Asutorufaのブログ

こんにちは

iptables

投稿日 2021-07-14|更新日: 2021-07-14|カテゴリ Network

iptables chain

    +---------------------------------------------------------+    |                   Network Card                          |    +---------------------------------------------------------+      |                                                    ^      |                                                    |      v                                                    | +----------+          is?      no    +-------+        +-----------+ |prerouting| ----> localhost ------> |forward| ---->  |postrouting| +----------+          |              +-------+        +-----------+                        | yes                                 ^                       |                                     |                       v                                     |                    +---------+                        +-----------+                    |  input  |                        |   output  |                    +---------+                        +-----------+                         |                                   ^                         |                                   |                         |                                   |                         v                                   |    +----------------------------------------------------------+    |                        user                              |    +----------------------------------------------------------+ out -> localhost: prerouting -> inputforward:          prerouting -> forward    -> postroutinglocalhost -> out: output     -> postrouting

iptables table:

  • filter:
  • nat:
  • magle:
  • raw:
table <-> chain  raw: PREROUTING, OUTPUT  mangle: PREROUTING, INPUT, FORWARD, OUTPUT, POSTROUTING  nat: PREROUTING, OUTPUT, POSTROUTING, INPUT  filter: INPUT, FORWARD, OUTPUT raw –> mangle –> nat –> filter   chain <-> tablePREROUTING: raw, mangle, natINPUT: mangle, filter, natFORWARD: mangle, filterOUTPUT: raw, mangle, nat, filterPOSTROUTING: mangle, nat

query

iptables -t <table> -nvL <chain>

iptables

0 件のコメント

©2026Asutorufa