<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
					xmlns:content="http://purl.org/rss/1.0/modules/content/"
					xmlns:wfw="http://wellformedweb.org/CommentAPI/"
					xmlns:atom="http://www.w3.org/2005/Atom"
				  >
<channel>
<atom:link rel="self"  type="application/rss+xml"  href="http://rulinux.net/rss_from_sect_4_subsect_1_thread_7466"  />
<title>rulinux.net - Форум - General - [iptables] полный NAT</title>
<link>http://rulinux.net/</link>
<description><![CDATA[Портал о GNU/Linux и не только]]></description>
<image><title>rulinux.net - Форум - General - [iptables] полный NAT</title>
<link>http://rulinux.net/</link>
<url>http://rulinux.net/rss_icon.png</url>
</image>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53739</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53739</guid>
<pubDate>Tue, 06 Jul 2010 20:41:29 +0400</pubDate>
<description><![CDATA[<p>ну да, не так просто во всей это штуке разобраться, искал что-то находил, оставлял в комментах, зато в результате работает стабильно - по этому конфигу любой фирме с самыми жесткими правилами безопасности(в рамках айпитаблов) можно в течении минуты настроить выход в сеть - профит!</p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53738</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53738</guid>
<pubDate>Tue, 06 Jul 2010 15:40:15 +0400</pubDate>
<description><![CDATA[<p><i>>382.  # РЕТЕУМБФШ ЧИПДСЭЙЕ UDP РБЛЕФЩ(РПТФ 5060 Й 16500) ОБ ЙОФЕТЖЕКУ eth0 (X.X.X.X) 383.  # ЧП ЧОХФТЕООАА УЕФШ ОБ 172.16.0.200 ОБ УППФЧЕФУФЧХАЭЙЕ РПТФЩ</i><br> оНДШЛЮК </p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53737</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53737</guid>
<pubDate>Tue, 06 Jul 2010 15:38:19 +0400</pubDate>
<description><![CDATA[<p>а, у тебя уже все заработало, незаметил =)</p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53736</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53736</guid>
<pubDate>Tue, 06 Jul 2010 15:37:42 +0400</pubDate>
<description><![CDATA[<p>вот мой файрвольчик</p><p><fieldset style="border: 1px dashed black; padding:0px;"><ol style="background-color:#3d3d3d;" start="1"><li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#!/bin/sh<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;INET_IP="xxx.xxx.xxx.xxx"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;INET_IFACE="eth0"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;INET_BROADCAST="xxx.xxx.xxx.255"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 1.2 Local Area Network configuration.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# your LAN's IP range and localhost IP. /24 means to only use the first 24<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# bits of the 32 bit IP address. the same as netmask 255.255.255.0<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;LAN_IP="10.0.0.1"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;LAN_IP_RANGE="10.0.0.0/24"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;LAN_IFACE="eth1"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 1.4 Localhost Configuration.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;LO_IFACE="lo"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;LO_IP="127.0.0.1"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 1.5 IPTables Configuration.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;IPTABLES="/sbin/iptables"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 1.6 Other Configuration.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;###########################################################################<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 2. Module loading.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Needed to initially load modules<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/depmod -a<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 2.1 Required modules<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_tables<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_conntrack<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe iptable_filter<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe iptable_mangle<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe iptable_nat<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_LOG<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_limit<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_state<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_string<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 2.2 Non-Required modules<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_owner<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_REJECT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ipt_MASQUERADE<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_conntrack_ftp<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_conntrack_irc<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_nat_ftp<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;/sbin/modprobe ip_nat_irc<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;###########################################################################<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 3. /proc set up.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 3.1 Required proc configuration<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;echo "1" > /proc/sys/net/ipv4/ip_forward<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 3.2 Non-Required proc configuration<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;echo "1" > /proc/sys/net/ipv4/conf/all/rp_filter<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;echo "1" > /proc/sys/net/ipv4/conf/all/proxy_arp<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;echo "1" > /proc/sys/net/ipv4/ip_dynaddr<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;###########################################################################<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4. rules set up.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;######<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1 Filter table<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# $IPTABLES -t filter -A FORWARD -i $LAN_IP -o $INET_IP -s $LAN_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.1 Set policies<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -P INPUT DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -P OUTPUT DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -P FORWARD ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.2 Create userspecified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Create chain for bad tcp packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -N bad_tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Create separate chains for ICMP, TCP and UDP to traverse<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -N allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -N tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -N udp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -N icmp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.3 Create content in userspecified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# bad_tcp_packets chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A bad_tcp_packets -p tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A bad_tcp_packets -p tcp ! --syn -m state --state NEW -j LOG --log-prefix "New not syn:"<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A bad_tcp_packets -p tcp ! --syn -m state --state NEW -j DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# allowed chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A allowed -p TCP --syn -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A allowed -p TCP -m state --state ESTABLISHED,RELATED -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A allowed -p TCP -j DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# TCP rules<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 20 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 21 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 22 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 80 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 8080 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 8081 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 113 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 4661 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 4662 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 4711 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 4712 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 6588 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 3128 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 3389 -j allowed<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# UDP ports<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 53 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 123 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 2074 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 4000 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 4665 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 4672 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 3389 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# In Microsoft Networks you will be swamped by broadcasts. These lines <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# will prevent them from showing up in the logs.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A udp_packets -p UDP -i $INET_IFACE -d $INET_BROADCAST --destination-port 135:139 -j DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# If we get DHCP requests from the Outside of our network, our logs will <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# be swamped as well. This rule will block them from getting logged.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#$IPTABLES -A udp_packets -p UDP -i $INET_IFACE -d 255.255.255.255 \<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#--destination-port 67:68 -j DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# ICMP rules<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A icmp_packets -p ICMP -s 0/0 --icmp-type 8 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A icmp_packets -p ICMP -s 0/0 --icmp-type 11 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.4 INPUT chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Bad TCP packets we don't want.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p tcp -j bad_tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Rules for special networks not part of the Internet<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ALL -i $LAN_IFACE -s $LAN_IP_RANGE -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ALL -i $LO_IFACE -s $LO_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ALL -i $LO_IFACE -s $LAN_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ALL -i $LO_IFACE -s $INET_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Special rule for DHCP requests from LAN, which are not caught properly<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# otherwise.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p UDP -i $LAN_IFACE --dport 67 --sport 68 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Rules for incoming packets from the internet.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ALL -d $INET_IP -m state --state ESTABLISHED,RELATED -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p TCP -i $INET_IFACE -j tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p UDP -i $INET_IFACE -j udp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -p ICMP -i $INET_IFACE -j icmp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# If you have a Microsoft Network on the outside of your firewall, you may <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# also get flooded by Multicasts. We drop them so we do not get flooded by <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# logs<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -i $INET_IFACE -d 224.0.0.0/8 -j DROP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Log weird packets that don't match the above.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A INPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT INPUT packet died: "<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.5 FORWARD chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Bad TCP packets we don't want<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -p tcp -j bad_tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Accept the packets we actually want to forward<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i $LAN_IFACE -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Log weird packets that don't match the above.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -m limit --limit 3/minute --limit-burst 3 -j LOG  --log-level DEBUG --log-prefix "IPT FORWARD packet died: "<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.1.6 OUTPUT chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Bad TCP packets we don't want.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A OUTPUT -p tcp -j bad_tcp_packets<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Special OUTPUT rules to decide which IP's to allow.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A OUTPUT -p ALL -s $LO_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A OUTPUT -p ALL -s $LAN_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A OUTPUT -p ALL -s $INET_IP -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Log weird packets that don't match the above.<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A OUTPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT OUTPUT packet died: "<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;######<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2 nat table<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.1 Set policies<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.2 Create user specified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.3 Create content in user specified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.4 PREROUTING chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.5 POSTROUTING chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# Enable simple IP Forwarding and Network Address Translation<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A POSTROUTING -o $INET_IFACE -j SNAT --to-source $INET_IP<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.2.6 OUTPUT chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;######<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3 mangle table<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.1 Set policies<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.2 Create user specified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.3 Create content in user specified chains<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.4 PREROUTING chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING --dst $INET_IP -p tcp --dport 4662 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING --dst $INET_IP -p udp --dport 4672 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4661 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4662 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p udp -d $INET_IP --dport 4672 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p udp -d $INET_IP --dport 4665 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4711 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4712 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 3389 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 12087 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 51909<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 51909 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.5 INPUT chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.6 FORWARD chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4661 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4662 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 4672 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 4665 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4711 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4712 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 3389 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 3389 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 51909 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 12087 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.7 OUTPUT chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# 4.3.8 POSTROUTING chain<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# РЕТЕУМБФШ ЧИПДСЭЙЕ UDP РБЛЕФЩ(РПТФ 5060 Й 16500) ОБ ЙОФЕТЖЕКУ eth0 (X.X.X.X)<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# ЧП ЧОХФТЕООАА УЕФШ ОБ 172.16.0.200 ОБ УППФЧЕФУФЧХАЭЙЕ РПТФЩ<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# iptables -t nat -A PREROUTING -p udp -d x.x.x.x --dport 5060 -j DNAT --to-destination 172.16.0.200 <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;# iptables -t nat -A PREROUTING -p udp -d x.x.x.x --dport 16500 -j DNAT --to-destination 172.16.0.200 <li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;#<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4661 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 4662 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 3389 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p udp -d $INET_IP --dport 4672 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p udp -d $INET_IP --dport 3389 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4661 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 4662 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 4672 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p udp --dport 3389 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 3389 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -t nat -A PREROUTING -p tcp -d $INET_IP --dport 12087 -j DNAT --to-destination 10.0.0.6<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;$IPTABLES -A FORWARD -i eth0 -d 10.0.0.6 -p tcp --dport 12087 -j ACCEPT<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;<li style="background-color:#000000; padding-left: 5px; color: gray">&nbsp;</ol></fieldset></p><p></p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53735</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53735</guid>
<pubDate>Fri, 02 Jul 2010 13:44:29 +0400</pubDate>
<description><![CDATA[<p>переношу в дженерал. </p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53734</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53734</guid>
<pubDate>Fri, 02 Jul 2010 09:49:20 +0400</pubDate>
<description><![CDATA[<p><i>>>/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE</i><br> <i>>>/sbin/iptables -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT</i><br> <i>>>/sbin/iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT</i><br> Вот так заработало. Спасибо. Забыл про форварды значит :)</p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53733</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53733</guid>
<pubDate>Fri, 02 Jul 2010 09:38:29 +0400</pubDate>
<description><![CDATA[<p>Попробуй сделать</p><p>iptables -I FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu </p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53732</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53732</guid>
<pubDate>Fri, 02 Jul 2010 09:37:24 +0400</pubDate>
<description><![CDATA[<p>бывает не сразу срабатывает по непонятным причинам. Проверь таблицу маршрутов.</p>]]></description>
</item>
<item>
<title>Re: [iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53731</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53731</guid>
<pubDate>Fri, 02 Jul 2010 09:37:22 +0400</pubDate>
<description><![CDATA[<p>/sbin/iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE</p><p>/sbin/iptables -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT</p><p>/sbin/iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT</p>]]></description>
</item>
<item>
<title>[iptables] полный NAT</title>
<link>https://rulinux.net/message.php?newsid=7466&amp;page=1#53730</link>
<guid>https://rulinux.net/message.php?newsid=7466&amp;page=1#53730</guid>
<pubDate>Fri, 02 Jul 2010 09:31:00 +0400</pubDate>
<description><![CDATA[<p>eth0 - внешка (xxx.xxx.xxx.xxx)</p><p>eth1 - локалка (192.168.3.180/24)</p><p># cat /proc/sys/net/ipv4/ip_forward </p><p>1</p><p>Надо сделать сабж. Давно делал и много. Может чего забыл?</p><p># iptables -t nat -A POSTROUTING -s 192.168.3.0/255.255.255.0 -o eth0 -j MASQUERADE</p><p>Все, кажись, должно работать.</p><p>В локалке машинке даю шлюзом 192.168.3.180. Инета нет. пинги во внешку не проходят тоже</p>]]></description>
</item>
</channel>
</rss>