Power, theMIROn, по первому пункту спасибо переделаю, а по второму
iptables-save
Code:
# Generated by iptables-save v1.3.8 on Fri Jul 3 12:08:38 2009
*nat
:PREROUTING ACCEPT [117532:12257770]
:POSTROUTING ACCEPT [56586:4550325]
:OUTPUT ACCEPT [9196:588820]
:VSERVER - [0:0]
-A PREROUTING -d 89.252.88.61 -j VSERVER
-A POSTROUTING -s ! 89.252.88.61 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -o br0 -j SNAT --to-source 192.168.0.1
-A VSERVER -p udp -m udp --dport 56354 -j DNAT --to-destination 192.168.0.202:56354
-A VSERVER -p udp -m udp --dport 53981 -j DNAT --to-destination 192.168.0.202:53980
-A VSERVER -p udp -m udp --dport 63622 -j DNAT --to-destination 192.168.0.10:63622
-A VSERVER -p tcp -m tcp --dport 53981 -j DNAT --to-destination 192.168.0.202:53980
-A VSERVER -p tcp -m tcp --dport 3724 -j DNAT --to-destination 192.168.96.1:3724
-A VSERVER -p udp -m udp --dport 34622 -j DNAT --to-destination 192.168.0.101:34622
-A VSERVER -p tcp -m tcp --dport 34622 -j DNAT --to-destination 192.168.0.101:34622
-A VSERVER -p udp -m udp --dport 53980 -j DNAT --to-destination 192.168.0.10:53980
-A VSERVER -p tcp -m tcp --dport 53980 -j DNAT --to-destination 192.168.0.10:53980-0
COMMIT
# Completed on Fri Jul 3 12:08:38 2009
# Generated by iptables-save v1.3.8 on Fri Jul 3 12:08:38 2009
*mangle
:PREROUTING ACCEPT [106239951:74973262815]
:INPUT ACCEPT [3019270:793834335]
:FORWARD ACCEPT [102454009:74085898892]
:OUTPUT ACCEPT [2438273:663905792]
:POSTROUTING ACCEPT [105184588:74857941157]
COMMIT
# Completed on Fri Jul 3 12:08:38 2009
# Generated by iptables-save v1.3.8 on Fri Jul 3 12:08:38 2009
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [24611:2058263]
:OUTPUT ACCEPT [451386:130722435]
:BRUTE - [0:0]
:MACS - [0:0]
:SECURITY - [0:0]
:logaccept - [0:0]
:logdrop - [0:0]
-A INPUT -m state --state INVALID -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -m state --state NEW -j ACCEPT
-A INPUT -i br0 -m state --state NEW -j ACCEPT
-A INPUT -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A INPUT -j DROP
-A INPUT -p tcp -m tcp --dport 443 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A FORWARD -d 192.168.0.10 -p tcp -m tcp --dport 53980 -j ACCEPT
-A FORWARD -i br0 -o br0 -j ACCEPT
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i ! br0 -o ppp0 -j DROP
-A FORWARD -i ! br0 -o vlan2 -j DROP
-A FORWARD -m conntrack --ctstate DNAT -j ACCEPT
-A FORWARD -o br0 -j DROP
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -m limit --limit 1/sec -j RETURN
-A SECURITY -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m limit --limit 1/sec -j RETURN
-A SECURITY -p udp -m limit --limit 5/sec -j RETURN
-A SECURITY -p icmp -m limit --limit 5/sec -j RETURN
-A SECURITY -j DROP
-A logaccept -m state --state NEW -j LOG --log-prefix "ACCEPT " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logaccept -j ACCEPT
-A logdrop -m state --state NEW -j LOG --log-prefix "DROP " --log-tcp-sequence --log-tcp-options --log-ip-options
-A logdrop -j DROP
COMMIT
# Completed on Fri Jul 3 12:08:38 2009
Порт 3724