sudo iptables -N home_users
!
sudo iptables -I home_users -d 10.20.190.0/23 -j ACCEPT
sudo iptables -I home_users -d 10.20.192.0/21 -j ACCEPT

sudo iptables -I FORWARD 64 -s 10.20.253.24/29 -d 10.20.0.0/16 -j home_users

This will cover networks destined within the home_users chain :

/21 = 10.20.190.0 – 10.20.191.255
/23 = 10.20.192.0 – 10.20.199.255

To add the chain home_users :
sudo iptables -N home_users
!
To delete the chain home_users :
sudo iptables -X home_users
!
!

“iptables –table nat –flush”

This will remove all chains from your current running netfilter table (firewall rules)…
you just dropped your pants.

!

“iptables –delete-chain”

This will remove all chains from your current running nat table
!

“iptables –table nat –delete-chain”

No need to do this after a flush!  There are no chains in your current running nat table
because you already flushed it.

!

“iptables –table nat –append POSTROUTING –out-interface eth0 -j MASQUERADE”

This will enable nat in your current running nat table until we get down to the restart below.
!

“echo 1 > /proc/sys/net/ipv4/ip_forward”

This will turn on routing.  To bad next time you boot, it will not be enabled.  Use sysct
!

“service iptables restart”
I love this one.  This command will un-do every “iptable” command above.
Now NAT is no longer running. When the iptables service is restarted, it reads
the saved config and anything was in “current running” is gone.
Instead, use iptables-save
.
!
!
The cleanest method of accomplishing this is to create a new chain which does both
the LOG and DROP for you
.

The following IPTABLES rules will create a LOGDROP chain.

Create the LOGDROP chain
iptables -N LOGDROP > /dev/null 2> /dev/null
iptables -F LOGDROP
iptables -A LOGDROP -j LOG –log-prefix “LOGDROP ”
iptables -A LOGDROP -j DROP

1. The first rule in this set creates the new chain.
The output is sent to /dev/null because if you attempt to run this twice on the
same system, you will get an error saying the chain already exists. It’s up to you if you
want to see that message or not.

2. The second rule flushes the contents of the chain, again, so that if you run it twice on the
same system you don’t have duplicate rules in the chain
.

3. The third rule LOGS the traffic with the added “LOGDROP” prefix and the fourth rule
DROP’s the traffic.

“iptables -A INPUT -p tcp –dport 80 -j LOGDROP”
Log and drop all connections to the HTTP port

As you can see, you now simply use the LOGDROP target in order to log and drop any
traffic you want
.You must ensure that you define the LOGDROP target BEFORE you
attempt to use it in a rule
.