da abbio90 » mar 23 mar 2021, 23:34
ip firewall nat
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; WAN
chain=srcnat action=masquerade out-interface=pppoe-out1 log=no log-prefix=""
1 ;;; WAN2
chain=srcnat action=masquerade out-interface=vlan40>>studio log=no log-prefix=""
2 ;;; masquerade DNS
chain=srcnat action=masquerade protocol=udp dst-address=10.246.159.222 src-address-list=masq DNS dst-port=53 log=no
log-prefix=""
3 chain=srcnat action=masquerade protocol=tcp dst-address=10.246.159.222 src-address-list=masq DNS dst-port=53 log=no
log-prefix=""
4 ;;; local-WAN
chain=srcnat action=masquerade dst-address=192.168.178.0/24 log=no log-prefix=""
5 ;;; VPN
chain=srcnat action=masquerade src-address=192.168.17.0/24 log=no log-prefix=""
6 ;;; MASQUERADE DAHUA
chain=srcnat action=masquerade src-address-list=OUT VPN out-interface=Vpn CHR log=no log-prefix=""
7 ;;; DST-NAT hairpinat - visione VTO che esce con CHR
chain=dstnat action=dst-nat to-addresses=10.246.161.2 protocol=tcp dst-address=83.xxx.xx.145 dst-port=37777 log=no
log-prefix=""
8 ;;; HAIRPINAT LAN
chain=srcnat action=masquerade src-address=10.246.159.0/24 dst-address=10.246.159.0/24 log=no log-prefix=""
9 ;;; DST hairpinat Hassio
chain=dstnat action=dst-nat to-addresses=10.246.159.221 to-ports=8123 protocol=tcp src-address=10.246.159.0/24
dst-address-list=WAN-IP dst-port=443 log=no log-prefix=""
10 ;;; hassio dst-port
chain=dstnat action=dst-nat to-addresses=10.246.159.221 to-ports=8123 protocol=tcp in-interface=pppoe-out1
dst-port=443 log=no log-prefix=""
11 X ;;; proxmox DST-PORT
chain=dstnat action=dst-nat to-addresses=10.246.159.220 to-ports=8006 protocol=tcp in-interface=pppoe-out1
dst-port=8006 log=no log-prefix=""
ip firewall mangle print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; OUT VTO con VPN
chain=prerouting action=mark-routing new-routing-mark=to-vpn passthrough=yes dst-address=!10.246.159.0/24
src-address-list=OUT VPN log=no log-prefix=""
il firewall non centra nulla...ho resettato i contatori e non lavorano i drop quando attivo il dst-nat..
inoltre ho disabilitato tutte le regole per prova e non cambia nulla...