@tomp offcourse.
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 5000
link/ether hidden_mac brd ff:ff:ff:ff:ff:ff
inet host_pulic_ip/26 brd xyz scope global eth0
valid_lft forever preferred_lft forever
inet public_ip_4/29 brd new_xyz scope global eth0:lxdbr1
valid_lft forever preferred_lft forever
9: lxdbr1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN group default qlen 1000
link/ether 3a:2b:12:5b:e0:60 brd ff:ff:ff:ff:ff:ff
inet 10.172.55.1/24 scope global lxdbr1
valid_lft forever preferred_lft forever
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
default via xx.xx.xx.xx dev eth0
10.172.55.0/24 dev lxdbr1 proto kernel scope link src 10.172.55.1
xx.xx.xx.xx/26 dev eth0 proto kernel scope link src host_pulic_ip
xx.xx.xx.yy/29 dev eth0 proto kernel scope link src public_ip_4
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
lxc network show lxdbr1
config:
ipv4.address: 10.172.55.1/24
ipv4.nat: "true"
ipv4.nat.address: public_ip_4
description: ""
name: lxdbr1
type: bridge
used_by:
- /1.0/instances/c1
managed: true
status: Created
locations:
- none
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
iptables -L -v -n -t nat
[sudo] password for admin:
Chain PREROUTING (policy ACCEPT 55 packets, 3280 bytes)
pkts bytes target prot opt in out source destination
150 8453 PREROUTING_direct all -- * * 0.0.0.0/0 0.0.0.0/0
150 8453 PREROUTING_ZONES_SOURCE all -- * * 0.0.0.0/0 0.0.0.0/0
150 8453 PREROUTING_ZONES all -- * * 0.0.0.0/0 0.0.0.0/0
Chain INPUT (policy ACCEPT 3 packets, 446 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 66 packets, 5002 bytes)
pkts bytes target prot opt in out source destination
294 21842 OUTPUT_direct all -- * * 0.0.0.0/0 0.0.0.0/0
Chain POSTROUTING (policy ACCEPT 66 packets, 5002 bytes)
pkts bytes target prot opt in out source destination
0 0 SNAT all -- * * 10.172.55.0/24 !10.172.55.0/24 /* generated for LXD network lxdbr1 */ to:public_ip_4
294 21842 POSTROUTING_direct all -- * * 0.0.0.0/0 0.0.0.0/0
294 21842 POSTROUTING_ZONES_SOURCE all -- * * 0.0.0.0/0 0.0.0.0/0
294 21842 POSTROUTING_ZONES all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT_direct (1 references)
pkts bytes target prot opt in out source destination
Chain POSTROUTING_ZONES (1 references)
pkts bytes target prot opt in out source destination
0 0 POST_public all -- * eth0 0.0.0.0/0 0.0.0.0/0 [goto]
0 0 POST_mailer all -- * br0 0.0.0.0/0 0.0.0.0/0
0 0 POST_internal all -- * br1 0.0.0.0/0 0.0.0.0/0 [goto]
294 21842 POST_public all -- * + 0.0.0.0/0 0.0.0.0/0 [goto]
Chain POSTROUTING_ZONES_SOURCE (1 references)
pkts bytes target prot opt in out source destination
Chain POST_internal (1 references)
pkts bytes target prot opt in out source destination
0 0 POST_internal_log all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 POST_internal_deny all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 POST_internal_allow all -- * * 0.0.0.0/0 0.0.0.0/0
Chain POST_internal_allow (1 references)
pkts bytes target prot opt in out source destination
Chain POST_internal_deny (1 references)
pkts bytes target prot opt in out source destination
Chain POST_internal_log (1 references)
pkts bytes target prot opt in out source destination
Chain POST_mailer (1 references)
pkts bytes target prot opt in out source destination
0 0 POST_mailer_log all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 POST_mailer_deny all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 POST_mailer_allow all -- * * 0.0.0.0/0 0.0.0.0/0
Chain POST_mailer_allow (1 references)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * !lo 0.0.0.0/0 0.0.0.0/0
Chain POST_mailer_deny (1 references)
pkts bytes target prot opt in out source destination
Chain POST_mailer_log (1 references)
pkts bytes target prot opt in out source destination
Chain POST_public (2 references)
pkts bytes target prot opt in out source destination
294 21842 POST_public_log all -- * * 0.0.0.0/0 0.0.0.0/0
294 21842 POST_public_deny all -- * * 0.0.0.0/0 0.0.0.0/0
294 21842 POST_public_allow all -- * * 0.0.0.0/0 0.0.0.0/0
Chain POST_public_allow (1 references)
pkts bytes target prot opt in out source destination
Chain POST_public_deny (1 references)
pkts bytes target prot opt in out source destination
Chain POST_public_log (1 references)
pkts bytes target prot opt in out source destination
Chain PREROUTING_ZONES (1 references)
pkts bytes target prot opt in out source destination
69 3683 PRE_public all -- eth0 * 0.0.0.0/0 0.0.0.0/0 [goto]
18 1712 PRE_public all -- + * 0.0.0.0/0 0.0.0.0/0 [goto]
Chain PREROUTING_ZONES_SOURCE (1 references)
pkts bytes target prot opt in out source destination
Chain PREROUTING_direct (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_internal (1 references)
pkts bytes target prot opt in out source destination
0 0 PRE_internal_log all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 PRE_internal_deny all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 PRE_internal_allow all -- * * 0.0.0.0/0 0.0.0.0/0
Chain PRE_internal_allow (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_internal_deny (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_internal_log (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_mailer_allow (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_mailer_deny (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_mailer_log (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_public (2 references)
pkts bytes target prot opt in out source destination
150 8453 PRE_public_log all -- * * 0.0.0.0/0 0.0.0.0/0
150 8453 PRE_public_deny all -- * * 0.0.0.0/0 0.0.0.0/0
150 8453 PRE_public_allow all -- * * 0.0.0.0/0 0.0.0.0/0
Chain PRE_public_allow (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_public_deny (1 references)
pkts bytes target prot opt in out source destination
Chain PRE_public_log (1 references)
pkts bytes target prot opt in out source destination
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
nfw list ruleset
sudo: nfw: command not found