# Generated by iptables-save v1.4.21 on Sun Jan 31 11:28:01 2016
*mangle
:PREROUTING ACCEPT [46499085:42671196516]
:INPUT ACCEPT [7262918:10111242491]
:FORWARD ACCEPT [39271051:32559874761]
:OUTPUT ACCEPT [3916186:358957281]
:POSTROUTING ACCEPT [43187196:32918829582]
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:65495 -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed on Sun Jan 31 11:28:01 2016
# Generated by iptables-save v1.4.21 on Sun Jan 31 11:28:01 2016
*filter
:INPUT ACCEPT [12289:1076888]
:FORWARD ACCEPT [729940:705371035]
:OUTPUT ACCEPT [9240:812516]
:fail2ban-ssh - [0:0]
-A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh
-A INPUT -s 192.168.1.10/32 -p tcp -m tcp --dport 443 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -s 192.168.1.10/32 -p tcp -m tcp --dport 80 -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -s 192.168.1.10/32 -p tcp -m tcp --dport 443 -j DROP
-A OUTPUT -s 192.168.1.10/32 -p tcp -m tcp --dport 80 -j DROP
-A fail2ban-ssh -j RETURN
COMMIT
# Completed on Sun Jan 31 11:28:01 2016
# Generated by iptables-save v1.4.21 on Sun Jan 31 11:28:01 2016
*nat
:PREROUTING ACCEPT [13660:1095359]
:INPUT ACCEPT [1594:161832]
:OUTPUT ACCEPT [345:21456]
:POSTROUTING ACCEPT [351:23450]
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A PREROUTING -p tcp -m tcp --dport 4040 -j DNAT --to-destination 192.168.1.10:3389
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -j MASQUERADE
COMMIT
# Completed on Sun Jan 31 11:28:01 2016
Тестирую так, сажусь за компьютер 192.168.1.10 и пробую там зайти на интернет странички. Еще открываю в консоле iptables -L -n -v смотрю на кол-во пакетов.