ipfw.conf
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -F
iptables -t nat -F
iptables -t mangle -F
iptables -X
iptables -t nat -X
iptables -t mangle -X
iptables -I INPUT -p TCP -s 95.31.1.168 --dport 40440 -j ACCEPT
### iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.4/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.12$
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.26/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.1$
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.40/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.1$
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.45/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.1$
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.66/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.1$
iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.120/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.0.$
# iptables -t nat -A PREROUTING -i eth0 ! -d 10.100.0.123/255.255.255.255 -p tcp -m multiport --dport 20,21,80,443,8080 -j DNAT --to 10.100.$
iptables -t nat -A POSTROUTING -s 10.100.0.4/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.26/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.40/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.45/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.66/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.120/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -t nat -A POSTROUTING -s 10.100.0.124/255.255.255.255 -j SNAT --to 89.208.121.198
iptables -A INPUT -i eth1 -p udp --dport 67:68 -j DROP
iptables -A INPUT -i eth1 -p udp --dport 135:139 -j DROP
iptables -A INPUT -i eth1 -p udp --dport 3128 -j DROP
iptables -A INPUT -i eth1 -p udp --dport 445 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 67:68 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 135:139 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 3128 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 80 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 443 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 445 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 10000 -j DROP
iptables -A INPUT -i eth1 -p tcp --dport 53 -j DROP
# iptables -I INPUT -i eth1 -j DROP
:: назад