CompTIA Linux+ (XK0-006)SecurityMedium
A server with two network interfaces needs to act as a NAT gateway so that internal clients on eth1 can reach the internet through eth0. Which iptables command correctly enables this masquerading behavior?
- Aiptables -A INPUT -i eth0 -j MASQUERADE
- Biptables -t nat -A PREROUTING -i eth0 -j MASQUERADE
- Ciptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
- Diptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
Show answer & explanationAnswer & explanation
Correct answer: C. iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
MASQUERADE is a NAT target applied to the POSTROUTING chain that dynamically rewrites the source address of outgoing packets to the address of the outbound interface (eth0), allowing internal hosts to share a single public IP for internet access.
Why the other options are wrong
- A. MASQUERADE is a nat-table target and cannot be applied to the INPUT chain, which handles locally destined traffic.
- B. MASQUERADE is not valid in PREROUTING; NAT destination rewriting there uses DNAT instead.
- D. This FORWARD rule permits traffic to be routed but does not perform the necessary address translation for internet-bound packets.
iptables MASQUERADE (NAT)
MASQUERADE is a NAT target used in the POSTROUTING chain to dynamically translate the source IP of outbound packets to the address of the exiting interface, commonly used for internet-sharing gateways with dynamic IPs.
- Applied in the nat table's POSTROUTING chain
- Ideal for interfaces with dynamic/DHCP-assigned IPs
- SNAT is the static-IP equivalent target
Memory trick: MASQUERADE hides internal IPs behind the gateway's public face, applied on the way OUT (POSTROUTING).