Показывайте текущие правила со шлюза.
root@shluz:~# iptables-save
# Generated by iptables-save v1.4.18 on Mon Apr 23 16:22:54 2018
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -i ppp0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A INPUT -i dsl-provider -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A INPUT -i eth0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A INPUT -i ppp0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A INPUT -i ppp0 -j LOG
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/24 -i eth1 -j ACCEPT
-A INPUT -d 255.255.255.255/32 -i eth1 -j DROP
-A INPUT -s 192.168.0.0/24 -i ppp0 -j DROP
-A INPUT -i ppp0 -p tcp -m tcp -m multiport --dports 21,20,-j ACCEPT
-A INPUT -d 3.4.5.3/32 -p tcp -m tcp -m multiport --dports 443,1194,992,5555,1701,500,4500 -j ACCEPT
-A INPUT -i ppp0 -p tcp -m tcp -m multiport --dports 8840,5555,1194 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 5555 -j ACCEPT
-A INPUT -i ppp0 -p tcp -m tcp --dport 10000:10100 -j ACCEPT
-A INPUT -s 192.168.0.0/24 -i ppp0 -p tcp -m tcp -m multiport --dports 8000,54645,2788,2713 -j DROP
-A INPUT -i ppp0 -p tcp -m tcp -m multiport --dports 8070,5555 -j ACCEPT
-A INPUT -i ppp0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -d 1.22.26.29/32 -j DROP
-A INPUT -j DROP
-A FORWARD -o ppp0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A FORWARD -i ppp0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A FORWARD -o dsl-provider -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A FORWARD -i dsl-provider -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A FORWARD -o eth0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A FORWARD -i eth0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A FORWARD -o ppp0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A FORWARD -i ppp0 -j LOG --log-prefix "BANDWIDTH_IN:" --log-level 7
-A FORWARD -o ppp0 -j LOG
-A FORWARD -i ppp0 -j LOG
-A FORWARD -s 192.168.0.0/24 -i eth1 -o ppp0 -j ACCEPT
-A FORWARD -s ip/32 -i ppp0 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -i ppp0 -o eth1 -j ACCEPT
-A FORWARD -s ip/32 -i ppp0 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 443 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 25 -j ACCEPT
-A FORWARD -i ppp0 -p tcp -m tcp -m multiport --dports 8840,5555,1194 -j ACCEPT
-A FORWARD -p tcp -m tcp -m multiport --dports 5555,1194 -j ACCEPT
-A FORWARD -i ppp0 -p tcp -m tcp -m multiport --dports 21,20,33,1194,82,83,81,44,37777,37778,8081,1723,1792 -j ACCEPT
-A FORWARD -i ppp0 -p tcp -m tcp --dport 10000:14000 -j ACCEPT
-A FORWARD -p tcp -m tcp -m multiport --dports 8070,80,5555 -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.0.0/24
-A FORWARD -s 82.5.254.190/32 -i ppp0 -j ACCEPT
-A FORWARD -i ppp0 -p tcp -m tcp --dport 1982 -j ACCEPT
-A FORWARD -i ppp0 -p tcp -m tcp -m multiport --dports 443,1194,992,5555,1701,500,4500 -j DROP
-A FORWARD -j DROP
-A OUTPUT -o ppp0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A OUTPUT -o dsl-provider -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A OUTPUT -o eth0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A OUTPUT -o ppp0 -j LOG --log-prefix "BANDWIDTH_OUT:" --log-level 7
-A OUTPUT -o ppp0 -j LOG
-A OUTPUT -j ACCEPT
COMMIT
# Completed on Mon Apr 23 16:22:54 2018
# Generated by iptables-save v1.4.18 on Mon Apr 23 16:22:54 2018
*mangle
:PREROUTING ACCEPT [25362425:18604351801]
:INPUT ACCEPT [2079956:1309655230]
:FORWARD ACCEPT [23278471:17290931585]
:OUTPUT ACCEPT [1965171:1351343271]
:POSTROUTING ACCEPT [25236380:18641576089]
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:65495 -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:65495 -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 443 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 10000:14000 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 25 -j ACCEPT
-A FORWARD -d 192.168.0.1/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 20 -j ACCEPT
COMMIT
# Completed on Mon Apr 23 16:22:54 2018
# Generated by iptables-save v1.4.18 on Mon Apr 23 16:22:54 2018
*nat
:PREROUTING ACCEPT [366245:36525067]
:INPUT ACCEPT [55753:4613844]
:OUTPUT ACCEPT [162904:9778878]
:POSTROUTING ACCEPT [25681:1256520]
-A PREROUTING ! -d 192.168.0.0/24 -i eth1 -p tcp -m tcp -m multiport --dports 80,8080,8083 -j DNAT --to-destination 192.168.0.1:31
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 10000:10100 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 21 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 20 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 8840 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -i ppp0 -p tcp -m tcp -m multiport --dports 8080,8083 -j DNAT --to-destination 192.168.1.20:8080-8083
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 8070 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 33 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 13000:14000 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 1194 -j DNAT --to-destination 192.168.0.9:1194
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 192.168.0.9:80
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp -m multiport --dports 82,83,81,44,37777,37778 -j DNAT --to-destination 192.168.0.9
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 143 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 389 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.
-A PREROUTING -d 3.4.5.3/32 -i ppp0 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.0.200:3389
-A OUTPUT -d 3.4.5.3/32 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.0.
-A OUTPUT -d 3.4.5.3/32 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.0.
-A OUTPUT -d 3.4.5.3/32 -p tcp -m tcp -m multiport --dports 8080,8083
-A OUTPUT -d 3.4.5.3/32 -p tcp -m tcp --dport 8070 -j DNAT --to-destination 192.168.
-A OUTPUT -d 3.4.5.3/32 -p tcp -m tcp -m multiport --dports 82,83,81,44,37777,37778 -j DNAT --to-destination 192.168.0.9
-A POSTROUTING -o ppp0 -j MASQUERADE
-A POSTROUTING -d 192.168.0/32 -p tcp -m tcp --dport 443 -j SNAT --to-source 192.168.0.1
-A POSTROUTING -d 192.168.0/32 -p tcp -m tcp --dport 25 -j SNAT --to-source 192.168.0.1
-A POSTROUTING -d 192.168.0.9/32 -p tcp -m tcp -m multiport --dports 82,83,81,44,37777,37778 -j SNAT --to-source 192.168.0.1
COMMIT
# Completed on Mon Apr 23 16:22:54 2018
root@shluz:~#