Добрый день, имеется Ubuntu Server 12.04, выступает в качестве шлюза, поднят squid в прозрачном режиме, iptables, NAT, до перезагрузки всё было замечательно, после перезагрузки отвалился SSH ( Connection Refused ) при попытке подключения, в логах:
Dec 6 16:31:05 PROXY kernel: [4217480.231733] init: ssh main process (31597) terminated with status 255
Dec 6 16:31:05 PROXY kernel: [4217480.231802] init: ssh respawning too fast, stopped
#! /sbin/iptables-restore
# Generated by iptables-save v1.4.12
*nat
:PREROUTING ACCEPT [1195:92907]
:INPUT ACCEPT [212:14627]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 25 -j DNAT --to-destination XXX.XXX.X.43:25
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 3000 -j DNAT --to-destination XXX.XXX.X.130:3389
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination XXX.XXX.X.43:80
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 5080 -j DNAT --to-destination XXX.XXX.X.146:80
-A PREROUTING -d [внешнийIP]/32 -p udp -m udp --dport 1:65534 -j DNAT --to-destination XXX.XXX.X.146
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 3389 -j DNAT --to-destination XXX.XXX.X.2:3389
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 5437 -j DNAT --to-destination XXX.XXX.X.124:5437
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 5438 -j DNAT --to-destination XXX.XXX.X.237:5438
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 7654 -j DNAT --to-destination XXX.XXX.X.210:3389
-A PREROUTING -d [внешнийIP]/32 -p tcp -m tcp --dport 8234 -j DNAT --to-destination XXX.XXX.X.170:3389
-A POSTROUTING -s XXX.XXX.X.0/24 -o ppp0 -j MASQUERADE
-A POSTROUTING -d XXX.XXX.X.43/32 -p tcp -m tcp --dport 25 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.130/32 -p tcp -m tcp --dport 3000 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.130/32 -p tcp -m tcp --dport 8839 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.43/32 -p tcp -m tcp --dport 80 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.146/32 -p udp -m udp --dport 1:65534 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.2/32 -p tcp -m tcp --dport 3389 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.124/32 -p tcp -m tcp --dport 5437 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.238/32 -p tcp -m tcp --dport 5438 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.210/32 -p tcp -m tcp --dport 7654 -j SNAT --to-source [внешнийIP]
-A POSTROUTING -d XXX.XXX.X.170/32 -p tcp -m tcp --dport 8234 -j SNAT --to-source [внешнийIP]
COMMIT
# Completed on
# Generated by iptables-save v1.4.12
*filter
:INPUT ACCEPT [60286:7057966]
:FORWARD ACCEPT [1453988:710593203]
:OUTPUT ACCEPT [26578:2205577]
COMMIT
# Completed
# Generated by iptables-save v1.4.12
*mangle
:PREROUTING ACCEPT [721473:368307169]
:INPUT ACCEPT [15758:1143642]
:FORWARD ACCEPT [705520:367143917]
:OUTPUT ACCEPT [9197:498383]
:POSTROUTING ACCEPT [714708:367641652]
-A FORWARD -o ppp0 -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1400:65495 -j TCPMSS --clamp-mss-to-pmtu
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT
# Completed