Courseiva
Networking →hardMultiple Choice

LFCS Networking Practice Question

A Linux router has two interfaces: eth0 (203.0.113.10/24) connected to the internet and eth1 (10.10.0.1/24) connected to an internal network. Internal clients can ping the router's eth1 address but cannot reach external websites. IP forwarding is enabled, and no firewall rules are present. Which command will allow the internal clients to reach the internet by masquerading their traffic?

⚠ Common exam trap

The trap here is placing MASQUERADE in PREROUTING or on the internal interface, confusing the direction of source NAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

For internal clients to reach the internet through a router, their private source addresses must be translated to the router's public address. This is done with a MASQUERADE rule in the nat table's POSTROUTING chain, applied to packets leaving the external interface. The other options either use the wrong chain, only permit forwarding without translation, or masquerade in the wrong direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE

    Why it's wrong here

    This rule masquerades traffic leaving via eth1, the internal interface, which is the wrong direction. Internal clients need their source address rewritten as packets exit the external interface eth0. Applying masquerade on eth1 would affect traffic destined for the internal network and would not enable internet access for the clients.

  • ✗

    iptables -t nat -A PREROUTING -i eth1 -j MASQUERADE

    Why it's wrong here

    Masquerading must occur in the POSTROUTING chain, after the routing decision, not in PREROUTING. PREROUTING is used for destination NAT (port forwarding) before routing. Placing a MASQUERADE target in PREROUTING is invalid because the target is only valid in the nat table's POSTROUTING chain; iptables will reject the rule with an error.

  • ✓

    iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

    Why this is correct

    This rule adds a source NAT (masquerade) rule to the POSTROUTING chain for packets leaving via eth0. It rewrites the source address of internal packets to the router's external IP, allowing return traffic to be routed back. This is the standard way to provide internet access for a private subnet when the external address is dynamic or when using a single public IP.

  • ✗

    iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT

    Why it's wrong here

    This rule only permits forwarding of packets from eth1 to eth0; it does not perform any address translation. Without NAT, internal clients' private source addresses would be sent to the internet, and responses would not return because private addresses are not routable. The rule is necessary for forwarding but insufficient for internet access.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.