data:image/s3,"s3://crabby-images/25e93/25e93b0d625dae36911be7e60ac57a79bbb33350" alt="Iptables dport"
data:image/s3,"s3://crabby-images/eb6d8/eb6d86c0933d9a10e8da11e18a60d0957ab93dc2" alt="iptables dport iptables dport"
A FORWARD -i enp1s0 -j REJECT -reject-with icmp-port-unreachable A FORWARD -o enp1s0 -j REJECT -reject-with icmp-port-unreachable A FORWARD -d 10.42.0.0/24 -o enp1s0 -m state -state RELATED,ESTABLISHED -j ACCEPT A INPUT -i lxcbr0 -p udp -m udp -dport 67 -j ACCEPT A INPUT -i lxcbr0 -p tcp -m tcp -dport 67 -j ACCEPT A INPUT -i lxcbr0 -p udp -m udp -dport 53 -j ACCEPT A INPUT -i lxcbr0 -p tcp -m tcp -dport 53 -j ACCEPT A INPUT -i enp1s0 -p tcp -m tcp -dport 53 -j ACCEPT
data:image/s3,"s3://crabby-images/b679c/b679cc2e88606ed68eabbd8087db958d6800fa41" alt="iptables dport iptables dport"
data:image/s3,"s3://crabby-images/4f7a0/4f7a0f787ac993a87f919bf2133fb66d60f3702a" alt="iptables dport iptables dport"
A INPUT -i enp1s0 -p udp -m udp -dport 53 -j ACCEPT A INPUT -i enp1s0 -p tcp -m tcp -dport 67 -j ACCEPT A INPUT -i enp1s0 -p udp -m udp -dport 67 -j ACCEPT A POSTROUTING -o lxcbr0 -p udp -m udp -dport 68 -j CHECKSUM -checksum-fill Here's the output of iptables-save when the forwarding is working: $ sudo iptables-save I only have to run the first command in order for the forwarding to work again. What is really mystifying is that the rules appear to actually persist - when I examine the output of iptables-save, they are still present. The problem is, the forwarding stops working not only after rebooting the PC, but even after suspending/sleep. I then use iptables-persistent and # iptables-save > /etc/iptables/rules.v4 to keep these rules in subsequent boots. To achieve that, I run the following commands: $ sudo iptables -I FORWARD -o enp1s0 -d 10.42.0.66 -j ACCEPT I am trying to forward packets received by a PC on port 16080 to port 3389 to another PC connected to it via Ethernet, where enp1s0 is the Ethernet interface and 10.42.0.66 is the IP of the connected computer.
data:image/s3,"s3://crabby-images/25e93/25e93b0d625dae36911be7e60ac57a79bbb33350" alt="Iptables dport"