Iptables Rules

less <filename> (reads a file)
vi <filename> (edits a file)

Local history file(s)

/.bash_history (records the last entries made, so less the file to read it)
/var/lib/iptables/rules-save (records the last entries saved in iptables)

Examples :

iptables -vnL  (lists the iptables ruleset)
iptables -vnL – t nat  (lists the iptables nat tables, i.e PREROUTING,POSTROUTING)

1. Inserts a rule in the INPUT chain at line 5 that allows 10.10.0.0/16 to 1.1.1.1

iptables -I INPUT 5 -s 10.10.0.0/16 -d 1.1.1.1 -j ACCEPT

2. Deletes the above rule :

iptables -D INPUT 5

-A will append the rule to the Chain, rather than insert it
-I will insert the rule to the Chain, rather than append it

3. REDIRECT port 80 traffic to port 8080

iptables -I PREROUTING 9 -t nat -s 1.1.1.1 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

4. Source NAT everything from 1.1.1.1 to go out as 2.2.2.2
iptables -I POSTROUTING 20 -t nat -s 1.1.1.1 -o eth1 -j SNAT –to-source 2.2.2.2

5.  Allows 1.1.1.1  to talk to our ranges and vpn box

iptables -I POSTROUTING 8 -t nat -s 1.1.1.1 -d 83.44.16.6 -j ACCEPT
iptables -I POSTROUTING 12 -t nat -s 1.1.1.1 -d 83.44.16.8/29 -j ACCEPT

6. /etc/init.d/iptables save (saves the changes made to iptables)

7. DNATs, SNATs and ports

-i eth1 (for in port)
-o eth1 (for out port)

–dport <port number> (destination port) –to <ip address> (NAT to an IP)

Examples :

Adds a rule in to POSTROUTING chain, to SNAT everything out of eth0 with a source address of 172.16.26.1 to 83.44.16.6

iptables -I POSTROUTING 6 -t nat -o eth0 -s 172.16.26.1 -j SNAT –to 83.44.16.6

8. Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201

iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201

9. Adds a rule in the FORWARD chain allowing everything from 10.10.1.2 with a destination tcp port of 25

iptables -I FORWARD -s 10.10.1.2 -p tcp –dport 25 -j ACCEPT