Destination IP address
of a packet. If a packet is matched, and this is the target of the rule, the packet,
and all subsequent packets in the same stream will be translated, and then routed
on to the correct device, host or network. This target can be extremely useful,
for example,when you have a host running your web server inside a
LAN, but no real IP to give it that will work
on the Internet. You could then tell the firewall to forward all packets going to
its own HTTP port, on to the real web server within the LAN. We may also specify a whole range of destination
IP addresses, and the DNAT mechanism will choose the destination IP address at random
for each stream. Hence, we will be able to deal with a kind of load balancing by
doing this.
Showing posts with label implementation. Show all posts
Showing posts with label implementation. Show all posts
Monday, September 5, 2011
implementation prerouting and postrouting
The DNAT target is used to do Destination Network Address Translation, which means
that it is used to rewrite the
Subscribe to:
Posts (Atom)