-P INPUT ACCEPT -P FORWARD ACCEPT -P OUTPUT ACCEPT -N FORWARD_IN_ZONES -N FORWARD_IN_ZONES_SOURCE -N FORWARD_OUT_ZONES -N FORWARD_OUT_ZONES_SOURCE -N FORWARD_direct -N FWDI_FedoraWorkstation -N FWDI_FedoraWorkstation_allow -N FWDI_FedoraWorkstation_deny -N FWDI_FedoraWorkstation_log -N FWDO_FedoraWorkstation -N FWDO_FedoraWorkstation_allow -N FWDO_FedoraWorkstation_deny -N FWDO_FedoraWorkstation_log -N INPUT_ZONES -N INPUT_ZONES_SOURCE -N INPUT_direct -N IN_FedoraWorkstation -N IN_FedoraWorkstation_allow -N IN_FedoraWorkstation_deny -N IN_FedoraWorkstation_log -N LIBVIRT_FWI -N LIBVIRT_FWO -N LIBVIRT_FWX -N LIBVIRT_INP -N LIBVIRT_OUT -N OUTPUT_direct -A INPUT -j LIBVIRT_INP -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -j INPUT_direct -A INPUT -j INPUT_ZONES_SOURCE -A INPUT -j INPUT_ZONES -A INPUT -m conntrack --ctstate INVALID -j DROP -A INPUT -j REJECT --reject-with icmp-host-prohibited -A FORWARD -j LIBVIRT_FWX -A FORWARD -j LIBVIRT_FWI -A FORWARD -j LIBVIRT_FWO -A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i lo -j ACCEPT -A FORWARD -j FORWARD_direct -A FORWARD -j FORWARD_IN_ZONES_SOURCE -A FORWARD -j FORWARD_IN_ZONES -A FORWARD -j FORWARD_OUT_ZONES_SOURCE -A FORWARD -j FORWARD_OUT_ZONES -A FORWARD -m conntrack --ctstate INVALID -j DROP -A FORWARD -j REJECT --reject-with icmp-host-prohibited -A OUTPUT -j LIBVIRT_OUT -A OUTPUT -j OUTPUT_direct -A FORWARD_IN_ZONES -i wlp58s0 -g FWDI_FedoraWorkstation -A FORWARD_IN_ZONES -g FWDI_FedoraWorkstation -A FORWARD_OUT_ZONES -o wlp58s0 -g FWDO_FedoraWorkstation -A FORWARD_OUT_ZONES -g FWDO_FedoraWorkstation -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_log -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_deny -A FWDI_FedoraWorkstation -j FWDI_FedoraWorkstation_allow -A FWDI_FedoraWorkstation -p icmp -j ACCEPT -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_log -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_deny -A FWDO_FedoraWorkstation -j FWDO_FedoraWorkstation_allow -A INPUT_ZONES -i wlp58s0 -g IN_FedoraWorkstation -A INPUT_ZONES -g IN_FedoraWorkstation -A IN_FedoraWorkstation -j IN_FedoraWorkstation_log -A IN_FedoraWorkstation -j IN_FedoraWorkstation_deny -A IN_FedoraWorkstation -j IN_FedoraWorkstation_allow -A IN_FedoraWorkstation -p icmp -j ACCEPT -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 22 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A IN_FedoraWorkstation_allow -p udp -m udp --dport 137 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A IN_FedoraWorkstation_allow -p udp -m udp --dport 138 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A IN_FedoraWorkstation_allow -d 224.0.0.251/32 -p udp -m udp --dport 5353 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A IN_FedoraWorkstation_allow -p udp -m udp --dport 1025:65535 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A IN_FedoraWorkstation_allow -p tcp -m tcp --dport 1025:65535 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT -A LIBVIRT_FWI -d 192.168.122.0/24 -o virbr0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A LIBVIRT_FWI -o virbr0 -j REJECT --reject-with icmp-port-unreachable -A LIBVIRT_FWI -d 192.169.122.0/24 -o virbr1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT -A LIBVIRT_FWI -o virbr1 -j REJECT --reject-with icmp-port-unreachable -A LIBVIRT_FWO -s 192.168.122.0/24 -i virbr0 -j ACCEPT -A LIBVIRT_FWO -i virbr0 -j REJECT --reject-with icmp-port-unreachable -A LIBVIRT_FWO -s 192.169.122.0/24 -i virbr1 -j ACCEPT -A LIBVIRT_FWO -i virbr1 -j REJECT --reject-with icmp-port-unreachable -A LIBVIRT_FWX -i virbr0 -o virbr0 -j ACCEPT -A LIBVIRT_FWX -i virbr1 -o virbr1 -j ACCEPT -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 53 -j ACCEPT -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT -A LIBVIRT_INP -i virbr0 -p udp -m udp --dport 67 -j ACCEPT -A LIBVIRT_INP -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT -A LIBVIRT_INP -i virbr1 -p udp -m udp --dport 53 -j ACCEPT -A LIBVIRT_INP -i virbr1 -p tcp -m tcp --dport 53 -j ACCEPT -A LIBVIRT_INP -i virbr1 -p udp -m udp --dport 67 -j ACCEPT -A LIBVIRT_INP -i virbr1 -p tcp -m tcp --dport 67 -j ACCEPT -A LIBVIRT_OUT -o virbr0 -p udp -m udp --dport 68 -j ACCEPT -A LIBVIRT_OUT -o virbr1 -p udp -m udp --dport 68 -j ACCEPT