Something like this:
My basic post-firewall layoutCode:#!/bin/sh WANIF=`nvram get wan_ifname` # deleting last firewal rules (policy) iptables -D INPUT -j DROP iptables -t nat -A PREROUTING -i ${WANIF} -p tcp --dport 80 -j DNAT --to-destination 192.168.1.110:8080 # Restablishing INPUT chain policy iptables -A INPUT -j DROP
WANIF is automatically set to your wan network interface
this rule forwards port 80 to port 8080 on the computer with ip 192.168.1.110