Есть локальная сеть, есть сервер с Ubuntu 12.04.
Нужно дать доступ из интернета к видеорегистратору. Он на 6036 порту, ip 10.0.24.248. В локальной всё работает.
Порт пробросил, но доступа нет
iptables-save:
# Generated by iptables-save v1.4.12 on Thu Oct 18 22:46:05 2012
*nat
:PREROUTING ACCEPT [5774:385747]
:INPUT ACCEPT [1430:84246]
:OUTPUT ACCEPT [54:9239]
:POSTROUTING ACCEPT [54:9239]
-A PREROUTING -d 83.172.0.119/32 -p tcp -m tcp --dport 6036 -j DNAT --to-destina tion 10.0.24.248:6036
-A PREROUTING -d 83.172.0.119/32 -p tcp -m tcp --dport 6036 -j DNAT --to-destina tion 10.0.24.248:6036
-A POSTROUTING -s 10.0.24.0/24 -o eth0 -j MASQUERADE
-A POSTROUTING -d 10.0.24.248/32 -p tcp -m tcp --dport 6036 -j SNAT --to-source 83.172.0.119
-A POSTROUTING -s 10.0.24.0/24 -o eth0 -j MASQUERADE
-A POSTROUTING -d 10.0.24.248/32 -p tcp -m tcp --dport 6036 -j SNAT --to-source 83.172.0.119
COMMIT
# Completed on Thu Oct 18 22:46:05 2012
# Generated by iptables-save v1.4.12 on Thu Oct 18 22:46:05 2012
*filter
:INPUT ACCEPT [42425:2302878]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [43475:2907376]
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 6036 -m state --state NEW -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m tcp --dport 6036 -m state --state NEW -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -i eth0 -p tcp -m tcp --dport 6036 -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -i eth0 -p tcp -m tcp --dport 6036 -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j REJECT --reject-with icmp-port-unreachable
COMMIT
# Completed on Thu Oct 18 22:46:05 2012