LFCS Networking Practice Question
A Linux server is configured as a router with IP forwarding enabled. It has two interfaces: eth0 (203.0.113.5/24) and eth1 (192.168.1.1/24). Clients on 192.168.1.0/24 need to reach the internet via eth0. The administrator has set up NAT using iptables with the rule: iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE. However, clients cannot access external websites. Which two actions should the administrator take to resolve the issue? (Choose two.)
⚠ Common exam trap
The trap here is focusing solely on NAT configuration while overlooking the need for IP forwarding and FORWARD chain rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that IP forwarding is enabled by checking the value of net.ipv4.ip_forward.
For a Linux router to forward traffic between interfaces, IP forwarding must be enabled, and the FORWARD chain must permit the traffic. Even with MASQUERADE configured, if either condition is not met, packets will be dropped. The administrator should verify net.ipv4.ip_forward and ensure FORWARD rules allow traffic from the internal to external interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a SNAT rule instead of MASQUERADE for better performance.
Why it's wrong here
MASQUERADE is appropriate when the external IP is dynamic. Replacing it with SNAT would require specifying a static IP, which may not be known or may change. This change does not address the likely causes of the failure, such as forwarding being blocked or disabled.
- ✗
Disable the firewall on the clients to allow outbound connections.
Why it's wrong here
Client firewalls are not typically the cause when all clients fail to reach the internet. The problem is on the router where NAT and forwarding are configured. Disabling client firewalls is a security risk and unlikely to resolve the issue if the router is not forwarding packets.
- ✓
Verify that IP forwarding is enabled by checking the value of net.ipv4.ip_forward.
Why this is correct
NAT alone does not enable routing. The kernel must have IP forwarding enabled, typically via sysctl net.ipv4.ip_forward=1. If this is disabled, packets from the internal network will not be forwarded to the external interface, causing the connectivity failure described.
- ✓
Ensure that the FORWARD chain policy is ACCEPT or add rules to allow forwarding from eth1 to eth0.
Why this is correct
By default, many distributions set the FORWARD chain policy to DROP. Even with NAT configured, packets must be allowed to traverse the router. The administrator must either set the policy to ACCEPT or add explicit rules permitting traffic from eth1 to eth0 and the return traffic, otherwise forwarding is blocked.
- ✗
Configure a default route on the router pointing to the ISP gateway.
Why it's wrong here
The router itself likely already has a default route to reach the internet. The issue is that clients cannot access external sites, which points to forwarding or NAT problems rather than the router's own default route. Adding a default route may be unnecessary and does not fix the client connectivity.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 406 original LFCS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.