=== filter table ===
Chain INPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    1   104 ACCEPT     0    --  eth0   *       fec1::/16            fec0::20             policy match dir in pol ipsec reqid 1 proto 50
    1   192 ACCEPT     50   --  eth0   *       ::/0                 ::/0                
    5  2602 ACCEPT     17   --  eth0   *       ::/0                 ::/0                 udp spt:500 dpt:500
    0     0 ACCEPT     17   --  eth0   *       ::/0                 ::/0                 udp spt:4500 dpt:4500
    0     0 ACCEPT     17   --  eth0   *       ::/0                 ::/0                 frag  last
    0     0 ACCEPT     58   --  *      *       ::/0                 ::/0                 ipv6-icmptype 135
    0     0 ACCEPT     58   --  *      *       ::/0                 ::/0                 ipv6-icmptype 136
    4  1188 ACCEPT     6    --  eth0   *       fec0::15             ::/0                 tcp spt:80
    0     0 LOG        0    --  *      *       ::/0                 ::/0                 LOG flags 0 level 4 prefix " IN: "

Chain FORWARD (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    1   104 ACCEPT     0    --  *      eth0    fec0::20             fec1::/16            policy match dir out pol ipsec reqid 1 proto 50
    1   192 ACCEPT     50   --  *      eth0    ::/0                 ::/0                
    6  2836 ACCEPT     17   --  *      eth0    ::/0                 ::/0                 udp spt:500 dpt:500
    0     0 ACCEPT     17   --  *      eth0    ::/0                 ::/0                 udp spt:4500 dpt:4500
    0     0 ACCEPT     58   --  *      *       ::/0                 ::/0                 ipv6-icmptype 135
    0     0 ACCEPT     58   --  *      *       ::/0                 ::/0                 ipv6-icmptype 136
    6   520 ACCEPT     6    --  *      eth0    ::/0                 fec0::15             tcp dpt:80
    0     0 LOG        0    --  *      *       ::/0                 ::/0                 LOG flags 0 level 4 prefix " OUT: "

=== nat table ===
Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

=== mangle table ===
Chain PREROUTING (policy ACCEPT 18 packets, 4566 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain INPUT (policy ACCEPT 18 packets, 4566 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 21 packets, 4124 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain POSTROUTING (policy ACCEPT 21 packets, 4124 bytes)
 pkts bytes target     prot opt in     out     source               destination