Коллеги, помогите разобраться вот с какой проблемой.
iptables-save
# Generated by iptables-save v1.4.4 on Mon May 6 15:35:42 2013
*mangle
:PREROUTING ACCEPT [1112588008:746155456142]
:INPUT ACCEPT [743473379:529623198259]
:FORWARD ACCEPT [362151848:215262892258]
:OUTPUT ACCEPT [445904123:436046795320]
:POSTROUTING ACCEPT [805274903:648564230125]
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:65495 -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Mon May 6 15:35:42 2013
# Generated by iptables-save v1.4.4 on Mon May 6 15:35:42 2013
*nat
:PREROUTING ACCEPT [22631:1965068]
:POSTROUTING ACCEPT [7904:539656]
:OUTPUT ACCEPT [23604759:4196259494]
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.0.174
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 81 -j DNAT --to-destination 192.168.0.131
-A PREROUTING -s 192.168.0.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 3128
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 4891 -j DNAT --to-destination 192.168.0.111:4891
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 4899 -j DNAT --to-destination 192.168.0.64:4899
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 48999 -j DNAT --to-destination 192.168.0.91:48999
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 2222 -j DNAT --to-destination 192.168.0.8:2222
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 48995 -j DNAT --to-destination 192.168.0.36:48995
-A PREROUTING -d xx.xx.xx.xx/32 -p tcp -m tcp --dport 48993 -j DNAT --to-destination 192.168.0.37:48993
-A POSTROUTING -s 192.168.0.0/24 -d 192.168.0.9/32 -p tcp -m multiport --dports 20,21,25,80,110,143,995 -j SNAT --to-source 192.168.0.9
-A POSTROUTING -s 192.168.0.0/24 -d 192.168.0.174/32 -p tcp -m tcp --dport 443 -j SNAT --to-source 192.168.0.9
-A POSTROUTING -s 192.168.0.0/24 -o ppp0 -j SNAT --to-source xx.xx.xx.xx
COMMIT
# Completed on Mon May 6 15:35:42 2013
# Generated by iptables-save v1.4.4 on Mon May 6 15:35:42 2013
*filter
:INPUT DROP [13269:7395907]
:FORWARD ACCEPT [7195:394815]
:OUTPUT ACCEPT [561525:515565988]
:allowed - [0:0]
:allowed_udp - [0:0]
:bad_tcp_packets - [0:0]
:fail2ban-postfix - [0:0]
:fail2ban-proftpd - [0:0]
:fail2ban-ssh - [0:0]
:fail2ban-ssh-ddos - [0:0]
:icmp_packets - [0:0]
:tcp_packets - [0:0]
:udpincoming_packets - [0:0]
-A INPUT -p tcp -j bad_tcp_packets
-A INPUT -i ppp0 -p icmp -j icmp_packets
-A INPUT -i ppp0 -p tcp -j tcp_packets
-A INPUT -i ppp0 -p udp -j udpincoming_packets
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/24 -j ACCEPT
-A INPUT -i ppp0 -j ACCEPT
-A INPUT -i ppp0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i tap0 -p tcp -j ACCEPT
-A INPUT -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT INPUT packet died:" --log-level 7
-A INPUT -p tcp -m tcp --dport 22 -j TARPIT
-A FORWARD -p tcp -j bad_tcp_packets
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m ipp2p --bit -j DROP
-A FORWARD -i ppp0 -j ACCEPT
-A FORWARD -i tap0 -j ACCEPT
-A FORWARD -o tap0 -j ACCEPT
-A FORWARD -p tcp -j tcp_packets
-A FORWARD -p icmp -j icmp_packets
-A FORWARD -p udp -j allowed_udp
-A FORWARD -m limit --limit 3/min --limit-burst 3 -j LOG --log-prefix "IPT FORWARD packet died:" --log-level 7
-A OUTPUT -p tcp -j bad_tcp_packets
-A allowed -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A allowed -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A allowed -p tcp -j DROP
-A allowed_udp -p udp -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A allowed_udp -p udp -j DROP
-A bad_tcp_packets -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A icmp_packets -p icmp -j ACCEPT
-A tcp_packets -p tcp -m multiport --dports 20,21,25,443,53,110,143,995,1194,22222,9080,8080,10200 -j allowed
-A tcp_packets -p tcp -m multiport --dports 993,123,465,1780,2222,4121,5222,5666,9418,10153,11520,60180,44301 -j allowed
-A tcp_packets -i ppp0 -p tcp -m multiport --dports 137:139,445 -j DROP
-A udpincoming_packets -p udp -m multiport --dports 53,9001 -j allowed_udp
COMMIT
# Completed on Mon May 6 15:35:42 2013
хочу цепочку FORWARD поставить в DROP, для борьбы с торрентами. Но как только ставлю ее в DROP, перестает работать ftp. Подскажите что можно сделать?