man iptables
http://www.frozentux.net/documents/iptables-tutorial/
man sysctl
暫時設定 ip_forward
echo 1 > /proc/sys/net/ipv4/ip_forward
永久設定 ip_forward,改 /etc/sysctl.conf
net.ipv4.ip_forward = 1
sysctl -p /etc/sysctl.conf
設定偽裝
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
設定鏈
iptables -P FORWARD ACCEPT