全部博文(230)
分类: LINUX
2006-01-26 02:22:01
Network
-----------+-----------
|
+---------+---------+
| [IPTABLES] |
| [PREROUTING] |
| +-------+-------+ |
| | conntrack | |
| +-------+-------+ |
| | mangle | | <- MARK WRITE
| +-------+-------+ |
| | IMQ | |
| +-------+-------+ |
| | nat | | <- DEST REWRITE
| +-------+-------+ | DNAT or REDIRECT or DE-MASQUERADE
+---------+---------+
|
+-------+-------+
| QOS |
| INGRESS |
+-------+-------+
|
packet is for +-------+-------+ packet is for
this machine | INPUT | another address
+--------------+ ROUTING +-------------------+
| | + PDBB | |
| +---------------+ |
+-------+-------+ |
| [IPTABLES] | |
| [INPUT] | |
| +-----+-----+ | |
| | mangle | | |
| +-----+-----+ | |
| | filter | | |
| +-----+-----+ | |
+-------+-------+ |
| |
+-------+-------+ |
| Local | +-------+-------+
| Process | | [IPTABLES] |
+-------+-------+ | [FORWARD] |
| | +-----+-----+ |
+-------+-------+ | | mangle | | <- MARK WRITE
| OUTPUT | | +-----+-----+ |
| ROUTING | | | filter | |
+-------+-------+ | +-----+-----+ |
| +-------+-------+
+-------+-------+ |
| [IPTABLES] | |
| [OUTPUT] | |
| +-----------+ | |
| | conntrack | | |
| +-----+-----+ | |
| | mangle | | <- MARK WRITE |
| +-----+-----+ | |
| | nat | | <-DEST REWRITE |
| +-----+-----+ | DNAT or REDIRECT |
| | filter | | |
| +-----+-----+ | |
+-------+-------+ |
| |
+----------------------+---------------------------+
|
+---------+---------+
| [IPTABLES] |
| [POSTROUTING] |
| +-------+-------+ |
| | mangle | | <- MARK WRITE
| +-------+-------+ |
| | nat | | <- SOURCE REWRITE
| +-------+-------+ | SNAT or MASQUERADE
| | IMQ | |
| +-------+-------+ |
+---------+---------+
|
+------+------+
| QOS |
| EGRESS |
+------+------+
|
-----------+-----------
Network