Hello, > 1. What does "client" mean? An IP, process? Source IP-address. > - Will all my connections go through one IP? Yes, until you don't change source IP. Only original source IP-address is using in hash function for selecting IP-address from NAT-pool. > - Or for each connection IP will be chosen randomly? This is default behaviour. Source and destination addresses are using for hash value calculation in this case. -- wbr, Oleg. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html