summaryrefslogtreecommitdiffstats
path: root/extensions/libipt_DNAT.man
blob: 7579e14e4925f52e84b1cfe5cb2136a11623b054 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
This target is only valid in the
.B nat
table, in the
.B PREROUTING
and
.B OUTPUT
chains, and user-defined chains which are only called from those
chains.  It specifies that the destination address of the packet
should be modified (and all future packets in this connection will
also be mangled), and rules should cease being examined.  It takes one
type of option:
.TP
.BR "--to-destination " "\fIipaddr\fP[-\fIipaddr\fP][:\fIport\fP-\fIport\fP]"
which can specify a single new destination IP address, an inclusive
range of IP addresses, and optionally, a port range (which is only
valid if the rule also specifies
.B "-p tcp"
or
.BR "-p udp" ).
If no port range is specified, then the destination port will never be
modified.
.RS
.PP
You can add several --to-destination options.  If you specify more
than one destination address, either via an address range or multiple
--to-destination options, a simple round-robin (one after another in
cycle) load balancing takes place between these adresses.