echo "1" > /proc/sys/net/ipv4/ip_forward
echo "1" > /proc/sys/net/ipv4/ip_dynaddr
echo "0" > /proc/sys/net/ipv4/conf/all/rp_filter
#Flush
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
#iptables -A INPUT -j LOG --log-prefix "EZAZ"
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth1 -j ACCEPT
iptables -A INPUT -i ppp+ -p tcp --dport 2222 -j ACCEPT
iptables -A INPUT -i eth0 -m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -m state --state RELATED -j ACCEPT
iptables -A INPUT -i ppp+ -m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -i ppp+ -m state --state RELATED -j ACCEPT
#iptables -t nat -A POSTROUTING -o ppp+ -j MASQUERADE
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 25 -j DNAT --to-destination 10.100.100.100:25
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j DNAT --to-destination 10.100.100.100:3128
iptables -t nat -A PREROUTING -i eth1 -p udp --dport 53 -j DNAT --to-destination 10.100.100.100:53
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 53 -j DNAT --to-destination 10.100.100.100:53
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 443 -j DNAT --to-destination 10.100.100.100:443
#remote desktop
iptables -A INPUT -i eth+ -p tcp --dport 3389 -j ACCEPT
iptables -t nat -A PREROUTING -i ppp+ -p tcp --dport 3389 -j DNAT --to-dest 10.100.100.200:3389
iptables -A FORWARD -p tcp -i eth+ --dport 3389 -d 10.100.100.200 -j ACCEPT
iptables -A FORWARD -i lo -o ppp+ -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED -j ACCEPT
iptables -A FORWARD -m state --state RELATED -j ACCEPT
miért nem tud 10.100.100.200-as gép rdp-zni kifelé?
hülye megoldás de már azt is csináltam hogy az összes drop-ot accept-re raktam és akkor sem ment.
tudna segíteni valaki?