All of lore.kernel.org
 help / color / mirror / Atom feed
From: Maxime de Roucy <maxime.deroucy@gmail.com>
To: netfilter@vger.kernel.org
Subject: nftables: Request for comments - packet flow diagram
Date: Tue, 09 May 2017 21:38:03 +0200	[thread overview]
Message-ID: <1494358682.1866.2.camel@gmail.com> (raw)

[-- Attachment #1: Type: text/plain, Size: 1281 bytes --]

Hello,

I recently switch from iptables to nftables (I have a very
simple/personal firewall).

When I built my iptables firewall I refereed to the packet flow diagram
(by Jan Engelhardt) on iptables Wikipedia web page : 
https://en.wikipedia.org/wiki/Iptables#/media/File:Netfilter-packet-flow.svg

Using this diagram for nftables firewall is hard as some concept
changed.

I did some tests and draw my own diagram (using yed editor) covering
all netdev, ip, ip6, inet, bridge and arp tables :

https://pelican.craoc.fr/#packet-flow

Direct URL and yed sources :
 * https://pelican.craoc.fr/images/packet_flow.svg
 * https://pelican.craoc.fr/images/packet_flow.graphml

Can you please verify it ? Feedback would be much appreciated :)
I am not a network expert but the subject interest me and I would like
to know if I misunderstand something.

I put this diagram on CC-BY-SA license so feel free to use/modify it if
you like.

Note: I draw an arp-forward-filter chain in the diagram because I can
create one, but I can't actually saw any packet going through it.
I think it's a bug, so I draw it anyway. More informations :

 * https://pelican.craoc.fr/#arp-vm1-vm2
 * http://marc.info/?l=netfilter&m=149410713429067
-- 
Regards
Maxime de Roucy

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

                 reply	other threads:[~2017-05-09 19:38 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1494358682.1866.2.camel@gmail.com \
    --to=maxime.deroucy@gmail.com \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.