What is netfilter/iptables?

发表于:2007-06-09来源:作者:点击数: 标签:
What is .net filter/iptables? netfilter and iptables are building blocks of a framework inside the Linux 2.4.x and 2.6.x kernel. Thisframework enables packet filtering, network address [and port] translation(NA[P]T) and other packet mangli

What is.netfilter/iptables?

netfilter and iptables are building blocks of a framework inside the Linux 2.4.x and 2.6.x kernel. This framework enables packet filtering, network address [and port] translation (NA[P]T) and other packet mangling. It is the re-designed and heavily improved suclearcase/" target="_blank" >ccessor of the previous Linux 2.2.x ipchains and Linux 2.0.x ipfwadm systems.

netfilter is a set of hooks inside the Linux kernel that allows kernel modules to register callback functions with the network stack. A registered callback function is then called back for every packet that traverses the respective hook within the network stack.

iptables is a generic table structure for the definition of rulesets. Each rule within an IP table consists of a number of classifiers (iptables matches) and one connected action (iptables target).

netfilter, iptables and the connection tracking as well as the NAT subsystem together build the whole framework.

Main Features

原文转自:http://www.ltesting.net