Moxa TC-6110-T-LX [37/117] Netfilter hierarchy for incoming packets

Moxa TC-6110-T-LX [37/117] Netfilter hierarchy for incoming packets
TC-6110 Linux User's Manual Managing Communications
3-19
Netfilter Hierarchy for Incoming Packets
This figure shows how packets traverse the table hierarchy. Outbound packets originating on the local network
start at the box labeled Local Process. Inbound packets start at the top box labeled Incoming Packets.
ATTENTION
Be careful when setting up
iptables rules.
Incorrectly configured rules can very easily break connectivity with
a
remote host. For simple setups requiring minimal configuration (five rules or less), Moxa recommends
directly configuring
iptables using the console and a standard editor.
For more complicated setups, users may
use Arno’s iptables firewall script, or for very large, extremely complicated setups Moxa recommends the
Shorelin
e Firewall. The following
links will take you to further information about iptables setups and the various
software packages mentioned above
.
The netfilter
/iptables Project Homepage: http://www.netfilter.org/index.html
The Official neftilter/iptables packet
-filtering HOWTO:
http://www.netfilter.org/documentation/HOWTO/packet-filtering-HOWTO.htm
Arno’s iptables
Firewall (click on IPTABLES FIREWALL tab at the top navigation ribbon):
http://rocky.eld.leidenuniv.nl/joomla/
The Shore
line Firewall Homepage (lots of information about netfilter/iptables, as well):
http://www.shorewall.net/Documentation_Index.html
Public iptables/neftilter Forum:
http://www.linuxguruz.com/iptables/
Incoming
Packets
Mangle Table
PREROUTING Chain
NAT Table
PREROUTING Chain
NAT Table
POSTROUTING Chain
Outgoing
Packets
Other Host
Packets
Mangle Table
FORWARD Chain
Filter Table
FORWARD Chain
Mangle Table
POSTROUTING Chain
Local Host
Packets
Mangle Table
INPUT Chain
Filter Table
INPUT Chain
Local
Process
Mangle Table
OUTPUT Chain
NAT Table
OUTPUT Chain
Filter Table
OUTPUT Chain

Содержание

Похожие устройства

Скачать