root@26506:~# ip ad
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
link/ether 52:54:00:b6:3f:80 brd ff:ff:ff:ff:ff:ff
inet 195.19.192.44/24 brd 195.19.192.255 scope global ens3
valid_lft forever preferred_lft forever
inet6 fe80::5054:ff:feb6:3f80/64 scope link
valid_lft forever preferred_lft forever
3: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
link/none
inet 10.7.0.2/32 scope global wg0
valid_lft forever preferred_lft forever
root@26506:~#
root@26506:~# iptables -nvL
Chain INPUT (policy DROP 80 packets, 3694 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:2306:2802 state NEW
Chain FORWARD (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT all -- * * 10.7.0.0/24 0.0.0.0/0
0 0 ACCEPT all -- wg0 * 0.0.0.0/0 0.0.0.0/0
159 8427 ACCEPT all -- * wg0 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:2306:2802 state NEW
0 0 ACCEPT udp -- ens3 * 0.0.0.0/0 10.7.0.3 udp dpts:2306:2802
0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpts:27015:27040 state NEW
0 0 ACCEPT udp -- ens3 * 0.0.0.0/0 10.7.0.3 udp dpts:27015:27040
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpts:27015:27040 state NEW
0 0 ACCEPT tcp -- ens3 * 0.0.0.0/0 10.7.0.3 tcp dpts:27015:27040
0 0 ufw-reject-forward all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-track-forward all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ufw-after-output all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-after-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-reject-output all -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ufw-track-output all -- * * 0.0.0.0/0 0.0.0.0/0
root@26506:~#
root@26506:~# iptables -nvL -t nat
Chain PREROUTING (policy ACCEPT 107 packets, 17086 bytes)
pkts bytes target prot opt in out source destination
66 3498 DNAT udp -- * * 0.0.0.0/0 195.19.192.44 udp dpts:2306:2802 to:10.7.0.3
0 0 DNAT udp -- * * 0.0.0.0/0 195.19.192.44 udp dpts:27015:27040 to:10.7.0.3
0 0 DNAT tcp -- * * 0.0.0.0/0 195.19.192.44 tcp dpts:27015:27040 to:10.7.0.3
Chain INPUT (policy ACCEPT 18 packets, 1104 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 50 packets, 3550 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 50 packets, 3550 bytes)
pkts bytes target prot opt in out source destination
66 3498 MASQUERADE udp -- * * 0.0.0.0/0 10.7.0.3 udp dpts:2306:2802
0 0 MASQUERADE udp -- * * 0.0.0.0/0 10.7.0.3 udp dpts:27015:27040
0 0 MASQUERADE tcp -- * * 0.0.0.0/0 10.7.0.3 tcp dpts:27015:27040
0 0 MASQUERADE all -- * ens3 0.0.0.0/0 0.0.0.0/0
0 0 SNAT all -- * * 10.7.0.0/24 !10.7.0.0/24 to:195.19.192.44
root@26506:~#