#
# nether iptables rules
+*raw
+:PREROUTING ACCEPT
+:OUTPUT ACCEPT
+:CHECK-LOCALHOST -
+-A OUTPUT -o lo -j CHECK-LOCALHOST
+-A OUTPUT -p udp -j NFQUEUE --queue-num 0 --queue-bypass
+-A OUTPUT -p udplite -j NFQUEUE --queue-num 0 --queue-bypass
+-A CHECK-LOCALHOST -p udp --dport 53 -j RETURN
+-A CHECK-LOCALHOST -j ACCEPT
+COMMIT
*mangle
:PREROUTING ACCEPT
:INPUT ACCEPT
-A INPUT ! -i lo -j SECMARK --selctx System
-A OUTPUT -o lo -j CHECK-LOCALHOST
-A OUTPUT -p igmp -j ACCEPT
--A OUTPUT -m conntrack --ctstate NEW ! --ctstatus CONFIRMED -j NFQUEUE --queue-num 0 --queue-bypass
--A OUTPUT -p udplite -j NFQUEUE --queue-num 0 --queue-bypass
--A CHECK-LOCALHOST -p udp --dport 53 -j RETURN
+-A OUTPUT -p tcp -m conntrack --ctstate NEW ! --ctstatus CONFIRMED -j NFQUEUE --queue-num 0 --queue-bypass
-A CHECK-LOCALHOST -p tcp --dport 53 -j RETURN
-A CHECK-LOCALHOST -j ACCEPT
COMMIT