source /etc/network/interfaces.d/*
auto lo eth0
iface lo inet loopback
allow-hotplug eth0
iface eth0 inet dhcp
auto vmbr0
iface vmbr0 inet static
address 10.10.10.10
netmask 255.255.255.0
bridge-ports none
bridge-stp off
bridge-fd 0
post-up echo 1 > /proc/sys/net/ipv4/ip_forward
post-up iptables -t nat -A POSTROUTING -s ‘10.10.10.0/24’ -o eth0 -j MASQUERADE
post-down iptables -t nat -D POSTROUTING -s ‘10.10.10.0/24’ -o eth0 -j MASQUERADE
post-up iptables -t raw -I PREROUTING -i fwbr+ -j CT –zone 1
post-down iptables -t raw -D PREROUTING -i fwbr+ -j CT –zone 1
#openwrt websites,“v-2-r-a-y”
post-up iptables -t nat -A PREROUTING -p tcp –dport 8010:8019 -j DNAT –to 10.10.10.1:8010-8019/8010
post-up iptables -A INPUT -p tcp –dport 8010:8019 -j ACCEPT
post-up iptables -t nat -A PREROUTING -p tcp –dport 8077 -j DNAT –to 10.10.10.1:8077
post-up iptables -A INPUT -p tcp –dport 8077 -j ACCEPT
#www,vnc:www cantbe host80,or it will block guest income
post-up iptables -t nat -A PREROUTING -p tcp –dport 8020:8029 -j DNAT –to 10.10.10.2:8020-8029/8020
post-up iptables -A INPUT -p tcp –dport 8020:8029 -j ACCEPT
post-up iptables -t nat -A PREROUTING -p tcp –dport 8059 -j DNAT –to 10.10.10.2:5900
post-up iptables -A INPUT -p tcp –dport 8059 -j ACCEPT
#anbox
post-up iptables -t nat -A PREROUTING -p tcp –dport 8030:8039 -j DNAT –to 10.10.10.3:8030-8039/8030
post-up iptables -A INPUT -p tcp –dport 8030:8039 -j ACCEPT
#winebox
post-up iptables -t nat -A PREROUTING -p tcp –dport 8040:8049 -j DNAT –to 10.10.10.4:8040-8049/8040
post-up iptables -A INPUT -p tcp –dport 8040:8049 -j ACCEPT