istio.io/istio@v0.0.0-20240520182934-d79c90f27776/tools/istio-iptables/pkg/capture/testdata/ipv6-dns-outbound-owner-groups-exclude.golden (about)

     1  iptables -t nat -N ISTIO_INBOUND
     2  iptables -t nat -N ISTIO_REDIRECT
     3  iptables -t nat -N ISTIO_IN_REDIRECT
     4  iptables -t nat -N ISTIO_OUTPUT
     5  iptables -t raw -N ISTIO_OUTPUT
     6  iptables -t nat -A ISTIO_INBOUND -p tcp --dport 15008 -j RETURN
     7  iptables -t nat -A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
     8  iptables -t nat -A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
     9  iptables -t nat -A OUTPUT -p tcp -j ISTIO_OUTPUT
    10  iptables -t nat -A ISTIO_OUTPUT -o lo -s 127.0.0.6/32 -j RETURN
    11  iptables -t nat -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -p tcp -m multiport ! --dports 53,15008 -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
    12  iptables -t nat -A ISTIO_OUTPUT -o lo -p tcp ! --dport 53 -m owner ! --uid-owner 1337 -j RETURN
    13  iptables -t nat -A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
    14  iptables -t nat -A ISTIO_OUTPUT -o lo ! -d 127.0.0.1/32 -p tcp ! --dport 15008 -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
    15  iptables -t nat -A ISTIO_OUTPUT -o lo -p tcp ! --dport 53 -m owner ! --gid-owner 1337 -j RETURN
    16  iptables -t nat -A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
    17  iptables -t nat -A ISTIO_OUTPUT -m owner --gid-owner 888 -j RETURN
    18  iptables -t nat -A ISTIO_OUTPUT -m owner --gid-owner ftp -j RETURN
    19  iptables -t nat -A ISTIO_OUTPUT -d 127.0.0.1/32 -j RETURN
    20  iptables -t nat -A OUTPUT -p udp -j ISTIO_OUTPUT
    21  iptables -t raw -A OUTPUT -p udp -j ISTIO_OUTPUT
    22  iptables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --uid-owner 1337 -j RETURN
    23  iptables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 1337 -j RETURN
    24  iptables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 888 -j RETURN
    25  iptables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner ftp -j RETURN
    26  iptables -t raw -A ISTIO_OUTPUT -p udp --dport 53 -m owner --uid-owner 1337 -j CT --zone 1
    27  iptables -t raw -A ISTIO_OUTPUT -p udp --sport 15053 -m owner --uid-owner 1337 -j CT --zone 2
    28  iptables -t raw -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 1337 -j CT --zone 1
    29  iptables -t raw -A ISTIO_OUTPUT -p udp --sport 15053 -m owner --gid-owner 1337 -j CT --zone 2
    30  ip6tables -t nat -N ISTIO_INBOUND
    31  ip6tables -t nat -N ISTIO_REDIRECT
    32  ip6tables -t nat -N ISTIO_IN_REDIRECT
    33  ip6tables -t nat -N ISTIO_OUTPUT
    34  ip6tables -t raw -N ISTIO_OUTPUT
    35  ip6tables -t nat -A ISTIO_INBOUND -p tcp --dport 15008 -j RETURN
    36  ip6tables -t nat -A ISTIO_REDIRECT -p tcp -j REDIRECT --to-ports 15001
    37  ip6tables -t nat -A ISTIO_IN_REDIRECT -p tcp -j REDIRECT --to-ports 15006
    38  ip6tables -t nat -A OUTPUT -p tcp -j ISTIO_OUTPUT
    39  ip6tables -t nat -A ISTIO_OUTPUT -o lo -s ::6/128 -j RETURN
    40  ip6tables -t nat -A ISTIO_OUTPUT -o lo ! -d ::1/128 -p tcp -m multiport ! --dports 53,15008 -m owner --uid-owner 1337 -j ISTIO_IN_REDIRECT
    41  ip6tables -t nat -A ISTIO_OUTPUT -o lo -p tcp ! --dport 53 -m owner ! --uid-owner 1337 -j RETURN
    42  ip6tables -t nat -A ISTIO_OUTPUT -m owner --uid-owner 1337 -j RETURN
    43  ip6tables -t nat -A ISTIO_OUTPUT -o lo ! -d ::1/128 -p tcp ! --dport 15008 -m owner --gid-owner 1337 -j ISTIO_IN_REDIRECT
    44  ip6tables -t nat -A ISTIO_OUTPUT -o lo -p tcp ! --dport 53 -m owner ! --gid-owner 1337 -j RETURN
    45  ip6tables -t nat -A ISTIO_OUTPUT -m owner --gid-owner 1337 -j RETURN
    46  ip6tables -t nat -A ISTIO_OUTPUT -m owner --gid-owner 888 -j RETURN
    47  ip6tables -t nat -A ISTIO_OUTPUT -m owner --gid-owner ftp -j RETURN
    48  ip6tables -t nat -A ISTIO_OUTPUT -d ::1/128 -j RETURN
    49  ip6tables -t nat -A OUTPUT -p udp -j ISTIO_OUTPUT
    50  ip6tables -t raw -A OUTPUT -p udp -j ISTIO_OUTPUT
    51  ip6tables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --uid-owner 1337 -j RETURN
    52  ip6tables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 1337 -j RETURN
    53  ip6tables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 888 -j RETURN
    54  ip6tables -t nat -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner ftp -j RETURN
    55  ip6tables -t raw -A ISTIO_OUTPUT -p udp --dport 53 -m owner --uid-owner 1337 -j CT --zone 1
    56  ip6tables -t raw -A ISTIO_OUTPUT -p udp --sport 15053 -m owner --uid-owner 1337 -j CT --zone 2
    57  ip6tables -t raw -A ISTIO_OUTPUT -p udp --dport 53 -m owner --gid-owner 1337 -j CT --zone 1
    58  ip6tables -t raw -A ISTIO_OUTPUT -p udp --sport 15053 -m owner --gid-owner 1337 -j CT --zone 2
    59  iptables-save
    60  ip6tables-save