sysctl net.ipv4.ip_forward что кажет?
net.ipv4.ip_forward = 1
что кажет sudo iptables-save?
# Generated by iptables-save v1.4.12 on Thu Sep 26 14:12:43 2013
*nat
:PREROUTING ACCEPT [401:37242]
:INPUT ACCEPT [393:23825]
:OUTPUT ACCEPT [393:24478]
:POSTROUTING ACCEPT [393:24478]
-A PREROUTING -d 192.168.0.30/32 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.1.30:80
-A PREROUTING -s 192.168.1.0/24 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A POSTROUTING -d 192.168.1.30/32 -p tcp -m tcp --dport 80 -j SNAT --to-source 192.168.1.1
-A POSTROUTING -s 192.168.1.0/24 -o eth0 -j MASQUERADE
COMMIT
# Completed on Thu Sep 26 14:12:43 2013
# Generated by iptables-save v1.4.12 on Thu Sep 26 14:12:43 2013
*filter
:INPUT ACCEPT [4157:1519484]
:FORWARD DROP [102:4608]
:OUTPUT ACCEPT [4579:2899751]
-A INPUT -s 62.212.74.161/32 -j DROP
-A INPUT -s 87.250.250.121/32 -j DROP
-A INPUT -s 173.224.209.248/32 -j DROP
-A INPUT -s 50.59.209.20/32 -j DROP
-A INPUT -s 122.155.13.144/32 -j DROP
-A INPUT -s 37.49.226.249/32 -j DROP
-A INPUT -i lo -j ACCEPT
-A FORWARD -i eth0 -o eth1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.1.2/32 -m mac --mac-source 00:1A:4D:F4:06:40 -j ACCEPT
-A FORWARD -s 192.168.1.3/32 -m mac --mac-source 00:16:CF:60:60:DC -j ACCEPT
-A FORWARD -s 192.168.1.4/32 -m mac --mac-source F4:6D:04:DA:24:C1 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j REJECT --reject-with icmp-port-unreachable
COMMIT