time nslookup ya.ru
Server: 10.1.1.2
Address: 10.1.1.2#53
Non-authoritative answer:
Name: ya.ru
Address: 93.158.134.3
Name: ya.ru
Address: 93.158.134.203
Name: ya.ru
Address: 213.180.193.3
Name: ya.ru
Address: 213.180.204.3
Name: ya.ru
Address: 77.88.21.3
Name: ya.ru
Address: 87.250.250.3
Name: ya.ru
Address: 87.250.250.203
Name: ya.ru
Address: 87.250.251.3
real 0m1.035s
user 0m0.000s
sys 0m0.016s
time nslookup ya.ru 8.8.8.8
Server: 8.8.8.8
Address: 8.8.8.8#53
Non-authoritative answer:
Name: ya.ru
Address: 213.180.193.3
Name: ya.ru
Address: 213.180.204.3
Name: ya.ru
Address: 77.88.21.3
Name: ya.ru
Address: 87.250.250.3
Name: ya.ru
Address: 87.250.250.203
Name: ya.ru
Address: 87.250.251.3
Name: ya.ru
Address: 93.158.134.3
Name: ya.ru
Address: 93.158.134.203
real 0m0.065s
user 0m0.004s
sys 0m0.012s
sudo iptables-save
# Generated by iptables-save v1.4.12 on Fri May 17 19:33:54 2013
*mangle
:PREROUTING ACCEPT [9037363:5181024106]
:INPUT ACCEPT [695435:75914422]
:FORWARD ACCEPT [8296453:5100394392]
:OUTPUT ACCEPT [678086:53350326]
:POSTROUTING ACCEPT [8974645:5153749972]
COMMIT
# Completed on Fri May 17 19:33:54 2013
# Generated by iptables-save v1.4.12 on Fri May 17 19:33:54 2013
*nat
:PREROUTING ACCEPT [835140:56800602]
:INPUT ACCEPT [379297:22496966]
:OUTPUT ACCEPT [11225:648411]
:POSTROUTING ACCEPT [6775:397983]
-A POSTROUTING -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.10.4/32 -o eth0 -j MASQUERADE
COMMIT
# Completed on Fri May 17 19:33:54 2013
# Generated by iptables-save v1.4.12 on Fri May 17 19:33:54 2013
*filter
:INPUT ACCEPT [678463:72609883]
:FORWARD ACCEPT [2419:689062]
:OUTPUT ACCEPT [678087:53353174]
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,ACK FIN -j LOG --log-prefix "«Stealth»"
-A INPUT -p tcp -m tcp --tcp-flags FIN,ACK FIN -j DROP
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP
-A INPUT -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP
-A INPUT -f -j DROP
-A FORWARD -s 192.168.10.4/32 -m mac --mac-source xx:xx:xx:xx:xx:xx -j ACCEPT
-A FORWARD -i eth1 -j DROP
-A FORWARD -i ppp0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 192.168.10.10/32 -p tcp -m tcp --dport 8080 -j ACCEPT
-A FORWARD -d 192.168.10.10/32 -p tcp -m tcp --dport 4444 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 22 -j ACCEPT
COMMIT
# Completed on Fri May 17 19:33:54 2013