It's just a stock 2.4.20 kernel

ifconfig eth0 netmask up
ifconfig eth0:0 netmask up
route add default gw

iptables -t nat -A PREROUTING -p tcp -s \! -d -j LOG
--log-prefix "DNAT:"
iptables -t nat -A PREROUTING -p tcp -s \! -d -j DNAT

iptables -A INPUT -m state --state RELATED -j LOG --log-prefix "RELATED:"
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -s -j ACCEPT
iptables -A INPUT -p tcp -m multiport -m state --state NEW --destination-port
21,22  -j ACCEPT

iptables -A INPUT -j LOG --log-prefix "REJECT:"
iptables -A INPUT -p tcp -j REJECT --reject-with tcp-reset

