Iptables PreRouting Rule

sudo iptables -t nat -vnL
sudo iptables -t nat -vnL –line-numbers
!

Port Forward From A Static Public Ip. Port Translation from 4000 to 3389.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_int -p tcp -m tcp –dport 4000 -j DNAT –to-destination 10.11.254.4:3389

Port Forward From Any Public Ip.
iptables -t nat -I PREROUTING -d internal_lan_int -p tcp -m tcp –dport 25 -j DNAT –to-destination 10.11.254.250:25

Port Forward From A Static Public Ip to Internal Lan Webserver.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_ip -p tcp -m tcp –dport 80 -j ACCEPT

Port Forward From A Static Public Ip. Port Redirection from 80 to 8080.
iptables -t nat -I PREROUTING -s public_ip -d internal_lan_ip -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
Port Forward From Any Public Ip. Port Redirection from 80 to 8080.
iptables -t nat -I PREROUTING -s internal_lan_ip -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080

Drop Port Forward Traffic from Public Ip.
iptables -t nat -I PREROUTING -s public_ip -j DROP

Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201
iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201

To Delete a rule :
sudo iptables -t nat -D PREROUTING 14

E.G :

Prerouting

If you have a server on your internal network that you want make available externally,
you can use the -j DNAT target of the PREROUTING chain in NAT to specify a
destination IP address and port where incoming packets requesting a connection to your
internal service can be forwarded.


use the following command
:
This rule specifies that the nat table use the built-in PREROUTING chain to
forward incoming HTTP requests exclusively to the listed destination IP address of 172.31.0.23.

For example, if you want to forward incoming HTTP requests to your dedicated
Apache HTTP Server at 172.31.0.23,

iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to 172.31.0.23:80

If you have a default policy of DROP in your FORWARD chain, you must append a rule to
forward all incoming HTTP requests so that destination NAT routing is possible.

To do this, use the following command:
This rule forwards all incoming HTTP requests from the firewall to the intended destination;
the Apache HTTP Server behind the firewall
.

iptables -A FORWARD -i eth0 -p tcp --dport 80 -d 172.31.0.23 -j ACCEPT