Originally Posted by
Omega
Покажите результат :
Code:
iptables -nvL
cat /tmp/nat_rules
cat /tmp/filter_rules
З.Ы. А случайно в настройках роутера
UPnP не включен ?
В Web-интерфейсе пытаюсь открыть 51413 на 192.168.1.200
Code:
iptables -nvL
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
10252 679K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
31782 6814K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
9 1098 ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 state NEW
34367 8209K ACCEPT all -- br0 * 0.0.0.0/0 0.0.0.0/0 state NEW
43 2496 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 flags:0x17/0x02
5 252 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21 flags:0x17/0x02
895K 50M DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT 155K packets, 9390K bytes)
pkts bytes target prot opt in out source destination
179 13233 ACCEPT tcp -- * * 0.0.0.0/0 192.168.1.110 tcp dpt:59084
927 95609 ACCEPT udp -- * * 0.0.0.0/0 192.168.1.110 udp dpt:59084
20 986 ACCEPT tcp -- * * 0.0.0.0/0 192.168.1.177 tcp dpt:59963
1327 96987 ACCEPT udp -- * * 0.0.0.0/0 192.168.1.177 udp dpt:59963
4426 276K ACCEPT all -- br0 br0 0.0.0.0/0 0.0.0.0/0
1655 171K DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
224K 13M TCPMSS tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 TCPMSS clamp to PMTU
71M 38G ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
0 0 DROP all -- !br0 ppp0 0.0.0.0/0 0.0.0.0/0
0 0 DROP all -- !br0 vlan2 0.0.0.0/0 0.0.0.0/0
6984 352K ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 ctstate DNAT
0 0 DROP all -- * br0 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 64971 packets, 14M bytes)
pkts bytes target prot opt in out source destination
Chain BRUTE (0 references)
pkts bytes target prot opt in out source destination
Chain MACS (0 references)
pkts bytes target prot opt in out source destination
Chain SECURITY (0 references)
pkts bytes target prot opt in out source destination
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x02 limit: avg 1/sec burst 5
0 0 RETURN tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp flags:0x17/0x04 limit: avg 1/sec burst 5
0 0 RETURN udp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5
0 0 RETURN icmp -- * * 0.0.0.0/0 0.0.0.0/0 limit: avg 5/sec burst 5
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Chain logaccept (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 7 level 4 prefix `ACCEPT '
0 0 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0
Chain logdrop (0 references)
pkts bytes target prot opt in out source destination
0 0 LOG all -- * * 0.0.0.0/0 0.0.0.0/0 state NEW LOG flags 7 level 4 prefix `DROP '
0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
Code:
cat /tmp/nat_rules
*nat
:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:VSERVER - [0:0]
-A PREROUTING -d 91.122.29.1 -j VSERVER
-A VSERVER -p udp -m udp --dport 59084 -j DNAT --to-destination 192.168.1.110:59084
-A VSERVER -p tcp -m tcp --dport 59084 -j DNAT --to-destination 192.168.1.110:59084
-A VSERVER -p udp -m udp --dport 59963 -j DNAT --to-destination 192.168.1.232:59963
-A VSERVER -p tcp -m tcp --dport 59963 -j DNAT --to-destination 192.168.1.232:59963
-A VSERVER -p udp -m udp --dport 42943 -j DNAT --to-destination 192.168.1.232:42943
-A VSERVER -p tcp -m tcp --dport 42943 -j DNAT --to-destination 192.168.1.232:42943
-A VSERVER -p tcp -m tcp --dport 51413 -j DNAT --to-destination 192.168.1.200:51413
-A VSERVER -p udp -m udp --dport 21428 -j DNAT --to-destination 192.168.1.110:21428
-A VSERVER -p tcp -m tcp --dport 21428 -j DNAT --to-destination 192.168.1.110:21428
-A VSERVER -p tcp -m tcp --dport 51413 -j DNAT --to-destination 192.168.1.200:51413
-A VSERVER -p tcp -m tcp --dport 51515 -j DNAT --to-destination 192.168.1.4:51515
-A POSTROUTING -o ppp0 ! -s 91.122.29.1 -j MASQUERADE
-A POSTROUTING -o br0 -s 192.168.1.0/24 -d 192.168.1.0/24 -j MASQUERADE
COMMIT
Code:
cat /tmp/filter_rules
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:MACS - [0:0]
:SECURITY - [0:0]
:BRUTE - [0:0]
:logaccept - [0:0]
:logdrop - [0:0]
-A SECURITY -p tcp --syn -m limit --limit 1/s -j RETURN
-A SECURITY -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j RETURN
-A SECURITY -p udp -m limit --limit 5/s -j RETURN
-A SECURITY -p icmp -m limit --limit 5/s -j RETURN
-A SECURITY -j DROP
-A INPUT -m state --state INVALID -j DROP
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A INPUT -i lo -m state --state NEW -j ACCEPT
-A INPUT -i br0 -m state --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 --syn -j ACCEPT
-A INPUT -p tcp -m tcp --dport 21 --syn -j ACCEPT
-A INPUT -j DROP
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
-A FORWARD -o ppp0 ! -i br0 -j DROP
-A FORWARD -o vlan2 ! -i br0 -j DROP
-A FORWARD -m conntrack --ctstate DNAT -j ACCEPT
-A FORWARD -o br0 -j DROP
-A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logaccept -j ACCEPT
-A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logdrop -j DROP
COMMIT