IP Masquerading

The default configuration is for the standard home router use case where packets going to the Internet must be masqueraded to the public IP that the ISP has provided. This is the IP of the WAN interface, so it is correct that checking the masquerade box on WAN will convert all outgoing packets to have the WAN interface as their source IP.

If the box is not checked, the source IP of packets bound to the Internet from the LAN (by forwarding them to WAN) will remain as the LAN IP of the originating PC. This will not work since the ISP does not keep a route back to your LAN.

2 Likes