1. Goal
Publish an internal service with NAT and clear PREROUTING and FORWARD rules.
2. Files and components involved
/proc/sys/net/ipv4/ip_forward
iptables
/etc/rc.d/rc.local
3. Operational flow
echo 1 > /proc/sys/net/ipv4/ip_forward
add DNAT and FORWARD rules
save firewall script
4. Operational verification
iptables -t nat -L -n -v
iptables -L FORWARD -n -v
test from external client
5. Practical notes
Apply network changes from a local console or with an emergency session ready, so you do not lose SSH access.
Every network change should have a rollback path ready: a second console, KVM access, or a temporary command to remove.
Quick checklist
[ ] Backup or copy of the existing configuration completed
[ ] Files and commands updated as expected
[ ] Local test completed successfully
[ ] Logs or final output verified
[ ] Rollback procedure documented