I read your article thought might ask you, i am have dom0 on with one eth0 on public ip, the xen vm is on private ip nat, all works okay. but when i try to to put prerouting rule for port 3389 to forward to vm from external it doesnt work.

iptables -A FORWARD -i eth0 -p tcp --dport 80 -d -j ACCEPT This rule allows forwarding of incoming HTTP requests from the firewall to its intended destination of the Apache HTTP Server server behind the firewall.

# iptables -P INPUT DROP # iptables -P FORWARD DROP # iptables -P OUTPUT ACCEPT # iptables -L -v # iptables-save > /etc/sysconfig/iptables # Generated by iptables-save v1.4.7 on Tue Mar 13 11:36:16 2012 How-To Guide – Introduction to IPTables – Linux Academy