
Chapter 2: Network Configuration
29
the packet should be modified (and all future packets in this connection are also mangled) and rules
should cease being examined. It takes one option.
MASQUERADE (NAT table only, IPv4 only)
This target is only valid in the nat table, in the POSTROUTING chain. It should only be used with
dynamically assigned IP (dialup) connections. If you have a static IP address, you should use the
SNAT target. Masquerading is equivalent to specifying a mapping to the IP address of the interface
the packet is going out on, but also has the effect that connections are forgotten when the interface
goes down. This is the correct behavior when the next dialup is unlikely to have the same interface
address (and hence any established connections are lost anyway). It supports one option.
REDIRECT (NAT table only, IPv4 only)
This target is only valid in the nat table, in the PREROUTING and OUTPUT chains and user-
defined chains which are only called from those chains. It alters the destination IP address to send
the packet to the machine itself (locally-generated packets are mapped to the 127.0.0.1 address). It
supports one option.
Table 2.18: DNAT Target
DNAT target
Description
- - to-destination <ipaddr>[-
<ipaddr>][:port-port]
This may specify a single new destination IP address, an inclusive range
of IP addresses and optionally, a port range (which is only valid if the
rule also specifies -p tcp or -p udp). If no port range is specified, then the
destination port is never modified.
Table 2.19: Masquerade Target
Target
Description
- - to-ports <port>[-<port>]
Specifies a range of source ports to use. This parameter overrides the default
SNAT source port-selection heuristics, see
SNAT (NAT table only, IPv4 only)
. This
parameter is valid when the rule specifies -p tcp or -p udp.
Table 2.20: Redirect Target
Target
Description
- - to-ports <port>[-<port>]
Specifies a range of source ports to use. This parameter overrides the default
SNAT source port-selection heuristics, see
SNAT (NAT table only, IPv4 only)
. This
parameter is valid when the rule specifies -p tcp or -p udp.
Содержание Cyclades ACS 5000 SERIES
Страница 1: ...CYCLADES ACS 5000 Command Reference Guide ...
Страница 8: ...vi Cyclades ACS 5000 Advanced Console Server Command Reference Guide ...
Страница 16: ...8 Cyclades ACS 5000 Advanced Console Server Command Reference Guide ...
Страница 40: ...32 Cyclades ACS 5000 Advanced Console Server Command Reference Guide ...
Страница 62: ...54 Cyclades ACS 5000 Advanced Console Server Command Reference Guide ...
Страница 76: ...68 Cyclades ACS 5000 Advanced Console Server Command Reference Guide ...
Страница 151: ......
Страница 152: ...590 814 501B For Technical Support www avocent com support ...