@up
i blocked all ports, i left only www, ftp, ssh, and 7171,7172 open with iptables...
Thing what i need is command to check all opened connections with ports and ipadresses, which i can run while i will be under atack to check ip and port of attacker