Есть большой-большой скрипт с правилами, привожу фрагмент:
$IPTABLES --append POSTROUTING -t nat --destination ${IP_CAM_POLUS} -j SNAT --to-source ${IP_GATEWAY_SELF}
$IPTABLES --append FORWARD --in-interface ${IFACE_NET_WITH_IP_CAM} --out-interface ${IFACE_FRW} --destination ${IP_CAM_POLUS} -j ACCEPT
$IPTABLES --append FORWARD --in-interface ${IFACE_FRW} --out-interface ${IFACE_NET_WITH_IP_CAM} --source ${IP_CAM_POLUS} -j ACCEPT
Nov 24 11:52:53 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=3308 DF PROTO=TCP SPT=55582 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0
Nov 24 11:52:56 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=3318 DF PROTO=TCP SPT=55582 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0
Nov 24 11:52:58 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=3321 DF PROTO=TCP SPT=55585 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0
Nov 24 11:53:01 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=52 TOS=0x00 PREC=0x00 TTL=126 ID=3324 DF PROTO=TCP SPT=55585 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0
Nov 24 11:53:02 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=3326 DF PROTO=TCP SPT=55582 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0
Nov 24 11:53:07 ig kernel: FRW-FWD: IN=eth3 OUT=eth3 SRC=192.168.101.78 DST=192.168.10.28 LEN=48 TOS=0x00 PREC=0x00 TTL=126 ID=3330 DF PROTO=TCP SPT=55585 DPT=5554 WINDOW=8192 RES=0x00 SYN URGP=0