Таблесы.
root@localhost:/etc/openvpn# iptables-save
# Generated by iptables-save v1.4.4 on Fri Feb 24 14:01:05 2012
*filter
:INPUT DROP [54648:4313891]
:FORWARD ACCEPT [50574:9220663]
:OUTPUT ACCEPT [1536587:1095623620]
:BAD - [0:0]
:DDoS - [0:0]
:SSH - [0:0]
-A INPUT -i tap0 -j ACCEPT
-A INPUT -i tun0 -j ACCEPT
-A INPUT -m state --state INVALID -j BAD
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p udp -m udp --dport 1701 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i vlan3 -p udp -m udp --dport 520 -j ACCEPT
-A INPUT -i vlan5 -j ACCEPT
-A INPUT -i vlan6 -j ACCEPT
-A INPUT -i vlan7 -j ACCEPT
-A INPUT -d 213.141.136.41/32 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -d 213.141.136.41/32 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT ! -i eth0 -p tcp -m multiport --dports 22,80,1411,2411,4111,5190 -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j DDoS
-A INPUT ! -i eth0 -p tcp -m tcp --dport 22 --tcp-flags FIN,SYN,RST,ACK SYN -j SSH
-A INPUT ! -i eth0 -p tcp -m multiport --dports 6925,43251,43252 -j ACCEPT
-A INPUT ! -i eth0 -p udp -m multiport --dports 43251,43252 -j ACCEPT
-A INPUT -d 10.113.73.31/32 -p tcp -m multiport --dports 22,80,1411,2411,4111,5190 -j ACCEPT
-A INPUT -d 213.141.136.41/32 -p tcp -m multiport --dports 22,80,1411 -j ACCEPT
-A INPUT -d 213.141.136.46/32 -p tcp -m multiport --dports 22,2411,4111 -j ACCEPT
-A FORWARD -m state --state INVALID -j BAD
-A FORWARD -p udp -m udp --dport 53 -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -m state --state INVALID -j BAD
-A BAD -j DROP
-A DDoS -m recent --set --name ddos --rsource
-A DDoS -m recent --update --seconds 1 --hitcount 15 --name ddos --rsource -j DROP
-A DDoS -j RETURN
-A SSH -m recent --set --name ssh_brute --rsource
-A SSH -m recent --update --seconds 3600 --hitcount 3 --name ssh_brute --rsource -j LOG --log-prefix "SSH Probe: " --log-level 6
-A SSH -m recent --update --seconds 3600 --hitcount 3 --name ssh_brute --rsource -j REJECT --reject-with icmp-port-unreachable
-A SSH -j RETURN
COMMIT
# Completed on Fri Feb 24 14:01:05 2012
# Generated by iptables-save v1.4.4 on Fri Feb 24 14:01:05 2012
*nat
:PREROUTING ACCEPT [91931:8732363]
:INPUT ACCEPT [17032:912035]
:OUTPUT ACCEPT [62133:4336452]
:POSTROUTING ACCEPT [63507:4555559]
-A PREROUTING ! -i eth0 -p udp -m udp --dport 25500 -j DNAT --to-destination 192.168.10.193:25500
-A PREROUTING ! -i eth0 -p tcp -m tcp --dport 25500 -j DNAT --to-destination 192.168.10.193:25500
-A PREROUTING ! -i eth0 -p tcp -m tcp --dport 26003 -j DNAT --to-destination 192.168.10.172:26003
-A PREROUTING ! -i eth0 -p udp -m udp --dport 26003 -j DNAT --to-destination 192.168.10.172:26003
-A PREROUTING -d 213.141.136.46/32 -p tcp -m multiport --dports 1209,1411,411 -j DNAT --to-destination 213.141.136.46:4111
-A PREROUTING -d 213.141.136.41/32 -p tcp -m multiport --dports 1209,4111,411 -j DNAT --to-destination 213.141.136.41:1411
-A PREROUTING -d 10.113.73.31/32 -p tcp -m multiport --dports 1209,4111,411 -j REDIRECT --to-ports 1411
-A PREROUTING ! -d 192.168.0.0/16 -i vlan5 -p tcp -m multiport --dports 21,25,80,443,8000,8080 -j DNAT --to-destination 192.168.100.1:8081
-A POSTROUTING -s 192.168.10.0/24 -o ppp1 -j MASQUERADE
-A POSTROUTING -s 192.168.10.0/24 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.10.0/24 -o vlan3 -j SNAT --to-source 10.113.73.31
COMMIT
# Completed on Fri Feb 24 14:01:05 2012
# Generated by iptables-save v1.4.4 on Fri Feb 24 14:01:05 2012
*mangle
:PREROUTING ACCEPT [1265738:95312846]
:INPUT ACCEPT [1201179:83767084]
:FORWARD ACCEPT [50582:9221015]
:OUTPUT ACCEPT [1536684:1095633219]
:POSTROUTING ACCEPT [1587257:1104875335]
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Fri Feb 24 14:01:05 2012
root@localhost:/etc/openvpn#
root@ovpnsrv:/etc/openvpn# iptables-save
# Generated by iptables-save v1.4.4 on Fri Feb 24 13:59:38 2012
*mangle
:PREROUTING ACCEPT [964838858:149734795870]
:INPUT ACCEPT [908165445:96216026418]
:FORWARD ACCEPT [56665543:53517697641]
:OUTPUT ACCEPT [896494470:139627718109]
:POSTROUTING ACCEPT [953160013:193145415750]
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Fri Feb 24 13:59:38 2012
# Generated by iptables-save v1.4.4 on Fri Feb 24 13:59:38 2012
*filter
:INPUT ACCEPT [1055679985:103374800964]
:FORWARD ACCEPT [56666007:53517944532]
:OUTPUT ACCEPT [1045782400:163516489357]
:SSH - [0:0]
-A INPUT ! -s 10.0.0.0/8 ! -i lo -p tcp -m tcp --dport 3306 -j REJECT --reject-with icmp-port-unreachable
-A INPUT ! -s 10.0.0.0/8 -p tcp -m tcp --dport 22 --tcp-flags FIN,SYN,RST,ACK SYN -j SSH
-A INPUT -s 80.89.139.134/32 -j REJECT --reject-with icmp-port-unreachable
-A SSH -m recent --set --name ssh_brute --rsource
-A SSH -m recent --update --seconds 600 --hitcount 3 --name ssh_brute --rsource -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Fri Feb 24 13:59:38 2012
# Generated by iptables-save v1.4.4 on Fri Feb 24 13:59:38 2012
*nat
:PREROUTING ACCEPT [631552:41946025]
:POSTROUTING ACCEPT [805398:40954282]
:OUTPUT ACCEPT [776930:39288576]
-A PREROUTING -d 10.155.1.66/32 -p tcp -m tcp --dport 411 -j REDIRECT --to-ports 4111
-A PREROUTING -d 10.14.1.66/32 -p tcp -m tcp --dport 411 -j REDIRECT --to-ports 4111
-A PREROUTING -d 94.45.162.166/32 -p tcp -m tcp --dport 411 -j REDIRECT --to-ports 4111
-A POSTROUTING -s 192.168.10.0/24 -j MASQUERADE
COMMIT
# Completed on Fri Feb 24 13:59:38 2012
root@ovpnsrv:/etc/openvpn#