|
The
two are functionally equivalent if you have a static ip address. The
difference is that if you MASQERADE the connection, then whenever a connection
is made, netfilter takes a few extra processor cycles to look up the ip address
of the interface that the connection is going out of. So using MASQERADE
instead of SNAT gives you (very slight) performance hit. There's really
very little difference, but if you happen to have a static IP, there's no reason
not to use SNAT.
-Joe
|
- -j MASQUERADE Markus Sj�str�m
- Re: -j MASQUERADE Ramin Alidousti
- RE: -j MASQUERADE Aldo S. Lagana
- Re: -j MASQUERADE Joe Patterson
- Re: -j MASQUERADE Chris Hoeschen
- -j MASQUERADE Markus Sj�str�m
