iptables-save的输出如下:
# Generated by iptables-save v1.2.8 on Thu Nov 17 15:22:32 2005
*filter
:INPUT ACCEPT [14086397:94541635194]
:FORWARD ACCEPT [3559:1237107]
:OUTPUT ACCEPT [13888784:3850656385]
-A INPUT -i eth1 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -j DROP
-A INPUT -i eth1 -p udp -j DROP
-A INPUT -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 23 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 139 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 22 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 23 -j ACCEPT
-A OUTPUT -p tcp -m tcp --sport 139 -j ACCEPT
COMMIT
# Completed on Thu Nov 17 15:22:32 2005
# Generated by iptables-save v1.2.8 on Thu Nov 17 15:22:32 2005
*nat
REROUTING ACCEPT [310920:28532802]

OSTROUTING ACCEPT [11939:725438]

:OUTPUT ACCEPT [11939:725438]
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -o eth1 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/255.255.255.0 -o eth1 -j MASQUERADE
COMMIT
# Completed on Thu Nov 17 15:22:32 2005