dst_bypass_tun0_dstport_udp_6.name='omr_dst_bypass_tun0_dstport_udp'
firewall.omr_dst_bypass_tun0_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_tun0_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_tun0_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_tun0_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_tun0_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_tun0_dstport_udp_6.set_xmark='0x65391500'
firewall.omr_dst_bypass_6in4_omr6in4_4=ipset
firewall.omr_dst_bypass_6in4_omr6in4_4.name='omr_dst_bypass_6in4_omr6in4_4'
firewall.omr_dst_bypass_6in4_omr6in4_4.match='dest_ip'
firewall.omr_dst_bypass_6in4_omr6in4_4.family='ipv4'
firewall.omr_dst_bypass_6in4_omr6in4_4.enabled='1'
firewall.omr_dst_bypass_6in4_omr6in4_6=ipset
firewall.omr_dst_bypass_6in4_omr6in4_6.name='omr_dst_bypass_6in4_omr6in4_6'
firewall.omr_dst_bypass_6in4_omr6in4_6.match='dest_ip'
firewall.omr_dst_bypass_6in4_omr6in4_6.family='ipv6'
firewall.omr_dst_bypass_6in4_omr6in4_6.enabled='1'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.name='omr_dst_bypass_6in4_omr6in4_rule'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.ipset='omr_dst_bypass_6in4_omr6in4_4'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.family='ipv4'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4.set_mark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.name='omr_dst_bypass_6in4_omr6in4_rule_accept'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_4_accept.mark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.name='omr_dst_bypass_6in4_omr6in4_srcip'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.family='ipv4'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.name='omr_dst_bypass_6in4_omr6in4_mac'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_mac_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.name='omr_dst_bypass_6in4_omr6in4_srcport_tcp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.name='omr_dst_bypass_6in4_omr6in4_srcport_udp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.name='omr_dst_bypass_6in4_omr6in4_dstport_tcp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.name='omr_dst_bypass_6in4_omr6in4_dstport_udp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_4.set_xmark='0x45391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.name='omr_dst_bypass_6in4_omr6in4_rule'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.ipset='omr_dst_bypass_6in4_omr6in4_6'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.family='ipv6'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6.set_mark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.name='omr_dst_bypass_6in4_omr6in4_rule_accept'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_dstip_6_accept.mark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.name='omr_dst_bypass_6in4_omr6in4_srcip'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.family='ipv6'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_srcip_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.name='omr_dst_bypass_6in4_omr6in4_mac'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.proto='all'
firewall.omr_dst_bypass_6in4_omr6in4_mac_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.name='omr_dst_bypass_6in4_omr6in4_srcport_tcp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_tcp_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.name='omr_dst_bypass_6in4_omr6in4_srcport_udp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_srcport_udp_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.name='omr_dst_bypass_6in4_omr6in4_dstport_tcp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_tcp_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6=rule
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.name='omr_dst_bypass_6in4_omr6in4_dstport_udp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_6in4_omr6in4_dstport_udp_6.set_xmark='0x65391201'
firewall.omr_dst_bypass_all_4=ipset
firewall.omr_dst_bypass_all_4.name='omr_dst_bypass_all_4'
firewall.omr_dst_bypass_all_4.match='dest_ip'
firewall.omr_dst_bypass_all_4.family='ipv4'
firewall.omr_dst_bypass_all_4.enabled='1'
firewall.omr_dst_bypass_all_6=ipset
firewall.omr_dst_bypass_all_6.name='omr_dst_bypass_all_6'
firewall.omr_dst_bypass_all_6.match='dest_ip'
firewall.omr_dst_bypass_all_6.family='ipv6'
firewall.omr_dst_bypass_all_6.enabled='1'
firewall.omr_dst_bypass_all_dstip_4=rule
firewall.omr_dst_bypass_all_dstip_4.name='omr_dst_bypass_all_rule'
firewall.omr_dst_bypass_all_dstip_4.ipset='omr_dst_bypass_all_4'
firewall.omr_dst_bypass_all_dstip_4.target='MARK'
firewall.omr_dst_bypass_all_dstip_4.src='lan'
firewall.omr_dst_bypass_all_dstip_4.dest=''
firewall.omr_dst_bypass_all_dstip_4.family='ipv4'
firewall.omr_dst_bypass_all_dstip_4.enabled='0'
firewall.omr_dst_bypass_all_dstip_4.proto='all'
firewall.omr_dst_bypass_all_dstip_4.set_mark='0x4539'
firewall.omr_dst_bypass_all_dstip_4_accept=rule
firewall.omr_dst_bypass_all_dstip_4_accept.name='omr_dst_bypass_all_rule_accept'
firewall.omr_dst_bypass_all_dstip_4_accept.target='ACCEPT'
firewall.omr_dst_bypass_all_dstip_4_accept.dest='
'
firewall.omr_dst_bypass_all_dstip_4_accept.family='ipv4'
firewall.omr_dst_bypass_all_dstip_4_accept.enabled='0'
firewall.omr_dst_bypass_all_dstip_4_accept.proto='all'
firewall.omr_dst_bypass_all_dstip_4_accept.mark='0x4539'
firewall.omr_dst_bypass_all_srcip_4=rule
firewall.omr_dst_bypass_all_srcip_4.name='omr_dst_bypass_all_srcip'
firewall.omr_dst_bypass_all_srcip_4.src='lan'
firewall.omr_dst_bypass_all_srcip_4.dest=''
firewall.omr_dst_bypass_all_srcip_4.family='ipv4'
firewall.omr_dst_bypass_all_srcip_4.target='MARK'
firewall.omr_dst_bypass_all_srcip_4.enabled='0'
firewall.omr_dst_bypass_all_srcip_4.proto='all'
firewall.omr_dst_bypass_all_srcip_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_mac_4=rule
firewall.omr_dst_bypass_all_mac_4.name='omr_dst_bypass_all_mac'
firewall.omr_dst_bypass_all_mac_4.src='lan'
firewall.omr_dst_bypass_all_mac_4.dest='
'
firewall.omr_dst_bypass_all_mac_4.target='MARK'
firewall.omr_dst_bypass_all_mac_4.enabled='0'
firewall.omr_dst_bypass_all_mac_4.proto='all'
firewall.omr_dst_bypass_all_mac_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_srcport_tcp_4=rule
firewall.omr_dst_bypass_all_srcport_tcp_4.name='omr_dst_bypass_all_srcport_tcp'
firewall.omr_dst_bypass_all_srcport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_all_srcport_tcp_4.src='lan'
firewall.omr_dst_bypass_all_srcport_tcp_4.dest=''
firewall.omr_dst_bypass_all_srcport_tcp_4.target='MARK'
firewall.omr_dst_bypass_all_srcport_tcp_4.enabled='0'
firewall.omr_dst_bypass_all_srcport_tcp_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_srcport_udp_4=rule
firewall.omr_dst_bypass_all_srcport_udp_4.name='omr_dst_bypass_all_srcport_udp'
firewall.omr_dst_bypass_all_srcport_udp_4.proto='udp'
firewall.omr_dst_bypass_all_srcport_udp_4.src='lan'
firewall.omr_dst_bypass_all_srcport_udp_4.dest='
'
firewall.omr_dst_bypass_all_srcport_udp_4.target='MARK'
firewall.omr_dst_bypass_all_srcport_udp_4.enabled='0'
firewall.omr_dst_bypass_all_srcport_udp_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_dstport_tcp_4=rule
firewall.omr_dst_bypass_all_dstport_tcp_4.name='omr_dst_bypass_all_dstport_tcp'
firewall.omr_dst_bypass_all_dstport_tcp_4.src='lan'
firewall.omr_dst_bypass_all_dstport_tcp_4.dest=''
firewall.omr_dst_bypass_all_dstport_tcp_4.target='MARK'
firewall.omr_dst_bypass_all_dstport_tcp_4.proto='tcp'
firewall.omr_dst_bypass_all_dstport_tcp_4.enabled='0'
firewall.omr_dst_bypass_all_dstport_tcp_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_dstport_udp_4=rule
firewall.omr_dst_bypass_all_dstport_udp_4.name='omr_dst_bypass_all_dstport_udp'
firewall.omr_dst_bypass_all_dstport_udp_4.src='lan'
firewall.omr_dst_bypass_all_dstport_udp_4.dest='
'
firewall.omr_dst_bypass_all_dstport_udp_4.proto='udp'
firewall.omr_dst_bypass_all_dstport_udp_4.target='MARK'
firewall.omr_dst_bypass_all_dstport_udp_4.enabled='0'
firewall.omr_dst_bypass_all_dstport_udp_4.set_xmark='0x4539'
firewall.omr_dst_bypass_all_dstip_6=rule
firewall.omr_dst_bypass_all_dstip_6.name='omr_dst_bypass_all_rule'
firewall.omr_dst_bypass_all_dstip_6.ipset='omr_dst_bypass_all_6'
firewall.omr_dst_bypass_all_dstip_6.target='MARK'
firewall.omr_dst_bypass_all_dstip_6.src='lan'
firewall.omr_dst_bypass_all_dstip_6.dest=''
firewall.omr_dst_bypass_all_dstip_6.family='ipv6'
firewall.omr_dst_bypass_all_dstip_6.enabled='0'
firewall.omr_dst_bypass_all_dstip_6.proto='all'
firewall.omr_dst_bypass_all_dstip_6.set_mark='0x6539'
firewall.omr_dst_bypass_all_dstip_6_accept=rule
firewall.omr_dst_bypass_all_dstip_6_accept.name='omr_dst_bypass_all_rule_accept'
firewall.omr_dst_bypass_all_dstip_6_accept.target='ACCEPT'
firewall.omr_dst_bypass_all_dstip_6_accept.dest='
'
firewall.omr_dst_bypass_all_dstip_6_accept.family='ipv6'
firewall.omr_dst_bypass_all_dstip_6_accept.enabled='0'
firewall.omr_dst_bypass_all_dstip_6_accept.proto='all'
firewall.omr_dst_bypass_all_dstip_6_accept.mark='0x6539'
firewall.omr_dst_bypass_all_srcip_6=rule
firewall.omr_dst_bypass_all_srcip_6.name='omr_dst_bypass_all_srcip'
firewall.omr_dst_bypass_all_srcip_6.src='lan'
firewall.omr_dst_bypass_all_srcip_6.dest=''
firewall.omr_dst_bypass_all_srcip_6.family='ipv6'
firewall.omr_dst_bypass_all_srcip_6.target='MARK'
firewall.omr_dst_bypass_all_srcip_6.enabled='0'
firewall.omr_dst_bypass_all_srcip_6.proto='all'
firewall.omr_dst_bypass_all_srcip_6.set_xmark='0x6539'
firewall.omr_dst_bypass_all_mac_6=rule
firewall.omr_dst_bypass_all_mac_6.name='omr_dst_bypass_all_mac'
firewall.omr_dst_bypass_all_mac_6.src='lan'
firewall.omr_dst_bypass_all_mac_6.dest='
'
firewall.omr_dst_bypass_all_mac_6.target='MARK'
firewall.omr_dst_bypass_all_mac_6.enabled='0'
firewall.omr_dst_bypass_all_mac_6.proto='all'
firewall.omr_dst_bypass_all_mac_6.set_xmark='0x6539'
firewall.omr_dst_bypass_all_srcport_tcp_6=rule
firewall.omr_dst_bypass_all_srcport_tcp_6.name='omr_dst_bypass_all_srcport_tcp'
firewall.omr_dst_bypass_all_srcport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_all_srcport_tcp_6.src='lan'
firewall.omr_dst_bypass_all_srcport_tcp_6.dest=''
firewall.omr_dst_bypass_all_srcport_tcp_6.target='MARK'
firewall.omr_dst_bypass_all_srcport_tcp_6.enabled='0'
firewall.omr_dst_bypass_all_srcport_tcp_6.set_xmark='0x6539'
firewall.omr_dst_bypass_all_srcport_udp_6=rule
firewall.omr_dst_bypass_all_srcport_udp_6.name='omr_dst_bypass_all_srcport_udp'
firewall.omr_dst_bypass_all_srcport_udp_6.proto='udp'
firewall.omr_dst_bypass_all_srcport_udp_6.src='lan'
firewall.omr_dst_bypass_all_srcport_udp_6.dest='
'
firewall.omr_dst_bypass_all_srcport_udp_6.target='MARK'
firewall.omr_dst_bypass_all_srcport_udp_6.enabled='0'
firewall.omr_dst_bypass_all_srcport_udp_6.set_xmark='0x6539'
firewall.omr_dst_bypass_all_dstport_tcp_6=rule
firewall.omr_dst_bypass_all_dstport_tcp_6.name='omr_dst_bypass_all_dstport_tcp'
firewall.omr_dst_bypass_all_dstport_tcp_6.src='lan'
firewall.omr_dst_bypass_all_dstport_tcp_6.dest=''
firewall.omr_dst_bypass_all_dstport_tcp_6.target='MARK'
firewall.omr_dst_bypass_all_dstport_tcp_6.proto='tcp'
firewall.omr_dst_bypass_all_dstport_tcp_6.enabled='0'
firewall.omr_dst_bypass_all_dstport_tcp_6.set_xmark='0x6539'
firewall.omr_dst_bypass_all_dstport_udp_6=rule
firewall.omr_dst_bypass_all_dstport_udp_6.name='omr_dst_bypass_all_dstport_udp'
firewall.omr_dst_bypass_all_dstport_udp_6.src='lan'
firewall.omr_dst_bypass_all_dstport_udp_6.dest='
'
firewall.omr_dst_bypass_all_dstport_udp_6.proto='udp'
firewall.omr_dst_bypass_all_dstport_udp_6.target='MARK'
firewall.omr_dst_bypass_all_dstport_udp_6.enabled='0'
firewall.omr_dst_bypass_all_dstport_udp_6.set_xmark='0x6539'

@KoulEl
Copy link
Author

KoulEl commented Mar 23, 2025

And what Milkywan sent me (it seems ok to me):

cat /etc/shorewall/rules

Shorewall version 4.0 - Sample Rules File for two-interface configuration.

Copyright (C) 2006-2014,2007 by the Shorewall Team

This library is free software; you can redistribute it and/or

modify it under the terms of the GNU Lesser General Public

License as published by the Free Software Foundation; either

version 2.1 of the License, or (at your option) any later version.

See the file README.txt for further details.

#------------------------------------------------------------------------------

For information about entries in this file, type "man shorewall-rules"

######################################################################################################################################################################################################

#ACTION SOURCE DEST PROTO DEST SOURCE ORIGINAL RATE USER/ MARK CONNLIMIT TIME HEADERS SWITCH HELPER

PORT PORT(S) DEST LIMIT GROUP

?SECTION ALL
?SECTION ESTABLISHED
?SECTION RELATED
?SECTION INVALID
?SECTION UNTRACKED
?SECTION NEW

Don't allow connection pickup from the net

Invalid(DROP) net all tcp

Accept DNS connections from the firewall to the network

DNS(ACCEPT) $FW net

Allow Ping from/to the VPN

Ping(ACCEPT) vpn $FW
Ping(ACCEPT) $FW vpn

Allow Ping from the firewall to the network

Ping(ACCEPT) $FW net

Drop Ping from the "bad" net zone.. and prevent your log from being flooded..

#Ping(DROP) net $FW
Ping(ACCEPT) net $FW

Accept connection from port > 65000 for shadowsocks and glorytun on the firewall

ACCEPT net $FW tcp 65000-65535
ACCEPT net $FW udp 65000-65535

Accept connection from SSH to the firewall

ACCEPT net $FW tcp 65222

DHCP forward to the VPN from the firewall

DHCPfwd(ACCEPT) $FW vpn

Redirect all port from 1 to 64999 to the VPN client from the network

#DNAT net vpn:$OMR_ADDR tcp 1-64999
#DNAT net vpn:$OMR_ADDR udp 1-64999
DNAT net vpn:$OMR_ADDR tcp 25 # OMR openmptcprouter redirect router 25 port tcp
DNAT net vpn:$OMR_ADDR tcp 21 # OMR openmptcprouter redirect router 21 port tcp
DNAT net vpn:$OMR_ADDR udp 20 # OMR openmptcprouter redirect router 20 port udp
DNAT net vpn:$OMR_ADDR tcp 443 # OMR openmptcprouter redirect router 443 port tcp
DNAT net vpn:$OMR_ADDR tcp 4433 # OMR openmptcprouter redirect router 4433 port tcp
DNAT net vpn:$OMR_ADDR tcp 4443 # OMR openmptcprouter redirect router 4443 port tcp
DNAT net vpn:$OMR_ADDR udp 10000 # OMR openmptcprouter redirect router 10000 port udp
DNAT net vpn:$OMR_ADDR tcp 2222 # OMR openmptcprouter redirect router 2222 port tcp
DNAT net vpn:$OMR_ADDR tcp 4435 # OMR openmptcprouter redirect router 4435 port tcp
DNAT net vpn:$OMR_ADDR tcp 4455 # OMR openmptcprouter redirect router 4455 port tcp
DNAT net vpn:$OMR_ADDR tcp 4466 # OMR openmptcprouter redirect router 4466 port tcp
DNAT net vpn:$OMR_ADDR tcp 4436 # OMR openmptcprouter redirect router 4436 port tcp
DNAT net vpn:$OMR_ADDR tcp 110 # OMR openmptcprouter redirect router 110 port tcp
DNAT net vpn:$OMR_ADDR tcp 143 # OMR openmptcprouter redirect router 143 port tcp
DNAT net vpn:$OMR_ADDR tcp 587 # OMR openmptcprouter redirect router 587 port tcp
DNAT net vpn:$OMR_ADDR tcp 993 # OMR openmptcprouter redirect router 993 port tcp
DNAT net vpn:$OMR_ADDR tcp 995 # OMR openmptcprouter redirect router 995 port tcp
DNAT net vpn:$OMR_ADDR tcp 20 # OMR openmptcprouter redirect router 20 port tcp
DNAT net vpn:$OMR_ADDR tcp 10090-10100 # OMR openmptcprouter redirect router 10090-10100 port tcp
DNAT net vpn:$OMR_ADDR tcp 22 # OMR openmptcprouter redirect router 22 port tcp
DNAT net vpn:$OMR_ADDR tcp 8080 # OMR openmptcprouter redirect router 8080 port tcp
DNAT net vpn:$OMR_ADDR tcp 63241 # OMR openmptcprouter redirect router 63241 port tcp
DNAT net vpn:$OMR_ADDR tcp 22027 # OMR openmptcprouter redirect router 22027 port tcp
DNAT net vpn:$OMR_ADDR tcp 22028 # OMR openmptcprouter redirect router 22028 port tcp
DNAT net vpn:$OMR_ADDR tcp 22029 # OMR openmptcprouter redirect router 22029 port tcp
DNAT net vpn:$OMR_ADDR tcp 4445-4446 # OMR openmptcprouter redirect router 4445-4446 port tcp
ACCEPT net $FW tcp 65301 # OMR openmptcprouter open openvpn port tcp
ACCEPT net $FW udp 65311 # OMR openmptcprouter open wireguard port udp
DNAT net vpn:$OMR_ADDR tcp 16881 # OMR openmptcprouter redirect router 16881 port tcp
DNAT net vpn:$OMR_ADDR udp 16881 # OMR openmptcprouter redirect router 16881 port udp
DNAT net vpn:$OMR_ADDR tcp 22026 # OMR openmptcprouter redirect router 22026 port tcp
DNAT net vpn:$OMR_ADDR tcp 80 # OMR openmptcprouter redirect router 80 port tcp

cat /etc/shorewall/params.vpn

VPS_ADDR=10.255.252.1
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
VPS_IFACE=tun0
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6
OMR_ADDR=10.255.252.6

@Ysurac
Copy link
Owner

Ysurac commented Mar 23, 2025

Can you try, if you have access on VPS, to do a ping 10.255.252.6 if yes then all data (when you try to reach from external source the server) should be forwarded on router and you should see them in tcpdump.
If not, I would need iptables-save on VPS.

Edit: In my test (after using the good IP...) it's working when SNAT rules are also set for web server.

@KoulEl
Copy link
Author

KoulEl commented Mar 23, 2025

I will ask Milkywan if they can do this for me since I have no access to the VPS, it is fully managed by them.

On my side, nothing has been changed on the router. It stopped working after the VPS update (if there's no solution, I'll ask Milkywan to downgrade to the former one in order to get access to my sites again).

@Ysurac
Copy link
Owner

Ysurac commented Mar 24, 2025

What is the result of ip r on the router ?
Not sure downgrade will help as I made no changes on this part.

@KoulEl
Copy link
Author

KoulEl commented Mar 24, 2025

Here it is :

root@OpenMPTCProuter:~# ip r
default via 10.255.252.1 dev tun0
default via 192.168.0.1 dev eth1 metric 6
default via 192.168.1.1 dev eth2 metric 7
default via 10.255.252.1 dev tun0 metric 1500
10.255.252.0/24 dev tun0 proto kernel scope link src 10.255.252.3
10.255.252.0/24 dev tun0 scope link metric 1500
45.13.104.49 metric 1
nexthop via 192.168.0.1 dev eth1 weight 100
nexthop via 192.168.1.1 dev eth2 weight 1
127.0.0.0/8 dev lo proto static scope link metric 5
192.168.0.0/24 dev eth1 scope link metric 6
192.168.1.0/24 dev eth2 scope link metric 7

@Ysurac
Copy link
Owner

Ysurac commented Mar 24, 2025

And ip a please ? to check if it's the correct VPN config set on VPS

@KoulEl
Copy link
Author

KoulEl commented Mar 24, 2025

An here it is (edited to insert blank line for easy reading):

root@OpenMPTCProuter:~# ip a

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host proto kernel_lo
valid_lft forever preferred_lft forever

2: ip6tnl0@NONE: mtu 1452 qdisc noop state DOWN group default qlen 1000
link/tunnel6 :: brd :: permaddr a268:3177:5eb4::

3: sit0@NONE: mtu 1480 qdisc noop state DOWN group default qlen 1000
link/sit 0.0.0.0 brd 0.0.0.0

4: gre0@NONE: mtu 1476 qdisc noop state DOWN group default qlen 1000
link/gre 0.0.0.0 brd 0.0.0.0

5: gretap0@NONE: <BROADCAST,MULTICAST> mtu 1462 qdisc noop state DOWN group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff

6: erspan0@NONE: <BROADCAST,MULTICAST> mtu 1450 qdisc noop state DOWN group default qlen 1000
link/ether 00:00:00:00:00:00 brd ff:ff:ff:ff:ff:ff

7: ip6gre0@NONE: mtu 1448 qdisc noop state DOWN group default qlen 1000
link/gre6 :: brd :: permaddr 1a65:39f7:a9a4::

8: teql0: mtu 1500 qdisc noop state DOWN group default qlen 100
link/void

9: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 00:0a:cd:31:d8:66 brd ff:ff:ff:ff:ff:ff
inet 192.168.5.1/24 brd 192.168.5.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fd3e:c459:2457::1/60 scope global noprefixroute
valid_lft forever preferred_lft forever
inet6 fe80::20a:cdff:fe31:d866/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever

10: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 00:18:7d:38:f0:9d brd ff:ff:ff:ff:ff:ff
inet 192.168.0.20/24 brd 192.168.0.255 scope global eth1
valid_lft forever preferred_lft forever
inet6 fe80::218:7dff:fe38:f09d/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever

11: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 00:18:7d:38:f0:9e brd ff:ff:ff:ff:ff:ff
inet 192.168.1.20/24 brd 192.168.1.255 scope global eth2
valid_lft forever preferred_lft forever
inet6 fe80::218:7dff:fe38:f09e/64 scope link proto kernel_ll
valid_lft forever preferred_lft forever

13: 6in4-omr6in4@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1280 qdisc noqueue state UNKNOWN group default qlen 1000
link/sit 10.255.252.6 peer 10.255.252.1
inet6 fd00::a00:2/126 scope global
valid_lft forever preferred_lft forever
inet6 fe80::aff:fc06/64 scope link
valid_lft forever preferred_lft forever

26: ifb4eth1: <BROADCAST,NOARP> mtu 1500 qdisc noop state DOWN group default qlen 32
link/ether 66:f7:2b:1b:21:e8 brd ff:ff:ff:ff:ff:ff

29: ifb4eth2: <BROADCAST,NOARP> mtu 1500 qdisc noop state DOWN group default qlen 32
link/ether 9a:32:59:85:18:5f brd ff:ff:ff:ff:ff:ff

31: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UNKNOWN group default qlen 100
link/none
inet 10.255.252.3/24 scope global tun0
valid_lft forever preferred_lft forever
inet6 fe80::3497:7cf0:f87e:fc4d/64 scope link stable-privacy proto kernel_ll
valid_lft forever preferred_lft forever

@Ysurac
Copy link
Owner

Ysurac commented Mar 24, 2025

VPN is now on "10.255.252.3", don't know if VPS side was updated. I will make some tests.

@KoulEl
Copy link
Author

KoulEl commented Mar 25, 2025

Here are the results from the VPS (thanks Milkywan):

Le ping ne passe pas

ping 10.255.252.6

PING 10.255.252.6 (10.255.252.6) 56(84) bytes of data.

^C

--- 10.255.252.6 ping statistics ---

16 packets transmitted, 0 received, 100% packet loss, time 15355ms

iptables-save

Generated by iptables-save v1.8.9 (nf_tables) on Mon Mar 24 20:06:26 2025

*mangle

:PREROUTING ACCEPT [97659619:54649998883]

:INPUT ACCEPT [76730665:45965484733]

:FORWARD ACCEPT [20779327:8662818063]

:OUTPUT ACCEPT [74380277:80920123570]

:POSTROUTING ACCEPT [95159603:89582941589]

:tcfor - [0:0]

:tcin - [0:0]

:tcout - [0:0]

:tcpost - [0:0]

:tcpre - [0:0]

-A PREROUTING -j tcpre

-A INPUT -j tcin

-A FORWARD -j MARK --set-xmark 0x0/0xff

-A FORWARD -j tcfor

-A OUTPUT -j tcout

-A POSTROUTING -j tcpost

COMMIT

Completed on Mon Mar 24 20:06:26 2025

Generated by iptables-save v1.8.9 (nf_tables) on Mon Mar 24 20:06:26 2025

*raw

:PREROUTING ACCEPT [97659619:54649998883]

:OUTPUT ACCEPT [74380277:80920123570]

-A PREROUTING -p udp -m udp --dport 10080 -j CT --helper amanda

-A PREROUTING -p tcp -m tcp --dport 21 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper ftp

-A PREROUTING -p udp -m udp --dport 1719 -j CT --helper RAS

-A PREROUTING -p tcp -m tcp --dport 1720 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper Q.931

-A PREROUTING -p tcp -m tcp --dport 6667 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper irc

-A PREROUTING -p udp -m udp --dport 137 -j CT --helper netbios-ns

-A PREROUTING -p tcp -m tcp --dport 1723 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper pptp

-A PREROUTING -p tcp -m tcp --dport 6566 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper sane

-A PREROUTING -p udp -m udp --dport 5060 -j CT --helper sip

-A PREROUTING -p udp -m udp --dport 161 -j CT --helper snmp

-A PREROUTING -p udp -m udp --dport 69 -j CT --helper tftp

-A OUTPUT -p udp -m udp --dport 10080 -j CT --helper amanda

-A OUTPUT -p tcp -m tcp --dport 21 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper ftp

-A OUTPUT -p udp -m udp --dport 1719 -j CT --helper RAS

-A OUTPUT -p tcp -m tcp --dport 1720 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper Q.931

-A OUTPUT -p tcp -m tcp --dport 6667 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper irc

-A OUTPUT -p udp -m udp --dport 137 -j CT --helper netbios-ns

-A OUTPUT -p tcp -m tcp --dport 1723 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper pptp

-A OUTPUT -p tcp -m tcp --dport 6566 --tcp-flags FIN,SYN,RST,ACK SYN -j CT --helper sane

-A OUTPUT -p udp -m udp --dport 5060 -j CT --helper sip

-A OUTPUT -p udp -m udp --dport 161 -j CT --helper snmp

-A OUTPUT -p udp -m udp --dport 69 -j CT --helper tftp

COMMIT

Completed on Mon Mar 24 20:06:26 2025

Generated by iptables-save v1.8.9 (nf_tables) on Mon Mar 24 20:06:26 2025

*filter

:INPUT DROP [0:0]

:FORWARD DROP [0:0]

:OUTPUT DROP [0:0]

:dsvpn+_fwd - [0:0]

:dsvpn+_in - [0:0]

:dsvpn+_out - [0:0]

:dynamic - [0:0]

:fw-net - [0:0]

:fw-vpn - [0:0]

:fw-vpncl - [0:0]

:gre-user+_fwd - [0:0]

:gre-user+_in - [0:0]

:gre-user+_out - [0:0]

:gt-tun+_fwd - [0:0]

:gt-tun+_in - [0:0]

:gt-tun+_out - [0:0]

:gt-udp-tun+_fwd - [0:0]

:gt-udp-tun+_in - [0:0]

:gt-udp-tun+_out - [0:0]

:logdrop - [0:0]

:logflags - [0:0]

:logreject - [0:0]

:mlvpn+_fwd - [0:0]

:mlvpn+_in - [0:0]

:mlvpn+_out - [0:0]

:net-fw - [0:0]

:net-vpn - [0:0]

:net-vpncl - [0:0]

:net_frwd - [0:0]

:omr-bonding_fwd - [0:0]

:omr-bonding_in - [0:0]

:omr-bonding_out - [0:0]

:reject - [0:0]

:sha-lh-09fd6f0194f6921505d9 - [0:0]

:sha-rh-ba23dbe2c0902cd72596 - [0:0]

:shorewall - [0:0]

:smurflog - [0:0]

:smurfs - [0:0]

:tcpflags - [0:0]

:tun+_fwd - [0:0]

:tun+_in - [0:0]

:tun+_out - [0:0]

:vpn-fw - [0:0]

:vpn-net - [0:0]

:vpn-vpn - [0:0]

:vpn-vpncl - [0:0]

:vpn_frwd - [0:0]

:vpncl-fw - [0:0]

:vpncl-net - [0:0]

:vpncl-vpn - [0:0]

:vpncl_frwd - [0:0]

:wg+_fwd - [0:0]

:wg+_in - [0:0]

:wg+_out - [0:0]

-A INPUT -i eth0 -j net-fw

-A INPUT -i gt-tun+ -j gt-tun+_in

-A INPUT -i tun+ -j tun+_in

-A INPUT -i mlvpn+ -j mlvpn+_in

-A INPUT -i dsvpn+ -j dsvpn+_in

-A INPUT -i gre-user+ -j gre-user+_in

-A INPUT -i omr-bonding -j omr-bonding_in

-A INPUT -i gt-udp-tun+ -j gt-udp-tun+_in

-A INPUT -i wg+ -j wg+_in

-A INPUT -i client-wg+ -j vpncl-fw

-A INPUT -i lo -j ACCEPT

-A INPUT -m addrtype --dst-type BROADCAST -j DROP

-A INPUT -m addrtype --dst-type ANYCAST -j DROP

-A INPUT -m addrtype --dst-type MULTICAST -j DROP

-A INPUT -g reject

-A FORWARD -i eth0 -j net_frwd

-A FORWARD -i gt-tun+ -j gt-tun+_fwd

-A FORWARD -i tun+ -j tun+_fwd

-A FORWARD -i mlvpn+ -j mlvpn+_fwd

-A FORWARD -i dsvpn+ -j dsvpn+_fwd

-A FORWARD -i gre-user+ -j gre-user+_fwd

-A FORWARD -i omr-bonding -j omr-bonding_fwd

-A FORWARD -i gt-udp-tun+ -j gt-udp-tun+_fwd

-A FORWARD -i wg+ -j wg+_fwd

-A FORWARD -i client-wg+ -j vpncl_frwd

-A FORWARD -m addrtype --dst-type BROADCAST -j DROP

-A FORWARD -m addrtype --dst-type ANYCAST -j DROP

-A FORWARD -m addrtype --dst-type MULTICAST -j DROP

-A FORWARD -g reject

-A OUTPUT -o eth0 -j fw-net

-A OUTPUT -o gt-tun+ -j gt-tun+_out

-A OUTPUT -o tun+ -j tun+_out

-A OUTPUT -o mlvpn+ -j mlvpn+_out

-A OUTPUT -o dsvpn+ -j dsvpn+_out

-A OUTPUT -o gre-user+ -j gre-user+_out

-A OUTPUT -o omr-bonding -j omr-bonding_out

-A OUTPUT -o gt-udp-tun+ -j gt-udp-tun+_out

-A OUTPUT -o wg+ -j wg+_out

-A OUTPUT -o client-wg+ -j fw-vpncl

-A OUTPUT -o lo -j ACCEPT

-A OUTPUT -m addrtype --dst-type BROADCAST -j DROP

-A OUTPUT -m addrtype --dst-type ANYCAST -j DROP

-A OUTPUT -m addrtype --dst-type MULTICAST -j DROP

-A OUTPUT -g reject

-A dsvpn+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A dsvpn+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A dsvpn+_fwd -p tcp -j tcpflags

-A dsvpn+_fwd -j vpn_frwd

-A dsvpn+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A dsvpn+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A dsvpn+_in -p tcp -j tcpflags

-A dsvpn+_in -j vpn-fw

-A dsvpn+_out -j fw-vpn

-A fw-net -p udp -m udp --dport 67:68 -j ACCEPT

-A fw-net -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A fw-net -p udp -m udp --dport 53 -m comment --comment DNS -j ACCEPT

-A fw-net -p tcp -m tcp --dport 53 -m comment --comment DNS -j ACCEPT

-A fw-net -p icmp -m icmp --icmp-type 8 -m comment --comment Ping -j ACCEPT

-A fw-net -j ACCEPT

-A fw-vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A fw-vpn -p icmp -m icmp --icmp-type 8 -m comment --comment Ping -j ACCEPT

-A fw-vpn -p udp -m udp --sport 67:68 --dport 67:68 -m comment --comment DHCPfwd -j ACCEPT

-A fw-vpn -j ACCEPT

-A fw-vpncl -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A fw-vpncl -m addrtype --dst-type BROADCAST -j DROP

-A fw-vpncl -m addrtype --dst-type ANYCAST -j DROP

-A fw-vpncl -m addrtype --dst-type MULTICAST -j DROP

-A fw-vpncl -g reject

-A gre-user+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gre-user+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gre-user+_fwd -p tcp -j tcpflags

-A gre-user+_fwd -j vpn_frwd

-A gre-user+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gre-user+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gre-user+_in -p tcp -j tcpflags

-A gre-user+_in -j vpn-fw

-A gre-user+_out -j fw-vpn

-A gt-tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gt-tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gt-tun+_fwd -p tcp -j tcpflags

-A gt-tun+_fwd -j vpn_frwd

-A gt-tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gt-tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gt-tun+_in -p tcp -j tcpflags

-A gt-tun+_in -j vpn-fw

-A gt-tun+_out -j fw-vpn

-A gt-udp-tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gt-udp-tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gt-udp-tun+_fwd -p tcp -j tcpflags

-A gt-udp-tun+_fwd -j vpn_frwd

-A gt-udp-tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A gt-udp-tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A gt-udp-tun+_in -p tcp -j tcpflags

-A gt-udp-tun+_in -j vpn-fw

-A gt-udp-tun+_out -j fw-vpn

-A logdrop -j DROP

-A logflags -j LOG --log-prefix "Shorewall:logflags:DROP:" --log-level 6 --log-ip-options

-A logflags -j DROP

-A logreject -j reject

-A mlvpn+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A mlvpn+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A mlvpn+_fwd -p tcp -j tcpflags

-A mlvpn+_fwd -j vpn_frwd

-A mlvpn+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A mlvpn+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A mlvpn+_in -p tcp -j tcpflags

-A mlvpn+_in -j vpn-fw

-A mlvpn+_out -j fw-vpn

-A net-fw -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A net-fw -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A net-fw -p udp -m udp --dport 67:68 -j ACCEPT

-A net-fw -p tcp -j tcpflags

-A net-fw -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A net-fw -p tcp -m conntrack --ctstate INVALID -j DROP

-A net-fw -p icmp -m icmp --icmp-type 8 -m comment --comment Ping -j ACCEPT

-A net-fw -p tcp -m tcp --dport 65000:65535 -j ACCEPT

-A net-fw -p udp -m udp --dport 65000:65535 -j ACCEPT

-A net-fw -p tcp -m tcp --dport 65222 -j ACCEPT

-A net-fw -p tcp -m tcp --dport 65301 -j ACCEPT

-A net-fw -p udp -m udp --dport 65311 -j ACCEPT

-A net-fw -m addrtype --dst-type BROADCAST -j DROP

-A net-fw -m addrtype --dst-type ANYCAST -j DROP

-A net-fw -m addrtype --dst-type MULTICAST -j DROP

-A net-fw -j DROP

-A net-vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A net-vpn -p tcp -m conntrack --ctstate INVALID -j DROP

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 25 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 21 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p udp -m udp --dport 20 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 443 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4433 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4443 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p udp -m udp --dport 10000 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 2222 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4435 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4455 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4466 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4436 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 110 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 143 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 587 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 993 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 995 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 20 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 10090:10100 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 22 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 8080 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 63241 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 22027 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 22028 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 22029 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 4445:4446 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 16881 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p udp -m udp --dport 16881 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 22026 -j ACCEPT

-A net-vpn -d 10.255.252.6/32 -p tcp -m tcp --dport 80 -j ACCEPT

-A net-vpn -m addrtype --dst-type BROADCAST -j DROP

-A net-vpn -m addrtype --dst-type ANYCAST -j DROP

-A net-vpn -m addrtype --dst-type MULTICAST -j DROP

-A net-vpn -j DROP

-A net-vpncl -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A net-vpncl -p tcp -m conntrack --ctstate INVALID -j DROP

-A net-vpncl -m addrtype --dst-type BROADCAST -j DROP

-A net-vpncl -m addrtype --dst-type ANYCAST -j DROP

-A net-vpncl -m addrtype --dst-type MULTICAST -j DROP

-A net-vpncl -j DROP

-A net_frwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A net_frwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A net_frwd -p tcp -j tcpflags

-A net_frwd -o gt-tun+ -j net-vpn

-A net_frwd -o tun+ -j net-vpn

-A net_frwd -o mlvpn+ -j net-vpn

-A net_frwd -o dsvpn+ -j net-vpn

-A net_frwd -o gre-user+ -j net-vpn

-A net_frwd -o omr-bonding -j net-vpn

-A net_frwd -o gt-udp-tun+ -j net-vpn

-A net_frwd -o wg+ -j net-vpn

-A net_frwd -o client-wg+ -j net-vpncl

-A omr-bonding_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A omr-bonding_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A omr-bonding_fwd -p tcp -j tcpflags

-A omr-bonding_fwd -j vpn_frwd

-A omr-bonding_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A omr-bonding_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A omr-bonding_in -p tcp -j tcpflags

-A omr-bonding_in -j vpn-fw

-A omr-bonding_out -j fw-vpn

-A reject -m addrtype --src-type BROADCAST -j DROP

-A reject -s 224.0.0.0/4 -j DROP

-A reject -p igmp -j DROP

-A reject -p tcp -j REJECT --reject-with tcp-reset

-A reject -p udp -j REJECT --reject-with icmp-port-unreachable

-A reject -p icmp -j REJECT --reject-with icmp-host-unreachable

-A reject -j REJECT --reject-with icmp-host-prohibited

-A shorewall -m recent --set --name %CURRENTTIME --mask 255.255.255.255 --rsource

-A smurflog -j LOG --log-prefix "Shorewall:smurfs:DROP:" --log-level 6

-A smurflog -j DROP

-A smurfs -s 0.0.0.0/32 -j RETURN

-A smurfs -m addrtype --src-type BROADCAST -g smurflog

-A smurfs -s 224.0.0.0/4 -g smurflog

-A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g logflags

-A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g logflags

-A tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g logflags

-A tcpflags -p tcp -m tcp --tcp-flags FIN,RST FIN,RST -g logflags

-A tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g logflags

-A tcpflags -p tcp -m tcp --tcp-flags FIN,PSH,ACK FIN,PSH -g logflags

-A tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g logflags

-A tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A tun+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A tun+_fwd -p tcp -j tcpflags

-A tun+_fwd -j vpn_frwd

-A tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A tun+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A tun+_in -p tcp -j tcpflags

-A tun+_in -j vpn-fw

-A tun+_out -j fw-vpn

-A vpn-fw -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpn-fw -p icmp -m icmp --icmp-type 8 -m comment --comment Ping -j ACCEPT

-A vpn-fw -p udp -m udp --sport 67:68 --dport 67:68 -m comment --comment DHCPfwd -j ACCEPT

-A vpn-fw -j ACCEPT

-A vpn-net -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpn-net -j ACCEPT

-A vpn-vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpn-vpn -m addrtype --dst-type BROADCAST -j DROP

-A vpn-vpn -m addrtype --dst-type ANYCAST -j DROP

-A vpn-vpn -m addrtype --dst-type MULTICAST -j DROP

-A vpn-vpn -j DROP

-A vpn-vpncl -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpn-vpncl -j ACCEPT

-A vpn_frwd -o eth0 -j vpn-net

-A vpn_frwd -o gt-tun+ -j vpn-vpn

-A vpn_frwd -o tun+ -j vpn-vpn

-A vpn_frwd -o mlvpn+ -j vpn-vpn

-A vpn_frwd -o dsvpn+ -j vpn-vpn

-A vpn_frwd -o gre-user+ -j vpn-vpn

-A vpn_frwd -o omr-bonding -j vpn-vpn

-A vpn_frwd -o gt-udp-tun+ -j vpn-vpn

-A vpn_frwd -o wg+ -j vpn-vpn

-A vpn_frwd -o client-wg+ -j vpn-vpncl

-A vpncl-fw -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A vpncl-fw -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A vpncl-fw -p tcp -j tcpflags

-A vpncl-fw -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpncl-fw -m addrtype --dst-type BROADCAST -j DROP

-A vpncl-fw -m addrtype --dst-type ANYCAST -j DROP

-A vpncl-fw -m addrtype --dst-type MULTICAST -j DROP

-A vpncl-fw -g reject

-A vpncl-net -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpncl-net -m addrtype --dst-type BROADCAST -j DROP

-A vpncl-net -m addrtype --dst-type ANYCAST -j DROP

-A vpncl-net -m addrtype --dst-type MULTICAST -j DROP

-A vpncl-net -g reject

-A vpncl-vpn -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

-A vpncl-vpn -j ACCEPT

-A vpncl_frwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A vpncl_frwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A vpncl_frwd -p tcp -j tcpflags

-A vpncl_frwd -o eth0 -j vpncl-net

-A vpncl_frwd -o gt-tun+ -j vpncl-vpn

-A vpncl_frwd -o tun+ -j vpncl-vpn

-A vpncl_frwd -o mlvpn+ -j vpncl-vpn

-A vpncl_frwd -o dsvpn+ -j vpncl-vpn

-A vpncl_frwd -o gre-user+ -j vpncl-vpn

-A vpncl_frwd -o omr-bonding -j vpncl-vpn

-A vpncl_frwd -o gt-udp-tun+ -j vpncl-vpn

-A vpncl_frwd -o wg+ -j vpncl-vpn

-A wg+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A wg+_fwd -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A wg+_fwd -p tcp -j tcpflags

-A wg+_fwd -j vpn_frwd

-A wg+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j dynamic

-A wg+_in -m conntrack --ctstate INVALID,NEW,UNTRACKED -j smurfs

-A wg+_in -p tcp -j tcpflags

-A wg+_in -j vpn-fw

-A wg+_out -j fw-vpn

COMMIT

Completed on Mon Mar 24 20:06:26 2025

Generated by iptables-save v1.8.9 (nf_tables) on Mon Mar 24 20:06:26 2025

*nat

:PREROUTING ACCEPT [716474:64517211]

:INPUT ACCEPT [399815:29602668]

:OUTPUT ACCEPT [214265:31683281]

:POSTROUTING ACCEPT [236700:33488651]

:eth0_masq - [0:0]

:net_dnat - [0:0]

-A PREROUTING -i eth0 -j net_dnat

-A POSTROUTING -o eth0 -j eth0_masq

-A eth0_masq -s 10.255.247.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.248.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.250.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.251.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.252.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.253.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.254.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 10.255.255.0/24 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 169.254.0.0/16 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 172.16.0.0/12 -j SNAT --to-source 45.13.104.49

-A eth0_masq -s 192.168.0.0/16 -j SNAT --to-source 45.13.104.49

-A net_dnat -p tcp -m tcp --dport 25 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 21 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p udp -m udp --dport 20 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 443 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4433 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4443 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p udp -m udp --dport 10000 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 2222 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4435 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4455 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4466 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4436 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 110 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 143 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 587 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 993 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 995 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 20 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 10090:10100 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 22 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 8080 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 63241 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 22027 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 22028 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 22029 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 4445:4446 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 16881 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p udp -m udp --dport 16881 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 22026 -j DNAT --to-destination 10.255.252.6

-A net_dnat -p tcp -m tcp --dport 80 -j DNAT --to-destination 10.255.252.6

COMMIT

Completed on Mon Mar 24 20:06:26 2025

@Ysurac
Copy link
Owner

Ysurac commented Mar 25, 2025

Oui l'IP VPN côté client a changé et le VPS n'est pas à jour. J'ai fait un fix que je test avant de le mettre dans la branche develop.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants