root@linux:~# cat /etc/rc.d/rc.local
#!/bin/sh
#
# /etc/rc.d/rc.local: Local system initialization script.
#
# Put any local setup commands in here:
iptables -t nat -F
iptables -F
#modprobe ip_contrack_ftp
modprobe ip_nat_ftp
iptables -A FORWARD -p tcp -m limit --limit 1/s -j ACCEPT
iptables -A INPUT -p tcp --syn -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 12345 -j LOG --log-prefix "Servico: BackOrifice"
iptables -A FORWARD -i eth0 -p tcp --dport 25 -j ACCEPT
[color=red]iptables -t nat -A PREROUTING -p udp -d 0/0 --dport 8002 -j DNAT --to 192.168.1.5:8002
iptables -t nat -A PREROUTING -p tcp -d 0/0 --dport 8001 -j DNAT --to 192.168.1.5:8001[/color]
iptables -A FORWARD -s 192.168.1.5/24 -p tcp --dport 1863 -j ACCEPT
iptables -A FORWARD -s 192.168.1.5/24 -d loginnet.passport.com -j ACCEPT
iptables -A FORWARD -s 192.168.1.0/24 -p tcp --dport 1863 -j REJECT --reject-with tcp-reset
iptables -A FORWARD -p tcp --dport 1863 -j REJECT
iptables -A FORWARD -s 192.168.1.0/24 -d webmessenger.msn.com -j REJECT
iptables -A FORWARD -d 64.4.13.0/24 -j REJECT
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j REDRECT --to-port 3128
iptables -t nat -A PREROUTING -i eth2 -p tcp --dport 80 -j REDIRECT --to-port 3128
########IP MASQUERADE ############
iptables -t nat -A POSTROUTING -s 0/0 -j MASQUERADE
iptables -t nat -L
squid
root@linux:~#