#大概這樣,有錯的請指教
/sbin/modprobe ipt_multiport
#turn on ip forwarding
echo 1 > /proc/sys/net/ipv4/ip_forward
#IPtables Default Policy
/sbin/iptables -P INPUT DROP
/sbin/iptables -P OUTPUT DROP
/sbin/iptables -P FORWARD DROP
#IP MASQUERADE
/sbin/iptables -t nat -A POSTROUTING -o $ext_eth -s $int_lan
-j SNAT --to $ext_ip
/sbin/iptables -A FORWARD -s $int_lan -p tcp -m multiport
--dport 80 -j ACCEPT
/sbin/iptables -A FORWARD -s $int_lan -p udp -m multiport
--dport 53,80 -j ACCEPT
/sbin/iptables -A FORWARD -s $int_lan -p tcp -m multiport
--sport 80 -j ACCEPT
/sbin/iptables -A FORWARD -s $int_lan -p udp -m multiport
--sport 53,80 -j ACCEPT
/sbin/iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
/sbin/iptables -A FORWARD -m state --state NEW,INVALID -j DROP