No to skaczylem .... jakies uwagi lub propozycje ??
# Generated by iptables-save v1.3.4 on Mon Mar 20 23:38:30 2006
*filter
:INPUT DROP [37:4958]
:FORWARD DROP [0:0]
:OUTPUT DROP [26:12348]
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m multiport --dports 135,445,1550,8074 -j DROP
-A INPUT -p tcp -m tcp --dport 113 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -p tcp -m tcp --dport 1080 -j REJECT --reject-with icmp-port-unreachable
-A INPUT -i eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 20 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 21 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 25 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 110 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 137 -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --dport 137 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 138 -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --dport 138 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 139 -j ACCEPT
-A INPUT -i eth1 -p udp -m udp --dport 139 -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --dport 3128 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 8 -m limit --limit 1/sec -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -j DROP
-A FORWARD -o lo -j ACCEPT
-A FORWARD -p tcp -m multiport --dports 135,445 -j DROP
-A FORWARD -p tcp -d 213.180.130.206 -j DROP
-A FORWARD -p tcp -d 217.74.64.236 -j DROP
-A FORWARD -p tcp -d 212.77.101.148 -j DROP
-A FORWARD -p tcp -d 193.17.41.18 -j DROP
-A FORWARD -p tcp -d 193.17.41.26 -j DROP
-A FORWARD -p tcp -d 80.252.0.132 -j DROP
-A FORWARD -p tcp -d 217.74.71.252 -j DROP
-A FORWARD -p tcp -d 212.244.112.150 -j DROP
-A FORWARD -p tcp -d 193.222.135.227 -j DROP
-A FORWARD -p tcp -m ipp2p --kazaa --gnu --edk --dc --bit --apple --soul --winmx --ares -j DROP
-A FORWARD -d 212.77.100.22/29 -j DROP
-A FORWARD -p tcp -s 217.17.41.0/24 --sport 443 -d 0/0 -j DROP
-A FORWARD -p tcp -s 0/0 -d 217.17.41.0/24 --dport 443 -j DROP
-A FORWARD -p tcp -s 212.126.20.0/24 --sport 443 -d 0/0 -j DROP
-A FORWARD -p tcp -s 0/0 -d 212.17.41.0/24 --dport 443 -j DROP
-A FORWARD -p tcp -s 217.17.41.0/24 --sport 8074 -d 0/0 -j DROP
-A FORWARD -p tcp -s 0/0 -d 217.17.41.0/24 --dport 8074 -j DROP
-A FORWARD -p tcp -s 212.126.20.0/24 --sport 8074 -d 0/0 -j DROP
-A FORWARD -p tcp -s 0/0 -d 212.17.41.0/24 --dport 8074 -j DROP
-A FORWARD -d 193.17.41.48/255.255.255.248 -j DROP
-A FORWARD -d 212.77.100.16/255.255.255.248 -j DROP
-A FORWARD -d 85.232.233.10 -j DROP
-A FORWARD -d 217.17.41.82 -j DROP
-A FORWARD -d 217.17.41.83 -j DROP
-A FORWARD -d 217.17.41.84 -j DROP
-A FORWARD -d 217.17.41.85 -j DROP
-A FORWARD -d 217.17.41.86 -j DROP
-A FORWARD -d 217.17.41.87 -j DROP
-A FORWARD -d 217.17.41.88 -j DROP
-A FORWARD -d 217.17.41.92 -j DROP
-A FORWARD -d 217.17.41.93 -j DROP
-A FORWARD -d 217.17.41.133 -j DROP
-A FORWARD -d 217.17.41.138 -j DROP
-A FORWARD -d 217.17.41.139 -j DROP
-A FORWARD -d 217.17.41.142 -j DROP
-A FORWARD -d 217.17.45.143 -j DROP
-A FORWARD -p tcp -m multiport --dports 1550,8074 -j DROP
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -i ! eth0 -d XXX.XXX.XXX.XXX -p tcp -m tcp --dport 25 -j ACCEPT
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 53 -j ACCEPT
-A FORWARD -i ! eth0 -p udp -m udp --dport 53 -j ACCEPT
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -i ! eth0 -d XXX.XXX.XXX.XXX -p tcp -m tcp --dport 110 -j ACCEPT
-A FORWARD -i ! eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j DROP
-A OUTPUT -j ACCEPT
COMMIT
# Completed on Mon Mar 20 23:38:30 2006
# Generated by iptables-save v1.3.4 on Mon Mar 20 23:38:30 2006
*mangle

REROUTING ACCEPT [4350:745384]
:INPUT ACCEPT [2623:218585]
:FORWARD ACCEPT [1725:526679]
:OUTPUT ACCEPT [2311:741428]

OSTROUTING ACCEPT [3993:1250239]
-A POSTROUTING -o eth1 -j TTL --ttl-set 1
COMMIT
# Completed on Mon Mar 20 23:38:30 2006
# Generated by iptables-save v1.3.4 on Mon Mar 20 23:38:30 2006
*nat

REROUTING ACCEPT [160:20217]

OSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Mon Mar 20 23:38:30 2006
Dzieki za odzew.