The invention provides a method and a device for achieving
packet forwarding. The method is applied to a
distributed firewall device which is at least composed of a plurality of interface boards, a plurality of business boards and a main control board. The method at least includes that each interface board receives a forward message in a
private network and sends the forward message to a corresponding business board, each business board receives the forward message, a source
internet protocol (IP) address of the forward message is modified to a preset
public network IP address of the local business board, a source port of the forward message is modified to any
network address translation port of a
network address translation port section distributed by the main control board, a
network address translation session is established, the converted forward message is sent to a corresponding interface board, and the interface boards send the converted forward message in a
public network. According to the method and the device, the main control board of a
distributed firewall distributes ports used for
network address translation (NAT) based on a request of each business board, and thereby the NAT is performed for the forward message, a corresponding NAT is established, and the new establishing and concurrence of the NAT session can increase with the increasing of the business boards.