Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Iptable detailed explanation

Shulou Source: shulou.com Published: 2022-06-01 05:51:51 10月04日 Update

Ordered rules form a chain chain

The set of chains forms the table table.

The default iptables table is called "filter" and contains three default chains.

For each package, the kernel chooses the appropriate one of the three chains to process:

. FORWARD chain rules for packets input from one network interface and forwarded to another network interface for output

. INPUT chain rules for packets destined for the native machine

. OUTPUT chain rules for packages sent from the local host

In addition to the filter table, iptables contains "NAT" and "mangle" tables.

. The mangle table contains the contents of network packets that can be modified or changed by chains outside of NAT and packet filtering.

Although the mangle table is convenient for special processing of packages, such as resetting the ttl value of IP packages, it is generally not used in most work environments.

The functions of the three rule tables are as follows:

Nat: this rule table has two rule chains, PREROUTING and POSTROUTING

The main function is to convert one-to-one, one-to-many, many-to-many URLs (SNAT, DNAT)

This list of rules should not be used for any purpose other than for URL conversion.

Mangle: this rule table has three rule chains: PREROUTING, FORWARD, and POSTROUTING.

In addition to rewriting packets during URL conversion, some special applications may also have to rewrite packets (TTL, TOS).

Or set MARK (to mark packets for subsequent filtering), in which case the work must be defined in the mangle rule table

Due to low usage, we are not going to discuss the use of mangle here.

Filter: this rule table is the default rule table, with three rule chains: INPUT, FORWARD and OUTPUT

As the name implies, this rule table is used for packet filtering (for example, DROP, LOG, ACCEPT, or REJECT).

We will establish all the basic rules in this rule table.

Reference: http://blog.chinaunix.net/uid-26000296-id-4111127.html

Tags: Rules three packets work URL network processing special function interface as the name implies one-on-one two host utilization content kernel action work meeting is in Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology Huawei macOS Shulou Information NVidia