fisher74,
ubunta 10.04
Я скачал squid3 без ssl
И таким видом красноглазия никогда не страдал
Касательно порта: на вебсервере для сайта разрешил порт 8000, т.е. изнутри он открывается по 192,168,1,240:8000, конечно пробросил
А снаружи нет
iptables -A FORWARD -i eth3 -p tcp -m multiport --dport 80,3389,8000,50000,50001 -j ACCEPT
iptables -A FORWARD -i eth2 -p tcp -m multiport --dport 80,3389,8000,50000,50001 -j ACCEPT
root@fuckingu1-gw:/home/fuckingu1# iptables-save
# Generated by iptables-save v1.4.4 on Fri May 4 13:24:55 2012
*mangle
:PREROUTING ACCEPT [4943827:3587701925]
:INPUT ACCEPT [3089702:2345820651]
:FORWARD ACCEPT [1773837:1234802556]
:OUTPUT ACCEPT [3411098:2540266324]
:POSTROUTING ACCEPT [5100272:3767777577]
COMMIT
# Completed on Fri May 4 13:24:55 2012
# Generated by iptables-save v1.4.4 on Fri May 4 13:24:55 2012
*nat
:PREROUTING ACCEPT [134206:12930217]
:POSTROUTING ACCEPT [57395:3449812]
:OUTPUT ACCEPT [57320:3445608]
-A PREROUTING -d 192.168.2.250/32 -p tcp -m tcp --dport 8000 -j DNAT --to-destination 192.168.1.240:8000
-A PREROUTING -d 192.168.2.250/32 -p tcp -m tcp --dport 50000 -j DNAT --to-destination 192.168.1.240:3389
-A PREROUTING -d 192.168.2.250/32 -p tcp -m tcp --dport 50001 -j DNAT --to-destination 192.168.1.254:3389
-A PREROUTING -i eth3 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 3128
-A POSTROUTING -s 192.168.1.0/24 -o eth2 -j MASQUERADE
COMMIT
# Completed on Fri May 4 13:24:55 2012
# Generated by iptables-save v1.4.4 on Fri May 4 13:24:55 2012
*filter
:INPUT ACCEPT [113383:7443462]
:FORWARD DROP [1363:119987]
:OUTPUT ACCEPT [74729:4166817]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth3 -p tcp -m multiport --dports 20,21,22,25,110,123,135,139,143,443,587,3389,8095,8000,80 -j ACCEPT
-A FORWARD -i eth3 -p udp -m multiport --dports 123,500,137,138,445,1701,1900 -j ACCEPT
-A FORWARD -i eth3 -p tcp -m multiport --dports 5938 -j ACCEPT
-A FORWARD -i eth3 -p tcp -m multiport --dports 80,3389,8000,50000,50001 -j ACCEPT
-A FORWARD -i eth2 -p tcp -m multiport --dports 80,3389,8000,50000,50001 -j ACCEPT
-A FORWARD -s 192.168.1.100/32 -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
COMMIT
=============
вопрос решен! стыдно но не был указан Default GW