Operation Manual

SFX SERIES USER’S GUIDE
Rev 2.2 57
Service for a copy of the iptables tutorial (see Chapter 3). The iptables facility under Linux is extensive and complex;
and Destination NAT is only one part of this facility. The Destination NAT submenu is intended to make configuration
of this function more user friendly.
Destination NAT of incoming IP packets is performed by the receiver according to the following rules
:
1. IP packets can originate from any of the available network interfaces and are processed by the receiver in
accordance with the data flow in Figure 2- 12.
2. Up to 25 rules can be maintained by the Destination NAT table. Rules are executed from the first rule to the
last rule, in sequence. Order matters; the first rule that is applicable to the incoming packet is applied.
Subsequent rules after that are ignored.
3. Packets can be filtered by Source IP Address/Port or Destination IP Address/Port, or both. Ports can only be
specified if UDP or TCP protocols are selected.
4. Where a rule applies to a packet, Destination Network Address Translation (DNAT) will be performed every
time – the destination IP address/port on the incoming packet is replaced with a new destination
address/port, as specified in the rule.
5. Provision is made in the rule table for additional iptables options, allowing for maximum flexibility. However,
extreme care should be taken when using additional options, and the iptables manual must be consulted in
this case. (One example of an option usage could be to specify a source network interface for the incoming
packets.)
When the Destination NAT submenu item is selected under Data Delivery, the Destination NAT Table page is
displayed for all applicable destination address translation rules. A sample Destination NAT Table page is shown in
Figure 2- 29. (One example of an option usage could be to specify a source network interface for the incoming
packets.)
Figure 2- 29 Destination NAT Table Page
The columns in the Destination NAT Table page are described under the Edit Destination NAT Table page (Figure 2-
30). Aside from the Common Menu Items, the following menu items are available: