# iptables -t nat -L -vxn Chain PREROUTING (policy ACCEPT 9022 packets, 614125 bytes) pkts bytes target prot opt in out source destination 71 5188 NAT_PREROUTING_CHAIN all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- ppp+ * 0.0.0.0/0 0.0.0.0/0 policy match dir in pol ipsec 71 5188 POST_NAT_PREROUTING_CHAIN all -- * * 0.0.0.0/0 0.0.0.0/0 Chain POSTROUTING (policy ACCEPT 32524 packets, 2262428 bytes) pkts bytes target prot opt in out source destination 22 1372 TCPMSS tcp -- * ppp+ 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 TCPMSS clamp to PMTU 186 13658 NAT_POSTROUTING_CHAIN all -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT all -- * ppp+ 0.0.0.0/0 0.0.0.0/0 policy match dir out pol ipsec 24 1746 MASQUERADE all -- * ppp+ 192.168.254.0/24 !192.168.254.0/24 0 0 MASQUERADE all -- * ppp+ 10.57.137.0/24 !10.57.137.0/24 162 11912 POST_NAT_POSTROUTING_CHAIN all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy ACCEPT 32510 packets, 2261540 bytes) pkts bytes target prot opt in out source destination Chain NAT_POSTROUTING_CHAIN (1 references) pkts bytes target prot opt in out source destination Chain NAT_PREROUTING_CHAIN (1 references) pkts bytes target prot opt in out source destination Chain POST_NAT_POSTROUTING_CHAIN (1 references) pkts bytes target prot opt in out source destination Chain POST_NAT_PREROUTING_CHAIN (1 references) pkts bytes target prot opt in out source destination