>iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
>iptables -A FORWARD -i eth0 -o eth1 -p tcp -s 192.168.10.15 --dport
>80 -j ACCEPT
НЕ РАБОТАЕТ!!! Все необходимые модули подключил, но все равно, ни ссш ни фтп ни вэб напрямую (т.е. не через проксю) не работают, почему? Привожу целиком и полностью iptables-save (192.168.10.15-тестовый внутренний ip, 1.2.3.4-реальный внешний ip) :
# Generated by iptables-save v1.2.7a on Fri Aug 19 00:51:32 2005
*nat
:PREROUTING ACCEPT [320:20003]
:POSTROUTING ACCEPT [9:601]
:OUTPUT ACCEPT [140:9518]
-A POSTROUTING -o eth1 -j SNAT --to-source 1.2.3.4
COMMIT
# Completed on Fri Aug 19 00:51:32 2005
# Generated by iptables-save v1.2.7a on Fri Aug 19 00:51:32 2005
*mangle
:PREROUTING ACCEPT [3596:1714345]
:INPUT ACCEPT [3518:1700085]
:FORWARD ACCEPT [77:14200]
:OUTPUT ACCEPT [3856:1625975]
:POSTROUTING ACCEPT [3931:1640059]
COMMIT
# Completed on Fri Aug 19 00:51:32 2005
# Generated by iptables-save v1.2.7a on Fri Aug 19 00:51:32 2005
*filter
:INPUT DROP [156:10923]
:FORWARD DROP [0:0]
:OUTPUT DROP [2:116]
:allowed - [0:0]
:icmp_packets - [0:0]
:tcp_packets - [0:0]
:udp_packets - [0:0]
-A INPUT -s 192.168.10.0/255.255.255.0 -i eth0 -p tcp -m tcp --dport 3128 -j ACCEPT
-A INPUT -s 127.0.0.1 -i lo -j ACCEPT
-A INPUT -s 192.168.10.1 -i lo -j ACCEPT
-A INPUT -s 1.2.3.4 -i lo -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 68 --dport 67 -j ACCEPT
-A INPUT -d 1.2.3.4 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth1 -p tcp -j tcp_packets
-A INPUT -i eth1 -p udp -j udp_packets
-A INPUT -i eth1 -p icmp -j icmp_packets
-A INPUT -s 192.168.10.0/255.255.255.0 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.10.0/255.255.255.0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -p tcp -j bad_tcp_packets
-A FORWARD -i eth0 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
**************
-A FORWARD -s 192.168.10.15 -i eth0 -o eth1 -p tcp -m tcp --dport 80 -j ACCEPT
**************
-A OUTPUT -s 127.0.0.1 -j ACCEPT
-A OUTPUT -s 192.168.10.1 -j ACCEPT
-A OUTPUT -s 1.2.3.4 -j ACCEPT
-A allowed -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A allowed -p tcp -m state --state RELATED,ESTABLISHED -j ACCEPT
-A allowed -p tcp -j DROP
-A icmp_packets -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A icmp_packets -p icmp -m icmp --icmp-type 11 -j ACCEPT
COMMIT