Networking · Concept · 11 min read

IP Masquerading, and the One Case Where SNAT Is Better

Every home router does this and almost nobody calls it by its name. The mechanism is one rewrite and one table row, and everything awkward about NAT comes from that row.

Written by Marko Ristic, Editor Updated Sep 23, 2026
1Rule, plus ip_forward, and a Linux host is a NAT router
2Things rewritten: the source address and usually the source port
0Inbound connections that work without a row created in advance
1Difference from SNAT: where the new address comes from
Short answer

Masquerading is source NAT that takes the new address from the outgoing interface at the moment the packet leaves. A whole private network shares one public address, and a connection tracking row is what lets the replies find their way back.

  • The address comes from the interface, read per packet
  • SNAT does the same with an address you configured, and is right on a static one
  • The source port is usually rewritten too, which is why it is also called PAT
  • The tracking row is the mechanism. No row, no reply
  • Inbound connections fail because no row exists for them yet
On this page

The rewriteWhat actually happens to a packet

Masquerading is three operations, and the third is the one people forget.

The source address is rewritten. A packet leaves 192.168.1.40 headed for the internet. The router replaces the source address with its own public address, so the destination sees the router rather than the workstation.

The source port is usually rewritten too. Twenty devices behind one address will eventually pick the same source port for two different conversations. The router changes one of them so the pair of address and port is unique, which is why this is also called port address translation.

The translation is recorded. The router writes an entry into its connection tracking table: this internal address and port maps to this external port, for this destination. When the reply arrives addressed to the public address on that external port, the table says where it belongs and the router reverses the translation.

That table is the whole mechanism. Without it the outbound rewrite would work and no reply would ever find its way home. Every property of NAT that people find surprising comes from the existence and the lifetime of those entries.

The ruleThe rule, in practice

On a Linux host acting as a router, masquerading is one rule and one kernel setting.

sysctl -w net.ipv4.ip_forward=1
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

The nftables equivalent does the same job in the same place.

nft add rule ip nat postrouting oifname "eth0" masquerade

Three details in those rules matter more than they look.

The chain is POSTROUTING. The rewrite has to happen after the kernel has decided which interface the packet leaves by, because the MASQUERADE target reads the address off that interface. Putting it anywhere earlier means the routing decision has not been made yet and there is no interface to read.

The rule matches the outgoing interface, not the source network. That is what makes it portable: the same rule works whatever addresses the internal network uses.

ip_forward has to be on. Without it the kernel drops packets that are not for itself, and the masquerade rule never sees them. A server that is routing nothing at all, with a rule that looks perfect, is almost always this.

On a firewall appliance the same thing exists under a different name, usually a checkbox on the outbound interface called NAT or hide NAT, and the behavior underneath is identical.

Against SNATMasquerading against source NAT

Both are source address translation and the difference is where the new address comes from.

SNAT uses an address you configured. You tell the kernel: rewrite to 203.0.113.10. The rule does that for every packet, without checking anything.

MASQUERADE uses the interface's current address. The kernel looks at whatever address the outgoing interface holds when the packet passes and uses that.

MasqueradingSource NAT
Address sourceThe interface, per packetConfigured in the rule
Works on a dynamic addressYesNo, it breaks on change
Cost per packetA lookup on the interfaceNone
Can map to several addressesNoYes, from a pool
On an address changeConnections are droppedThe rule is simply wrong
Right choiceDynamic addressesStatic addresses

That last row is the entire decision. On a static public address, SNAT is fractionally cheaper because the kernel does no lookup per packet, and it can map to a pool of addresses rather than one.

On a dynamic address it is a rule that silently becomes wrong the next time the provider changes your address, and MASQUERADE is the correct answer.

The behavior on an address change is worth noting rather than discovering. The MASQUERADE target drops the connection tracking entries when the interface address goes away, which is right: those connections were using an address that no longer exists and could never have completed.

InboundWhy NAT breaks inbound connections

Everything difficult about NAT follows from one fact: the translation table is created by outbound traffic.

A packet arriving from the internet for a connection nobody started has no entry in the table, so the router does not know which internal machine it is for. It cannot guess, and it drops it.

That is not a security feature that somebody designed, it is an unavoidable consequence of many machines sharing one address, and the fact that it acts like a firewall is a side effect people came to rely on.

Three mechanisms work around it, and each has a cost.

Port forwarding rules create a static entry by hand: traffic to this external port always goes to this internal host. It works, it is manual, and one external port can only be forwarded to one internal host.

Connection tracking helpers are kernel modules that watch protocols carrying addresses inside the payload, FTP being the standard example, and open the necessary entries automatically. They are the reason certain protocols work at all through NAT, and they have historically been a source of security problems.

NAT traversal techniques let two machines behind separate NAT devices reach each other by both starting outbound connections to a third party that introduces them. This is how most voice, video and peer to peer software works today.

Where it appearsWhere masquerading appears

Every home and small office router. The provider gives one public address and the router masquerades the whole internal network behind it. Almost nobody calls it masquerading in that context, but that is what it is.

Linux routers and firewalls. The MASQUERADE target in iptables and its nftables equivalent, which is where the name comes from and where most people meet the word.

Containers. The default Docker bridge network installs masquerade rules so container traffic leaves behind the host address, which is why a container reaches out freely and nothing reaches in without a published port.

Cloud instances. A server with a private address reaching the internet through a NAT gateway is the same pattern at a different scale, with the same inbound consequence.

PitfallsWhere people go wrong

Using MASQUERADE on a static public address. It works, and SNAT is the correct target. Configure the address you actually have.

Expecting inbound connections to work. They cannot, unless something creates the table entry in advance. Port forwarding, a traversal technique, or a VPN.

Running two layers of NAT without noticing. A provider box that routes plus your own firewall that routes is double NAT. Outbound works, inbound breaks in ways that are hard to trace, and the fix is putting one of them into bridge mode.

Treating NAT as a firewall. It drops unsolicited inbound traffic because it cannot do anything else, not because it inspected anything. A real firewall makes decisions; NAT is a table lookup that failed.

Forgetting the table has a size. Connection tracking entries are finite, and a busy server or a port scan can fill the table. When it is full, new connections fail while existing ones continue, which is a confusing failure to diagnose.

Writing the rule and forgetting ip_forward. The rule is correct, the kernel is dropping the packets before it ever runs, and nothing in the rule counters suggests why.

Assuming the port stays the same. The source port is usually rewritten, so an internal capture and an external capture of the same conversation show different port numbers. This surprises people reading logs from both sides.

THE REWRITE IS EASY. THE TABLE ROW IS THE WHOLE MECHANISM.LEAVING THE WORKSTATIONsrc 192.168.1.40:51422dst 93.184.216.34:443MASQUERADEPOSTROUTINGON THE INTERNETsrc 203.0.113.10:60318dst 93.184.216.34:443THE CONNECTION TRACKING ROW THAT REWRITE JUST CREATED192.168.1.40:51422 maps to 203.0.113.10:60318 for 93.184.216.34:443REPLY ARRIVESsrc 93.184.216.34:443dst 203.0.113.10:60318ROW MATCHEDreversedBACK TO THE WORKSTATIONsrc 93.184.216.34:443dst 192.168.1.40:51422AN INBOUND PACKET WITH NO MATCHING ROW CANNOT BE DELIVERED. NOTHING DECIDED THAT, IT IS ARITHMETIC.Which is why inbound needs port forwarding, a traversal technique, or a VPN, and never just a rule.MASQUERADE reads the address off the interface. SNAT uses one you typed. That is the only difference.
The middle band is the part that is never drawn and always matters. Delete that row and the packet on the right can never come home.

ComparisonFour kinds of translation, and the two rows that map them

CriterionMasqueradingSNATDNATPort forwarding
What it rewritesThe sourceThe sourceThe destinationThe destination
Direction it enablesOutboundOutboundInboundInbound
Address comes fromThe interfaceConfiguredConfiguredConfigured
Needs a static addressNoYesYesYes
Creates table entriesOn demandOn demandIn advanceIn advance
Typical useA dynamic internet linkA static onePublishing a servicePublishing one port

The first two rows are the map. Source translation gets a private network out, destination translation lets something in, and port forwarding is destination translation with a port number attached to it.

FAQFrequently asked questions

What is IP masquerading?

Source network address translation where the new source address is taken from the outgoing interface at the time the packet is sent, so a whole private network appears on the internet as one address.

What is the difference between MASQUERADE and SNAT?

Both rules rewrite the source address. MASQUERADE reads the address from the interface for every packet, and SNAT uses an address configured in the rule. MASQUERADE works on a dynamic address and SNAT does not.

Which should I use?

MASQUERADE if the public address changes, SNAT if it does not. On a static address SNAT is slightly cheaper for the kernel and can also map to a pool of addresses.

What is the iptables masquerade rule?

One line in the nat table POSTROUTING chain, matching the outgoing interface: iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE. Enabling net.ipv4.ip_forward is what makes the Linux host route at all.

Is masquerading the same as PAT?

Effectively yes. Port address translation, NAT overload and masquerading all describe many private addresses sharing one public address, distinguished by port number.

Why does the source port change?

Because several internal machines will eventually choose the same source port, and the router needs each translated connection to be unique. Rewriting the port is what makes many-to-one sharing possible.

How do replies find their way back?

Through the connection tracking table, which recorded the translation when the outbound packet left. Reply traffic is matched against it and translated back.

Why can nothing connect in from the outside?

Because inbound packets for a connection nobody started have no entry in the translation table, so the router has no way to know which internal machine they are for.

Is NAT a security feature?

It blocks unsolicited inbound traffic as a side effect of not being able to route it. That is useful and it is not a firewall, because nothing has been inspected or decided.

What happens when the public address changes?

Masquerading drops the existing connection tracking entries, because those connections used an address that no longer exists. New connections work immediately with the new address.

Does Docker use masquerading?

Yes. The default bridge network installs masquerade rules so container traffic leaves behind the host address, which is why containers reach out freely and nothing reaches in without a published port.

What is double NAT?

Two devices translating in series, usually a provider box and your own router. Outbound traffic works and inbound breaks, and bridging one of the two is the fix.

Can the connection tracking table fill up?

Yes. It has a fixed size, and a busy network or a port scan can exhaust it. New connections then fail while existing ones keep working.

Does masquerading work for IPv6?

It exists and is almost never appropriate. IPv6 gives every device a routable address, so the address shortage that made this necessary does not apply.

Read next · Ports What Is a Port Number? The source port is what makes many-to-one sharing possible, and it is worth knowing where those numbers come from. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.