From 5dfd40802647bee8bdbf189798931155fb0c52b8 Mon Sep 17 00:00:00 2001 From: Andy Bavier Date: Fri, 25 Jul 2008 19:24:43 +0000 Subject: [PATCH] Clean up --- PlanetLabConf/iptables-Internet2 | 43 +++++++++++++------------------- 1 file changed, 17 insertions(+), 26 deletions(-) diff --git a/PlanetLabConf/iptables-Internet2 b/PlanetLabConf/iptables-Internet2 index 04331f5..2c8a807 100644 --- a/PlanetLabConf/iptables-Internet2 +++ b/PlanetLabConf/iptables-Internet2 @@ -1,38 +1,29 @@ -# Iptables rules for Internet2 (exempt) nodes. Nodes sending traffic to any of the IPs -# in the Internet2 ipset (hash) will end up the the slice's exempt queue. This supersedes the default config that lives in svn/iptables/planetlab-config -# -# $Id$ -# -# Generated by iptables-save v1.3.8 on Fri Jul 25 15:09:03 2008 -*nat -:PREROUTING ACCEPT [0:0] -:POSTROUTING ACCEPT [0:0] -:OUTPUT ACCEPT [0:0] -COMMIT -# Completed on Fri Jul 25 15:09:03 2008 -# Generated by iptables-save v1.3.8 on Fri Jul 25 15:09:03 2008 +# Iptables rules for Internet2 (exempt) nodes. Nodes sending traffic +# to any of the IPs in the Internet2 ipset (hash) will end up the the +# slice's exempt queue. This supersedes the default config that lives +# in svn/iptables/planetlab-config + *filter -:INPUT ACCEPT [0:0] -:FORWARD ACCEPT [0:0] -:OUTPUT ACCEPT [0:0] -:BLACKLIST - [0:0] -:LOGDROP - [0:0] +:INPUT ACCEPT +:FORWARD ACCEPT +:OUTPUT ACCEPT +:BLACKLIST - +:LOGDROP - -A OUTPUT -j BLACKLIST -A OUTPUT -o eth0 -j ULOG --ulog-cprange 54 --ulog-qthreshold 16 -A LOGDROP -j LOG -A LOGDROP -j DROP COMMIT -# Completed on Fri Jul 25 15:09:03 2008 -# Generated by iptables-save v1.3.8 on Fri Jul 25 15:09:03 2008 + *mangle -:PREROUTING ACCEPT [0:0] -:INPUT ACCEPT [0:0] -:FORWARD ACCEPT [0:0] -:OUTPUT ACCEPT [0:0] -:POSTROUTING ACCEPT [0:0] +:PREROUTING ACCEPT +:INPUT ACCEPT +:FORWARD ACCEPT +:OUTPUT ACCEPT +:POSTROUTING ACCEPT -A INPUT -j MARK --copy-xid 0x0 -A POSTROUTING -j MARK --copy-xid 0x0 -A POSTROUTING -j CLASSIFY --set-class 0001:1000 --add-mark -A POSTROUTING -m set --set Internet2 dst -j CLASSIFY --set-class 0001:2000 --add-mark COMMIT -# Completed on Fri Jul 25 15:09:03 2008 + -- 2.43.0