> Да не у кого я ничего не выдергивал. Правила создавались программой fwbuilder,
> это еще больше пол конфига сократил. Была вообще портянка:) Ну и
> недоглядел остался форвард. Поэтому и спрашивал достаточно или нет. Решил сделать
> пинги по проще,типа такого
> $IPTABLES -A INPUT -p icmp -m icmp -i eth0 --icmp-type echo-reply -j
> ACCEPT
> $IPTABLES -A OUTPUT -p icmp -m icmp -o eth0 --icmp-type echo-request -j
> ACCEPT
Слова request и reply смотреть в словаре.
# \/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
# Cmd Line : 1
# Command : interface eth0 i
# Creating chain 'in_i' under 'INPUT' in table 'filter'
/sbin/iptables -t filter -N in_i
/sbin/iptables -t filter -A INPUT -i eth0 -j in_i
# Creating chain 'out_i' under 'OUTPUT' in table 'filter'
/sbin/iptables -t filter -N out_i
/sbin/iptables -t filter -A OUTPUT -o eth0 -j out_i
# > OK <
# FireHOL [interface:i] > server ping accept
# \/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/
# Cmd Line : 2
# Command : server ping accept
# Preparing for service 'ping' of type 'server' under interface 'i'
# Creating chain 'in_i_ping_s1' under 'in_i' in table 'filter'
/sbin/iptables -t filter -N in_i_ping_s1
/sbin/iptables -t filter -A in_i -j in_i_ping_s1
# Creating chain 'out_i_ping_s1' under 'out_i' in table 'filter'
/sbin/iptables -t filter -N out_i_ping_s1
/sbin/iptables -t filter -A out_i -j out_i_ping_s1
# Running complex rules function rules_ping() for server 'ping'
/sbin/iptables -t filter -A in_i_ping_s1 -p icmp -m state --state NEW\,ESTABLISHED --icmp-type echo-request -j ACCEPT
/sbin/iptables -t filter -A out_i_ping_s1 -p icmp -m state --state ESTABLISHED --icmp-type echo-reply -j ACCEPT
# > OK <
# FireHOL [interface:i] > quit
version 5
interface eth0 i
server ping accept