Ну да, в post-firewall строка
Code:
iptables -A INPUT -p tcp --dport 1555 -j ACCEPT
запуск dropbear
Code:
#!/bin/sh
killall dropbear
dropbear -p 1555 -d /usr/local/etc/dropbear/dropbear_dss_host_key -r /usr/local/etc/dropbear/dropbear_rsa_host_key
и вот так все работает

и вот еще
Code:
[I'm@Router /]$ iptables -L INPUT -vn
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
1443 75004 ACCEPT tcp -- vlan1 * 0.0.0.0/0 10.131.4.163 tcp dpt:81 flags:0x16/0x02
4161 409K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
50M 13G ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
43697 2622K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 state NEW
5482 726K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0 state NEW
0 0 ACCEPT tcp -- * * 0.0.0.0/0 192.168.1.1 tcp dpt:80
696 38181 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
579 29256 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21
7 336 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:1555
0 0 ACCEPT icmp -- * * 194.84.10.0/24 192.168.1.0/24 icmp type 8
0 0 ACCEPT icmp -- * * 195.239.98.16/28 192.168.1.0/24 icmp type 8
0 0 ACCEPT icmp -- * * 212.164.199.16/28 192.168.1.0/24 icmp type 8
0 0 ACCEPT icmp -- * * 193.178.135.16/28 192.168.1.0/24 icmp type 8
0 0 ACCEPT udp -- * * 194.84.10.0/24 192.168.1.0/24 udp dpts:33434:33700
0 0 ACCEPT udp -- * * 195.239.98.16/28 192.168.1.0/24 udp dpts:33434:33700
0 0 ACCEPT udp -- * * 212.164.199.16/28 192.168.1.0/24 udp dpts:33434:33700
0 0 ACCEPT udp -- * * 193.178.135.16/28 192.168.1.0/24 udp dpts:33434:33700
0 0 ACCEPT tcp -- * * 194.84.10.0/24 192.168.1.0/24 tcp spt:200 dpts:1024:65535
0 0 ACCEPT tcp -- * * 195.239.98.16/28 192.168.1.0/24 tcp spt:200 dpts:1024:65535
0 0 ACCEPT tcp -- * * 212.164.199.16/28 192.168.1.0/24 tcp spt:200 dpts:1024:65535
0 0 ACCEPT tcp -- * * 193.178.135.16/28 192.168.1.0/24 tcp spt:200 dpts:1024:65535
654K 76M DROP all -- * * 0.0.0.0/0 0.0.0.0/0
[I'm@Router /]$ iptables -L -vnt nat
Chain PREROUTING (policy ACCEPT 2442K packets, 371M bytes)
pkts bytes target prot opt in out source destination
1620 81484 DNAT tcp -- * * 0.0.0.0/0 10.131.4.163 tcp dpt:80 to:10.131.4.163:81
0 0 DROP tcp -- vlan1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:81
920K 75M VSERVER all -- * * 0.0.0.0/0 10.131.4.163
Chain POSTROUTING (policy ACCEPT 698K packets, 44M bytes)
pkts bytes target prot opt in out source destination
938K 95M MASQUERADE all -- * vlan1 !10.131.4.163 0.0.0.0/0
9947 630K MASQUERADE all -- * br0 192.168.0.0/22 192.168.0.0/22
Chain OUTPUT (policy ACCEPT 44341 packets, 2772K bytes)
pkts bytes target prot opt in out source destination
Chain VSERVER (1 references)
pkts bytes target prot opt in out source destination
0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8082 to:192.168.1.1:80
55632 2743K DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:20658 to:192.168.1.68:20658
3426 173K DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:4662 to:192.168.1.75:4662
603K 39M DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:4672 to:192.168.1.75:4672
173 8950 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:20659 to:192.168.1.75:20659
0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:7523 to:192.168.1.68:7523
0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:7524 to:192.168.1.68:7524
0 0 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:5190 to:192.168.1.68:5190
872 41856 DNAT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306 to:192.168.1.68:3306
0 0 DNAT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:3306 to:192.168.1.68:3306