less <filename> (reads a file)
vi <filename> (edits a file)
Local history file(s)
/.bash_history (records the last entries made, so less the file to read it)
/var/lib/iptables/rules-save (records the last entries saved in iptables)
Examples :
iptables -vnL (lists the iptables ruleset)
iptables -vnL – t nat (lists the iptables nat tables, i.e PREROUTING,POSTROUTING)
1. Inserts a rule in the INPUT chain at line 5 that allows 10.10.0.0/16 to 1.1.1.1
iptables -I INPUT 5 -s 10.10.0.0/16 -d 1.1.1.1 -j ACCEPT
2. Deletes the above rule :
iptables -D INPUT 5
-A will append the rule to the Chain, rather than insert it
-I will insert the rule to the Chain, rather than append it
3. REDIRECT port 80 traffic to port 8080
iptables -I PREROUTING 9 -t nat -s 1.1.1.1 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080
4. Source NAT everything from 1.1.1.1 to go out as 2.2.2.2
iptables -I POSTROUTING 20 -t nat -s 1.1.1.1 -o eth1 -j SNAT –to-source 2.2.2.2
5. Allows 1.1.1.1 to talk to our ranges and vpn box
iptables -I POSTROUTING 8 -t nat -s 1.1.1.1 -d 83.44.16.6 -j ACCEPT
iptables -I POSTROUTING 12 -t nat -s 1.1.1.1 -d 83.44.16.8/29 -j ACCEPT
6. /etc/init.d/iptables save (saves the changes made to iptables)
7. DNATs, SNATs and ports
-i eth1 (for in port)
-o eth1 (for out port)
–dport <port number> (destination port) –to <ip address> (NAT to an IP)
Examples :
Adds a rule in to POSTROUTING chain, to SNAT everything out of eth0 with a source address of 172.16.26.1 to 83.44.16.6
iptables -I POSTROUTING 6 -t nat -o eth0 -s 172.16.26.1 -j SNAT –to 83.44.16.6
8. Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201
iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp –dport 443 -j DNAT –to 172.16.209.201
9. Adds a rule in the FORWARD chain allowing everything from 10.10.1.2 with a destination tcp port of 25
iptables -I FORWARD -s 10.10.1.2 -p tcp –dport 25 -j ACCEPT