$ ss -ltnp
State Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0 80 127.0.0.1:3306 0.0.0.0:* users:(("mysqld",pid=15376,fd=28))
LISTEN 0 50 0.0.0.0:139 0.0.0.0:* users:(("smbd",pid=1448,fd=35))
LISTEN 0 128 127.0.0.1:63342 0.0.0.0:* users:(("java",pid=1156,fd=345))
LISTEN 0 128 0.0.0.0:80 0.0.0.0:* users:(("nginx",pid=7296,fd=6),("nginx",pid=7295,fd=6),("nginx",pid=7294,fd=6),("nginx",pid=7293,fd=6),("nginx",pid=7292,fd=6))
LISTEN 0 128 127.0.0.1:5939 0.0.0.0:* users:(("teamviewerd",pid=1375,fd=12))
LISTEN 0 128 127.0.0.53%lo:53 0.0.0.0:* users:(("systemd-resolve",pid=745,fd=13))
LISTEN 0 5 127.0.0.1:631 0.0.0.0:* users:(("cupsd",pid=15971,fd=7))
LISTEN 0 50 0.0.0.0:445 0.0.0.0:* users:(("smbd",pid=1448,fd=34))
LISTEN 0 128 127.0.0.1:6942 0.0.0.0:* users:(("java",pid=1156,fd=152))
LISTEN 0 50 [::]:139 [::]:* users:(("smbd",pid=1448,fd=33))
LISTEN 0 128 [::]:80 [::]:* users:(("nginx",pid=7296,fd=7),("nginx",pid=7295,fd=7),("nginx",pid=7294,fd=7),("nginx",pid=7293,fd=7),("nginx",pid=7292,fd=7))
LISTEN 0 5 [::1]:631 [::]:* users:(("cupsd",pid=15971,fd=6))
LISTEN 0 50 [::]:445 [::]:* users:(("smbd",pid=1448,fd=32))
$ iptables-save
# Generated by iptables-save v1.6.1 on Thu Jul 26 16:51:58 2018
*nat
:PREROUTING ACCEPT [136008:10205603]
:INPUT ACCEPT [54829:6379408]
:OUTPUT ACCEPT [66167:4291817]
:POSTROUTING ACCEPT [66104:4288037]
-A PREROUTING -d 217.149.177.16/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.16.8.170:80
-A PREROUTING -d 217.149.177.16/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 127.0.0.1
-A PREROUTING -d 217.149.177.16/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.16.8.170
-A OUTPUT -d 217.149.177.16/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 127.0.0.1
-A OUTPUT -d 217.149.177.16/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 172.16.8.170
-A POSTROUTING -s 192.168.10.0/24 -o eth1 -j MASQUERADE
-A POSTROUTING -s 172.16.8.170/32 -o ppp0 -j MASQUERADE
-A POSTROUTING -d 127.0.0.1/32 -p tcp -m tcp --dport 80 -j SNAT --to-source 127.0.0.1
-A POSTROUTING -d 172.16.8.170/32 -p tcp -m tcp --dport 80 -j SNAT --to-source 172.16.8.170
COMMIT
# Completed on Thu Jul 26 16:51:58 2018
# Generated by iptables-save v1.6.1 on Thu Jul 26 16:51:58 2018
*filter
:INPUT ACCEPT [12510060:15548298933]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [8450115:733075808]
-A FORWARD -d 172.16.8.170/32 -i ppp0 -o enp1s0 -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 127.0.0.1/32 -i ppp0 -o lo -p tcp -m tcp --dport 80 -j ACCEPT
-A FORWARD -d 172.16.8.170/32 -i ppp0 -p tcp -m tcp --dport 80 -j ACCEPT
COMMIT
# Completed on Thu Jul 26 16:51:58 2018