Почему на 1 комп пускает удаленно а на другой нет?
Т.е. стучусь по адресу белому в офис и на компы 0.2 и 0.105 попадаю.
Но на машину 0.213:47397 Ну ни как ((.
Код: Выделить всё
# iptables-save
# Generated by iptables-save v1.4.7 on Thu Jun 12 16:10:41 2014
*mangle
:PREROUTING ACCEPT [19056:3199472]
:INPUT ACCEPT [1353:598787]
:FORWARD ACCEPT [17698:2599865]
:OUTPUT ACCEPT [1253:614375]
:POSTROUTING ACCEPT [18948:3214004]
COMMIT
# Completed on Thu Jun 12 16:10:41 2014
# Generated by iptables-save v1.4.7 on Thu Jun 12 16:10:41 2014
*nat
:PREROUTING ACCEPT [276:20571]
:POSTROUTING ACCEPT [19:1113]
:OUTPUT ACCEPT [18:1061]
-A PREROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
-A PREROUTING -d 211/32 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.0.2:3389
-A PREROUTING -d 211/32 -p tcp -m tcp --dport 43237 -j DNAT --to-destination 192.168.0.105:43237
[b]-A PREROUTING -d 211/32 -p tcp -m tcp --dport 47397 -j DNAT --to-destination 192.168.0.213:47397 [/b]
-A POSTROUTING -s 192.168.0.0/24 -o eth1 -j SNAT --to-source 77.108.98.211
-A POSTROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 110 -j SNAT --to-source 79
-A POSTROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 995 -j SNAT --to-source 79
-A POSTROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 993 -j SNAT --to-source 79
-A POSTROUTING -s 192.168.0.0/24 -p tcp -m tcp --dport 25 -j SNAT --to-source 79
COMMIT
# Completed on Thu Jun 12 16:10:41 2014
# Generated by iptables-save v1.4.7 on Thu Jun 12 16:10:41 2014
*filter
:INPUT ACCEPT [313:23723]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1250:614139]
-A INPUT -i eth1 -p tcp -m tcp --dport 10000 -j DROP
-A INPUT -i eth1 -p tcp -m tcp --dport 52993 -j DROP
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 1194 -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 2743 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 53 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 43247 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp -m multiport --dports 5901:5903,6001:6003,47397,43237,3389,20,21 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 10000 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 3128 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 1194 -j ACCEPT
-A FORWARD -p tcp -m multiport --dports 80,8080,3128,53,110,143,443,3389,2747,20,22,995,47128,43237,1194 -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 47397 -j ACCEPT
-A FORWARD -p tcp -m tcp --dport 43247 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
COMMIT