I started my travels into the depths of iptable script hacking by starting with a GUI/application/whatever that created a working shell script to configure netfilter. Then went through and hand edited it to my tastes. That's the key part - open 'er up and read it. Learn what does what and how. Once happy - it was trivial to load and run.
This is but one of many, but it is the one I've used the longest:
http://easyfwgen.morizot.net/gen/
Yes, it's old - but still a gem. Also easy to setup on your own, local server!
Best part is the resulting script is so nicely commented it makes learning your way around and building your own custom scripts later on a near snap. It also makes a sound framework to use as a start point for most any firewall.
__________________
If it ain't broke, you're not trying hard enough.
Reg User
#227845 - 18 boxen up and counting