Страница 24 из 111
Note that this time the packet was passed through the INPUT chain instead of the FORWARD chain. Quite logical. Most probably the only thing that's really logical about the traversing of tables and chains in your eyes in the begi
ing, but if you continue to think about it, you'll find it will get clearer in time.Now we look at the outgoing packets from our own local host and what steps they go through.
Table 6-2. Source local host (our own machine)
StepTableChainComment1 Local process/application (i.e., server/client program)2 Routing decision. What source address to use, what outgoing interface to use, and other necessary information that needs to be gathered.3rawOUTPUTThis is where you do work before the coection tracking has taken place for locally generated packets. You can mark coections so that they will not be tracked for example.4 The state machine5mangleOUTPUTThis is where we mangle packets, it is suggested that you do not filter in this chain since it can have side effects.6natOUTPUTThis chain can be used to NAT outgoing packets from the firewall itself.7 Routing decision, since the previous mangle and nat changes may have changed how the packet should be routed.8filterOUTPUTThis is where we filter packets going out from the local host.9manglePOSTROUTINGThe POSTROUTING chain in the mangle table is mainly used when we want to do mangling on packets before they leave our host, but after the actual routing decisions. This chain will be hit by both packets just traversing the firewall, as well as packets created by the firewall itself.10natPOSTROUTINGThis is where we do SNAT as described earlier. It is suggested that you don't do filtering here since it can have side effects, and certain packets might slip through even though you set a default policy of DROP.11 Goes out on some interface (e.g., eth0)12 On the wire (e.g., Internet)