192.168.20.1是Route的話用inputadd action=accept chain=input dst-port=1234 protocol=tcp src-address=140.1.1.1區網設備某一台設備端口轉發的話,你應該使用NAT/dst-natadd action=dst-nat chain=dstnat dst-port=1234 protocol=tcp src-address=140.1.1.1 to-addresses=192.168.20.2