pyrvo, ne moje da ne puskash nishto i da iskash IT, posle
ne se polzva nat tablicata za da filtrirash portove. napravi
si edin stateful ruleset i otgore pusni icq kato iskash,
vypreki che ne e nujno - mojesh da poluchavash msgs prez icq
serverite bez da ima nujda da se polzva 5190.
IPT=iptables
$IPT -t filter -A INPUT -i eth+ -m state --state
ESTABLISHED,RELATED -j ACCEPT
$IPT -t filter -A INPUT -i ! eth+ -m state --state NEW -j
ACCEPT
$IPT -I INPUT -t filter -s 0/0 -i eth+ -p tcp --dport 5190
-j ACCEPT
$IPT -t filter -A INPUT -i eth+ -m state --state NEW,INVALID
-j REJECT --reject-with icmp-proto-unreachable
# masq..
echo 1 > /proc/sys/net/ipv4/ip_forward
$IPT -t nat -A POSTROUTING -o eth+ -s 0/0 -j MASQUERADE
--
btw, procheti okolo dnat/snat.. daje vsichko :-)
|