ufw route allow in on eth0 out on eth1 to port 80 proto tcp This rule allows any packets coming in on eth0 to traverse the firewall out on eth1 to tcp port 80 on In addition to routing rules and policy, you must also setup IP forwarding. This may be done by setting the following in /etc/ufw/sysctl.conf:

ufw historically used IPT_MODULES in /etc/defaults/ufw to load various connection tracking modules, but use of this mechanism has been deprecated for some time. These days, the kernel defaults to deactivating flows for various connection tracking modules so users have to perform an extra sysctl step to use this old mechanism anyway, so empty

