thiagomcinfo
(usa CentOS)
Enviado em 21/04/2014 - 16:15h
Pessoal desde ja agradeço:
Seguinte troquei o servidor ad da empresa, dai depois recnectei o squid, kerberos e etc...
Agora funciona navegação authenticada pelo AD, mais não consigo acessar emails externos via outlook e nem ftp!
Segue os conf´s:
IPTABLES:
# Generated by iptables-save v1.3.5 on Thu Dec 16 09:06:55 2010
*filter
:INPUT DROP [0:0]
:FORWARD DROP [5814:473969]
:OUTPUT ACCEPT [2207030:928570205]
:sshguard - [0:0]
-A INPUT -s 187.45.213.196 -p tcp -m tcp --dport 8090 -j DROP
-A INPUT -s 221.195.4.92 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -s 201.47.246.170 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -s 201.148.157.151 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -s 125.39.82.251 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -s 124.247.193.78 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -s 60.217.229.226 -p tcp -m tcp --dport 22 -j DROP
-A INPUT -p tcp -m tcp --dport 22 -j sshguard
-A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type any -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -s 146.164.48.1 -d 200.205.36.252 -i eth1 -p udp -m udp --dport 123 -j ACCEPT
-A INPUT -s 143.107.255.15 -d 200.205.36.252 -i eth1 -p udp -m udp --dport 123 -j ACCEPT
-A INPUT -s 200.20.186.75 -d 200.205.36.252 -i eth1 -p udp -m udp --dport 123 -j ACCEPT
-A INPUT -s 200.144.121.33 -d 200.205.36.252 -i eth1 -p udp -m udp --dport 123 -j ACCEPT
-A INPUT -s 200.192.112.8 -d 200.205.36.252 -i eth1 -p udp -m udp --dport 123 -j ACCEPT
-A INPUT -p udp -m state --state NEW -m udp --dport 53 -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -i eth0 -p tcp -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -i eth0 -p udp -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -d 192.168.0.0/255.255.255.0 -i eth0 -p icmp -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.0.37 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.0.41 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.0.25 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 192.168.0.2 -p tcp -m tcp --dport 3389 -j ACCEPT
-A FORWARD -s 200.169.222.131 -d 192.168.0.1 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -s 200.169.222.130 -d 192.168.0.1 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -s 200.230.21.0/255.255.255.0 -d 192.168.0.1 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -s 192.168.0.0/255.255.255.0 -p udp -m udp --dport 53 -j ACCEPT
-A FORWARD -s 192.168.0.231 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.40 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.39 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.30 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.30 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.33 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.12 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.24 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.34 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.232 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.38 -p icmp -j ACCEPT
-A FORWARD -s 192.168.0.31 -p tcp -m multiport --dports 1433 -j ACCEPT
-A FORWARD -s 192.168.0.2 -p tcp -m multiport --dports 7177 -j ACCEPT
-A FORWARD -s 192.168.0.2 -p tcp -m multiport --dports 5500:5600 -j ACCEPT
-A FORWARD -s 192.168.0.29 -p tcp -m multiport --dports 20,21,1433,5432,3389 -j ACCEPT
-A FORWARD -s 192.168.0.16 -p tcp -m multiport --dports 20,21,1433,5432,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.103 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,3456,587 -j ACCEPT
-A FORWARD -s 192.168.0.20 -p tcp -m multiport --dports 1433 -j ACCEPT
-A FORWARD -s 192.168.0.231 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.231 -p tcp -m multiport --dports 3306,5222,8443,8888 -j ACCEPT
-A FORWARD -s 192.168.0.40 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.40 -p tcp -m multiport --dports 3306,5222,8443 -j ACCEPT
-A FORWARD -s 192.168.0.12 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.12 -p tcp -m multiport --dports 3306,5222,8433,8888 -j ACCEPT
-A FORWARD -s 192.168.0.32 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.32 -p tcp -m multiport --dports 3306,5222,8443,8888 -j ACCEPT
-A FORWARD -s 192.168.0.30 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.30 -p tcp -m multiport --dports 3306,8443 -j ACCEPT
-A FORWARD -s 192.168.0.38 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j ACCEPT
-A FORWARD -s 192.168.0.38 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.38 -p tcp -m multiport --dports 2180,39365,6514,1972,6515,1973,80,443 -j ACCEPT
-A FORWARD -s 192.168.0.11 -p tcp -m multiport --dports 25,110,143,465,995,587,1863,3389 -j ACCEPT
-A FORWARD -s 192.168.0.36 -p tcp -m multiport --dports 25,110,143,465,995,587,1863,3389 -j ACCEPT
-A FORWARD -s 192.168.0.31 -p tcp -m multiport --dports 20,21,25,110,143,465,995,587,1863,2121,3389 -j ACCEPT
-A FORWARD -s 192.168.0.33 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j ACCEPT
-A FORWARD -s 192.168.0.33 -p tcp -m multiport --dports 2180,7004,7003,7005
-A FORWARD -s 192.168.0.12 -p tcp -m multiport --dports 2180,21,1433
-A FORWARD -s 192.168.0.24 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j ACCEPT
-A FORWARD -s 192.168.0.24 -p tcp -m multiport --dports 2180,7004,7003,7005
-A FORWARD -s 192.168.0.37 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.35 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.41 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.25 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.94 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j ACCEPT
-A FORWARD -s 192.168.0.34 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j ACCEPT
-A FORWARD -s 192.168.0.34 -p tcp -m multiport --dports 2180,7004,7003,7005,587
-A FORWARD -s 192.168.0.37 -p tcp -m multiport --dports 5800,5900,2121,8090,3050,5432,587,5222 -j ACCEPT
-A FORWARD -s 192.168.0.35 -p tcp -m multiport --dports 5800,5900,2121,8090,3050,5432,587,5222 -j ACCEPT
-A FORWARD -s 192.168.0.41 -p tcp -m multiport --dports 5800,5900,2121,8090,3050,5432,587,5222 -j ACCEPT
-A FORWARD -s 192.168.0.37 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.35 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.41 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.25 -p tcp -m multiport --dports 5800,5900,2121,8090,3050,5432,587 -j ACCEPT
-A FORWARD -s 192.168.0.25 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.33 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
#-A FORWARD -s 192.168.0.12 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.24 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.34 -p tcp -m multiport --dports 1024:65534 -j ACCEPT
-A FORWARD -s 192.168.0.24 -p tcp -m multiport --dports 3389 -j ACCEPT
-A FORWARD -s 192.168.0.81 -p tcp -m multiport --dports 3389 -j ACCEPT
#-A FORWARD -s 192.168.0.25 -p tcp -m multiport --dports 3389 -j ACCEPT
-A FORWARD -s 192.168.0.52 -p tcp -m multiport --dports 3389 -j ACCEPT
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 4661:4662 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p udp -m udp --sport 4465 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 8577 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 8577 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 1214 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p udp -m udp --sport 1214 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 3551 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m tcp --sport 3531 -j DROP
-A OUTPUT -s 200.205.36.252 -o eth1 -p tcp -m multiport --sports 6881,6889,8090,7004,7003,7005 -j DROP
COMMIT
# Completed on Thu Dec 16 09:06:55 2010
# Generated by iptables-save v1.3.5 on Thu Dec 16 09:06:55 2010
*nat
:PREROUTING ACCEPT [30598:2428602]
:POSTROUTING ACCEPT [144062:8738746]
:OUTPUT ACCEPT [144400:8767646]
-A PREROUTING -s 200.160.108.5 -d 200.205.36.252 -p tcp -m tcp --dport 1433 -j DNAT --to-destination 192.168.0.31:1433
-A PREROUTING -s 189.11.243.254 -d 200.205.36.252 -p tcp -m tcp --dport 1433 -j DNAT --to-destination 192.168.0.31:1433
-A PREROUTING -s 200.169.222.131 -d 200.205.36.252 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.0.1:22
-A PREROUTING -s 200.169.222.130 -d 200.205.36.252 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.0.1:22
-A PREROUTING -s 200.230.21.0/255.255.255.0 -d 200.205.36.252 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.0.1:22
-A POSTROUTING -s 192.168.0.231 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.40 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.30 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.33 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.24 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.34 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.232 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.38 -p icmp -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/255.255.255.0 -p udp -m udp --dport 53 -j MASQUERADE
-A PREROUTING -p tcp --dport 7177 -j DNAT --to 192.168.0.2:7177
-A PREROUTING -p tcp --dport 5500:5600 -j DNAT --to 192.168.0.2
-A PREROUTING -s 201.246.47.5 -d 200.205.36.252 -p tcp -m tcp --dport 1433 -j DNAT --to-destination 192.168.0.31:1433
-A POSTROUTING -s 192.168.0.36 -p tcp -m multiport --dports 20,21,25,110,5432,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.29 -p tcp -m multiport --dports 20,21,1433,5432,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.16 -p tcp -m multiport --dports 20,21,1433,5432,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.103 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,3456,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.20 -p tcp -m multiport --dports 1433 -j MASQUERADE
-A POSTROUTING -s 192.168.0.231 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.231 -p tcp -m multiport --dports 3306,5222,8443,8888 -j MASQUERADE
-A POSTROUTING -s 192.168.0.40 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.40 -p tcp -m multiport --dports 3306,5222,8443 -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -p tcp -m multiport --dports 3306,5222,8443,8888 -j MASQUERADE
-A POSTROUTING -s 192.168.0.32 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.32 -p tcp -m multiport --dports 3306,5222,8443,8888 -j MASQUERADE
-A POSTROUTING -s 192.168.0.30 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.30 -p tcp -m multiport --dports 3306,8443 -j MASQUERADE
-A POSTROUTING -s 192.168.0.38 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1433,3050,5432,1863,2121,3389,5900,5800 -j MASQUERADE
-A POSTROUTING -s 192.168.0.38 -p tcp -m multiport --dports 39365,6514,1972,6515,1973,80,443 -j MASQUERADE
-A POSTROUTING -s 192.168.0.38 -d 189.47.139.217 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.11 -p tcp -m multiport --dports 25,110,143,465,995,587,1863,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.36 -p tcp -m multiport --dports 25,110,143,465,995,587,1863,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.34 -p tcp -m multiport --dports 25,110,143,465,995,587,1863,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.31 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.33 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,5800,5900,2121,1863,8090 -j MASQUERADE
-A POSTROUTING -s 192.168.0.33 -p tcp -m multiport --dports 2180,7004,7005,7003
-A POSTROUTING -s 192.168.0.35 -p tcp -m multiport --dports 2180,7004,7005,7003
-A POSTROUTING -s 192.168.0.12 -p tcp -m multiport --dports 2180,7004,7005,7003
-A POSTROUTING -s 192.168.0.12 -p tcp -m multiport --dports 21,2180,2180,1433
-A POSTROUTING -s 192.168.0.24 -p tcp -m multiport --dports 21,2180,2180
-A POSTROUTING -s 192.168.0.33 -d 187.45.233.45 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 187.45.233.45 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
#-A POSTROUTING -s 192.168.0.12 -d 187.45.233.45 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.24 -d 187.45.233.45 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.33 -d 187.45.206.186 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 187.202.3.21 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
#-A POSTROUTING -s 192.168.0.12 -d 187.202.3.21 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -d 187.202.3.21 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 187.202.136.25 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 187.45.206.186 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.12 -d 187.202.136.25 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.24 -d 187.45.244.127 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A PREROUTING -s 187.45.244.127 -p tcp -i eth1 --dport 7005 -j DNAT --to 192.168.0.33
-A PREROUTING -s 187.45.244.45 -p tcp -i eth1 --dport 7003 -j DNAT --to 192.168.0.33
-A PREROUTING -s 187.45.244.186 -p tcp -i eth1 --dport 7004 -j DNAT --to 192.168.0.33
-A PREROUTING -s 187.45.244.45 -p tcp -i eth1 --dport 7004 -j DNAT --to 192.168.0.33
#-A PREROUTING -s 187.45.244.127 -p tcp -i eth1 --dport 7005 -j DNAT --to 192.168.0.24
-A PREROUTING -s 187.45.244.45 -p tcp -i eth1 --dport 7003 -j DNAT --to 192.168.0.24
-A PREROUTING -s 187.45.244.186 -p tcp -i eth1 --dport 7004 -j DNAT --to 192.168.0.24
-A PREROUTING -s 187.45.244.45 -p tcp -i eth1 --dport 7004 -j DNAT --to 192.168.0.24
-A POSTROUTING -s 192.168.0.37 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -p tcp -m multiport --dports 21,21,25,110,143,465,995,1863,2121,3389,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.41 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.25 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.94 -p tcp -m multiport --dports 20,21,25,110,143,465,995,1863,2121,3389,587 -j MASQUERADE
-A POSTROUTING -s 192.168.0.37 -p tcp -m multiport --dports 5800,5900,2121,1433,3050,5432,5222 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -p tcp -m multiport --dports 5800,5900,2121,1433,3050,5432,5222 -j MASQUERADE
-A POSTROUTING -s 192.168.0.41 -p tcp -m multiport --dports 5800,5900,2121,1433,3050,5432,5222 -j MASQUERADE
-A POSTROUTING -s 192.168.0.37 -d 189.47.139.217 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 189.47.139.217 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.41 -d 189.47.139.217 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.25 -p tcp -m multiport --dports 5800,5900,2121,1433,3050,5432 -j MASQUERADE
-A POSTROUTING -s 192.168.0.25 -d 189.47.139.217 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.25 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j MASQUERADE
-A POSTROUTING -s 192.168.0.38 -d 187.45.233.45 -p tcp -m multiport --dports 1024:65534 -j MASQUERADE
-A POSTROUTING -s 192.168.0.37 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j MASQUERADE
-A POSTROUTING -s 192.168.0.35 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j MASQUERADE
-A POSTROUTING -s 192.168.0.41 -d 189.126.109.250 -p tcp -m tcp --dport 80 -j MASQUERADE
-A POSTROUTING -s 192.168.0.24 -p tcp -m multiport --dports 3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.40 -p tcp -m multiport --dports 3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.81 -p tcp -m multiport --dports 3389 -j MASQUERADE
#-A POSTROUTING -s 192.168.0.25 -p tcp -m multiport --dports 3389 -j MASQUERADE
-A POSTROUTING -s 192.168.0.52 -p tcp -m multiport --dports 3389 -j MASQUERADE
COMMIT
# Completed on Thu Dec 16 09:06:55 2010