# Generated by iptables-save v1.8.9 on Thu Jul 18 19:07:45 2024
*raw
:PREROUTING ACCEPT [330917937:301970615511]
:OUTPUT ACCEPT [3912156:2099052544]
COMMIT
# Completed on Thu Jul 18 19:07:45 2024
# Generated by iptables-save v1.8.9 on Thu Jul 18 19:07:45 2024
*filter
:INPUT ACCEPT [13:784]
:FORWARD ACCEPT [644:33190]
:OUTPUT ACCEPT [2:152]
:GROUP-clusterblocklist-IN - [0:0]
:GROUP-clusterblocklist-OUT - [0:0]
:GROUP-remotemanagement-IN - [0:0]
:GROUP-remotemanagement-OUT - [0:0]
:GROUP-vm-generalports-IN - [0:0]
:GROUP-vm-generalports-OUT - [0:0]
:PVEFW-Drop - [0:0]
:PVEFW-DropBroadcast - [0:0]
:PVEFW-FORWARD - [0:0]
:PVEFW-FWBR-IN - [0:0]
:PVEFW-FWBR-OUT - [0:0]
:PVEFW-HOST-IN - [0:0]
:PVEFW-HOST-OUT - [0:0]
:PVEFW-INPUT - [0:0]
:PVEFW-OUTPUT - [0:0]
:PVEFW-Reject - [0:0]
:PVEFW-SET-ACCEPT-MARK - [0:0]
:PVEFW-logflags - [0:0]
:PVEFW-reject - [0:0]
:PVEFW-smurflog - [0:0]
:PVEFW-smurfs - [0:0]
:PVEFW-tcpflags - [0:0]
:f2b-sshd - [0:0]
:tap101i0-IN - [0:0]
:tap101i0-OUT - [0:0]
:tap102i0-IN - [0:0]
:tap102i0-OUT - [0:0]
:tap200i0-IN - [0:0]
:tap200i0-OUT - [0:0]
-A INPUT -p tcp -m multiport --dports 22,2222 -j f2b-sshd
-A INPUT -s 103.145.253.165/32 -j DROP
-A INPUT -j PVEFW-INPUT
-A FORWARD -j PVEFW-FORWARD
-A OUTPUT -j PVEFW-OUTPUT
-A GROUP-clusterblocklist-IN -j MARK --set-xmark 0x0/0x80000000
-A GROUP-clusterblocklist-IN -m set --match-set PVEFW-3700B5D8 src -m limit --limit 1/sec -j NFLOG --nflog-prefix ":0:6:GROUP-clusterblocklist-IN: "
-A GROUP-clusterblocklist-IN -m set --match-set PVEFW-3700B5D8 src -j DROP
-A GROUP-clusterblocklist-IN -m comment --comment "PVESIG:OgKsFz9l97esJKqlVSGfscndhPg"
-A GROUP-clusterblocklist-OUT -j MARK --set-xmark 0x0/0x80000000
-A GROUP-clusterblocklist-OUT -m comment --comment "PVESIG:KvVvAcbu7fxAOcEKcZV8MrigwCc"
-A GROUP-remotemanagement-IN -j MARK --set-xmark 0x0/0x80000000
-A GROUP-remotemanagement-IN -p tcp -m tcp --dport 3128 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-remotemanagement-IN -p tcp -m tcp --dport 8006 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-remotemanagement-IN -p tcp -m tcp --dport 2222 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-remotemanagement-IN -s 80.24.1.207/32 -p icmp -m icmp --icmp-type 8 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-remotemanagement-IN -s 81.137.216.70/32 -p icmp -m icmp --icmp-type 8 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-remotemanagement-IN -m comment --comment "PVESIG:cgrRXOBmAIjJ9L+Ujk2v8Q7nhjE"
-A GROUP-remotemanagement-OUT -j MARK --set-xmark 0x0/0x80000000
-A GROUP-remotemanagement-OUT -m comment --comment "PVESIG:PEnB39dzhaYQmiqyZ4MuobUpSbc"
-A GROUP-vm-generalports-IN -j MARK --set-xmark 0x0/0x80000000
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 2222 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p icmp -m icmp --icmp-type 8 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --dport 1194 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 25 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 465 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 587 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 11371 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --sport 500 --dport 500 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p ah -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --dport 500 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --dport 4500 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p esp -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --sport 500 --dport 500 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p esp -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 993 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 993 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 465 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 25 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 443 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p udp -m udp --dport 53 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 53 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -p tcp -m tcp --dport 80 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-IN -m comment --comment "PVESIG:9UWLtGX58RUO8GkFyOHMbmPIwck"
-A GROUP-vm-generalports-OUT -j MARK --set-xmark 0x0/0x80000000
-A GROUP-vm-generalports-OUT -p udp -m udp --dport 53 -m limit --limit 1/sec -j NFLOG --nflog-prefix ":0:6:GROUP-vm-generalports-OUT: "
-A GROUP-vm-generalports-OUT -p udp -m udp --dport 53 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-OUT -p tcp -m tcp --dport 53 -m limit --limit 1/sec -j NFLOG --nflog-prefix ":0:6:GROUP-vm-generalports-OUT: "
-A GROUP-vm-generalports-OUT -p tcp -m tcp --dport 53 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-OUT -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j NFLOG --nflog-prefix ":0:6:GROUP-vm-generalports-OUT: "
-A GROUP-vm-generalports-OUT -p icmp -m icmp --icmp-type 8 -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-OUT -m limit --limit 1/sec -j NFLOG --nflog-prefix ":0:6:GROUP-vm-generalports-OUT: "
-A GROUP-vm-generalports-OUT -g PVEFW-SET-ACCEPT-MARK
-A GROUP-vm-generalports-OUT -m comment --comment "PVESIG:4PAcW7m2wtCG/fOKesv8UFij/yc"
-A PVEFW-Drop -j PVEFW-DropBroadcast
-A PVEFW-Drop -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
-A PVEFW-Drop -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A PVEFW-Drop -m conntrack --ctstate INVALID -j DROP
-A PVEFW-Drop -p udp -m multiport --dports 135,445 -j DROP
-A PVEFW-Drop -p udp -m udp --dport 137:139 -j DROP
-A PVEFW-Drop -p udp -m udp --sport 137 --dport 1024:65535 -j DROP
-A PVEFW-Drop -p tcp -m multiport --dports 135,139,445 -j DROP
-A PVEFW-Drop -p udp -m udp --dport 1900 -j DROP
-A PVEFW-Drop -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
-A PVEFW-Drop -p udp -m udp --sport 53 -j DROP
-A PVEFW-Drop -m comment --comment "PVESIG:83WlR/a4wLbmURFqMQT3uJSgIG8"
-A PVEFW-DropBroadcast -m addrtype --dst-type BROADCAST -j DROP
-A PVEFW-DropBroadcast -m addrtype --dst-type MULTICAST -j DROP
-A PVEFW-DropBroadcast -m addrtype --dst-type ANYCAST -j DROP
-A PVEFW-DropBroadcast -d 224.0.0.0/4 -j DROP
-A PVEFW-DropBroadcast -m comment --comment "PVESIG:NyjHNAtFbkH7WGLamPpdVnxHy4w"
-A PVEFW-FORWARD -m conntrack --ctstate INVALID -j DROP
-A PVEFW-FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A PVEFW-FORWARD -m physdev --physdev-in fwln+ --physdev-is-bridged -j PVEFW-FWBR-IN
-A PVEFW-FORWARD -m physdev --physdev-out fwln+ --physdev-is-bridged -j PVEFW-FWBR-OUT
-A PVEFW-FORWARD -m comment --comment "PVESIG:qnNexOcGa+y+jebd4dAUqFSp5nw"
-A PVEFW-FWBR-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
-A PVEFW-FWBR-IN -m physdev --physdev-out tap101i0 --physdev-is-bridged -j tap101i0-IN
-A PVEFW-FWBR-IN -m physdev --physdev-out tap102i0 --physdev-is-bridged -j tap102i0-IN
-A PVEFW-FWBR-IN -m physdev --physdev-out tap200i0 --physdev-is-bridged -j tap200i0-IN
-A PVEFW-FWBR-IN -m comment --comment "PVESIG:ovMMyMwniQBaQ59zh20REGXH94o"
-A PVEFW-FWBR-OUT -m physdev --physdev-in tap101i0 --physdev-is-bridged -j tap101i0-OUT
-A PVEFW-FWBR-OUT -m physdev --physdev-in tap102i0 --physdev-is-bridged -j tap102i0-OUT
-A PVEFW-FWBR-OUT -m physdev --physdev-in tap200i0 --physdev-is-bridged -j tap200i0-OUT
-A PVEFW-FWBR-OUT -m comment --comment "PVESIG:gEL0+u13Q1xGxS6dfoYMGjNrOWE"
-A PVEFW-HOST-IN -i lo -j ACCEPT
-A PVEFW-HOST-IN -m conntrack --ctstate INVALID -j DROP
-A PVEFW-HOST-IN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A PVEFW-HOST-IN -m conntrack --ctstate INVALID,NEW -j PVEFW-smurfs
-A PVEFW-HOST-IN -p igmp -j RETURN
-A PVEFW-HOST-IN -i eno1 -j GROUP-remotemanagement-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -i vmbr0 -j GROUP-remotemanagement-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -i vmbr1 -j GROUP-remotemanagement-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -j GROUP-clusterblocklist-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -j GROUP-vm-generalports-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -j GROUP-remotemanagement-IN
-A PVEFW-HOST-IN -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 8006 -j RETURN
-A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 5900:5999 -j RETURN
-A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 3128 -j RETURN
-A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 22 -j RETURN
-A PVEFW-HOST-IN -p tcp -m set --match-set PVEFW-0-management-v4 src -m tcp --dport 60000:60050 -j RETURN
-A PVEFW-HOST-IN -j PVEFW-Drop
-A PVEFW-HOST-IN -j DROP
-A PVEFW-HOST-IN -m comment --comment "PVESIG:tntmvSxKKf4NDT9zNl759JuApTs"
-A PVEFW-HOST-OUT -o lo -j ACCEPT
-A PVEFW-HOST-OUT -m conntrack --ctstate INVALID -j DROP
-A PVEFW-HOST-OUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A PVEFW-HOST-OUT -p igmp -j RETURN
-A PVEFW-HOST-OUT -o eno1 -j GROUP-remotemanagement-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -o vmbr0 -j GROUP-remotemanagement-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -o vmbr1 -j GROUP-remotemanagement-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -j GROUP-clusterblocklist-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -j GROUP-vm-generalports-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -j GROUP-remotemanagement-OUT
-A PVEFW-HOST-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A PVEFW-HOST-OUT -d 195.154.176.0/24 -p tcp -m tcp --dport 8006 -j RETURN
-A PVEFW-HOST-OUT -d 195.154.176.0/24 -p tcp -m tcp --dport 22 -j RETURN
-A PVEFW-HOST-OUT -d 195.154.176.0/24 -p tcp -m tcp --dport 5900:5999 -j RETURN
-A PVEFW-HOST-OUT -d 195.154.176.0/24 -p tcp -m tcp --dport 3128 -j RETURN
-A PVEFW-HOST-OUT -j RETURN
-A PVEFW-HOST-OUT -m comment --comment "PVESIG:FTq/62+1+fG2Dsm9Vlim9YlsS7g"
-A PVEFW-INPUT -j PVEFW-HOST-IN
-A PVEFW-INPUT -m comment --comment "PVESIG:+5iMmLaxKXynOB/+5xibfx7WhFk"
-A PVEFW-OUTPUT -j PVEFW-HOST-OUT
-A PVEFW-OUTPUT -m comment --comment "PVESIG:LjHoZeSSiWAG3+2ZAyL/xuEehd0"
-A PVEFW-Reject -j PVEFW-DropBroadcast
-A PVEFW-Reject -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
-A PVEFW-Reject -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A PVEFW-Reject -m conntrack --ctstate INVALID -j DROP
-A PVEFW-Reject -p udp -m multiport --dports 135,445 -j PVEFW-reject
-A PVEFW-Reject -p udp -m udp --dport 137:139 -j PVEFW-reject
-A PVEFW-Reject -p udp -m udp --sport 137 --dport 1024:65535 -j PVEFW-reject
-A PVEFW-Reject -p tcp -m multiport --dports 135,139,445 -j PVEFW-reject
-A PVEFW-Reject -p udp -m udp --dport 1900 -j DROP
-A PVEFW-Reject -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -j DROP
-A PVEFW-Reject -p udp -m udp --sport 53 -j DROP
-A PVEFW-Reject -m comment --comment "PVESIG:h3DyALVslgH5hutETfixGP08w7c"
-A PVEFW-SET-ACCEPT-MARK -j MARK --set-xmark 0x80000000/0x80000000
-A PVEFW-SET-ACCEPT-MARK -m comment --comment "PVESIG:Hg/OIgIwJChBUcWU8Xnjhdd2jUY"
-A PVEFW-logflags -j DROP
-A PVEFW-logflags -m comment --comment "PVESIG:MN4PH1oPZeABMuWr64RrygPfW7A"
-A PVEFW-reject -m addrtype --dst-type BROADCAST -j DROP
-A PVEFW-reject -s 224.0.0.0/4 -j DROP
-A PVEFW-reject -p icmp -j DROP
-A PVEFW-reject -p tcp -j REJECT --reject-with tcp-reset
-A PVEFW-reject -p udp -j REJECT --reject-with icmp-port-unreachable
-A PVEFW-reject -p icmp -j REJECT --reject-with icmp-host-unreachable
-A PVEFW-reject -j REJECT --reject-with icmp-host-prohibited
-A PVEFW-reject -m comment --comment "PVESIG:Jlkrtle1mDdtxDeI9QaDSL++Npc"
-A PVEFW-smurflog -j DROP
-A PVEFW-smurflog -m comment --comment "PVESIG:2gfT1VMkfr0JL6OccRXTGXo+1qk"
-A PVEFW-smurfs -s 0.0.0.0/32 -j RETURN
-A PVEFW-smurfs -m addrtype --src-type BROADCAST -g PVEFW-smurflog
-A PVEFW-smurfs -s 224.0.0.0/4 -g PVEFW-smurflog
-A PVEFW-smurfs -m comment --comment "PVESIG:HssVe5QCBXd5mc9kC88749+7fag"
-A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -g PVEFW-logflags
-A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -g PVEFW-logflags
-A PVEFW-tcpflags -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -g PVEFW-logflags
-A PVEFW-tcpflags -p tcp -m tcp --tcp-flags FIN,SYN FIN,SYN -g PVEFW-logflags
-A PVEFW-tcpflags -p tcp -m tcp --sport 0 --tcp-flags FIN,SYN,RST,ACK SYN -g PVEFW-logflags
-A PVEFW-tcpflags -m comment --comment "PVESIG:CMFojwNPqllyqD67NeI5m+bP5mo"
-A f2b-sshd -s 93.123.39.184/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.100/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 124.232.197.15/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.37/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.101/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.152/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.83/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.36/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 92.118.39.115/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 182.66.79.118/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN
-A tap101i0-IN -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A tap101i0-IN -j GROUP-vm-generalports-IN
-A tap101i0-IN -m mark --mark 0x80000000/0x80000000 -j ACCEPT
-A tap101i0-IN -j PVEFW-Drop
-A tap101i0-IN -j DROP
-A tap101i0-IN -m comment --comment "PVESIG:jpL+IXwVdBoeaL6k/WQonP1GdxQ"
-A tap101i0-OUT -p udp -m udp --sport 68 --dport 67 -g PVEFW-SET-ACCEPT-MARK
-A tap101i0-OUT -m mac ! --mac-source 52:54:00:00:15:74 -j DROP
-A tap101i0-OUT -m set ! --match-set PVEFW-101-ipfilter-net0-v4 src -j DROP
-A tap101i0-OUT -j MARK --set-xmark 0x0/0x80000000
-A tap101i0-OUT -j GROUP-vm-generalports-OUT
-A tap101i0-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A tap101i0-OUT -g PVEFW-SET-ACCEPT-MARK
-A tap101i0-OUT -m comment --comment "PVESIG:bxecZvgfeNVLrIPhi0AtqNlluXo"
-A tap102i0-IN -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A tap102i0-IN -p udp -m udp --dport 1194 -j ACCEPT
-A tap102i0-IN -j GROUP-vm-generalports-IN
-A tap102i0-IN -m mark --mark 0x80000000/0x80000000 -j ACCEPT
-A tap102i0-IN -j PVEFW-Drop
-A tap102i0-IN -j DROP
-A tap102i0-IN -m comment --comment "PVESIG:L1xR2s2nrWMLSGDErqpyoWmHbcc"
-A tap102i0-OUT -p udp -m udp --sport 68 --dport 67 -g PVEFW-SET-ACCEPT-MARK
-A tap102i0-OUT -m mac ! --mac-source 52:54:00:00:15:82 -j DROP
-A tap102i0-OUT -m set ! --match-set PVEFW-102-ipfilter-net0-v4 src -j DROP
-A tap102i0-OUT -j MARK --set-xmark 0x0/0x80000000
-A tap102i0-OUT -j GROUP-vm-generalports-OUT
-A tap102i0-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A tap102i0-OUT -g PVEFW-SET-ACCEPT-MARK
-A tap102i0-OUT -m comment --comment "PVESIG:o5dSY2n0Sp8AqCdBrLIsFqvxAkQ"
-A tap200i0-IN -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A tap200i0-IN -p tcp -m tcp --dport 2223 -m limit --limit 1/sec -j NFLOG --nflog-prefix ":200:6:tap200i0-IN: ACCEPT: "
-A tap200i0-IN -p tcp -m tcp --dport 2223 -j ACCEPT
-A tap200i0-IN -j GROUP-vm-generalports-IN
-A tap200i0-IN -m mark --mark 0x80000000/0x80000000 -j ACCEPT
-A tap200i0-IN -j PVEFW-Drop
-A tap200i0-IN -j DROP
-A tap200i0-IN -m comment --comment "PVESIG:hJ9ftNjYa+6rFPCab9S2g9rgGMA"
-A tap200i0-OUT -p udp -m udp --sport 68 --dport 67 -g PVEFW-SET-ACCEPT-MARK
-A tap200i0-OUT -m mac ! --mac-source 52:54:00:00:1a:dc -j DROP
-A tap200i0-OUT -m set ! --match-set PVEFW-200-ipfilter-net0-v4 src -j DROP
-A tap200i0-OUT -j MARK --set-xmark 0x0/0x80000000
-A tap200i0-OUT -j GROUP-vm-generalports-OUT
-A tap200i0-OUT -m mark --mark 0x80000000/0x80000000 -j RETURN
-A tap200i0-OUT -g PVEFW-SET-ACCEPT-MARK
-A tap200i0-OUT -m comment --comment "PVESIG:Al1BTaSASgP6BA15wnOrg5fRbos"
COMMIT
# Completed on Thu Jul 18 19:07:45 2024