root@OpenWrt:~# iptables -L -vn
Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 4219 452K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 691 89082 input_rule all -- * * 0.0.0.0/0 0.0.0.0/0 523 49686 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 22 1144 syn_flood tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 151 33512 zone_lan_input all -- br-lan * 0.0.0.0/0 0.0.0.0 /0 0 0 zone_wan_input all -- ds-wan * 0.0.0.0/0 0.0.0.0 /0 17 5884 zone_wan_input all -- eth1.2 * 0.0.0.0/0 0.0.0.0 /0
Chain FORWARD (policy DROP 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 75 4674 forwarding_rule all -- * * 0.0.0.0/0 0.0.0. 0/0 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 32 1652 zone_lan_forward all -- br-lan * 0.0.0.0/0 0.0.0 .0/0 43 3022 zone_wan_forward all -- ds-wan * 0.0.0.0/0 0.0.0 .0/0 0 0 zone_wan_forward all -- eth1.2 * 0.0.0.0/0 0.0.0 .0/0 43 3022 reject all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 4219 452K ACCEPT all -- * lo 0.0.0.0/0 0.0.0.0/0 653 245K output_rule all -- * * 0.0.0.0/0 0.0.0.0/0 605 241K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED 4 1053 zone_lan_output all -- * br-lan 0.0.0.0/0 0.0.0. 0/0 44 2823 zone_wan_output all -- * ds-wan 0.0.0.0/0 0.0.0. 0/0 0 0 zone_wan_output all -- * eth1.2 0.0.0.0/0 0.0.0. 0/0
Chain forwarding_lan_rule (1 references) pkts bytes target prot opt in out source destination
Chain forwarding_rule (1 references) pkts bytes target prot opt in out source destination
Chain forwarding_wan_rule (1 references) pkts bytes target prot opt in out source destination
Chain input_lan_rule (1 references) pkts bytes target prot opt in out source destination
Chain input_rule (1 references) pkts bytes target prot opt in out source destination
Chain input_wan_rule (1 references) pkts bytes target prot opt in out source destination
Chain output_lan_rule (1 references) pkts bytes target prot opt in out source destination
Chain output_rule (1 references) pkts bytes target prot opt in out source destination
Chain output_wan_rule (1 references) pkts bytes target prot opt in out source destination
Chain reject (5 references) pkts bytes target prot opt in out source destination 43 3022 REJECT tcp -- * * 0.0.0.0/0 0.0.0.0/0 reject-with tcp-reset 9 2772 REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain syn_flood (1 references) pkts bytes target prot opt in out source destination 22 1144 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 25/sec burst 50 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_dest_ACCEPT (4 references) pkts bytes target prot opt in out source destination 4 1053 ACCEPT all -- * br-lan 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_forward (1 references) pkts bytes target prot opt in out source destination 32 1652 forwarding_lan_rule all -- * * 0.0.0.0/0 0. 0.0.0/0 32 1652 zone_wan_dest_ACCEPT all -- * * 0.0.0.0/0 0 .0.0.0/0 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT 0 0 zone_lan_dest_ACCEPT all -- * * 0.0.0.0/0 0 .0.0.0/0
Chain zone_lan_input (1 references) pkts bytes target prot opt in out source destination 151 33512 input_lan_rule all -- * * 0.0.0.0/0 0.0.0.0 /0 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT 151 33512 zone_lan_src_ACCEPT all -- * * 0.0.0.0/0 0. 0.0.0/0
Chain zone_lan_output (1 references) pkts bytes target prot opt in out source destination 4 1053 output_lan_rule all -- * * 0.0.0.0/0 0.0.0. 0/0 4 1053 zone_lan_dest_ACCEPT all -- * * 0.0.0.0/0 0 .0.0.0/0
Chain zone_lan_src_ACCEPT (1 references) pkts bytes target prot opt in out source destination 151 33512 ACCEPT all -- br-lan * 0.0.0.0/0 0.0.0.0/0 ctstate NEW,UNTRACKED
Chain zone_wan_dest_ACCEPT (2 references) pkts bytes target prot opt in out source destination 76 4475 ACCEPT all -- * ds-wan 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * eth1.2 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_dest_REJECT (1 references) pkts bytes target prot opt in out source destination 0 0 reject all -- * ds-wan 0.0.0.0/0 0.0.0.0/0 0 0 reject all -- * eth1.2 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_forward (2 references) pkts bytes target prot opt in out source destination 43 3022 forwarding_wan_rule all -- * * 0.0.0.0/0 0. 0.0.0/0 0 0 zone_lan_dest_ACCEPT esp -- * * 0.0.0.0/0 0 .0.0.0/0 0 0 zone_lan_dest_ACCEPT udp -- * * 0.0.0.0/0 0 .0.0.0/0 udp dpt:500 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT 43 3022 zone_wan_dest_REJECT all -- * * 0.0.0.0/0 0 .0.0.0/0
Chain zone_wan_input (2 references) pkts bytes target prot opt in out source destination 17 5884 input_wan_rule all -- * * 0.0.0.0/0 0.0.0.0 /0 8 3112 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:68 0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmptype 8 0 0 ACCEPT 2 -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT 9 2772 zone_wan_src_REJECT all -- * * 0.0.0.0/0 0. 0.0.0/0
Chain zone_wan_output (2 references) pkts bytes target prot opt in out source destination 44 2823 output_wan_rule all -- * * 0.0.0.0/0 0.0.0. 0/0 44 2823 zone_wan_dest_ACCEPT all -- * * 0.0.0.0/0 0 .0.0.0/0
Chain zone_wan_src_REJECT (1 references) pkts bytes target prot opt in out source destination 0 0 reject all -- ds-wan * 0.0.0.0/0 0.0.0.0/0 9 2772 reject all -- eth1.2 * 0.0.0.0/0 0.0.0.0/0
root@OpenWrt:~# iptables -t nat -L -vn
Chain PREROUTING (policy ACCEPT 162 packets, 29744 bytes) pkts bytes target prot opt in out source destination 162 29744 prerouting_rule all -- * * 0.0.0.0/0 0.0.0.0/0 130 26321 zone_lan_prerouting all -- br-lan * 0.0.0.0/0 0.0.0.0/0 31 3034 zone_wan_prerouting all -- ds-wan * 0.0.0.0/0 0.0.0.0/0 1 389 zone_wan_prerouting all -- eth1.2 * 0.0.0.0/0 0.0.0.0/0
Chain INPUT (policy ACCEPT 35 packets, 3411 bytes) pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 2171 packets, 163K bytes) pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 2143 packets, 161K bytes) pkts bytes target prot opt in out source destination 2213 165K postrouting_rule all -- * * 0.0.0.0/0 0.0.0.0/0 70 3867 ACCEPT all -- * ds-wan 0.0.0.0/0 0.0.0.0/0 3 704 zone_lan_postrouting all -- * br-lan 0.0.0.0/0 0.0.0.0/0 0 0 zone_wan_postrouting all -- * ds-wan 0.0.0.0/0 0.0.0.0/0 0 0 zone_wan_postrouting all -- * eth1.2 0.0.0.0/0 0.0.0.0/0
Chain postrouting_lan_rule (1 references) pkts bytes target prot opt in out source destination
Chain postrouting_rule (1 references) pkts bytes target prot opt in out source destination
Chain postrouting_wan_rule (1 references) pkts bytes target prot opt in out source destination
Chain prerouting_lan_rule (1 references) pkts bytes target prot opt in out source destination
Chain prerouting_rule (1 references) pkts bytes target prot opt in out source destination
Chain prerouting_wan_rule (1 references) pkts bytes target prot opt in out source destination
Chain zone_lan_postrouting (1 references) pkts bytes target prot opt in out source destination 3 704 postrouting_lan_rule all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_lan_prerouting (1 references) pkts bytes target prot opt in out source destination 130 26321 prerouting_lan_rule all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_postrouting (2 references) pkts bytes target prot opt in out source destination 0 0 postrouting_wan_rule all -- * * 0.0.0.0/0 0.0.0.0/0
Chain zone_wan_prerouting (2 references) pkts bytes target prot opt in out source destination 32 3423 prerouting_wan_rule all -- * * 0.0.0.0/0 0.0.0.0/0
root@OpenWrt:~# ip link
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 532 link/ether 60:38:e0:c5:45:b0 brd ff:ff:ff:ff:ff:ff
3: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 532 link/ether 62:38:e0:c5:45:b0 brd ff:ff:ff:ff:ff:ff
5: ip6tnl0@NONE: <NOARP> mtu 1452 qdisc noop state DOWN qlen 1000 link/tunnel6 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00 brd 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
6: wlan0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000 link/ether 60:38:e0:c5:45:b2 brd ff:ff:ff:ff:ff:ff
7: wlan1: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000 link/ether 60:38:e0:c5:45:b1 brd ff:ff:ff:ff:ff:ff
8: mlan0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000 link/ether 60:38:e0:c5:45:b3 brd ff:ff:ff:ff:ff:ff
9: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP qlen 1000 link/ether 62:38:e0:c5:45:b0 brd ff:ff:ff:ff:ff:ff
10: eth0.1@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master br-lan state UP qlen 1000 link/ether 62:38:e0:c5:45:b0 brd ff:ff:ff:ff:ff:ff
11: eth1.2@eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP qlen 1000 link/ether 60:38:e0:c5:45:b0 brd ff:ff:ff:ff:ff:ff
12: ds-wan@NONE: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1280 qdisc noqueue state UNKNOWN qlen 1000 link/tunnel6 2a:02:xx:xx:xx:xx:00:0c:xx:6d:80:2d:8e:3b:5e:1f peer 2a:xx:xx:xx:xx:00:00:00:00:00:00:00:00:13:40:00