Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Jörg Harmuth" <harmuth@mnemon.de>
To: netfilter@lists.netfilter.org
Subject: Re: NAT tables and FILTER tables
Date: Wed, 14 Sep 2005 14:03:58 +0200	[thread overview]
Message-ID: <432811AE.6010604@mnemon.de> (raw)
In-Reply-To: <43280926.5090508@india.tejasnetworks.com>

Aseem Rastogi wrote:
> in continuation:
> 
> i am actually trying to understand how nat and default filter table work 
> together. my understanding is this:
> 
> when a packet is encountered it is either:
> 
> 1. a new connection creation request packet.
> 
> 2. a packet associated with a connection that has been mangled by NAT 
> earlier.
> 
> 3. a packet assiciated with a connection that has not been mangled by 
> NAT earlier.

Not really. Each packet is one of:

-> NEW packet with SYN set
-> NEW packet without SYN set
-> Part of a connection which has seen at least the SYN packet

Basically, a NEW packet means, that there is no entry in the conntrack 
table.

> Each case goes like this:
> 
> Case 1: NAT table is considerd. Packet passes through PREROUTING chain, 
> routing decision and then POSTROUTING chain.

No. Then filter/INPUT or filter/FORWARD - always.

> Case 1a -- If either of them modified the packet, this packet and all 
> subsequent packets of this connection DO NOT PASS THROUGH FILTER TABLE 
> CHAINS.
> 
> Case 1b -- None of NAT tables modifies packet. It passes through FILTER 
> table chains as usual.

No. See above.

> Case 2: This packet follows the fate of its earlier packets. (PREROUTING 
> AND POSTROUTING NAT table chains BUT NO FILTER table chains)
> 
> Case 3. Passes through FILTER TABLE chains.
> 
> is this correct??

No. It is almost vice-versa. Only NEW packet pass nat table, but all 
packets pass filter table.

If you apply NAT to the first packet, these subsequent packet will be 
NATed automagically, so - in your words - they follow the fate of their 
earlier packet concerning NAT.

HTH and have a nice time,

Joerg

PS: May I recommend Oskar Andreasson's excellent iptables tutorial at 
http://iptables-tutorial.frozentux.net/chunkyhtml/index.html ?

> Aseem Rastogi wrote:
> 
>> Hi,
>>
>> I have a small query.
>>
>> I have read that whenever a packet requesting a connection is 
>> encountered, NAT table is used. My question is : Does it mean that for 
>> new connection request packets ONLY NAT table is considered and not 
>> default FILTER table?



  reply	other threads:[~2005-09-14 12:03 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-09-14 11:07 NAT tables and FILTER tables Aseem Rastogi
2005-09-14 11:27 ` Aseem Rastogi
2005-09-14 12:03   ` Jörg Harmuth [this message]
2005-09-14 12:21     ` Aseem Rastogi
2005-09-14 11:35 ` Rob Sterenborg
2005-09-14 13:13   ` /dev/rob0

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=432811AE.6010604@mnemon.de \
    --to=harmuth@mnemon.de \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox