Вот, проксями не баловался, но правила от ebox:
# Generated by iptables-save v1.4.4 on Tue Feb 8 14:08:09 2011
*nat
:PREROUTING ACCEPT [1717:335593]
:POSTROUTING ACCEPT [82:5099]
:OUTPUT ACCEPT [82:5099]
:postmodules - [0:0]
:premodules - [0:0]
-A PREROUTING -j premodules
-A POSTROUTING -j postmodules
-A POSTROUTING ! -s 192.168.10.51/32 -o eth0 -j SNAT --to-source 192.168.10.51
COMMIT
# Completed on Tue Feb 8 14:08:09 2011
# Generated by iptables-save v1.4.4 on Tue Feb 8 14:08:09 2011
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:drop - [0:0]
:fdns - [0:0]
:fdrop - [0:0]
:ffwdrules - [0:0]
:fglobal - [0:0]
:fmodules - [0:0]
:fnoexternal - [0:0]
:fnospoof - [0:0]
:fobjects - [0:0]
:fredirects - [0:0]
:ftoexternalonly - [0:0]
:idrop - [0:0]
:iexternal - [0:0]
:iexternalmodules - [0:0]
:iglobal - [0:0]
:iintservs - [0:0]
:imodules - [0:0]
:inoexternal - [0:0]
:inointernal - [0:0]
:inospoof - [0:0]
:log - [0:0]
:odrop - [0:0]
:oglobal - [0:0]
:ointernal - [0:0]
:omodules - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state INVALID -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -j inospoof
-A INPUT -j iexternalmodules
-A INPUT -j iexternal
-A INPUT -j inoexternal
-A INPUT -j imodules
-A INPUT -j iintservs
-A INPUT -j iglobal
-A INPUT -p icmp ! -f -m icmp --icmp-type 8 -m state --state NEW -j ACCEPT
-A INPUT -p icmp ! -f -m icmp --icmp-type 0 -m state --state NEW -j ACCEPT
-A INPUT -p icmp ! -f -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
-A INPUT -p icmp ! -f -m icmp --icmp-type 4 -m state --state NEW -j ACCEPT
-A INPUT -p icmp ! -f -m icmp --icmp-type 11 -m state --state NEW -j ACCEPT
-A INPUT -p icmp ! -f -m icmp --icmp-type 12 -m state --state NEW -j ACCEPT
-A INPUT -j idrop
-A FORWARD -m state --state INVALID -j DROP
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j fnospoof
-A FORWARD -j fredirects
-A FORWARD -j fmodules
-A FORWARD -j ffwdrules
-A FORWARD -j fnoexternal
-A FORWARD -j fdns
-A FORWARD -j fobjects
-A FORWARD -j fglobal
-A FORWARD -p icmp ! -f -m icmp --icmp-type 8 -m state --state NEW -j ACCEPT
-A FORWARD -p icmp ! -f -m icmp --icmp-type 0 -m state --state NEW -j ACCEPT
-A FORWARD -p icmp ! -f -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
-A FORWARD -p icmp ! -f -m icmp --icmp-type 4 -m state --state NEW -j ACCEPT
-A FORWARD -p icmp ! -f -m icmp --icmp-type 11 -m state --state NEW -j ACCEPT
-A FORWARD -p icmp ! -f -m icmp --icmp-type 12 -m state --state NEW -j ACCEPT
-A FORWARD -j fdrop
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -m state --state INVALID -j DROP
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -j ointernal
-A OUTPUT -j omodules
-A OUTPUT -j oglobal
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 8 -m state --state NEW -j ACCEPT
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 0 -m state --state NEW -j ACCEPT
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 3 -m state --state NEW -j ACCEPT
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 4 -m state --state NEW -j ACCEPT
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 11 -m state --state NEW -j ACCEPT
-A OUTPUT -p icmp ! -f -m icmp --icmp-type 12 -m state --state NEW -j ACCEPT
-A OUTPUT -j odrop
-A drop -j DROP
-A fdns -d 192.168.10.135/32 -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
-A fdns -d 192.168.10.135/32 -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
-A fdrop -j drop
-A fglobal -j ACCEPT
-A fnoexternal -i eth0 -m state --state NEW -j fdrop
-A fnospoof -s 192.168.10.0/24 ! -i eth0 -j fdrop
-A ftoexternalonly -o eth0 -j ACCEPT
-A ftoexternalonly -j fdrop
-A idrop -j drop
-A iexternal -m state --state NEW -j ACCEPT
-A iexternal -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
-A iexternal -p tcp -m tcp --dport 389 -m state --state NEW -j ACCEPT
-A iexternal -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
-A iglobal -p udp -m udp --dport 138 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 138 -m state --state NEW -j ACCEPT
-A iglobal -p udp -m udp --dport 137 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 137 -m state --state NEW -j ACCEPT
-A iglobal -p udp -m udp --dport 139 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 139 -m state --state NEW -j ACCEPT
-A iglobal -p udp -m udp --dport 445 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 445 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 8888 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 389 -m state --state NEW -j drop
-A iglobal -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT
-A iglobal -p tcp -m tcp --dport 443 -m state --state NEW -j ACCEPT
-A inoexternal -i eth0 -m state --state NEW -j idrop
-A inospoof -s 192.168.10.0/24 ! -i eth0 -j idrop
-A log -j RETURN
-A odrop -j drop
-A oglobal -m state --state NEW -j ACCEPT
-A oglobal -p tcp -m tcp --dport 80 -m state --state NEW -j ACCEPT
-A ointernal -d 192.168.10.135/32 -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
-A ointernal -d 192.168.10.135/32 -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
COMMIT
# Completed on Tue Feb 8 14:08:09 2011
# Generated by iptables-save v1.4.4 on Tue Feb 8 14:08:09 2011
*mangle
:PREROUTING ACCEPT [103302:24253869]
:INPUT ACCEPT [103126:24245125]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [74065:11163876]
:POSTROUTING ACCEPT [74065:11163876]
-A PREROUTING -j CONNMARK --restore-mark --nfmask 0xffffffff --ctmask 0xffffffff
-A PREROUTING -m mark --mark 0x0/0xff -m mac --mac-source 00:24:1D:50:68:19 -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -m mark --mark 0x0/0xff -j MARK --set-xmark 0x1/0xffffffff
-A PREROUTING -j CONNMARK --save-mark --nfmask 0xffffffff --ctmask 0xffffffff
-A OUTPUT -j CONNMARK --restore-mark --nfmask 0xffffffff --ctmask 0xffffffff
-A OUTPUT -m mark --mark 0x0/0xff -j MARK --set-xmark 0x1/0xffffffff
-A OUTPUT -j CONNMARK --save-mark --nfmask 0xffffffff --ctmask 0xffffffff
-A POSTROUTING -j CONNMARK --save-mark --nfmask 0xff --ctmask 0xffffffff
COMMIT
# Completed on Tue Feb 8 14:08:09 2011
Перегрузил ebox firewall и прокси теперь не просит.... (хотя сам комп полность отправлял в ребут)....