我用这个文件就可以通过代理上网,映射有21端口可以用,过滤了192.168.1.2上网
# Generated by iptables-save v1.2.7a on Wed Sep 1 19:15:45 2004
*nat
REROUTING ACCEPT [1065308]

OSTROUTING ACCEPT [0]

:OUTPUT ACCEPT [154]
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 61.134.1.9:53
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 61.134.1.4:53
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 61.134.3.11:53
-A PREROUTING -p udp -m udp --dport 53 -j DNAT --to-destination 202.100.4.15:53
-A PREROUTING -d 219.180.X.X -p tcp -m tcp --dport 21 -j DNAT --to-destination 192.168.1.3:21
-A PREROUTING -d 219.180.X.X -p tcp -m tcp --dport 20 -j DNAT --to-destination 192.168.1.3:20
-A PREROUTING -i eth1 -p tcp -m tcp --dport 135:139 -j DROP
-A PREROUTING -i eth1 -p udp -m udp --dport 137:139 -j DROP
-A POSTROUTING -o eth0 -j MASQUERADE
-A POSTROUTING -d 192.168.1.3 -p tcp -m tcp --dport 21 -j SNAT --to-source 192.168.1.1
-A POSTROUTING -d 192.168.1.3 -p tcp -m tcp --dport 20 -j SNAT --to-source 192.168.1.1
COMMIT
# Completed on Wed Sep 1 19:15:45 2004
# Generated by iptables-save v1.2.7a on Wed Sep 1 19:15:45 2004
*filter
:INPUT DROP [645322]
:FORWARD DROP [0]
:OUTPUT DROP [0]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i eth1 -j ACCEPT
-A FORWARD -d 192.168.1.2 -p tcp -j DROP
-A FORWARD -s 192.168.1.2 -p tcp -j DROP
-A FORWARD -d 192.168.1.3 -o eth1 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -s 192.168.1.3 -i eth1 -p tcp -m tcp --sport 21 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -d 192.168.1.3 -o eth1 -p tcp -m tcp --dport 20 -j ACCEPT
-A FORWARD -s 192.168.1.3 -i eth1 -p tcp -m tcp --sport 20 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -m state --state NEW -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -m state --state INVALID,NEW -j DROP
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
-A OUTPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p icmp -j ACCEPT
-A OUTPUT -o eth1 -j ACCEPT
COMMIT
# Completed on Wed Sep 1 19:15:45 2004
我用这个文件就可以通过代理上网,映射有21端口可以用
大家帮帮我吧,