CompTIA Linux+ (XK0-006)SecurityMedium

A server with two network interfaces needs to act as a NAT gateway so that internal clients on eth1 can reach the internet through eth0. Which iptables command correctly enables this masquerading behavior?

  1. Aiptables -A INPUT -i eth0 -j MASQUERADE
  2. Biptables -t nat -A PREROUTING -i eth0 -j MASQUERADE
  3. Ciptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
  4. Diptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
Show answer & explanation

Correct answer: C. iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

MASQUERADE is a NAT target applied to the POSTROUTING chain that dynamically rewrites the source address of outgoing packets to the address of the outbound interface (eth0), allowing internal hosts to share a single public IP for internet access.

Why the other options are wrong

  • A. MASQUERADE is a nat-table target and cannot be applied to the INPUT chain, which handles locally destined traffic.
  • B. MASQUERADE is not valid in PREROUTING; NAT destination rewriting there uses DNAT instead.
  • D. This FORWARD rule permits traffic to be routed but does not perform the necessary address translation for internet-bound packets.

iptables MASQUERADE (NAT)

MASQUERADE is a NAT target used in the POSTROUTING chain to dynamically translate the source IP of outbound packets to the address of the exiting interface, commonly used for internet-sharing gateways with dynamic IPs.

  • Applied in the nat table's POSTROUTING chain
  • Ideal for interfaces with dynamic/DHCP-assigned IPs
  • SNAT is the static-IP equivalent target

Memory trick: MASQUERADE hides internal IPs behind the gateway's public face, applied on the way OUT (POSTROUTING).

More Security questions