# iptables -xvnL
Code:
Chain INPUT (policy ACCEPT 13477 packets, 30237796 bytes)
pkts bytes target prot opt in out source destination
390682 194839737 ufw-before-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
390682 194839737 ufw-before-input all -- * * 0.0.0.0/0 0.0.0.0/0
360214 171892758 ufw-after-input all -- * * 0.0.0.0/0 0.0.0.0/0
359321 171746197 ufw-after-logging-input all -- * * 0.0.0.0/0 0.0.0.0/0
359321 171746197 ufw-reject-input all -- * * 0.0.0.0/0 0.0.0.0/0
359321 171746197 ufw-track-input all -- * * 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT 240 packets, 15432 bytes)
pkts bytes target prot opt in out source destination
921841 428191312 ufw-before-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
921841 428191312 ufw-before-forward all -- * * 0.0.0.0/0 0.0.0.0/0
862549 343443931 ufw-after-forward all -- * * 0.0.0.0/0 0.0.0.0/0
862549 343443931 ufw-after-logging-forward all -- * * 0.0.0.0/0 0.0.0.0/0
862549 343443931 ufw-reject-forward all -- * * 0.0.0.0/0 0.0.0.0/0
862549 343443931 ufw-track-forward all -- * * 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT 10986 packets, 59241446 bytes)
pkts bytes target prot opt in out source destination
365377 239428735 ufw-before-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
365377 239428735 ufw-before-output all -- * * 0.0.0.0/0 0.0.0.0/0
337769 200495441 ufw-after-output all -- * * 0.0.0.0/0 0.0.0.0/0
337769 200495441 ufw-after-logging-output all -- * * 0.0.0.0/0 0.0.0.0/0
337769 200495441 ufw-reject-output all -- * * 0.0.0.0/0 0.0.0.0/0
337769 200495441 ufw-track-output all -- * * 0.0.0.0/0 0.0.0.0/0
Chain ufw-after-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-logging-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-logging-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-logging-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-after-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-logging-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-logging-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-logging-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-before-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-reject-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-reject-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-reject-output (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-track-forward (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-track-input (1 references)
pkts bytes target prot opt in out source destination
Chain ufw-track-output (1 references)
pkts bytes target prot opt in out source destination
iptables -t nat -xvnL
Code:
Chain PREROUTING (policy ACCEPT 223 packets, 24100 bytes)
pkts bytes target prot opt in out source destination
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28936 to:192.168.2.36:3389
2 120 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28836 to:192.168.2.36:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 to:192.168.2.31:80
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443 to:192.168.2.31:443
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28931 to:192.168.2.31:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28937 to:192.168.2.37:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28837 to:192.168.2.37:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28938 to:192.168.2.38:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28838 to:192.168.2.38:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:818 to:192.168.2.32:818
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:29032 to:192.168.2.32:29032
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:8088 to:192.168.2.32:8088
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28932 to:192.168.2.32:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28832 to:192.168.2.32:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28933 to:192.168.2.33:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28833 to:192.168.2.33:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:4848 to:192.168.2.34:4848
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:81 to:192.168.2.34:81
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28934 to:192.168.2.34:22
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28935 to:192.168.2.35:3389
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28835 to:192.168.2.35:1433
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28922 to:192.168.2.2:22
Chain INPUT (policy ACCEPT 122 packets, 9379 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 28 packets, 3269 bytes)
pkts bytes target prot opt in out source destination
Chain POSTROUTING (policy ACCEPT 263 packets, 15197 bytes)
pkts bytes target prot opt in out source destination
11 698 MASQUERADE all -- * eno1 192.168.0.0/16 0.0.0.0/0
Ok. I see it. e.g.
Code:
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28936 to:192.168.2.36:3389
The old port forwarding is the 1st two. They work. Even with 'ufw disable'
All the vollowing ones e.g.
Code:
0 0 DNAT tcp -- eno1 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:28835 to:192.168.2.35:1433
Does NOT work (even though direct access to 192.168.2.35:1433 does work).
Bookmarks