iptables NAT Table: Network Address Translation Rules
The nat table in iptables is responsible for performing Network Address Translation, which involves modifying the source or destination IP addresses and/or ports of packets. This is crucial for functionalities like sharing a single public IP address among multiple private IP addresses (MASQUERADE), or directing incoming public traffic to an internal private host (DNAT).
The two primary chains in the nat table are:
PREROUTING: Used for Destination NAT (DNAT) – modifying packets as they first arrive, before routing decisions are made.POSTROUTING: Used for Source NAT (SNAT) – modifying packets just before they leave the system, after routing decisions are made.
1. SNAT (Source NAT) and MASQUERADE Examples
Source NAT changes the source IP address of packets. MASQUERADE is a special form of SNAT designed for interfaces with dynamically assigned IP addresses (like DHCP connections), as it automatically uses the IP address of the outgoing interface.
Example 1: Basic MASQUERADE
This rule performs Source NAT for all traffic originating from the 192.168.2.0/24 subnet when it exits through the eth0 interface. The source IP address of these packets will be changed to the IP address of eth0.
iptables -t nat -A POSTROUTING -s 192.168.2.0/24 -o eth0 -j MASQUERADE-t nat: Specifies that we are working in thenattable.-A POSTROUTING: Appends this rule to thePOSTROUTINGchain.-s 192.168.2.0/24: Matches packets whose source IP address is within this subnet.-o eth0: Matches packets that are leaving the system via theeth0network interface.-j MASQUERADE: The target action; it tellsiptablesto replace the packet’s source IP with the IP of the outgoing interface (eth0).
Example 2: MASQUERADE for Traffic to External Destinations
This rule masquerades traffic from 10.44.1.0/24 only if it’s destined for networks other than 172.32.1.0/24, when exiting via eth0. The ! operator negates the destination match.
iptables -t nat -A POSTROUTING -s 10.44.1.0/24 '!' -d 172.32.1.0/24 -o eth0 -j MASQUERADE'!' -d 172.32.1.0/24: Matches packets where the destination IP address is not within the172.32.1.0/24subnet.
Example 3: Inserting a MASQUERADE Rule at a Specific Position
Rules can be inserted at a specific line number within a chain using -I. This is important for controlling rule order, as iptables processes rules sequentially.
iptables -t nat -I POSTROUTING 2 -s 10.44.4.0/24 -d 172.32.1.0/24 -o eth0 -j MASQUERADE-I POSTROUTING 2: Inserts this rule at position 2 in thePOSTROUTINGchain. Any existing rule at position 2 (and subsequent rules) will be shifted down.
2. DNAT (Destination NAT) Examples
Destination NAT changes the destination IP address and/or port of incoming packets, often used for port forwarding or load balancing. (A common DNAT example is found in baselinev1.md within the NAT table section.)
# Example: Port Forwarding (from baselinev1.md)
# Redirect incoming TCP traffic on port 443 on eth0 to an internal host 192.168.2.100 on port 443
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j DNAT --to 192.168.2.100:443Warning: Always exercise caution when configuring iptables NAT rules. Incorrect rules can break network connectivity for services or entire subnets. It’s recommended to test thoroughly in a controlled environment.