LFCS Networking Practice Question
A Linux router has two interfaces: eth0 (203.0.113.10/24) connected to the internet and eth1 (10.10.0.1/24) connected to an internal network. Internal clients can ping the router's eth1 address but cannot reach external websites. IP forwarding is enabled, and no firewall rules are present. Which command will allow the internal clients to reach the internet by masquerading their traffic?
⚠ Common exam trap
The trap here is placing MASQUERADE in PREROUTING or on the internal interface, confusing the direction of source NAT.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
For internal clients to reach the internet through a router, their private source addresses must be translated to the router's public address. This is done with a MASQUERADE rule in the nat table's POSTROUTING chain, applied to packets leaving the external interface. The other options either use the wrong chain, only permit forwarding without translation, or masquerade in the wrong direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
Why it's wrong here
This rule masquerades traffic leaving via eth1, the internal interface, which is the wrong direction. Internal clients need their source address rewritten as packets exit the external interface eth0. Applying masquerade on eth1 would affect traffic destined for the internal network and would not enable internet access for the clients.
- ✗
iptables -t nat -A PREROUTING -i eth1 -j MASQUERADE
Why it's wrong here
Masquerading must occur in the POSTROUTING chain, after the routing decision, not in PREROUTING. PREROUTING is used for destination NAT (port forwarding) before routing. Placing a MASQUERADE target in PREROUTING is invalid because the target is only valid in the nat table's POSTROUTING chain; iptables will reject the rule with an error.
- ✓
iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
Why this is correct
This rule adds a source NAT (masquerade) rule to the POSTROUTING chain for packets leaving via eth0. It rewrites the source address of internal packets to the router's external IP, allowing return traffic to be routed back. This is the standard way to provide internet access for a private subnet when the external address is dynamic or when using a single public IP.
- ✗
iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
Why it's wrong here
This rule only permits forwarding of packets from eth1 to eth0; it does not perform any address translation. Without NAT, internal clients' private source addresses would be sent to the internet, and responses would not return because private addresses are not routable. The rule is necessary for forwarding but insufficient for internet access.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.