Im doing exactly the same except with a HDD install and eth0 and eth1 swapped.
ITs working right now
Heres my setup, switch eth0 and eth1 for you![]()
I set it via webmin but with this as reference you should get it working
Chain OUTPUT (policy DROP)
target root@lepeanuts:~# more /var/lib/iptables/active
# Generated by iptables-save v1.2.9 on Sun Feb 1 20:05:07 2004
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
-A INPUT -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j ACCEPT
-A OUTPUT -j ACCEPT
COMMIT
# Completed on Sun Feb 1 20:05:07 2004
# Generated by iptables-save v1.2.9 on Sun Feb 1 20:05:07 2004
*nat
:OUTPUT ACCEPT [0:0]
:PREROUTING ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -s 192.168.0.0/255.255.0.0 -j MASQUERADE
COMMIT
# Completed on Sun Feb 1 20:05:07 2004
# Generated by iptables-save v1.2.9 on Sun Feb 1 20:05:07 2004
*mangle
:PREROUTING ACCEPT [1232:98033]
:INPUT ACCEPT [1222:97427]
:FORWARD ACCEPT [10:606]
:OUTPUT ACCEPT [1232:98313]
:POSTROUTING ACCEPT [1232:98033]
uttos - [0:0]
retos - [0:0]
-A PREROUTING -j pretos
-A OUTPUT -j outtos
-A outtos -p tcp -m tcp --dport 22 -j TOS --set-tos 0x10
-A outtos -p tcp -m tcp --sport 22 -j TOS --set-tos 0x10
-A outtos -p tcp -m tcp --dport 21 -j TOS --set-tos 0x10
-A outtos -p tcp -m tcp --sport 21 -j TOS --set-tos 0x10
-A outtos -p tcp -m tcp --sport 20 -j TOS --set-tos 0x08
-A outtos -p tcp -m tcp --dport 20 -j TOS --set-tos 0x08
-A pretos -p tcp -m tcp --dport 22 -j TOS --set-tos 0x10
-A pretos -p tcp -m tcp --sport 22 -j TOS --set-tos 0x10
-A pretos -p tcp -m tcp --dport 21 -j TOS --set-tos 0x10
-A pretos -p tcp -m tcp --sport 21 -j TOS --set-tos 0x10
-A pretos -p tcp -m tcp --sport 20 -j TOS --set-tos 0x08
-A pretos -p tcp -m tcp --dport 20 -j TOS --set-tos 0x08
COMMIT
# Completed on Sun Feb 1 20:05:07 2004
prot opt source destination
ACCEPT all -- anywhere anywhere
Then you need to setup masquerading


Reply With Quote










