Да вот как просили,
1.iptables-save
2.cat /tmp/nat_rulesCode:# Generated by iptables-save v1.2.7a on Sat Aug 29 00:13:06 2009 *nat :PREROUTING ACCEPT [327:43098] :POSTROUTING ACCEPT [53:5096] :OUTPUT ACCEPT [34:4088] COMMIT # Completed on Sat Aug 29 00:13:06 2009 # Generated by iptables-save v1.2.7a on Sat Aug 29 00:13:06 2009 *mangle :PREROUTING ACCEPT [1136:191738] :INPUT ACCEPT [823:158086] :FORWARD ACCEPT [177:9736] :OUTPUT ACCEPT [617:97065] :POSTROUTING ACCEPT [908:147590] COMMIT # Completed on Sat Aug 29 00:13:06 2009 # Generated by iptables-save v1.2.7a on Sat Aug 29 00:13:06 2009 *filter :INPUT ACCEPT [0:0] :FORWARD ACCEPT [170:9340] :OUTPUT ACCEPT [452:66536] :MACS - [0:0] :SECURITY - [0:0] :logaccept - [0:0] :logdrop - [0:0] -A INPUT -m state --state INVALID -j DROP -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT -A INPUT -i lo -m state --state NEW -j ACCEPT -A INPUT -i br0 -m state --state NEW -j ACCEPT -A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT -A INPUT -p tcp -m tcp --dport 21 -j ACCEPT -A INPUT -j DROP -A FORWARD -d 192.168.1.221 -p udp -m udp --dport 22560 -j ACCEPT -A FORWARD -d 192.168.1.221 -p udp -m udp --dport 22559 -j ACCEPT -A FORWARD -d 192.168.1.221 -p udp -m udp --dport 22558 -j ACCEPT -A FORWARD -i br0 -o br0 -j ACCEPT -A FORWARD -m state --state INVALID -j DROP -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j TCPMSS --clamp-mss-to-pmtu -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i ! br0 -o ppp0 -j DROP -A FORWARD -i ! br0 -o vlan1 -j DROP -A FORWARD -m conntrack --ctstate DNAT -j ACCEPT -A FORWARD -o br0 -j DROP -A SECURITY -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN -A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN -A SECURITY -p udp -m limit --limit 5/sec -j RETURN -A SECURITY -p icmp -m limit --limit 5/sec -j RETURN -A SECURITY -j DROP -A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options -A logaccept -j ACCEPT -A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options -A logdrop -j DROP COMMIT # Completed on Sat Aug 29 00:13:06 2009
Спасибо.Code:*nat :PREROUTING ACCEPT [0:0] :POSTROUTING ACCEPT [0:0] :OUTPUT ACCEPT [0:0] :VSERVER - [0:0] -A PREROUTING -d 95.24.199.153 -j VSERVER -A PREROUTING -d 10.91.58.167 -j VSERVER -A VSERVER -p udp -m udp --dport 0 -j DNAT --to-destination 192.168.1.221:0 -A VSERVER -p tcp -m tcp --dport 8980 -j DNAT --to-destination 192.168.1.221:8980 -A VSERVER -p tcp -m tcp --dport 37161 -j DNAT --to-destination 192.168.1.74:37161 -A VSERVER -p tcp -m tcp --dport 16221 -j DNAT --to-destination 192.168.1.221:16221 -A VSERVER -p udp -m udp --dport 16221 -j DNAT --to-destination 192.168.1.221:16221 -A VSERVER -p tcp -m tcp --dport 16221 -j DNAT --to-destination 192.168.1.221:16221 -A VSERVER -p udp -m udp --dport 16221 -j DNAT --to-destination 192.168.1.221:16221 -A POSTROUTING -o ppp0 ! -s 95.24.199.153 -j MASQUERADE -A POSTROUTING -o vlan1 ! -s 10.91.58.167 -j MASQUERADE -A POSTROUTING -o br0 -s 192.168.1.0/24 -d 192.168.1.0/24 -j MASQUERADE COMMIT













