Всем привет.
Для начала:
eth1 Link encap:Ethernet HWaddr 00:15:5d:15:cb:0f
inet addr:192.168.11.251 Bcast:192.168.11.255 Mask:255.255.255.128
inet6 addr: fe80::215:5dff:fe15:cb0f/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:10579005 errors:0 dropped:4537886 overruns:0 frame:0
TX packets:829963 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:5675815562 (5.6 GB) TX bytes:217801020 (217.8 MB)
eth2 Link encap:Ethernet HWaddr 00:15:5d:15:cb:10
inet addr:X.X.X.X Bcast:X.X.X.X Mask:255.255.255.252
inet6 addr: fe80::215:5dff:fe15:cb10/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4462347 errors:0 dropped:833827 overruns:0 frame:0
TX packets:3965476 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:811107969 (811.1 MB) TX bytes:2404853474 (2.4 GB)
lo Link encap:Локальная петля (Loopback)
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:3024900 errors:0 dropped:0 overruns:0 frame:0
TX packets:3024900 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:400069187 (400.0 MB) TX bytes:400069187 (400.0 MB)
tun1 Link encap:UNSPEC HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
inet addr:10.10.10.1 P-t-P:10.10.10.2 Mask:255.255.255.255
UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:100
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
net.ipv4.ip_forward=1
#! /sbin/iptables-restore
# Generated by iptables-save v1.4.12 on Mon Jan 11 00:34:56 2016
*filter
:INPUT ACCEPT [4:244]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1203:159105]
-A INPUT -p icmp -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p udp -m udp --dport 1140 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A INPUT -i eth2 -j ACCEPT
-A INPUT -i tun1 -j ACCEPT
-A INPUT -i eth2 -p tcp -m multiport --dports 22 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth2 -j ACCEPT
-A FORWARD -s 192.168.0.0/16 -j ACCEPT
-A FORWARD -p icmp -j ACCEPT
-A FORWARD -i tun1 -o eth2 -j ACCEPT
-A FORWARD -i tun1 -o eth1 -j ACCEPT
COMMIT
# Completed on Mon Jan 11 #! /sbin/iptables-restore
Mon Jan 11 00:34:57 2016