Добрый день, опять двадцатьпять, пропустить bittorrent sync через ubuntu server
bittorrent sync настроен на порт 12169, установление на windows где основной шлюз ubuntu server
eth0 - в интернет (192.168.32.36)
eth1 - в сеть (192.168.1.101)
клиент - 192.168.1.100
# Generated by iptables-save v1.4.12 on Tue Feb 25 12:30:19 2014
*mangle
:PREROUTING ACCEPT [73791:38351660]
:INPUT ACCEPT [58681:35138831]
:FORWARD ACCEPT [14217:3089492]
:OUTPUT ACCEPT [54946:36957791]
:POSTROUTING ACCEPT [69163:40047283]
COMMIT
# Completed on Tue Feb 25 12:30:19 2014
# Generated by iptables-save v1.4.12 on Tue Feb 25 12:30:19 2014
*nat
:PREROUTING ACCEPT [2606:274265]
:INPUT ACCEPT [730:39407]
:OUTPUT ACCEPT [449:27057]
:POSTROUTING ACCEPT [7:434]
-A PREROUTING -d 192.168.32.36/32 -p tcp -m tcp --dport 12169 -j DNAT --to-destination 192.168.1.100:12169
-A PREROUTING ! -d 192.168.1.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 3128
-A POSTROUTING -o eth0 -j MASQUERADE
-A POSTROUTING -d 192.168.1.100/32 -p tcp -m tcp --dport 12169 -j SNAT --to-source 192.168.32.36
COMMIT
# Completed on Tue Feb 25 12:30:19 2014
# Generated by iptables-save v1.4.12 on Tue Feb 25 12:30:19 2014
*filter
:INPUT DROP [312:32408]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [54791:36979884]
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -m conntrack --ctstate NEW -j ACCEPT
-A INPUT -s 192.168.1.0/24 -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m multiport --dports 25,110,143,465,587,993,995,2525 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -i eth1 -o eth0 -p tcp -m tcp --dport 443 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -i eth1 -o eth0 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -i eth1 -p tcp -m conntrack --ctstate NEW -m tcp --dport 12169 -j ACCEPT
-A OUTPUT -d 192.168.1.0/24 -o eth1 -p tcp -m tcp --sport 22 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
COMMIT
# Completed on Tue Feb 25 12:30:19 2014
не могу понять что не так почему не работают правила
#Перенаправление для BittorrentSync
iptables -A FORWARD -m conntrack --ctstate NEW -i eth1 -p tcp -m tcp --dport 12169 -j ACCEPT
iptables -t nat -A PREROUTING -p tcp -m tcp -d 192.168.32.36 --dport 12169 -j DNAT --to-destination 192.168.1.100:12169
# Это правило обратно подменяет IP отправителя на внешний
iptables -t nat -A POSTROUTING -p tcp --dst 192.168.1.100 --dport 12169 -j SNAT --to-source 192.168.32.36
спасибо за помощь, форум лопатил, гугл тоже...