Linux Advanced Routing and Traffic Control list
 help / color / mirror / Atom feed
From: Julian Anastasov <ja@ssi.bg>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] ipchains + mark in output chain ?
Date: Mon, 17 Jun 2002 19:11:05 +0000	[thread overview]
Message-ID: <marc-lartc-102434115706092@msgid-missing> (raw)
In-Reply-To: <marc-lartc-102389248503844@msgid-missing>


	Hello,

On Mon, 17 Jun 2002, Leonardo Balliache wrote:

> This diagram, subject to discusion and improvement for more experimented
> people in the list to be depurated, can help to clarify things:
>
>
>                                    Network
>                            -----------+-----------
>                                       |
>                               +-------+------+
>                               |    mangle    |
>                               |  PREROUTING  |
>                               +-------+------+
>                                       |
>                               +-------+------+    Policy rule database
>                               |     PRDB     | <- controlled by ip rule
>                               +-------+------+
>                                       |
>                               +-------+------+
>                               |      nat     |
>                               |  PREROUTING  |
>                               +-------+------+
>                                       |
>                packet is for  +-------+------+ packet is for
>                this address   |   ROUTING    | another address
>                +--------------+  DECISION ?  +---------------+
>                |              +--------------+               |
>        +-------+------+                                      |
>        |    filter    |                                      |
>        |    INPUT     |                                      |
>        +-------+------+                                      |
>                |                                             |
>        +-------+------+                                      |
>        |    Local     |                                      |
>        |   Process    |                                      |
>        +-------+------+                                      |


	ROUTING


>                |                                             |
>        +-------+------+                               +------+------+
>        |    mangle    |                               |   filter    |
>        |    OUTPUT    |                               |   FORWARD   |
>        +-------+------+                               +------+------+
>                |                                             |
>        +-------+------+                                      |
>        |     nat      |                                      |
>        |    OUTPUT    |                                      |
>        +-------+------+                                      |
>                |                                             |
>        +-------+------+                                      |
>        |    filter    |                                      |
>        |    OUTPUT    |                                      |
>        +-------+------+                                      |
>                |              +--------------+               |
>                +--------------+   ROUTING    +---------------+
>                               |  DECISION ?  | <- controlled by ip route
>                               +-------+------+
>                                       |
>                               +-------+------+
>                               |     nat      |
>                               | POSTROUTING  |
>                               +-------+------+
>                                       |
>                               +-------+------+
>                               |   TRAFFIC    |
>                               |    QUEUE     | <- controlled by tc
>                               +-------+------+
>                                       |
>                            -----------+-----------
>                                    Network
>
>
> After all of us agree the diagram could be published at Stef site (with his
> permission, of course) to be have as a reference to people using the list.

	Where is the routing decision of the local process, before
OUTPUT? Or only I see it :) Also, there is a big difference between
input and output routing decision, may be this diagram can show it :)

> Best regards,
>
> Leonardo Balliache
> leoball@opalsoft.net

Regards

--
Julian Anastasov <ja@ssi.bg>

_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

  parent reply	other threads:[~2002-06-17 19:11 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-06-12 14:32 [LARTC] ipchains + mark in output chain ? Ludovic Drolez
2002-06-12 14:48 ` Stef Coene
2002-06-17 18:55 ` Leonardo Balliache
2002-06-17 19:11 ` Julian Anastasov [this message]
2002-06-17 19:20 ` Ciprian Niculescu
2002-06-17 19:31 ` Julian Anastasov
2002-06-17 19:42 ` Ciprian Niculescu
2002-06-17 20:35 ` Julian Anastasov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=marc-lartc-102434115706092@msgid-missing \
    --to=ja@ssi.bg \
    --cc=lartc@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox