分类: 网络与安全
2006-11-22 13:47:27
Network -----------+----------- | +---------+---------+ | [IPTABLES] | | [PREROUTING] | | +-------+-------+ | | | conntrack | | | +-------+-------+ | | | mangle | | <- MARK WRITE | +-------+-------+ | | | IMQ | | | +-------+-------+ | | | nat | | <- DEST REWRITE | +-------+-------+ | DNAT or REDIRECT or DE-MASQUERADE +---------+---------+ | +-------+-------+ | QOS | | INGRESS | +-------+-------+ | packet is for +-------+-------+ packet is for this machine | INPUT | another address +--------------+ ROUTING +-------------------+ | | + PDBB | | | +---------------+ | +-------+-------+ | | [IPTABLES] | | | [INPUT] | | | +-----+-----+ | | | | mangle | | | | +-----+-----+ | | | | filter | | | | +-----+-----+ | | +-------+-------+ | | | +-------+-------+ | | Local | +-------+-------+ | Process | | [IPTABLES] | +-------+-------+ | [FORWARD] | | | +-----+-----+ | +-------+-------+ | | mangle | | <- MARK WRITE | OUTPUT | | +-----+-----+ | | ROUTING | | | filter | | +-------+-------+ | +-----+-----+ | | +-------+-------+ +-------+-------+ | | [IPTABLES] | | | [OUTPUT] | | | +-----------+ | | | | conntrack | | | | +-----+-----+ | | | | mangle | | <- MARK WRITE | | +-----+-----+ | | | | nat | | <-DEST REWRITE | | +-----+-----+ | DNAT or REDIRECT | | | filter | | | | +-----+-----+ | | +-------+-------+ | | | +----------------------+---------------------------+ | +---------+---------+ | [IPTABLES] | | [POSTROUTING] | | +-------+-------+ | | | mangle | | <- MARK WRITE | +-------+-------+ | | | nat | | <- SOURCE REWRITE | +-------+-------+ | SNAT or MASQUERADE | | IMQ | | | +-------+-------+ | +---------+---------+ | +------+------+ | QOS | | EGRESS | +------+------+ | -----------+----------- Network