# Generated by iptables-save v1.4.21 on Sun Aug 16 11:38:50 2015 *nat :PREROUTING ACCEPT [5546:445703] :INPUT ACCEPT [5422:421384] :OUTPUT ACCEPT [217:17738] :POSTROUTING ACCEPT [217:17738] -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535 -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535 -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE COMMIT # Completed on Sun Aug 16 11:38:50 2015 # Generated by iptables-save v1.4.21 on Sun Aug 16 11:38:50 2015 *mangle :PREROUTING ACCEPT [150352:92864345] :INPUT ACCEPT [150228:92840026] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [118770:112294367] :POSTROUTING ACCEPT [118770:112294367] -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill COMMIT # Completed on Sun Aug 16 11:38:50 2015 # Generated by iptables-save v1.4.21 on Sun Aug 16 11:38:50 2015 *filter :INPUT ACCEPT [150228:92840026] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [118770:112294367] -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT -A FORWARD -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT -A FORWARD -i virbr0 -o virbr0 -j ACCEPT -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-unreachable -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-unreachable -A OUTPUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT COMMIT # Completed on Sun Aug 16 11:38:50 2015