danilovav писал(а):
Аналогично, при помощи PBR все делается, но forward table - alt_dmz, а return - main. Ну и правила IP rules
Спасибо!
Добавил:
Routing Rules:
2 direct_dmz lan neoserverAddress: 192.168.0.114 dmz all-nets Address: 0.0.0.0/0 all_services
Forward routing table: dmz;
Return routing table: main;
Service: all_services
В IP Rules добавил:
1 SAT_DNS_Relay_NS SAT lan neoserverAddress: 192.168.0.114 core lan_ipAddress: 192.168.0.1 dns-allDestination ports: 53
2 Allow_DNS_Relay_NS NAT lan neoserverAddress: 192.168.0.114 core lan_ipAddress: 192.168.0.1 dns-allDestination ports: 53
3 allow_ping-outbound_NS NAT lan neoserverAddress: 192.168.0.114 dmz all-netsAddress: 0.0.0.0/0 ping-outbound
4 allow_ftp-passthrough_NS NAT lan neoserverAddress: 192.168.0.114 dmz all-netsAddress: 0.0.0.0/0 ftp-passthroughDestination ports: 21
5 allow_standard_NS NAT lan neoserverAddress: 192.168.0.114 dmz all-netsAddress: 0.0.0.0/0 all_services
НЕ работает

В логах:
2011-02-07
15:51:35 Info CONN
600005 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 56684
53 conn_close_natsat
close
conn=close connnewsrcip=192.168.1.100 connnewsrcport=35603 connnewdestip=81.23.96.138 connnewdestport=53 origsent=51 termsent=51
2011-02-07
15:51:34 Info CONN
600005 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 59662
53 conn_close_natsat
close
conn=close connnewsrcip=192.168.1.100 connnewsrcport=25324 connnewdestip=81.23.96.138 connnewdestport=53 origsent=51 termsent=51
2011-02-07
15:51:34 Info CONN
600005 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 35048
53 conn_close_natsat
close
conn=close connnewsrcip=192.168.1.100 connnewsrcport=14331 connnewdestip=81.23.96.138 connnewdestport=53 origsent=51 termsent=51
2011-02-07
15:51:34 Info CONN
600005 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 57226
53 conn_close_natsat
close
conn=close connnewsrcip=192.168.1.100 connnewsrcport=2728 connnewdestip=81.23.96.138 connnewdestport=53 origsent=51 termsent=51
2011-02-07
15:49:24 Info CONN
600004 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 56684
53 conn_open_natsat
satdestrule=SAT_DNS_Relay_NS conn=open connnewsrcip=192.168.1.100 connnewsrcport=35603 connnewdestip=81.23.96.138 connnewdestport=53
2011-02-07
15:49:24 Info CONN
600004 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 57226
53 conn_open_natsat
satdestrule=SAT_DNS_Relay_NS conn=open connnewsrcip=192.168.1.100 connnewsrcport=2728 connnewdestip=81.23.96.138 connnewdestport=53
2011-02-07
15:49:24 Info CONN
600004 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 35048
53 conn_open_natsat
satdestrule=SAT_DNS_Relay_NS conn=open connnewsrcip=192.168.1.100 connnewsrcport=14331 connnewdestip=81.23.96.138 connnewdestport=53
2011-02-07
15:49:23 Info CONN
600004 Allow_DNS_Relay_NS UDP lan
wan 192.168.0.114
192.168.0.1 59662
53 conn_open_natsat
satdestrule=SAT_DNS_Relay_NS conn=open connnewsrcip=192.168.1.100 connnewsrcport=25324 connnewdestip=81.23.96.138 connnewdestport=53