"Firewall" firewall classification, filtering process

Source: Internet
Author: User

First, what's the firewall doing?

Anti-attack, optimize routing table, optimize network card delivery, filtering strategy

Second, the firewall classification

Four layers: Network layer firewall, faster-"packet filter Firewall seven layer: Proxy layer Gateway Firewall, more secure, less efficient-" service firewall products of the two combined four, firewall Workflow 4. 1 packet Filter Firewall working principle 4.2 The service firewall works on the application layer to implement the firewall function. It provides a partial transport-related state, provides full application-related state and partial transmission of information, and can process and manage information. The following is the data transfer process for the input and output in the server the following is Iptables table, chain, rule relationship four, proxy-type firewall Key Technology 3.1 NAT source Destination address translation is the abbreviation of Network address translation, this form is mainly for the source and purpose of I The conversion of P or port is more unrelated to Linux native, and is more relevant to computers in the local area network after the Linux host.
    • Prerouting: Rules to be performed before routing is determined (dnat/redirect)
    • Postrouting: Rules to be made after routing is determined (Snat/masquerade)
    • OUTPUT: Related to packets sent out
3.2 Filter IP filtering, in forward
    • INPUT: Mainly related to the packet that wants to enter our Linux native;
    • OUTPUT: Mainly related to our Linux native to send out the packet;
    • FORWARD: This is not related to Linux native, he can "forward the packet" to the back end of the computer, with the following NAT table correlation is higher.
3.3 Mangle Modifying the contents of a packet this table is primarily related to the routing flags for special packets, with only the prerouting and OUTPUT chains in the early stages, but the INPUT and 2.4.18 chains were added after the kernel FORWARD. Since this table is highly correlated with special flags, it is less likely to use the Mangle form in a simple environment like ours. V. References http://blog.chinaunix.net/uid-26495963-id-3279216.html http://www.linuxso.com/linuxpeixun/10332.html

"Firewall" firewall classification, filtering process

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.