[arch-general] iptables forward policy

Bastian Beischer bastian.beischer at rwth-aachen.de
Sun Aug 26 13:16:07 EDT 2012


Dear Juan,

see the section on logging in the wiki:

https://wiki.archlinux.org/index.php/Iptables#Logging

Cheers
Bastian

On Sun, Aug 26, 2012 at 7:11 PM, Juan Diego Tascón <juantascon at gmail.com> wrote:
> Thanks for both replies. The graphic does it a lot more
> understandable. Is there any way to debug iptables, I mean, like a
> tool where I can visualize the path of a packet and where exactly it
> gets dropped/accepted and also realtime packets headers (src, dst,
> proto, dport, sport, etc)?
>
> On Sat, Aug 25, 2012 at 12:56 PM, Corrado Primier <ilbardo at gmail.com> wrote:
>> 2012/8/25 Juan Diego Tascón <juantascon at gmail.com>:
>>> Good day,
>>
>> Hello :)
>>
>>> I'm thinking of
>>> setting the default FORWARD policy to ACCEPT as my default INPUT
>>> policy is DROP and unless there is a valid FORWARD rule for a given
>>> port the packets wont go anywhere. I'm I right on this?
>>
>> You're wrong. Either a packet goes through the INPUT chain or it goes
>> through the FORWARD chain, depending on its destination. Take a look
>> at this packet flow diagram:
>> http://www.linuxhomenetworking.com/wiki/images/f/f0/Iptables.gif
>>
>> Corrado



-- 
Bastian Beischer
RWTH Aachen University of Technology

@CERN
Office: Bdg 32-4-B12
Phone: +41-22-76-75750
E-mail: bastian.beischer at cern.ch
Address: CERN, CH-1211 Geneve 23

@RWTH Aachen
Office: 28 C 203
Phone: +49-241-80-27205
E-mail: beischer at physik.rwth-aachen.de
Address: I. Physikalisches Institut B, Sommerfeldstr. 14, D-52074 Aachen


More information about the arch-general mailing list