$IPT -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
for DNS in $(grep ^n /etc/resolv.conf |awk '{print $2}'); do
$IPT -A INPUT -p udp -s $DNS --sport domain -j ACCEPT
done
$IPT -A INPUT -p tcp --sport $http -j ACCEPT
$IPT -A INPUT -p tcp --sport $ftp -j ACCEPT
$IPT -A INPUT -p tcp --sport $smtp -j ACCEPT
$IPT -A INPUT -p tcp --sport $pop3 -j ACCEPT
$IPT -A INPUT -p tcp --sport $sql -j ACCEPT
iptables -A FORWARD -p tcp -d $你的内网服务ip --dport $你的内网服务端口 -m state --state NEW -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT