Rules which work well as router on Ubuntu Mate
From MyWiki
# Generated by iptables-save v1.6.0 on Wed Jan 17 12:57:59 2018 *filter :INPUT ACCEPT [3042716:316035492] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [2584596:185631118] #-A FORWARD -i enxb827ebaced3e -o tun0 -m state --state RELATED,ESTABLISHED -j ACCEPT -A FORWARD -i enxb827ebaced3e -o tun0 -j ACCEPT COMMIT #sshguard - [0:0] #-A INPUT -j sshguard *nat :PREROUTING ACCEPT [23978:1493968] :INPUT ACCEPT [107:30172] :OUTPUT ACCEPT [1193:75732] :POSTROUTING ACCEPT [302:21040] #-A POSTROUTING -o tun0 -j MASQUERADE COMMIT # Completed on Wed Jan 17 12:57:59 2018 me@me-desktop:/etc/iptables$