<b>ip a</b><div><div>1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN</div><div>š š link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00</div><div>š š inet <a href="http://127.0.0.1/8">127.0.0.1/8</a> scope host lo</div>
<div>2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000</div><div>š š link/ether 00:17:31:d3:7a:40 brd ff:ff:ff:ff:ff:ff</div><div>š š inet <a href="http://172.27.149.252/24">172.27.149.252/24</a> brd 172.27.149.255 scope global eth0</div>
<div>3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000</div><div>š š link/ether 1c:7e:e5:cc:d6:d3 brd ff:ff:ff:ff:ff:ff</div><div>š š inet <a href="http://192.168.1.170/24">192.168.1.170/24</a> brd 192.168.1.255 scope global eth1</div>
<div>4: eth2: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast state DOWN qlen 1000</div><div>š š link/ether 34:08:04:29:d1:91 brd ff:ff:ff:ff:ff:ff</div><div><br></div><div><b>iptables -L -n -v</b></div>
<div><div>Chain INPUT (policy ACCEPT 136 packets, 14443 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div><br></div><div>Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)</div>
<div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div>š š 0 š š 0 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š<a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š state RELATED,ESTABLISHED</div>
<div>š š 0 š š 0 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š172.27.149.5</div><div>š š22 š1128 ACCEPT š š all š-- š* š š š* š š š 192.168.1.130 š š š š<a href="http://0.0.0.0/0">0.0.0.0/0</a></div>
<div>š š 2 š 120 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š192.168.1.130</div></div><div><br></div><b>iptables -t nat -L -n -v</b></div><div><div>Chain INPUT (policy ACCEPT 136 packets, 14443 bytes)</div>
<div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div><br></div><div>Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div>
<div>š š 0 š š 0 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š<a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š state RELATED,ESTABLISHED</div><div>š š 0 š š 0 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š172.27.149.5</div>
<div>š š22 š1128 ACCEPT š š all š-- š* š š š* š š š 192.168.1.130 š š š š<a href="http://0.0.0.0/0">0.0.0.0/0</a></div><div>š š 2 š 120 ACCEPT š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š192.168.1.130</div>
<div><br></div><div>Chain OUTPUT (policy ACCEPT 57 packets, 6444 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div>[root@host-1 sysconfig]# iptables -t nat -L -n -v</div>
<div>Chain PREROUTING (policy ACCEPT 43 packets, 5776 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div>š š 1 š š60 DNAT š š š all š-- š* š š š* š š š <a href="http://0.0.0.0/0">0.0.0.0/0</a> š š š š š š172.27.149.5 š š š što:192.168.1.130</div>
<div><br></div><div>Chain POSTROUTING (policy ACCEPT 17 packets, 892 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div>š š 6 š 360 SNAT š š š all š-- š* š š š* š š š 192.168.1.130 š š š !<a href="http://192.168.1.0/24">192.168.1.0/24</a> š š što:172.27.149.5</div>
<div><br></div><div>Chain OUTPUT (policy ACCEPT 16 packets, 832 bytes)</div><div>špkts bytes target š š prot opt in š š out š š source š š š š š š š destination</div><div><br></div><div><br></div><div><br></div>ÞÅÔ×ÅÒÇ, 28 ÆÅ×ÒÁÌÑ 2013šÇ. ÐÏÌØÚÏ×ÁÔÅÌØ Viacheslav Dubrovskyi ÐÉÓÁÌ:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000">
28.02.2013 06:12, ðÁ×ÅÌ é×ÁÎÏ× ÐÉÛÅÔ:<br>
<span style="white-space:pre-wrap">> îÅ ÓÏ×ÓÅÍ ÐÏÎÑÌ ÐÒÏ ËÁËÉÅ ËÌÀÞÉ
ÉÄÅÔ ÒÅÞØ?<br>
> ÓÈÅÍÁ ÔÁËÁÑ:<br>
> ÔÅÓÔÏ×ÙÊ ÓÅÒ×ÅÒ<br>
> ×ÎÕÔÒÅÎÎÉÊ ip - 192.168.1.170<br>
> ×ÎÅÛÎÉÊ ip - 172.27.149.252<br>
> ÎÅÏÂÈÏÄÉÍÏ ÔÅÌÅÆÏÎ Ó ip 192.168.1.130 ×ÙÈÏÄÉÌ × 172-À ÓÅÔØ c
ÁÄÒÅÓÏÍ 172.27.149.5<br>
</span>üÔÏ ÎÅ ×ÏÚÍÏÖÎÏ. åÓÌÉ ÔÕÄÁ, ÐÁËÅÔ ÄÏÊÄÅÔ ÎÏÒÍÁÌØÎÏ, ÔÏ
ÏÂÒÁÔÎÏ, ÏÎ ÐÏÊÄÅÔ ÎÁ IP 172.27.149.5. á × ×ÁÛÅÊ ÓÈÅÍÅ ÎÅÔ ÄÅ×ÁÊÓÁ Ó
ÔÁËÉÍ IP.<br>
<br>
<span style="white-space:pre-wrap">> äÏÂÁ×ÌÑÀ ÐÒÁ×ÉÌÁ × iptables<br>
> -A PREROUTING -d 172.27.149.5 -j DNAT --to-destination
192.168.1.130<br>
> -A POSTROUTING -s 192.168.1.130 -j SNAT --to-source
172.27.149.5<br>
><br>
> -A FORWARD -s 192.168.1.130 -j ACCEPT<br>
> -A FORWARD -d 192.168.1.130 -j ACCEPT<br>
> -A FORWARD -d 172.27.149.5 -j ACCEPT<br>
> -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT<br>
><br>
> ðÒÉ ÜÔÏÍ ÐÉÎÇÉ ÎÁ ÁÄÒÅÓ 172.27.149.5 ÉÄÕÔ. ÔÏÌØËÏ, Ë
ÓÏÖÁÌÅÎÉÀ, ÔÏÌØËÏ ÐÉÎÇÉ É ÉÄÕÔ.<br>
><br>
> ÞÔÏ ÎÅ ÔÁË? <br>
</span>îÅ ×ÅÒÉÔÓÑ.<br>
ðÏËÁÖÉÔÅ Ó ×ÁÛÅÇÏ ÒÏÕÔÅÒÁ ×Ù×ÏÄ ËÏÍÁÎÄ <br>
# ip a<br>
# iptables -L -n -v<br>
# iptables -t nat -L -n -v<br>
<br>
<br>
<br>
-- <br>
WBR,<br>
Viacheslav Dubrovskyi<br>
<br>
</div>
</blockquote></div>