iptables -v -L
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 Trace udp -- any any anywhere anywhere udp dpt:8123 ctstate NEW
0 0 Trace tcp -- any any anywhere anywhere tcp dpt:8123 ctstate NEW
0 0 ACCEPT all -- lo any anywhere anywhere /* !fw3 */
1188 86018 input_rule all -- any any anywhere anywhere /* !fw3: Custom input rule chain */
202 33947 ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED /* !fw3 */
930 48360 syn_flood tcp -- any any anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN /* !fw3 */
959 50602 zone_lan_input all -- br-lan any anywhere anywhere /* !fw3 */
0 0 zone_wan_input all -- eth0.2 any anywhere anywhere /* !fw3 */
27 1469 zone_wan_input all -- wwan0 any anywhere anywhere /* !fw3 */
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
11623 12M forwarding_rule all -- any any anywhere anywhere /* !fw3: Custom forwarding rule chain */
11437 12M ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED /* !fw3 */
186 50891 zone_lan_forward all -- br-lan any anywhere anywhere /* !fw3 */
0 0 zone_wan_forward all -- eth0.2 any anywhere anywhere /* !fw3 */
0 0 zone_wan_forward all -- wwan0 any anywhere anywhere /* !fw3 */
0 0 reject all -- any any anywhere anywhere /* !fw3 */
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- any lo anywhere anywhere /* !fw3 */
1217 192K output_rule all -- any any anywhere anywhere /* !fw3: Custom output rule chain */
1137 187K ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED /* !fw3 */
2 224 zone_lan_output all -- any br-lan anywhere anywhere /* !fw3 */
0 0 zone_wan_output all -- any eth0.2 anywhere anywhere /* !fw3 */
78 4589 zone_wan_output all -- any wwan0 anywhere anywhere /* !fw3 */
Chain LOG_Trace (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG tcp -- any any anywhere anywhere tcp dpt:8123 LOG level warning prefix "<[[--- Trace 8123 ---]]> : "
0 0 udp -- any any anywhere anywhere udp dpt:8123
Chain Trace (2 references)
pkts bytes target prot opt in out source destination
0 0 LOG_Trace tcp -- any any anywhere anywhere tcp dpt:8123
0 0 LOG_Trace udp -- any any anywhere anywhere udp dpt:8123
Chain forwarding_lan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain forwarding_rule (1 references)
pkts bytes target prot opt in out source destination
Chain forwarding_wan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain input_lan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain input_rule (1 references)
pkts bytes target prot opt in out source destination
Chain input_wan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain output_lan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain output_rule (1 references)
pkts bytes target prot opt in out source destination
Chain output_wan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain reject (3 references)
pkts bytes target prot opt in out source destination
27 1469 REJECT tcp -- any any anywhere anywhere /* !fw3 */ reject-with tcp-reset
0 0 REJECT all -- any any anywhere anywhere /* !fw3 */ reject-with icmp-port-unreachable
Chain syn_flood (1 references)
pkts bytes target prot opt in out source destination
930 48360 RETURN tcp -- any any anywhere anywhere tcp flags:FIN,SYN,RST,ACK/SYN limit: avg 25/sec burst 50 /* !fw3 */
0 0 DROP all -- any any anywhere anywhere /* !fw3 */
Chain zone_lan_dest_ACCEPT (4 references)
pkts bytes target prot opt in out source destination
2 224 ACCEPT all -- any br-lan anywhere anywhere /* !fw3 */
Chain zone_lan_forward (1 references)
pkts bytes target prot opt in out source destination
186 50891 forwarding_lan_rule all -- any any anywhere anywhere /* !fw3: Custom lan forwarding rule chain */
186 50891 zone_wan_dest_ACCEPT all -- any any anywhere anywhere /* !fw3: Zone lan to wan forwarding policy */
6 301 ACCEPT all -- any any anywhere anywhere ctstate DNAT /* !fw3: Accept port forwards */
0 0 zone_lan_dest_ACCEPT all -- any any anywhere anywhere /* !fw3 */
Chain zone_lan_input (1 references)
pkts bytes target prot opt in out source destination
959 50602 input_lan_rule all -- any any anywhere anywhere /* !fw3: Custom lan input rule chain */
0 0 ACCEPT all -- any any anywhere anywhere ctstate DNAT /* !fw3: Accept port redirections */
959 50602 zone_lan_src_ACCEPT all -- any any anywhere anywhere /* !fw3 */
Chain zone_lan_output (1 references)
pkts bytes target prot opt in out source destination
2 224 output_lan_rule all -- any any anywhere anywhere /* !fw3: Custom lan output rule chain */
2 224 zone_lan_dest_ACCEPT all -- any any anywhere anywhere /* !fw3 */
Chain zone_lan_src_ACCEPT (1 references)
pkts bytes target prot opt in out source destination
959 50602 ACCEPT all -- br-lan any anywhere anywhere ctstate NEW,UNTRACKED /* !fw3 */
Chain zone_wan_dest_ACCEPT (3 references)
pkts bytes target prot opt in out source destination
0 0 DROP all -- any eth0.2 anywhere anywhere ctstate INVALID /* !fw3: Prevent NAT leakage */
0 0 ACCEPT all -- any eth0.2 anywhere anywhere /* !fw3 */
31 1348 DROP all -- any wwan0 anywhere anywhere ctstate INVALID /* !fw3: Prevent NAT leakage */
227 53831 ACCEPT all -- any wwan0 anywhere anywhere /* !fw3 */
Chain zone_wan_forward (2 references)
pkts bytes target prot opt in out source destination
0 0 forwarding_wan_rule all -- any any anywhere anywhere /* !fw3: Custom wan forwarding rule chain */
0 0 zone_lan_dest_ACCEPT esp -- any any anywhere anywhere /* !fw3: Allow-IPSec-ESP */
0 0 zone_lan_dest_ACCEPT udp -- any any anywhere anywhere udp dpt:isakmp /* !fw3: Allow-ISAKMP */
0 0 ACCEPT all -- any any anywhere anywhere ctstate DNAT /* !fw3: Accept port forwards */
0 0 zone_wan_dest_ACCEPT all -- any any anywhere anywhere /* !fw3 */
Chain zone_wan_input (2 references)
pkts bytes target prot opt in out source destination
27 1469 input_wan_rule all -- any any anywhere anywhere /* !fw3: Custom wan input rule chain */
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:bootpc /* !fw3: Allow-DHCP-Renew */
0 0 ACCEPT icmp -- any any anywhere anywhere icmp echo-request /* !fw3: Allow-Ping */
0 0 ACCEPT igmp -- any any anywhere anywhere /* !fw3: Allow-IGMP */
0 0 ACCEPT all -- any any anywhere anywhere ctstate DNAT /* !fw3: Accept port redirections */
27 1469 zone_wan_src_REJECT all -- any any anywhere anywhere /* !fw3 */
Chain zone_wan_output (2 references)
pkts bytes target prot opt in out source destination
78 4589 output_wan_rule all -- any any anywhere anywhere /* !fw3: Custom wan output rule chain */
78 4589 zone_wan_dest_ACCEPT all -- any any anywhere anywhere /* !fw3 */
Chain zone_wan_src_REJECT (1 references)
pkts bytes target prot opt in out source destination
0 0 reject all -- eth0.2 any anywhere anywhere /* !fw3 */
27 1469 reject all -- wwan0 any anywhere anywhere /* !fw3 */
iptables -v -L -t nat
Chain PREROUTING (policy ACCEPT 1725 packets, 193K bytes)
pkts bytes target prot opt in out source destination
1731 194K prerouting_rule all -- any any anywhere anywhere /* !fw3: Custom prerouting rule chain */
1729 193K zone_lan_prerouting all -- br-lan any anywhere anywhere /* !fw3 */
0 0 zone_wan_prerouting all -- eth0.2 any anywhere anywhere /* !fw3 */
2 205 zone_wan_prerouting all -- wwan0 any anywhere anywhere /* !fw3 */
Chain INPUT (policy ACCEPT 1233 packets, 64932 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 109 packets, 7409 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 33 packets, 2360 bytes)
pkts bytes target prot opt in out source destination
260 54992 postrouting_rule all -- any any anywhere anywhere /* !fw3: Custom postrouting rule chain */
6 301 zone_lan_postrouting all -- any br-lan anywhere anywhere /* !fw3 */
0 0 zone_wan_postrouting all -- any eth0.2 anywhere anywhere /* !fw3 */
222 52451 zone_wan_postrouting all -- any wwan0 anywhere anywhere /* !fw3 */
Chain postrouting_lan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain postrouting_rule (1 references)
pkts bytes target prot opt in out source destination
Chain postrouting_wan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_lan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_rule (1 references)
pkts bytes target prot opt in out source destination
Chain prerouting_wan_rule (1 references)
pkts bytes target prot opt in out source destination
Chain zone_lan_postrouting (1 references)
pkts bytes target prot opt in out source destination
6 301 postrouting_lan_rule all -- any any anywhere anywhere /* !fw3: Custom lan postrouting rule chain */
0 0 SNAT tcp -- any any 192.168.1.0/24 HASSIO.lan tcp dpt:https /* !fw3: hassio443 (reflection) */ to:192.168.1.1
0 0 SNAT tcp -- any any 192.168.1.0/24 HASSIO.lan tcp dpt:www /* !fw3: hasio80 (reflection) */ to:192.168.1.1
6 301 SNAT tcp -- any any 192.168.1.0/24 HASSIO.lan tcp dpt:8123 /* !fw3: hasio8123 (reflection) */ to:192.168.1.1
0 0 SNAT udp -- any any 192.168.1.0/24 HASSIO.lan udp dpt:8123 /* !fw3: hasio8123 (reflection) */ to:192.168.1.1
Chain zone_lan_prerouting (1 references)
pkts bytes target prot opt in out source destination
1729 193K prerouting_lan_rule all -- any any anywhere anywhere /* !fw3: Custom lan prerouting rule chain */
0 0 DNAT tcp -- any any 192.168.1.0/24 apn-5-60-8-76.dynamic.gprs.plus.pl tcp dpt:https /* !fw3: hassio443 (reflection) */ to:192.168.1.166:443
0 0 DNAT tcp -- any any 192.168.1.0/24 apn-5-60-8-76.dynamic.gprs.plus.pl tcp dpt:www /* !fw3: hasio80 (reflection) */ to:192.168.1.166:80
6 301 DNAT tcp -- any any 192.168.1.0/24 apn-5-60-8-76.dynamic.gprs.plus.pl tcp dpt:8123 /* !fw3: hasio8123 (reflection) */ to:192.168.1.166:8123
0 0 DNAT udp -- any any 192.168.1.0/24 apn-5-60-8-76.dynamic.gprs.plus.pl udp dpt:8123 /* !fw3: hasio8123 (reflection) */ to:192.168.1.166:8123
Chain zone_wan_postrouting (2 references)
pkts bytes target prot opt in out source destination
222 52451 postrouting_wan_rule all -- any any anywhere anywhere /* !fw3: Custom wan postrouting rule chain */
222 52451 MASQUERADE all -- any any anywhere anywhere /* !fw3 */
Chain zone_wan_prerouting (2 references)
pkts bytes target prot opt in out source destination
2 205 prerouting_wan_rule all -- any any anywhere anywhere /* !fw3: Custom wan prerouting rule chain */
0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:https /* !fw3: hassio443 */ to:192.168.1.166:443
0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:www /* !fw3: hasio80 */ to:192.168.1.166:80
0 0 DNAT tcp -- any any anywhere anywhere tcp dpt:8123 /* !fw3: hasio8123 */ to:192.168.1.166:8123
0 0 DNAT udp -- any any anywhere anywhere udp dpt:8123 /* !fw3: hasio8123 */ to:192.168.1.166:8123