[root@localhost sysconfig]# iptables-save -c
# Generated by iptables-save v1.2.8 on Wed Oct 18 18:11:36 2006
*filter
:INPUT ACCEPT [119968:107087164]
:FORWARD ACCEPT [19441:8342346]
:OUTPUT ACCEPT [120774:106784654]
COMMIT
# Completed on Wed Oct 18 18:11:36 2006
# Generated by iptables-save v1.2.8 on Wed Oct 18 18:11:36 2006
*nat
REROUTING ACCEPT [17442:4564702]

OSTROUTING ACCEPT [699:274778]

:OUTPUT ACCEPT [4468:501085]
[2689:171792] -A PREROUTING -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128
[1:40] -A PREROUTING -i ppp0 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.0.3:3389
[0:0] -A PREROUTING -d 219.142.138.129 -i ppp0 -p tcp -m tcp --dport 3389 -j DNAT --to-destination 192.168.0.3:3389
[4720:291879] -A POSTROUTING -o ppp0 -j MASQUERADE
COMMIT
# Completed on Wed Oct 18 18:11:36 2006
iptables做网关,内网30台电脑上网,使用的是电信的拨号,ip是动态的,192.168.0.3是内网的一台win2003的机器,但是输入iptables -t nat -A PREROUTING -i ppp0 -p tcp -d 219.142.138.129 --dport 3389 -j DNAT --to 192.168.0.3:3389 时ip没有变。