On Thu, 2012-02-02 at 08:48 +0100, Guido Anzuoni wrote: > The much more specific question is: in order to correctly perform SNAT > and DNAT, is it necessary to bind the referenced addresses > to some interface ? Well, I can't see why you'd want to SNAT to an IP address that isn't assigned to the interface in question? I don't know whether it would work or not though. As for DNAT, the destination address wouldn't necessarily be on the same machine, so the answer is no. Unless I'm misunderstanding your question? Andy -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html