• Linux Kernel Packet Traveling


                               Network
                        -----------+-----------
                                   |
                      +--------------------------+
              +-------+-------+        +---------+---------+
              |    IPCHAINS   |        |      IPTABLES     |
              |     INPUT     |        |     PREROUTING    |
              +-------+-------+        | +-------+-------+ |
                      |                | |   conntrack   | |
                      |                | +-------+-------+ |
                      |                | |    mangle     | | <- MARK WRITE  
                      |                | +-------+-------+ |
                      |                | |      IMQ      | |
                      |                | +-------+-------+ |
                      |                | |      nat      | | <- DEST REWRITE
                      |                | +-------+-------+ |     DNAT or REDIRECT or DE-MASQUERADE
                      |                +---------+---------+
                      +------------+-------------+
                                   |
                           +-------+-------+
                           |      QOS      |
                           |    INGRESS    |
                           +-------+-------+
                                   |
             packet is for +-------+-------+ packet is for
              this machine |     INPUT     | another address
            +--------------+    ROUTING    +--------------+
            |              |    + PDBB     |              |
            |              +---------------+              |
    +-------+-------+                                     |
    |   IPTABLES    |                                     |
    |     INPUT     |                                     |
    | +-----+-----+ |                                     |
    | |   mangle  | |                                     |
    | +-----+-----+ |                                     |
    | |   filter  | |                                     |
    | +-----+-----+ |                                     |
    +-------+-------+                                     |
            |                               +---------------------------+
    +-------+-------+                       |                           |
    |     Local     |               +-------+-------+           +-------+-------+
    |    Process    |               |    IPCHAINS   |           |    IPTABLES   |
    +-------+-------+               |    FORWARD    |           |    FORWARD    |
            |                       +-------+-------+           | +-----+-----+ |
    +-------+-------+                       |                   | |  mangle   | | <- MARK WRITE
    |    OUTPUT     |                       |                   | +-----+-----+ |
    |    ROUTING    |                       |                   | |  filter   | |
    +-------+-------+                       |                   | +-----+-----+ |
            |                               |                   +-------+-------+
    +-------+-------+                       |                           |
    |    IPTABLES   |                       +---------------------------+
    |     OUTPUT    |                                     |
    | +-----------+ |                                     |
    | | conntrack | |                                     |
    | +-----+-----+ |                                     |
    | |   mangle  | | <- MARK WRITE                       |
    | +-----+-----+ |                                     |
    | |    nat    | | <-DEST REWRITE                      |
    | +-----+-----+ |     DNAT or REDIRECT                |
    | |   filter  | |                                     |
    | +-----+-----+ |                                     |
    +-------+-------+                                     |
            |                                             |
            +----------------------+----------------------+
                                   |
                      +------------+------------+
                      |                         |
              +-------+-------+       +---------+---------+
              |    IPCHAINS   |       |      IPTABLES     |
              |     OUTPUT    |       |    POSTROUTING    |
              +-------+-------        | +-------+-------+ |
                      |               | |    mangle     | | <- MARK WRITE  
                      |               | +-------+-------+ |
                      |               | |      nat      | | <- SOURCE REWRITE
                      |               | +-------+-------+ |      SNAT or MASQUERADE
                      |               | |      IMQ      | |
                      |               | +-------+-------+ |
                      |               +---------+---------+
                      +------------+------------+
                                   |
                            +------+------+
                            |     QOS     |
                            |    EGRESS   |
                            +------+------+
                                   |
                        -----------+-----------
                                Network
  • 相关阅读:
    在弹出窗口中显示带checkbox的
    列属性设定-隐藏列
    Aggregations应用-合计(total)、小计(subtotal)、平均值(average)
    排序(sort)、小计(subtotal)
    过滤器(filter)
    显示图标(ICON)和提示信息(Tooltips)
    单元格style应用-按钮、热点(hotspot)、checkbox等
    布局列分组
    图床-1
    q-1
  • 原文地址:https://www.cnblogs.com/sixloop/p/linux_packet_travel.html
Copyright © 2020-2023  润新知