Here is the saved iptables rules after applying firewall.iptables from chillispot docs
# Generated by iptables-save v1.3.5 on Sat May 23 05:12:41 2009
*mangle
:PREROUTING ACCEPT [1536:156906]
:INPUT ACCEPT [663:77454]
:FORWARD ACCEPT [83:9382]
:OUTPUT ACCEPT [206:30088]
:POSTROUTING ACCEPT [210:30358]
COMMIT
# Completed on Sat May 23 05:12:41 2009
# Generated by iptables-save v1.3.5 on Sat May 23 05:12:41 2009
*filter
:INPUT DROP [18:5514]
:FORWARD ACCEPT [4:270]
:OUTPUT ACCEPT [206:30088]
:RH-Firewall-1-INPUT - [0:0]
-A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A RH-Firewall-1-INPUT -i eth0 -p tcp -m tcp --dport 22 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A RH-Firewall-1-INPUT -i eth1 -p tcp -m tcp --dport 22 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
#-A RH-Firewall-1-INPUT -i eth0 -j REJECT --reject-with icmp-port-unreachable
#-A RH-Firewall-1-INPUT -i eth1 -j DROP
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 80 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 443 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 3990 --tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A FORWARD -i eth1 -j DROP
-A FORWARD -o eth1 -j DROP
COMMIT
# Completed on Sat May 23 05:12:41 2009
# Generated by iptables-save v1.3.5 on Sat May 23 05:12:41 2009
*nat
:PREROUTING ACCEPT [5768:594546]
:POSTROUTING ACCEPT [2:72]
:OUTPUT ACCEPT [18:1081]
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Sat May 23 05:12:41 2009
Am Just not that good with iptables maybe this will help shade some light on why the router does not work after applying this rules and chillispot redirect does not work too. Also need to ssh from the internal interface.
Thanks