{"id":233,"date":"2010-06-02T18:44:19","date_gmt":"2010-06-02T18:44:19","guid":{"rendered":"http:\/\/wiki.freeiz.com\/?p=233"},"modified":"2016-08-09T12:00:51","modified_gmt":"2016-08-09T12:00:51","slug":"iptables-prerouting-rule","status":"publish","type":"post","link":"https:\/\/wiki-see.info\/wp\/2010\/06\/02\/iptables-prerouting-rule\/","title":{"rendered":"Iptables PreRouting Rule"},"content":{"rendered":"<p>sudo iptables -t nat -vnL<br \/>\nsudo iptables -t nat -vnL\u00a0\u2013line-numbers<br \/>\n!<\/p>\n<p><strong>Port Forward From A Static Public Ip. Port Translation from 4000 to 3389.<\/strong><br \/>\niptables -t nat -I PREROUTING -s\u00a0<em>public_ip<\/em> -d\u00a0<em>internal_lan_int<\/em> -p tcp -m tcp &#8211;dport 4000 -j DNAT &#8211;to-destination 10.11.254.4:3389<\/p>\n<p><strong>Port Forward From Any Public Ip<\/strong>.<br \/>\niptables -t nat -I PREROUTING -d\u00a0<em>internal_lan_int<\/em> -p tcp -m tcp &#8211;dport 25 -j DNAT &#8211;to-destination 10.11.254.250:25<\/p>\n<p><strong>Port Forward From\u00a0A Static Public Ip to Internal Lan Webserver.<\/strong><br \/>\niptables -t nat -I PREROUTING -s\u00a0<em>public_ip<\/em> -d\u00a0<em>internal_lan_ip<\/em> -p tcp -m tcp &#8211;dport 80 -j ACCEPT<\/p>\n<p><strong>Port Forward From A Static Public Ip. Port\u00a0Redirection from 80 to 8080.<\/strong><br \/>\niptables -t nat -I PREROUTING -s\u00a0<em>public_ip<\/em> -d\u00a0<em>internal_lan_ip<\/em> -p tcp -m tcp &#8211;dport 80 -j REDIRECT &#8211;to-ports 8080<br \/>\n<strong><strong>Port Forward From Any Public Ip<\/strong>. Port\u00a0Redirection from 80 to 8080.<\/strong><br \/>\niptables -t nat -I PREROUTING -s\u00a0<em>internal_lan_ip<\/em> -p tcp -m tcp &#8211;dport 80 -j REDIRECT &#8211;to-ports 8080<\/p>\n<p><strong>Drop Port Forward Traffic from Public Ip<\/strong>.<br \/>\niptables -t nat -I PREROUTING -s\u00a0<em>public_ip<\/em> -j DROP<\/p>\n<p><strong>Adds a rule in PREROUTING to DNAT everything from 83.44.16.6 on tcp port 443 to 172.16.209.201<br \/>\n<\/strong>iptables -t nat -I PREROUTING -d 83.44.16.6 -p tcp \u2013dport 443 -j DNAT \u2013to 172.16.209.201<\/p>\n<p><strong>To Delete a rule<\/strong> :<br \/>\nsudo iptables -t nat -D PREROUTING 14<\/p>\n<p>E.G :<br \/>\n<strong><br \/>\nPrerouting<\/strong><a id=\"id2888032\"><\/a><\/p>\n<p>If you have a server on your internal network that you want make available externally,<br \/>\nyou can use the <code>-j DNAT<\/code> target of the PREROUTING chain in NAT to specify a<br \/>\ndestination IP address and port where incoming packets requesting a connection to your<br \/>\ninternal service can be forwarded.<\/p>\n<p><strong><br \/>\nuse the following command<\/strong>:<em><br \/>\nThis rule specifies that the nat table use the built-in PREROUTING chain to<br \/>\nforward incoming HTTP requests exclusively to the listed destination IP address of 172.31.0.23.<\/em><\/p>\n<p>For example, if you want to forward incoming HTTP requests to your dedicated<br \/>\nApache HTTP Server at 172.31.0.23,<\/p>\n<p><!-- ======================================================= --> <!-- Created by AbiWord, a free, Open Source wordprocessor.  --> <!-- For more information visit http:\/\/www.abisource.com.    --> <!-- ======================================================= --> <!-- #toc, .toc, .mw-warning { \tborder: 1px solid #aaa; \tbackground-color: #f9f9f9; \tpadding: 5px; \tfont-size: 95%; } #toc h2, .toc h2 { \tdisplay: inline; \tborder: none; \tpadding: 0; \tfont-size: 100%; \tfont-weight: bold; } #toc #toctitle, .toc #toctitle, #toc .toctitle, .toc .toctitle { \ttext-align: center; } #toc ul, .toc ul { \tlist-style-type: none; \tlist-style-image: none; \tmargin-left: 0; \tpadding-left: 0; \ttext-align: left; } #toc ul ul, .toc ul ul { \tmargin: 0 0 0 2em; } #toc .toctoggle, .toc .toctoggle { \tfont-size: 94%; }@media print, projection, embossed { \tbody { \t\tpadding-top:1in; \t\tpadding-bottom:1in; \t\tpadding-left:1in; \t\tpadding-right:1in; \t} } body { \tfont-family:'Times New Roman'; \tcolor:#000000; \twidows:2; \tfont-style:normal; \ttext-indent:0in; \tfont-variant:normal; \tfont-weight:normal; \tfont-size:12pt; \ttext-decoration:none; \ttext-align:left; } table { } td { \tborder-collapse:collapse; \ttext-align:left; \tvertical-align:top; } --><\/p>\n<div><\/div>\n<pre>iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to 172.31.0.23:80\n<strong><span style=\"font-family: Georgia;\">\n<\/span><\/strong><\/pre>\n<div>\n<p>If you have a default policy of DROP in your <strong>FORWARD chain<\/strong>, you must append a rule to<br \/>\nforward all incoming HTTP requests so that destination NAT routing is possible.<\/p>\n<p><strong>To do this, use the following command<\/strong>:<br \/>\n<em>This rule forwards all incoming HTTP requests from the firewall to the intended destination;<br \/>\nthe Apache HTTP Server behind the firewall<\/em>.<\/p>\n<pre>iptables -A FORWARD -i eth0 -p tcp --dport 80 -d 172.31.0.23 -j ACCEPT<\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>sudo iptables -t nat -vnL sudo iptables -t nat -vnL\u00a0\u2013line-numbers ! Port Forward From A Static Public Ip. Port Translation from 4000 to 3389. iptables -t nat -I PREROUTING -s\u00a0public_ip -d\u00a0internal_lan_int -p tcp -m tcp &#8211;dport 4000 -j DNAT &#8211;to-destination 10.11.254.4:3389 Port Forward From Any Public Ip. iptables -t nat -I PREROUTING -d\u00a0internal_lan_int -p tcp [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[404,565],"class_list":["post-233","post","type-post","status-publish","format-standard","hentry","category-iptables-linux","tag-iptables-prerouting","tag-prerouting"],"_links":{"self":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/233","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/comments?post=233"}],"version-history":[{"count":1,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/233\/revisions"}],"predecessor-version":[{"id":4667,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/posts\/233\/revisions\/4667"}],"wp:attachment":[{"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/media?parent=233"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/categories?post=233"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiki-see.info\/wp\/wp-json\/wp\/v2\/tags?post=233"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}