/sbin/iptables -t nat -A PREROUTING -p tcp -d 10.10.10.8 --dport 8888 -j DNAT --to-destination 10.10.10.11:80
gefest iptables # ./startfwFATAL: Module iptables_nat not found.
gefest ~ # lsmodModule Size Used byiptable_filter 2304 0iptable_nat 4996 0ip_nat 12460 1 iptable_natip_tables 9816 2 iptable_filter,iptable_nat
*filter:INPUT DROP [0:0]:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]:PSCAN - [0:0]:SSH_BF - [0:0][0:0] -A INPUT -s 0.0.0.0/255.0.0.0 -i eth0 -j DROP[0:0] -A INPUT -s 1.0.0.0/255.0.0.0 -i eth0 -j DROP[0:0] -A INPUT -s 127.0.0.0/255.0.0.0 -i lo -j ACCEPT[0:0] -A INPUT -s 127.0.0.0/255.0.0.0 -j DROP[0:0] -A INPUT -s 10.0.0.0/255.0.0.0 -i eth0 -j DROP[0:0] -A INPUT -s 172.16.0.0/255.240.0.0 -i eth0 -j DROP[0:0] -A INPUT -d 255.255.255.255 -j DROP[0:0] -A INPUT -s 169.254.0.0/255.255.0.0 -i eth0 -j DROP[0:0] -A INPUT -i eth0 -p tcp -m tcp ! --tcp-flags SYN,RST,ACK SYN -m state --state NEW -j DROP[0:0] -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT[0:0] -A INPUT -p icmp -m icmp --icmp-type 0 -j ACCEPT[0:0] -A INPUT -p icmp -m icmp --icmp-type 3 -j ACCEPT[0:0] -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT[0:0] -A INPUT -p icmp -m icmp --icmp-type 11 -j ACCEPT[0:0] -A INPUT -i eth0 -p tcp -j PSCAN[0:0] -A INPUT -d 62.149.13.87 -p tcp -m tcp --dport 443 -j ACCEPT[0:0] -A INPUT -d 62.149.13.87 -p tcp -m tcp --dport 80 -j ACCEPT[0:0] -A INPUT -p tcp -m tcp --dport 53 -j ACCEPT[0:0] -A INPUT -p udp -m udp --dport 53 -j ACCEPT[0:0] -A INPUT -p tcp -m tcp --dport 5678 -j ACCEPT[0:0] -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --set --name SSH --rsource -j SSH_BF[0:0] -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG SYN -m limit --limit 1/sec --limit-burst 4 -j RETURN[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG SYN -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "SYN flood:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG SYN -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -m limit --limit 1/sec --limit-burst 4 -j RETURN[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "Xmas portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,PSH,URG -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN -m limit --limit 1/sec --limit-burst 4 -j RETURN[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "SYN FIN portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -m limit --limit 1/sec --limit-burst 4 -j RETURN[0:0] -A PSCAN -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "SYN RST portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags SYN,RST SYN,RST -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -m limit --limit 2/min --limit-burst 2 -m state --state INVALID,NEW,RELATED,UNTRACKED -j LOG --log-prefix "FIN portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN -m state --state INVALID,NEW,RELATED,UNTRACKED -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "ALL flags portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG FIN,SYN,RST,PSH,ACK,URG -j DROP[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -m limit --limit 2/min --limit-burst 2 -j LOG --log-prefix "ALL flags portscan:"[0:0] -A PSCAN -p tcp -m tcp --tcp-flags FIN,SYN,RST,PSH,ACK,URG NONE -j DROP[0:0] -A SSH_BF -m recent ! --rcheck --seconds 120 --hitcount 5 --name SSH --rsource -j RETURN[0:0] -A SSH_BF -j DROP[0:0] -A SSH_BF -j LOG --log-prefix "SSH Brute Force Attempt: "COMMIT*mangle:PREROUTING ACCEPT [0:0]:INPUT ACCEPT [0:0]:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]:POSTROUTING ACCEPT [0:0]COMMIT*nat:PREROUTING ACCEPT [0:0]:POSTROUTING ACCEPT [0:0]:OUTPUT ACCEPT [0:0]COMMIT