$ sudo iptables-save
# Generated by iptables-save v1.4.10 on Fri Oct 10 19:36:29 2014
*nat
:PREROUTING ACCEPT [46095019:3539019284]
:INPUT ACCEPT [11041205:662643368]
:OUTPUT ACCEPT [3906290:268944897]
:POSTROUTING ACCEPT [545029:63147499]
-A PREROUTING -d 111.111.111.111/32 -p tcp -m tcp --dport 80 -j DNAT --to-destinati on 192.168.0.72
-A PREROUTING -d 192.168.0.241/32 -p tcp -m tcp --dport 80 -j DNAT --to-destinat ion 192.168.0.72
-A PREROUTING -s 192.168.0.0/24 -p udp -m udp --dport 53 -j DNAT --to-destinatio n 194.85.128.10
-A PREROUTING -s 192.168.0.0/24 -p udp -m udp --dport 53 -j DNAT --to-destinatio n 212.44.130.6
-A PREROUTING -p tcp -m tcp --dport 1110 -j DNAT --to-destination 178.208.83.99: 110
-A PREROUTING -p tcp -m tcp --dport 2222 -j DNAT --to-destination 192.168.10.5:2 2
-A PREROUTING -d 111.111.111.111/32 -p tcp -m tcp --dport 1313 -j DNAT --to-destina tion 192.168.100.16:80
-A PREROUTING -d 111.111.111.111/32 -p tcp -m tcp --dport 1314 -j DNAT --to-destina tion 192.168.100.16:554
-A PREROUTING -d 111.111.111.111/32 -p tcp -m tcp --dport 69 -j DNAT --to-destinati on 192.168.100.16:69
-A POSTROUTING -o eth2 -j MASQUERADE
COMMIT
# Completed on Fri Oct 10 19:36:29 2014
# Generated by iptables-save v1.4.10 on Fri Oct 10 19:36:29 2014
*mangle
:PREROUTING ACCEPT [1180307452:905606210388]
:INPUT ACCEPT [163268354:116812652483]
:FORWARD ACCEPT [1008887354:787690207317]
:OUTPUT ACCEPT [155083208:120566646749]
:POSTROUTING ACCEPT [1163518906:908231705279]
COMMIT
# Completed on Fri Oct 10 19:36:29 2014
# Generated by iptables-save v1.4.10 on Fri Oct 10 19:36:29 2014
*filter
:INPUT ACCEPT [2011100:2114024919]
:FORWARD DROP [3916:223895]
:OUTPUT ACCEPT [3763163:3039447679]
-A INPUT -p tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJEC T --reject-with tcp-reset
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j LOG --log-prefix "New not syn:"
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A INPUT -s 127.0.0.1/32 -p tcp -j ACCEPT
-A INPUT -s 192.168.0.0/24 -p tcp -m multiport --dports 21,22,25,110,995,8080,31 28,1723 -j ACCEPT
-A INPUT -s 192.168.0.0/24 -p tcp -m multiport --dports 22,3128,80 -j ACCEPT
-A INPUT -s 192.168.0.0/24 -p udp -m udp ! --dport 53 -j DROP
-A INPUT -s 192.168.0.241/32 -p udp -m multiport ! --dports 123,53 -j DROP
-A INPUT -s 192.168.100.0/27 -j ACCEPT
-A INPUT -s 198.168.10.0/28 -j ACCEPT
-A INPUT -s 198.168.10.16/28 -j ACCEPT
-A INPUT -s 198.168.10.32/28 -j ACCEPT
-A INPUT -s 198.168.10.48/28 -j ACCEPT
-A FORWARD -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -i eth0 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -p tcp -m multiport --dports 21,25,160,110,995,587, 993,1024,87,9080,9443,8470,465,1723,1701 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -p tcp -m multiport --dports 143,587,9443,1110 -j A CCEPT
-A FORWARD -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.2/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.3/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.5/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.50/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.80/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.244/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -s 192.168.0.250/32 -p udp -m udp --dport 123 -j ACCEPT
-A FORWARD -d 192.168.0.72/32 -i eth2 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -s 192.168.0.20/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.21/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.22/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.23/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.24/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.19/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53,445 -j ACCEPT
-A FORWARD -s 192.168.0.18/32 -j ACCEPT
-A FORWARD -s 192.168.0.26/32 -j ACCEPT
-A FORWARD -s 192.168.0.27/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.28/32 -p tcp -m multiport --dports 3389,1723,4899,139,55 00,160,53 -j ACCEPT
-A FORWARD -s 192.168.0.29/32 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -p udp -m udp --dport 53 -j ACCEPT
-A FORWARD -s 192.168.0.75/32 -p tcp -m multiport --dports 3400:3800 -j ACCEPT
-A FORWARD -s 192.168.0.75/32 -p udp -m multiport --dports 3400:3800 -j ACCEPT
-A FORWARD -s 192.168.0.75/32 -j ACCEPT
-A FORWARD -s 192.168.0.248/32 -p tcp -m multiport --dports 80,443,1025:60000 -j ACCEPT
-A FORWARD -s 192.168.0.248/32 -p udp -m multiport --dports 80,443,1025:60000 -j ACCEPT
-A FORWARD -s 192.168.0.148/32 -j ACCEPT
-A FORWARD -s 192.168.0.222/32 -j ACCEPT
-A FORWARD -s 192.168.0.135/32 -p tcp -m multiport --dports 8585,9080,9443 -j AC CEPT
-A FORWARD -s 192.168.0.67/32 -j ACCEPT
-A FORWARD -s 192.168.0.124/32 -j ACCEPT
-A FORWARD -s 192.168.0.160/32 -j ACCEPT
-A FORWARD -s 192.168.0.1/32 -j ACCEPT
-A FORWARD -s 192.168.0.33/32 -j ACCEPT
-A FORWARD -s 192.168.0.70/32 -p tcp -m multiport --dports 80,52500:52900 -j ACC EPT
-A FORWARD -s 192.168.0.92/32 -j ACCEPT
-A FORWARD -s 192.168.0.195/32 -j ACCEPT
-A FORWARD -s 192.168.0.74/32 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -p udp -m multiport --dports 5060:5061,87,53,1701 - j ACCEPT
-A FORWARD -d 91.207.165.0/24 -p udp -m udp --dport 16384:32768 -j ACCEPT
-A FORWARD -s 192.168.0.51/32 -p udp -m udp --dport 16384:32768 -j ACCEPT
-A FORWARD -s 192.168.0.51/32 -p udp -m udp --sport 16384:32768 -j ACCEPT
-A FORWARD -s 192.168.0.25/32 -p udp -m udp --dport 4100:4200 -j ACCEPT
-A FORWARD -s 192.168.0.25/32 -p tcp -m tcp --dport 4100:4200 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -p icmp -j ACCEPT
-A FORWARD -p tcp -m multiport --dports 22,2222 -j ACCEPT
-A FORWARD -d 192.168.10.5/32 -p icmp -j ACCEPT
-A FORWARD -s 192.168.10.5/32 -p icmp -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -i eth2 -p tcp -m tcp --dport 1313 -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -p tcp -m multiport --dports 80 -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -i eth2 -p tcp -m tcp --dport 1314 -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -p tcp -m multiport --dports 554 -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -i eth2 -p tcp -m tcp --dport 69 -j ACCEPT
-A FORWARD -d 192.168.100.16/32 -p tcp -m multiport --dports 69 -j ACCEPT
-A FORWARD -s 192.168.100.0/27 -j ACCEPT
-A FORWARD -s 198.168.10.0/28 -j ACCEPT
-A FORWARD -s 198.168.10.16/28 -j ACCEPT
-A FORWARD -s 198.168.10.32/28 -j ACCEPT
-A FORWARD -s 198.168.10.48/28 -j ACCEPT
-A FORWARD -s 192.168.10.52/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.52/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.53/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.53/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.54/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.54/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.36/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.36/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.20/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.20/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.4/32 -p tcp -m multiport --dports 80,26948 -j ACCEPT
-A FORWARD -s 192.168.10.4/32 -p udp -m multiport --dports 26948 -j ACCEPT
-A FORWARD -s 192.168.10.5/32 -p udp -m multiport --dports 500,4500 -j ACCEPT
-A FORWARD -s 192.168.0.111/32 -j ACCEPT
-A FORWARD -s 192.168.0.65/32 -p tcp -m multiport --dports 3389,139,160,53 -j AC CEPT
-A FORWARD -s 192.168.0.66/32 -p tcp -m multiport --dports 3389,139,160,53 -j AC CEPT
-A FORWARD -s 192.168.10.53/32 -j ACCEPT
-A FORWARD -s 192.168.10.53/32 -j ACCEPT
-A FORWARD -s 192.168.10.52/32 -j ACCEPT
-A FORWARD -s 192.168.10.54/32 -j ACCEPT
-A FORWARD -s 192.168.10.4/32 -j ACCEPT
-A FORWARD -s 192.168.10.36/32 -j ACCEPT
-A FORWARD -s 192.168.10.20/32 -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -i eth0 -m conntrack --ctstate NEW -j DROP
-A FORWARD -s 192.168.0.124/32 -i eth0 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.0.0/24 -i eth0 -m conntrack --ctstate NEW -j DROP
-A FORWARD -s 192.168.0.124/32 -i eth0 -m conntrack --ctstate NEW -j ACCEPT
-A FORWARD -s 192.168.0.84/32 -j ACCEPT
-A OUTPUT -s 192.168.100.0/27 -j ACCEPT
-A OUTPUT -s 198.168.10.0/28 -j ACCEPT
-A OUTPUT -s 198.168.10.16/28 -j ACCEPT
-A OUTPUT -s 198.168.10.32/28 -j ACCEPT
-A OUTPUT -s 198.168.10.48/28 -j ACCEPT
COMMIT