| 
						
						
							
								
							
						
						
					 | 
					 | 
					@ -38,7 +38,6 @@ COMMIT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					# SSH-Server
 | 
					 | 
					 | 
					 | 
					# SSH-Server
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
 | 
					 | 
					 | 
					 | 
					-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					# iperf3
 | 
					 | 
					 | 
					 | 
					# iperf3
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -p tcp -m tcp -s 10.30.0.0/18 --dport 5201 -j ACCEPT
 | 
					 | 
					 | 
					 | 
					 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -p tcp -m tcp -s 10.222.0.0/16 --dport 5201 -j ACCEPT
 | 
					 | 
					 | 
					 | 
					-A INPUT -p tcp -m tcp -s 10.222.0.0/16 --dport 5201 -j ACCEPT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					
 | 
					 | 
					 | 
					 | 
					
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					{% if 'fastd' in group_names %}
 | 
					 | 
					 | 
					 | 
					{% if 'fastd' in group_names %}
 | 
				
			
			
		
	
	
		
		
			
				
					| 
						
						
						
							
								
							
						
					 | 
					 | 
					@ -54,7 +53,6 @@ COMMIT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					# ntp
 | 
					 | 
					 | 
					 | 
					# ntp
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -p udp -m udp --dport 123 -j ACCEPT
 | 
					 | 
					 | 
					 | 
					-A INPUT -p udp -m udp --dport 123 -j ACCEPT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					# fastd / wg
 | 
					 | 
					 | 
					 | 
					# fastd / wg
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -s 10.30.0.0/18 -p udp -m udp --dport 10010:10023 -j DROP
 | 
					 | 
					 | 
					 | 
					 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -s 10.222.0.0/16 -p udp -m udp --dport 10010:10023 -j DROP
 | 
					 | 
					 | 
					 | 
					-A INPUT -s 10.222.0.0/16 -p udp -m udp --dport 10010:10023 -j DROP
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A INPUT -p udp -m udp --dport 10010:10023 -j ACCEPT
 | 
					 | 
					 | 
					 | 
					-A INPUT -p udp -m udp --dport 10010:10023 -j ACCEPT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					# wireguard_mesh
 | 
					 | 
					 | 
					 | 
					# wireguard_mesh
 | 
				
			
			
		
	
	
		
		
			
				
					| 
						
							
								
							
						
						
							
								
							
						
						
					 | 
					 | 
					@ -86,8 +84,6 @@ COMMIT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A FORWARD -o {{ ansible_default_ipv4.interface }} -j REJECT
 | 
					 | 
					 | 
					 | 
					-A FORWARD -o {{ ansible_default_ipv4.interface }} -j REJECT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A FORWARD -d 10.222.0.0/16 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
					 | 
					 | 
					 | 
					-A FORWARD -d 10.222.0.0/16 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A FORWARD -s 10.222.0.0/16 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
					 | 
					 | 
					 | 
					-A FORWARD -s 10.222.0.0/16 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A FORWARD -d 10.30.0.0/18 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
					 | 
					 | 
					 | 
					 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					-A FORWARD -s 10.30.0.0/18 -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
 | 
					 | 
					 | 
					 | 
					 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					
 | 
					 | 
					 | 
					 | 
					
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					COMMIT
 | 
					 | 
					 | 
					 | 
					COMMIT
 | 
				
			
			
		
	
		
		
			
				
					
					 | 
					 | 
					 | 
					*nat
 | 
					 | 
					 | 
					 | 
					*nat
 | 
				
			
			
		
	
	
		
		
			
				
					| 
						
							
								
							
						
						
						
					 | 
					 | 
					
 
 |