сегодня прописал как выше указано, ребут проверяю пропускает:
iptables -L:
target prot opt source destination
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:domain
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
iptables-save
# Generated by iptables-save v1.4.12 on Thu Mar 6 09:20:05 2014
*nat
:PREROUTING ACCEPT [7615:1092183]
:INPUT ACCEPT [985:134296]
:OUTPUT ACCEPT [359:22868]
:POSTROUTING ACCEPT [1893:112880]
COMMIT
# Completed on Thu Mar 6 09:20:05 2014
# Generated by iptables-save v1.4.12 on Thu Mar 6 09:20:05 2014
*filter
:INPUT ACCEPT [2867:308776]
:FORWARD ACCEPT [24715:2682472]
:OUTPUT ACCEPT [1052:115509]
-A FORWARD -p tcp -m tcp --dport 53 -j ACCEPT
-A FORWARD -p udp -m udp --dport 53 -j ACCEPT
COMMIT
# Completed on Thu Mar 6 09:20:05 2014
при попытке просто вести:
iptables -A PREROUTING -i p4p1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 8081
выдает:
iptables: No chain/target/match by that name.
Пользователь решил продолжить мысль 06 Марта 2014, 07:06:28:
если так прописать:
iptables -t nat -A PREROUTING -i p4p1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 8081
то ошибке не выдает. сохранился ребтнул пробую открыть сайт, не открывается.
iptables -F
iptables -t nat -F
iptables -P FORWARD DROP
iptables -A FORWARD -p tcp --dport 53 -j ACCEPT
iptables -A FORWARD -p udp --dport 53 -j ACCEPT
iptables -t nat -A PREROUTING -i p4p1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 8081
iptables -t nat -A POSTROUTING -o p2p1 -j MASQUERADE
iptables-save
# Generated by iptables-save v1.4.12 on Thu Mar 6 10:05:39 2014
*nat
:PREROUTING ACCEPT [7835:1222633]
:INPUT ACCEPT [1343:149245]
:OUTPUT ACCEPT [1045:65701]
:POSTROUTING ACCEPT [481:30515]
-A PREROUTING -i p4p1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 8081
-A POSTROUTING -o p2p1 -j MASQUERADE
COMMIT
# Completed on Thu Mar 6 10:05:39 2014
# Generated by iptables-save v1.4.12 on Thu Mar 6 10:05:39 2014
*filter
:INPUT ACCEPT [440:302729]
:FORWARD DROP [4:828]
:OUTPUT ACCEPT [481:306432]
-A FORWARD -p tcp -m tcp --dport 53 -j ACCEPT
-A FORWARD -p udp -m udp --dport 53 -j ACCEPT
COMMIT
# Completed on Thu Mar 6 10:05:39 2014
iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:domain
ACCEPT udp -- anywhere anywhere udp dpt:domain
Chain OUTPUT (policy ACCEPT)
target prot opt source destination