Figure 14-1 Iptables Packet Flow Diagram
You need to specify the table and the chain for each firewall rule you create.
There is an exception: Most rules are related to filtering, so iptables assumes that any
chain that’s defined without an associated table will be a part of the filter table.
The filter table is therefore the default.
To help make this clearer, take a look at the way packets are handled by iptables.
In Figure 14.1 a TCP packet from the Internet arrives at the firewall’s interface
on Network A to create a data connection.
The packet is first examined by your rules in the mangle table’s PREROUTING chain,
if any. It is then inspected by the rules in the nat table’s PREROUTING chain to see
whether the packet requires DNAT.
It is then routed.
If the packet is destined for a protected network, then it is filtered by the rules in the
FORWARD chain of the filter table and, if necessary, the packet undergoes SNAT in the
POSTROUTING chain before arriving at Network B. When the destination server
decides to reply, the packet undergoes the same sequence of steps.
Both the FORWARD and POSTROUTING chains may be configured to implement
quality of service (QoS) features. in their mangle tables, but this is not usually done
in SOHO environments.
If the packet is destined for the firewall itself, then it passes through the
mangle table of the INPUT chain, if configured, before being filtered by the rules in
the INPUT chain of the filter table before. If it successfully passes these tests then it is
processed by the intended application on the firewall.
At some point, the firewall needs to reply. This reply is routed and inspected by the
rules in the OUTPUT chain of the mangle table, if any. Next, the rules in the OUTPUT
chain of the nat table determine whether DNAT is required and the rules in the OUTPUT
chain of the filter table are then inspected to help restrict unauthorized packets.
Finally, before the packet is sent back to the Internet, SNAT and QoS mangling is done
by the POSTROUTING chain
Table 14-1 Processing For Packets Routed By The Firewall
| Queue Type | Queue Function | Packet Transformation Chain in Queue | Chain Function |
|---|---|---|---|
| Filter | Packet filtering |
FORWARD
|
Filters packets to servers accessible by another NIC on the firewall. |
INPUT
|
Filters packets destined to the firewall. |
||
OUTPUT
|
Filters packets originating from the firewall. |
||
| Nat | Network Address Translation |
PREROUTING
|
Address translation occurs before routing. Facilitates the transformation of the destination IP address to be compatible with the firewall’s routing table. Used with NAT of the destination IP address, also known as destination NAT or DNAT. |
POSTROUTING
|
Address translation occurs after routing. This implies that there was no need to modify the destination IP address of the packet as in pre-routing. Used with NAT of the source IP address using either one-to-one or many-to-one NAT. This is known as source NAT, or SNAT. |
||
OUTPUT
|
Network address translation for packets generated by the firewall. (Rarely used in SOHO environments) |
||
| Mangle | TCP header modification |
PREROUTING
POSTROUTING
OUTPUT
INPUT
FORWARD
|
Modification of the TCP packet quality of service bits before routing occurs. (Rarely used in SOHO environments) |

Comments
(There are currently no comments for this post.)