Linux Netfilter discussions
 help / color / mirror / Atom feed
* Hello .. Packet path :)
@ 2003-12-03 15:30 Michael Gale
  2003-12-03 16:46 ` Ramin Dousti
  0 siblings, 1 reply; 3+ messages in thread
From: Michael Gale @ 2003-12-03 15:30 UTC (permalink / raw)
  To: netfilter

Hello,

	I am trying to make a packet go through the least amount of chains / tables as possible for performance.

I have read through the online documentation about netfilter and this "Linux Firewalls Second Edition" book (which was ok). 

But I still have some questions about the order in which the tables are checked. Here is what I think happens when a pack comes in and should be forwarded to a internal machine

Firewall External interface:
Packet comes in:
NAT table PREROUTING 
NAT talbe OUTPUT
NAT table POSTROUTING
filter table INPUT
filter table OUTPUT or forward

Then you would have the same thing when the packet leaves the internal interface.

Of course this is if you break it down by interface first.

Please let me know if this is correct ?

-- 
Michael Gale
Network Administrator
Utilitran Corporation


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2003-12-03 16:46 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-03 15:30 Hello .. Packet path :) Michael Gale
2003-12-03 16:46 ` Ramin Dousti
2003-12-03 15:49   ` Michael Gale

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox