Originally Posted by
Power
Но вы не до конца привели вывод команды iptables-save. Хотелось бы остальное тоже увидеть.
Сорри, привожу полностью
Code:
[admin@wl500gp root]$ iptables-save
# Generated by iptables-save v1.2.7a on Fri Jan 2 00:15:55 1970
*nat
:PREROUTING ACCEPT [36974:3030999]
:POSTROUTING ACCEPT [23804:1412441]
:OUTPUT ACCEPT [23815:1415489]
:VSERVER - [0:0]
-A PREROUTING -d 188.163.8.253 -j VSERVER
-A PREROUTING -d 10.71.58.234 -j VSERVER
-A POSTROUTING -s ! 188.163.8.253 -o ppp0 -j MASQUERADE
-A POSTROUTING -s ! 10.71.58.234 -o vlan1 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/255.255.255.0 -d 192.168.1.0/255.255.255.0 -o br0 -j MASQUERADE
-A VSERVER -p tcp -m tcp --dport 30702 -j DNAT --to-destination 192.168.1.3:30702
-A VSERVER -p tcp -m tcp --dport 30700 -j DNAT --to-destination 192.168.1.2:30700
-A VSERVER -p udp -m udp --dport 30700 -j DNAT --to-destination 192.168.1.2:30700
-A VSERVER -p tcp -m tcp --dport 30700 -j DNAT --to-destination 192.168.1.1:30700
-A VSERVER -p udp -m udp --dport 30700 -j DNAT --to-destination 192.168.1.1:30700
-A VSERVER -p tcp -m tcp --dport 30701 -j DNAT --to-destination 192.168.1.1:30701
-A VSERVER -p udp -m udp --dport 30701 -j DNAT --to-destination 192.168.1.1:30701
-A VSERVER -p tcp -m tcp --dport 30799 -j DNAT --to-destination 192.168.1.1:30799
-A VSERVER -p udp -m udp --dport 30799 -j DNAT --to-destination 192.168.1.1:30799
-A VSERVER -p tcp -m tcp --dport 30702 -j DNAT --to-destination 192.168.1.3:30702
-A VSERVER -p udp -m udp --dport 30702 -j DNAT --to-destination 192.168.1.3:30702
COMMIT
# Completed on Fri Jan 2 00:15:55 1970
# Generated by iptables-save v1.2.7a on Fri Jan 2 00:15:55 1970
*mangle
:PREROUTING ACCEPT [1256740:676794437]
:INPUT ACCEPT [732622:330999895]
:FORWARD ACCEPT [519002:345306422]
:OUTPUT ACCEPT [652543:127274355]
:POSTROUTING ACCEPT [1211691:487556823]
COMMIT
# Completed on Fri Jan 2 00:15:55 1970
# Generated by iptables-save v1.2.7a on Fri Jan 2 00:15:55 1970
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [35493:2667576]
:OUTPUT ACCEPT [652446:127258641]
:MACS - [0:0]
:SECURITY - [0:0]
:logaccept - [0:0]
:logdrop - [0:0]
-A INPUT -m state --state INVALID -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -m state --state NEW -j ACCEPT
-A INPUT -i br0 -m state --state NEW -j ACCEPT
-A INPUT -i ppp0 -m state --state NEW -j SECURITY
-A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -j DROP
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ! br0 -o ppp0 -j DROP
-A FORWARD -i ! br0 -o vlan1 -j DROP
-A FORWARD -i ! br0 -m state --state NEW -j SECURITY
-A FORWARD -m conntrack --ctstate DNAT -j ACCEPT
-A FORWARD -o br0 -j DROP
-A SECURITY -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN
-A SECURITY -p udp -m limit --limit 5/sec -j RETURN
-A SECURITY -p icmp -m limit --limit 5/sec -j RETURN
-A SECURITY -j DROP
-A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logaccept -j ACCEPT
-A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logdrop -j DROP
COMMIT
# Completed on Fri Jan 2 00:15:55 1970
а можно это временное решение, каким-то образом адаптировать для роутера ? ( встали торренты)