ifconfig -a
Code:
br0 Link encap:Ethernet HWaddr 00:24:8C:4D:BC:CC
inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:275482071 errors:0 dropped:0 overruns:0 frame:0
TX packets:259900185 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:3477189139 (3.2 GiB) TX bytes:4239507524 (3.9 GiB)
eth0 Link encap:Ethernet HWaddr 00:24:8C:4D:BC:CC
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:490417481 errors:43941 dropped:0 overruns:11409 frame:11409
TX packets:491113922 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3370396471 (3.1 GiB) TX bytes:3414021124 (3.1 GiB)
Interrupt:4 Base address:0x1000
eth1 Link encap:Ethernet HWaddr 00:24:8C:4D:BC:CC
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4229181 errors:0 dropped:0 overruns:0 frame:8920775
TX packets:8162662 errors:2949 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1141724728 (1.0 GiB) TX bytes:410535356 (391.5 MiB)
Interrupt:13 Base address:0x5000
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MULTICAST MTU:16436 Metric:1
RX packets:771646 errors:0 dropped:0 overruns:0 frame:0
TX packets:771646 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:70695756 (67.4 MiB) TX bytes:70695756 (67.4 MiB)
vlan0 Link encap:Ethernet HWaddr 00:24:8C:4D:BC:CC
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:271938178 errors:0 dropped:0 overruns:0 frame:0
TX packets:253788088 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:3658385535 (3.4 GiB) TX bytes:1074180743 (1.0 GiB)
vlan1 Link encap:Ethernet HWaddr 00:24:8C:4D:BC:CC
inet addr:85.159.41.58 Bcast:85.159.41.63 Mask:255.255.255.224
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:218479298 errors:0 dropped:0 overruns:0 frame:0
TX packets:237325834 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:3769397726 (3.5 GiB) TX bytes:2339840381 (2.1 GiB)
iptables-save
Code:
# Generated by iptables-save v1.3.8 on Wed Nov 18 14:35:27 2009
*nat
:PREROUTING ACCEPT [13180612:1377531874]
:POSTROUTING ACCEPT [9600698:1054396812]
:OUTPUT ACCEPT [125121:14116947]
:VSERVER - [0:0]
-A PREROUTING -d 85.159.41.58 -j VSERVER
-A POSTROUTING -s ! 85.159.41.58 -o vlan1 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/255.255.255.0 -d 192.168.1.0/255.255.255.0 -o br0 -j SNAT --to-source 192.168.1.1
-A VSERVER -p udp -m udp --dport 51554 -j DNAT --to-destination 192.168.1.185:51554
-A VSERVER -p udp -m udp --dport 23319 -j DNAT --to-destination 192.168.1.3:23319
-A VSERVER -p tcp -m tcp --dport 23319 -j DNAT --to-destination 192.168.1.3:23319
-A VSERVER -p tcp -m tcp --dport 55766 -j DNAT --to-destination 192.168.1.221:55766
-A VSERVER -p udp -m udp --dport 55766 -j DNAT --to-destination 192.168.1.221:55766
-A VSERVER -p udp -m udp --dport 39806 -j DNAT --to-destination 192.168.1.221:39806
-A VSERVER -p tcp -m tcp --dport 39806 -j DNAT --to-destination 192.168.1.221:39806
-A VSERVER -p udp -m udp --dport 49870 -j DNAT --to-destination 192.168.1.221:49870
-A VSERVER -j DNAT --to-destination 192.168.1.3
-A VSERVER -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.1.38:7215
-A VSERVER -p tcp -m tcp --dport 16114 -j DNAT --to-destination 192.168.1.3:16114
-A VSERVER -p udp -m udp --dport 16114 -j DNAT --to-destination 192.168.1.3:16114
-A VSERVER -p tcp -m tcp --dport 55767 -j DNAT --to-destination 192.168.1.185:55766
-A VSERVER -p udp -m udp --dport 55767 -j DNAT --to-destination 192.168.1.185:55766
COMMIT
# Completed on Wed Nov 18 14:35:28 2009
# Generated by iptables-save v1.3.8 on Wed Nov 18 14:35:28 2009
*mangle
:PREROUTING ACCEPT [477111883:245051863411]
:INPUT ACCEPT [40215747:13885639820]
:FORWARD ACCEPT [434920939:230609557517]
:OUTPUT ACCEPT [62900024:81699324694]
:POSTROUTING ACCEPT [498207964:312383859205]
COMMIT
# Completed on Wed Nov 18 14:35:28 2009
# Generated by iptables-save v1.3.8 on Wed Nov 18 14:35:28 2009
*filter
:INPUT ACCEPT [284619:29831038]
:FORWARD ACCEPT [14921468:889468506]
:OUTPUT ACCEPT [62872017:81697095021]
:BRUTE - [0:0]
:MACS - [0:0]
:SECURITY - [0:0]
:logaccept - [0:0]
:logdrop - [0:0]
-A INPUT -m state --state INVALID -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -m state --state NEW -j ACCEPT
-A INPUT -i br0 -m state --state NEW -j ACCEPT
-A INPUT -d 224.0.0.0/240.0.0.0 -p igmp -j ACCEPT
-A INPUT -d 224.0.0.0/240.0.0.0 -p udp -m udp ! --dport 1900 -j ACCEPT
-A FORWARD -d 192.168.1.185 -p udp -m udp --dport 55766 -j ACCEPT
-A FORWARD -d 192.168.1.185 -p tcp -m tcp --dport 55766 -j ACCEPT
-A FORWARD -d 192.168.1.3 -p udp -m udp --dport 16114 -j ACCEPT
-A FORWARD -d 192.168.1.3 -p tcp -m tcp --dport 16114 -j ACCEPT
-A FORWARD -d 192.168.1.38 -p tcp -m tcp --dport 7215 -j ACCEPT
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -d 224.0.0.0/240.0.0.0 -p udp -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ! br0 -o vlan1 -j DROP
-A FORWARD -m conntrack --ctstate DNAT -j ACCEPT
-A FORWARD -o br0 -j DROP
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN
-A SECURITY -p udp -m limit --limit 5/sec -j RETURN
-A SECURITY -p icmp -m limit --limit 5/sec -j RETURN
-A SECURITY -j DROP
-A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logaccept -j ACCEPT
-A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logdrop -j DROP
COMMIT
# Completed on Wed Nov 18 14:35:28 2009
route -n
Code:
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
85.159.41.33 0.0.0.0 255.255.255.255 UH 0 0 0 vlan1
85.159.41.32 0.0.0.0 255.255.255.224 U 0 0 0 vlan1
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br0
127.0.0.0 0.0.0.0 255.0.0.0 U 0 0 0 lo
0.0.0.0 85.159.41.33 0.0.0.0 UG 0 0 0 vlan1
Народ ко мне из сети заходит с того же ипа что у мну интернет, но почему то не работает только с сетью , с инета народ заходит, а с сети что-то блокирует!