iptables NAT Table: Network Address Translation Rules

The nat table in iptables is responsible for performing Network Address Translation, which involves modifying the source or destination IP addresses and/or ports of packets. This is crucial for functionalities like sharing a single public IP address among multiple private IP addresses (MASQUERADE), or directing incoming public traffic to an internal private host (DNAT).

The two primary chains in the nat table are:

  • PREROUTING: Used for Destination NAT (DNAT) – modifying packets as they first arrive, before routing decisions are made.
  • POSTROUTING: Used for Source NAT (SNAT) – modifying packets just before they leave the system, after routing decisions are made.

1. SNAT (Source NAT) and MASQUERADE Examples

Source NAT changes the source IP address of packets. MASQUERADE is a special form of SNAT designed for interfaces with dynamically assigned IP addresses (like DHCP connections), as it automatically uses the IP address of the outgoing interface.

Example 1: Basic MASQUERADE

This rule performs Source NAT for all traffic originating from the 192.168.2.0/24 subnet when it exits through the eth0 interface. The source IP address of these packets will be changed to the IP address of eth0.

iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -o eth0 -j MASQUERADE
  • -t nat: Specifies that we are working in the nat table.
  • -A POSTROUTING: Appends this rule to the POSTROUTING chain.
  • -s 192.168.2.0/24: Matches packets whose source IP address is within this subnet.
  • -o eth0: Matches packets that are leaving the system via the eth0 network interface.
  • -j MASQUERADE: The target action; it tells iptables to replace the packet’s source IP with the IP of the outgoing interface (eth0).

Example 2: MASQUERADE for Traffic to External Destinations

This rule masquerades traffic from 10.44.1.0/24 only if it’s destined for networks other than 172.32.1.0/24, when exiting via eth0. The ! operator negates the destination match.

iptables -t nat -A POSTROUTING -s 10.44.1.0/24 '!' -d 172.32.1.0/24 -o eth0 -j MASQUERADE
  • '!' -d 172.32.1.0/24: Matches packets where the destination IP address is not within the 172.32.1.0/24 subnet.

Example 3: Inserting a MASQUERADE Rule at a Specific Position

Rules can be inserted at a specific line number within a chain using -I. This is important for controlling rule order, as iptables processes rules sequentially.

iptables -t nat -I POSTROUTING 2 -s 10.44.4.0/24 -d 172.32.1.0/24 -o eth0 -j MASQUERADE
  • -I POSTROUTING 2: Inserts this rule at position 2 in the POSTROUTING chain. Any existing rule at position 2 (and subsequent rules) will be shifted down.

2. DNAT (Destination NAT) Examples

Destination NAT changes the destination IP address and/or port of incoming packets, often used for port forwarding or load balancing. (A common DNAT example is found in baselinev1.md within the NAT table section.)

# Example: Port Forwarding (from baselinev1.md)
# Redirect incoming TCP traffic on port 443 on eth0 to an internal host 192.168.2.100 on port 443
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j DNAT --to 192.168.2.100:443

Warning: Always exercise caution when configuring iptables NAT rules. Incorrect rules can break network connectivity for services or entire subnets. It’s recommended to test thoroughly in a controlled environment.