
D-16 iptables man Pages
LX Series Configuration Guide
POSTROUTING chain. It specifies that the source address
of the packet should be modified (and all future packets
in this connection will also be mangled), and rules should
cease being examined. It takes one option:
--to-source <ipaddr>[-<ipaddr>][:port-port]
which can specify a single new source IP address,
an inclusive range of IP addresses, and optionally,
a port range (which is only valid if the rule also
specifies -p tcp or -p udp). If no port range is
specified, then source ports below 512 will be
mapped to other ports below 512: those between 512
and 1023 inclusive will be mapped to ports below
1024, and other ports will be mapped to 1024 or
above. Where possible, no port alteration will
occur.
DNAT
This target is only valid in the nat table, in the PRE
ROUTING and OUTPUT chains, and user-defined chains which
are only called from those chains. It specifies that the
destination address of the packet should be modified (and
all future packets in this connection will also be man
gled), and rules should cease being examined. It takes
one option:
--to-destination <ipaddr>[-<ipaddr>][:port-port]
which can specify a single new destination IP
address, an inclusive range of IP addresses, and
optionally, a port range (which is only valid if
the rule also specifies -p tcp or -p udp). If no
port range is specified, then the destination port
will never be modified.
MASQUERADE
This target is only valid in the nat table, in the
POSTROUTING chain. It should only be used with dynami
cally assigned IP (dialup) connections: if you have a
static IP address, you should use the SNAT target. Mas
Kommentare zu diesen Handbüchern