1 2 3 4 5 6 7
table ip x { flags dormant chain y { type nat hook prerouting priority filter; policy accept; } }