Baru: nic nie stoi na przeszkodzie, żebyś sobie zrobił SNAT
zamiast MASQUERADE.
zciech:
Cytuj:
Iptables tutorial 1.2.2
[...]
If you have a static IP connection, you should instead [MASQUERADE - przyp.viater] use the SNAT target.
[...]
It is still possible to use the MASQUERADE target instead of SNAT even though you do have a static IP, however, it is not favorable since it will add extra overhead, and there may be inconsistencies in the future which will thwart your existing scripts and render them "unusable".