# Generated by iptables-save v1.4.2 on Sat Oct 15 22:50:49 2011
*raw
:PREROUTING ACCEPT [2578681508:1846388752171]
:OUTPUT ACCEPT [548803997:741376736867]
COMMIT
# Completed on Sat Oct 15 22:50:49 2011
# Generated by iptables-save v1.4.2 on Sat Oct 15 22:50:49 2011
*mangle
:PREROUTING ACCEPT [2611759303:1869236317012]
:INPUT ACCEPT [899395474:763309418041]
:FORWARD ACCEPT [1706404348:1105057880002]
:OUTPUT ACCEPT [555776349:750994844538]
:POSTROUTING ACCEPT [2263377964:1856119035199]
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Sat Oct 15 22:50:49 2011
# Generated by iptables-save v1.4.2 on Sat Oct 15 22:50:49 2011
*nat
:PREROUTING ACCEPT [9843616:828382980]
:POSTROUTING ACCEPT [31014706:1763858663]
:OUTPUT ACCEPT [7018832:458379165]
-A PREROUTING -d ! 192.168.110.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j DNAT --to-destination 192.168.110.1:3128
-A POSTROUTING -s 192.168.110.0/24 -o eth0 -j MASQUERADE
COMMIT
# Completed on Sat Oct 15 22:50:49 2011
# Generated by iptables-save v1.4.2 on Sat Oct 15 22:50:49 2011
*filter
:INPUT DROP [30043:4068884]
:FORWARD DROP [1945:245248]
:OUTPUT ACCEPT [306563150:420856844531]
-A INPUT -m conntrack --ctstate INVALID -j DROP
-A INPUT -i ! lo -m addrtype --src-type LOCAL -j DROP
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i eth1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth1 -m conntrack --ctstate NEW -j ACCEPT
-A INPUT -i eth0 -p icmp -j ACCEPT
-A FORWARD -m conntrack --ctstate INVALID -j DROP
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
-A FORWARD -s 192.168.110.0/24 -i eth1 -p tcp -m multiport --dports 80,8080,443,25,110,1723,143,993,21,20 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.110.0/24 -i eth1 -p udp -m multiport --dports 53,123 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.110.0/24 -i eth1 -p icmp -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.110.0/24 -i eth1 -p gre -m conntrack --ctstate NEW -j ACCEPT
COMMIT
# Completed on Sat Oct 15 22:50:49 2011
Пользователь решил продолжить мысль 15 Октября 2011, 23:03:33:
как то так