Инет работает норм, прокидывания норм, Но есть небольшая загвоздочка. Нет доступа у разрешенных машин на некоторые сайты (aliexpress.com например) и сайты грузятка какбы с задержкой. Если через проксю то все норм, все работает.
# Generated by iptables-save v1.4.4 on Thu Sep 20 23:26:58 2012
*nat
:PREROUTING ACCEPT [640:37521]
:POSTROUTING ACCEPT [33:3116]
:OUTPUT ACCEPT [33:3116]
[2:96] -A PREROUTING -d 193.33.144.197/32 -p tcp -m tcp --dport 60124 -j DNAT --to-destination 192.168.1.6:3389
[0:0] -A PREROUTING -d 193.33.144.197/32 -p tcp -m tcp --dport 60123 -j DNAT --to-destination 192.168.1.10:3389
[2:96] -A PREROUTING -d 193.33.144.197/32 -p tcp -m tcp --dport 1723 -j DNAT --to-destination 192.168.1.8
[2:96] -A POSTROUTING -d 192.168.1.6/32 -p tcp -m tcp --dport 3389 -j SNAT --to-source 192.168.1.1
[0:0] -A POSTROUTING -d 192.168.1.10/32 -p tcp -m tcp --dport 3389 -j SNAT --to-source 192.168.1.1
[8:404] -A POSTROUTING -s 192.168.1.0/24 -o ppp0 -j MASQUERADE
[2:96] -A POSTROUTING -d 192.168.1.8/32 -p tcp -m tcp --dport 1723 -j SNAT --to-source 192.168.1.1
[0:0] -A OUTPUT -d 193.33.144.197/32 -p tcp -m tcp --dport 60124 -j DNAT --to-destination 192.168.1.6:3389
[0:0] -A OUTPUT -d 193.33.144.197/32 -p tcp -m tcp --dport 60123 -j DNAT --to-destination 192.168.1.10:3389
[0:0] -A OUTPUT -d 193.33.144.197/32 -p tcp -m tcp --dport 1723 -j DNAT --to-destination 192.168.1.8
COMMIT
# Completed on Thu Sep 20 23:26:58 2012
# Generated by iptables-save v1.4.4 on Thu Sep 20 23:26:58 2012
*filter
:INPUT ACCEPT [2010:173588]
:FORWARD DROP [537:26319]
:OUTPUT ACCEPT [1674:266133]
:fail2ban-apache - [0:0]
:fail2ban-courierauth - [0:0]
:fail2ban-dovecot - [0:0]
:fail2ban-postfix - [0:0]
:fail2ban-roundcube - [0:0]
:fail2ban-ssh - [0:0]
:fail2ban-ssh-ddos - [0:0]
[0:0] -A INPUT -p tcp -m multiport --dports 80,443 -j fail2ban-apache
[968:86248] -A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh
[0:0] -A INPUT -p tcp -m multiport --dports 25,465 -j fail2ban-postfix
[71:3318] -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,2000 -j fail2ban-dovecot
[71:3318] -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,2000 -j fail2ban-postfix
[71:3318] -A INPUT -p tcp -m multiport --dports 80,443,25,587,110,995,143,993,2000 -j fail2ban-roundcube
[968:86248] -A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh-ddos
[968:86248] -A INPUT -p tcp -m tcp --dport 22 -j fail2ban-ssh
[71:3318] -A INPUT -p tcp -m multiport --dports 25,465,143,220,993,110,995 -j fail2ban-courierauth
[48:7512] -A INPUT -i lo -j ACCEPT
[87:28387] -A FORWARD -d 192.168.1.6/32 -i ppp0 -o eth1 -p tcp -j ACCEPT
[0:0] -A FORWARD -d 192.168.1.10/32 -i ppp0 -o eth1 -p tcp -j ACCEPT
[21:1704] -A FORWARD -d 192.168.1.8/32 -i ppp0 -o eth1 -p tcp -m tcp --dport 1723 -j ACCEPT
[5479:605089] -A FORWARD -i ppp0 -o eth1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
[48:4879] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source E0:CB:4E:C0:BD:9D -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 04:46:65:BA:69:00 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 64:A7:69:FE:70:3A -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 6C:62:6D:0E:B6:57 -j ACCEPT
[84:6716] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 6C:62:6D:0E:B6:53 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:1C:C0:54:78:0E -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:19:D1:84:D0:6D -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:19:D1:84:D3:65 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:08:CA:2A:CB:8C -j ACCEPT
[4414:2178338] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:15:17:EA:68:95 -j ACCEPT
[0:0] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 00:15:17:1B:22:3D -j ACCEPT
[86:13771] -A FORWARD -i eth1 -o ppp0 -m mac --mac-source 18:A9:05:FB:9B:85 -j ACCEPT
[0:0] -A fail2ban-apache -j RETURN
[71:3318] -A fail2ban-courierauth -j RETURN
[71:3318] -A fail2ban-dovecot -j RETURN
[71:3318] -A fail2ban-postfix -j RETURN
[0:0] -A fail2ban-postfix -j RETURN
[71:3318] -A fail2ban-roundcube -j RETURN
[1936:172496] -A fail2ban-ssh -j RETURN
[968:86248] -A fail2ban-ssh-ddos -j RETURN
COMMIT
# Completed on Thu Sep 20 23:26:58 2012