הנה, מ - man iptables של CentOS 6.2
ֻ
DNAT
This target is only valid in the nat table, in the PREROUTING and OUTPUT chains, and user-defined chains which are only
called from those chains. It specifies that the destination address of the packet should be modified (and all future pack-
ets in this connection will also be mangled), and rules should cease being examined. It takes one type of option:
--to-destination [ipaddr][-ipaddr][
ort[-port]]
which can specify a single new destination IP address, an inclusive range of IP addresses, and optionally, a port
range (which is only valid if the rule also specifies -p tcp or -p udp). If no port range is specified, then the
destination port will never be modified. If no IP address is specified then only the destination port will be modi-
fied.
In Kernels up to 2.6.10 you can add several --to-destination options. For those kernels, if you specify more than one
destination address, either via an address range or multiple --to-destination options, a simple round-robin (one
after another in cycle) load balancing takes place between these addresses. Later Kernels (>= 2.6.11-rc1) don’t have
the ability to NAT to multiple ranges anymore.