2 ArcFi,
"sudo iptables-save"
# Generated by iptables-save v1.4.18 on Wed Dec 18 13:53:59 2013
*mangle
:PREROUTING ACCEPT [24510:2023545]
:INPUT ACCEPT [23246:1888123]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [3714:508455]
:POSTROUTING ACCEPT [3782:525285]
COMMIT
# Completed on Wed Dec 18 13:53:59 2013
# Generated by iptables-save v1.4.18 on Wed Dec 18 13:53:59 2013
*nat
:PREROUTING ACCEPT [20520:1525233]
:INPUT ACCEPT [316:44617]
:OUTPUT ACCEPT [50:10034]
:POSTROUTING ACCEPT [50:10034]
COMMIT
# Completed on Wed Dec 18 13:53:59 2013
# Generated by iptables-save v1.4.18 on Wed Dec 18 13:53:59 2013
*filter
:INPUT DROP [19000:1354849]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -s 192.168.1.0/24 -i eth0 -m state --state NEW,ESTABLISHED -j ACCEPT
-A INPUT -s 10.0.0.3/32 -i tap0 -m state --state NEW,ESTABLISHED -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p icmp -j ACCEPT
-A FORWARD -s 10.0.0.3/32 -d 10.0.0.0/24 -m state --state NEW,ESTABLISHED -j ACCEPT
-A OUTPUT -p icmp -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -s 192.168.1.0/24 -o eth0 -m state --state NEW,ESTABLISHED -j ACCEPT
-A OUTPUT -s 10.0.0.0/8 -o tap0 -m state --state NEW,ESTABLISHED -j ACCEPT
COMMIT
# Completed on Wed Dec 18 13:53:59 2013
"ip a ; ip r"
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
link/ether 08:00:27:29:0c:c8 brd ff:ff:ff:ff:ff:ff
inet 192.168.1.254/24 brd 192.168.1.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80::a00:27ff:fe29:cc8/64 scope link
valid_lft forever preferred_lft forever
4: tap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/ether 4e:b2:66:f4:a2:0a brd ff:ff:ff:ff:ff:ff
inet 10.0.0.1/8 brd 10.255.255.255 scope global tap0
valid_lft forever preferred_lft forever
inet6 fe80::4cb2:66ff:fef4:a20a/64 scope link
valid_lft forever preferred_lft forever
default via 192.168.1.1 dev eth0
10.0.0.0/8 dev tap0 proto kernel scope link src 10.0.0.1
192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.254
2 Keper3d, мне не нужно, чтобы клиенты могли попадать в локалку.