сетевки работают(не указывал шлюз у провайдера2), но трасировка не проходит со второго провайдера через интерфейс...
sudo traceroute ya.ru -i eth0
traceroute to ya.ru (93.158.134.3), 30 hops max, 60 byte packets
1 ip71-1.ipblk.ksn.ru (80.242.71.1) 0.581 ms 0.584 ms 0.586 ms
2 r2.ksn.ru (80.242.64.89) 0.829 ms 1.081 ms 1.058 ms
3 kuchum-xe-0-0-2.yndx.net (193.232.87.42) 1.171 ms 1.380 ms 1.491 ms
4 sverdlov-xe-0-0-3.yndx.net (213.180.213.68) 23.559 ms 23.639 ms 23.620 ms
5 neun-ae1-70.yndx.net (213.180.213.74) 45.321 ms 45.576 ms 45.555 ms
6 * * *
7 ugr-b-c1-ae5.yndx.net (87.250.239.53) 48.433 ms 48.415 ms 48.387 ms
8 * * *
9 * * *
10 www.yandex.ru (93.158.134.3) 48.927 ms 49.367 ms 54.563 ms
sudo traceroute ya.ru -i eth2
traceroute to ya.ru (213.180.204.3), 30 hops max, 60 byte packets
1 * * *
2 * * *
3 * * *
4 * * *
5 * * *
6 * * *
7 * * *
8 * * *
9 * * *
10 * * *
11 * * *
12 * * *
13 * * *
14 * * *
15 * * *
16 * * *
17 * * *
18 * * *
19 * * *
20 * * *
21 * * *
22 * * *
23 * * *
24 * * *
25 * * *
26 * * *
27 * * *
28 * * *
29 * * *
30 * * *
ip a; ip r
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 1000
link/ether 40:61:86:35:f7:9f brd ff:ff:ff:ff:ff:ff
inet 192.168.0.1/24 brd 192.168.0.255 scope global eth1
inet 192.168.10.1/20 brd 192.168.25.255 scope global eth1:2
inet6 fe80::4261:86ff:fe35:f79f/64 scope link
valid_lft forever preferred_lft forever
3: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 1000
link/ether 54:e6:fc:82:40:9b brd ff:ff:ff:ff:ff:ff
inet 94.180.105.17/24 brd 94.180.105.255 scope global eth2
inet6 fe80::56e6:fcff:fe82:409b/64 scope link
valid_lft forever preferred_lft forever
4: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 1000
link/ether 00:26:5a:7c:2d:80 brd ff:ff:ff:ff:ff:ff
inet 80.242.71.53/24 brd 80.242.71.255 scope global eth0
inet6 fe80::226:5aff:fe7c:2d80/64 scope link
valid_lft forever preferred_lft forever
5: tun0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 100
link/[65534]
inet 192.168.137.1 peer 192.168.137.2/32 scope global tun0
6: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1486 qdisc pfifo_fast state UNKNOWN qlen 3
link/ppp
inet 192.168.101.1 peer 192.168.101.2/32 scope global ppp0
192.168.137.2 dev tun0 proto kernel scope link src 192.168.137.1
192.168.101.2 dev ppp0 proto kernel scope link src 192.168.101.1
192.168.0.0/24 dev eth1 proto kernel scope link src 192.168.0.1
192.168.137.0/24 via 192.168.137.2 dev tun0
80.242.71.0/24 dev eth0 proto kernel scope link src 80.242.71.53
94.180.105.0/24 dev eth2 proto kernel scope link src 94.180.105.17
192.168.0.0/20 dev eth1 proto kernel scope link src 192.168.10.1
default via 80.242.71.1 dev eth0 metric 100
iptables-save
# Generated by iptables-save v1.4.4 on Thu Apr 23 13:44:05 2015
*nat
:PREROUTING ACCEPT [7852:629623]
:POSTROUTING ACCEPT [1228:80413]
:OUTPUT ACCEPT [1179:71048]
-A PREROUTING ! -s 192.168.0.250/32 ! -d 192.168.0.0/16 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8888
-A PREROUTING -d 80.242.71.53/32 -p tcp -m tcp --dport 8035 -j DNAT --to-destination 192.168.0.111
-A PREROUTING -d 80.242.71.53/32 -p tcp -m tcp --dport 8036 -j DNAT --to-destination 192.168.0.115
-A PREROUTING -d 80.242.71.53/32 -p tcp -m tcp --dport 8037 -j DNAT --to-destination 192.168.0.115
-A PREROUTING -d 80.242.71.53/32 -p tcp -m tcp --dport 8022 -j DNAT --to-destination 192.168.0.254
-A PREROUTING -d 80.242.71.53/32 -p udp -m udp --dport 35060 -j DNAT --to-destination 192.168.0.101
-A PREROUTING -d 80.242.71.53/32 -p udp -m udp --dport 16000:16255 -j DNAT --to-destination 192.168.0.102
-A PREROUTING -d 80.242.71.53/32 -p udp -m udp --dport 5060 -j DNAT --to-destination 192.168.0.254
-A PREROUTING -d 80.242.71.53/32 -p udp -m udp --dport 20000:30000 -j DNAT --to-destination 192.168.0.254
-A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
COMMIT
# Completed on Thu Apr 23 13:44:05 2015
# Generated by iptables-save v1.4.4 on Thu Apr 23 13:44:05 2015
*filter
:INPUT ACCEPT [1933:331608]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [60653:37097230]
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -i tun+ -j ACCEPT
-A INPUT -p gre -j ACCEPT
-A INPUT -p esp -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
-A FORWARD -d 192.168.0.254/32 -i eth0 -o eth1 -p udp -m udp --dport 20000:30000 -j ACCEPT
-A FORWARD -d 192.168.0.254/32 -i eth0 -o eth1 -p udp -m udp --dport 5060 -j ACCEPT
-A FORWARD -d 192.168.0.102/32 -i eth0 -o eth1 -p udp -m udp --dport 16000:16255 -j ACCEPT
-A FORWARD -d 192.168.0.101/32 -i eth0 -o eth1 -p udp -m udp --dport 35060 -j ACCEPT
-A FORWARD -d 192.168.0.254/32 -i eth0 -o eth1 -p tcp -m tcp --dport 8022 -j ACCEPT
-A FORWARD -d 192.168.0.115/32 -i eth0 -o eth1 -p tcp -m tcp --dport 8037 -j ACCEPT
-A FORWARD -d 192.168.0.115/32 -i eth0 -o eth1 -p tcp -m tcp --dport 8036 -j ACCEPT
-A FORWARD -d 192.168.0.111/32 -i eth0 -o eth1 -p tcp -m tcp --dport 8035 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -j ACCEPT
-A FORWARD -p udp -m udp --dport 1194 -j ACCEPT
-A FORWARD -i tun+ -j ACCEPT
-A FORWARD -o tun+ -j ACCEPT
-A FORWARD -i tun+ -j ACCEPT
-A FORWARD -o tun+ -j ACCEPT
-A OUTPUT -p gre -j ACCEPT
COMMIT